EU AI Act · Regulation (EU) 2024/1689
01 / 06

The law doesn't ask whether you use AI.
It asks whether you can prove it.

As of August 2, 2026, the regulation applies throughout the European Union. This page summarizes its requirements and when they apply, and allows you to classify your own system using the same eleven questions that the platform uses. No registration or data submission required.

Written for senior management and the legal department. Free of unnecessary technical jargon.

Schedule and Penalties
02 / 06
Dec. 2
2027

Deadline for high-risk systems listed in Annex III, following the extension provided for in the AI Omnibus (effective July 27, 2026).

Feb. 2, 2025Prohibited practices (Art. 5) and AI literacy (Art. 4). Now subject to penalties.
Aug. 2, 2025General-purpose AI models: provider obligations and EU governance.
Aug. 2, 2026General application: Article 50 transparency and the penalty regime.
Dec. 2026New prohibited practice: systems that generate non-consensual sexual or intimate content, or child sexual abuse material.
Dec. 2, 2027High-risk systems listed in Annex III: employment, credit, insurance, education, critical infrastructure, and public administration.
Aug. 2, 2028High risk under Annex I: AI embedded in products already subject to regulation (machinery, medical devices, vehicles).
€35 million

or 7% of worldwide annual turnover, for prohibited practices.

€15 million

or 3% of worldwide annual turnover, for failing to comply with high-risk obligations.

Art. 26

These obligations apply to whoever deploys the system, not just whoever develops it.

Dates under Regulation (EU) 2024/1689, as amended by the AI Omnibus. Source: European Commission.

Four risk levels
03 / 06

The regulation does not regulate “AI” per se. It regulates specific uses based on the harm they may cause.

The more a system affects people's lives, the more the law requires. Most business applications involve minimal or limited risk. Decisions regarding credit, employment, insurance, or public services are high-risk, and that is where evidence is needed.

Unacceptable

Prohibited practices under Article 5. These may not be marketed or used in the EU.

High

Annex III and safety components. Risk management, documentation, record-keeping, human supervision, and conformity assessment.

Limited

Chatbots, generated content, emotion recognition. Transparency requirements under Article 50.

Minimal

The rest. No specific obligations beyond AI literacy and voluntary best practices.

Guideline Classifier
04 / 06

What level is
's system?

Eleven questions. The risk level, reasons and obligations update as you answer. It follows the same logic as the initial assessment at V-PROOF; the result is for guidance only and does not replace a formal assessment.

01
Does the system engage in any practices prohibited under Article 5?

Subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing based solely on profiling, emotion recognition in the workplace or in educational institutions, biometric categorization of sensitive attributes, and real-time remote biometric identification in public spaces. Starting in December 2026, this will also include the generation of non-consensual sexual or intimate content.

02
Is it used in any of the high-risk areas listed in Annex III?
03
Is it a safety component of a product covered by EU harmonization legislation?

Machinery, medical devices, vehicles, toys, elevators…

04
Does it make, or substantially influence, decisions that have legal consequences for individuals or that affect them in a similar way?

Hiring, credit, benefits, medical triage, qualifications, access to services.

05
Does it interact directly with people?

A chatbot, an assistant.

06
Does it generate synthetic content (text, images, audio or video)?
07
Does it recognize emotions or perform biometric classification?
08
What data does it process?
09
How much autonomy does it have?
10
Is the model or service provided by a third party?
11
Does it affect minors or vulnerable groups?
Classification
Answer to classify
Reasons
  • They will appear here as you answer.
Obligations That Are Triggered
  • They will appear here as you answer.
Register this system with supporting evidence

For reference only. None of the information you enter leaves your browser. The formal classification is determined by the platform’s initial evaluation and is recorded with an attestation.

What is required, and how to prove it
05 / 06

Each article makes a specific request. Each one leaves specific evidence.

For a high-risk system, these are the main obligations and the proof that V-PROOF generates for each one. What is recorded is the cryptographic fingerprint of the event, never the data itself.

ArticleObligationHow it is demonstrated
Art. 9Lifecycle Risk Management SystemRecord of inherent and residual risks, including mitigation measures
Art. 10governance: training, validation and test setsData assets: legal basis and retention periods
Art. 11Technical DocumentationSystem profile and sealed evidence
Art. 12Event Log During OperationAudit log with no way to delete
Art. 14Human OversightHuman Validation and Approvals with Attestation
Art. 26Deployer obligationsInventory with a designated owner and initial assessment
Art. 27Fundamental Rights Impact AssessmentSealed evidence and approval status
Art. 50Transparency of Generated ContentV-Seal® and watermark showing the human/AI ratio
Art. 73Notification of Serious IncidentsAlerts, Incidents with Root Causes, and Remediation

A general overview of the regulations. This does not constitute legal advice; specific application depends on each system and its formal evaluation.

A high-risk case
06 / 06

An assistant that screens CVs. How it is governed, step by step.

Learn how an organization registers the system, classifies it as high risk (Annex III, employment), obtains approval with human oversight, and and produces its first third-party-verifiable evidence.

December 2027 will be here sooner than you think.
Start by finding out what systems you have.