Skip to main content
    Pritect

    Regulation

    EU AI Act
    From legal text to evidence

    The EU Artificial Intelligence Act is the first horizontal law governing artificial intelligence. It sorts AI systems by the risk they pose, bans a short list of practices outright, and puts detailed duties on the organisations that build high-risk systems and on the organisations that deploy them.

    Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending certain Union legislative acts (Artificial Intelligence Act)

    CELEX
    32024R1689
    Official Journal
    OJ L, 2024/1689, 12.7.2024
    Articles
    113
    Jurisdiction
    🇪🇺 Europe
    Status
    In force
    Read the text on EUR-Lex

    From the Official Journal to a tracked obligation

    Three stages, and the legal text is not rewritten at any of them.

    1. 01

      The article

      The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.

    2. 02

      The clause

      Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.

    3. 03

      Your obligation

      You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.

    Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.

    Key dates

    Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.

    1. 13 Jun 2024

      Adopted by the Parliament and the Council

    2. 12 Jul 2024

      Published in the Official Journal

    3. 1 Aug 2024

      Entered into force

      Art. 113

    4. 2 Aug 2026

      General application begins

      Art. 113

    The articles that create work

    The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.

    113
    Articles
    16
    Tracked

    The regulation runs to 113 articles. Pritect decomposes 16 of them clause by clause into obligations you can adopt, own and evidence: the requirements that attach to a high-risk AI system, the duties that fall on the provider that builds one and on the organisation that deploys it, and the transparency duties that apply whether or not a system is high risk. The rest are deliberately not decomposed, because they are not duties you discharge. Articles 1 to 8 set the subject matter, scope, definitions, prohibited practices and the high-risk classification rules, Articles 22 to 24 address authorised representatives, importers and distributors, Articles 28 to 49 govern notifying authorities, notified bodies, standards and conformity assessment, Articles 51 to 56 cover general-purpose AI models, Articles 57 to 72 cover innovation measures, governance, the EU database and post-market monitoring, and Articles 74 to 113 govern market surveillance, remedies, penalties and the final provisions. Article 15 and Article 73 are catalogued at clause level but sit outside the article list the AI governance review confirmed for this hub, so they are not listed here. The set grows as the catalogue is extended.

    Requirements for high-risk systems

    Chapter III, Section 2, Art. 9 to 14

    • Art. 9Risk management system
    • Art. 10Data and data governance
    • Art. 11Technical documentation
    • Art. 12Record-keeping
    • Art. 13Transparency and provision of information to deployers
    • Art. 14Human oversight

    Obligations of providers and deployers

    Chapter III, Section 3, Art. 16 to 27

    • Art. 16Obligations of providers of high-risk AI systems
    • Art. 17Quality management system
    • Art. 18Documentation keeping
    • Art. 19Automatically generated logs
    • Art. 20Corrective actions and duty of information
    • Art. 21Cooperation with competent authorities
    • Art. 25Responsibilities along the AI value chain
    • Art. 26Obligations of deployers of high-risk AI systems
    • Art. 27Fundamental rights impact assessment for high-risk AI systems

    Transparency obligations

    Chapter IV, Art. 50

    • Art. 50Transparency obligations for providers and deployers of certain AI systems

    Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.

    Common questions

    The questions teams ask first, answered plainly.

    Which AI systems count as high risk?
    Article 6 sets the classification rules. A system is high risk where it is a safety component of a product covered by other Union law, or where it falls in one of the areas listed in Annex III, such as employment, education, essential services, law enforcement and migration. Pritect records the classification and the reasoning behind it against each system.
    Are we a provider or a deployer?
    The Act puts different duties on each. A provider develops a system, or has one developed, and places it on the market under its own name. A deployer uses a system under its own authority. Putting your own name on a system you bought can make you a provider under Article 25, which is why Pritect asks the question per system rather than per organisation.
    Do we need a fundamental rights impact assessment?
    Article 27 requires one from deployers that are public bodies or that provide public services, and from deployers of certain creditworthiness and insurance pricing systems, before a high-risk system is put into use. Pritect runs the screening and keeps the assessment attached to the system it belongs to.
    When do the obligations start to apply?
    Article 113 staggers commencement. The general date of application is the one shown in the timeline above, with the prohibited practices and the general provisions applying earlier, and the rules for high-risk systems that are safety components of regulated products applying later. Pritect tracks which date governs each system you have recorded.
    What has to be disclosed to people?
    Article 50 requires that people are told when they are interacting with an AI system, that synthetic audio, image, video and text is marked as artificially generated, and that emotion recognition and biometric categorisation are disclosed to the people exposed to them. These duties apply whether or not the system is high risk.

    This page summarises publicly available legal text so you can orient yourself. It is not legal advice.

    See it against your own records

    Bring one processing activity, one supplier and one open request. We will show you where each of them lands.