A short, opinionated summary of Regulation (EU) 2024/1689. Not legal advice. For the
full text, see the Official Journal.
A more detailed walk is on the EU AI Act hub.
Chapter III — high-risk AI systems (Article 6 onwards, Annex III). Strict requirements on data, documentation, transparency, human oversight, accuracy, robustness, cybersecurity.
Chapter IV — transparency obligations for providers and deployers of certain AI systems (Article 50). Limited-risk class.
Unacceptable risk — Article 5 prohibited practices. Social scoring, real-time biometric identification in public spaces (limited exceptions), untargeted facial scraping, predictive policing on profiling alone, emotion inference in the workplace, biometric categorisation inferring sensitive attributes.
High risk — Annex III systems + safety components under Article 6(1). 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.
Minimal risk — no specific obligations. Voluntary codes of conduct encouraged.
Article 50 (the one most users feel)
Article 50 covers limited-risk AI systems that interact with people, generate
or manipulate content, or read emotions / biometrics. The obligations are:
Art 50(1) — chatbot disclosure. Users must know they're talking to an AI.
Art 50(2) — synthetic content marking in a machine-readable way.
Art 50(3) — deepfake disclosure.
Art 50(4) — synthetic text published to inform the public must be marked.
Art 50(5) — biometric / emotion inference disclosure.
Fines: up to 3% of global annual turnover or €15M, whichever is higher.
Conformity routes
Article 43 internal-control — most Annex III systems can self-assess. The Article 43 route requires credible self-assessment evidence (frozen harness, deterministic execution, signed artefacts, corpus-watch). See Article 43, with evidence.
Notified body — for some Annex III systems and Article 6(1) safety components, third-party assessment by a notified body is required. CSOAI is not a notified body.
Dates
Entered force: 1 August 2024.
Article 5 prohibited practices: 2 February 2025.
General-purpose AI obligations: 2 August 2025.
Most obligations (including high-risk, Article 50): 2 August 2026.
Embedded high-risk systems in regulated products: 2 August 2027.