The Act tiers obligations by risk: prohibited practices (such as social scoring and most real-time biometric identification in public); high-risk systems requiring risk management, data governance, human oversight, and conformity assessment; transparency duties for systems like chatbots and synthetic content; and lighter rules for minimal-risk uses. Obligations phase in from 2025 onward, with separate duties for providers, deployers, and general-purpose AI model makers.
Key points
Use-based classificationThe same model can be minimal-risk in one use and high-risk in another — obligations follow the system’s use, not the technology label.
Phased applicationBans and general-purpose AI duties came first; high-risk system obligations follow later — the applicable dates depend on the organization’s role as provider or deployer.
Important limitationThe AI Act regulates AI systems and their market placement, not general cybersecurity. It interacts with GDPR, DORA, the CRA, and sector rules — compliance with one does not satisfy the others, and much of the practical detail still depends on harmonized standards and guidance.