Implementation reference ยท Last updated 5 July 2026
EU AI Act compliance matrix
A structured mapping of specific AI Act articles to the concrete actions required per risk tier, with the applicable deadline. Use it as a working reference alongside your inventory and compliance checklist.
| Article | Topic | Applies to | Required action | Deadline |
|---|---|---|---|---|
| Art. 5 | Prohibited practices | Prohibited | Withdraw or block any use of social scoring, untargeted facial-image scraping, emotion recognition at work/school, biometric categorisation by sensitive traits, or manipulative/exploitative AI. | In force since 2 Feb 2025 |
| Art. 4 | AI competency | All providers/deployers | Take appropriate measures so staff who operate or oversee AI build up adequate AI competency - role-specific and refreshed as tools change. | In force since 2 Aug 2026 |
| Art. 50 | Transparency to users | Limited (transparency) | Inform users when they interact with AI (chatbots), and clearly mark AI-generated or manipulated content (including deepfakes). Marking grace period for pre-existing generative systems ends 2 Dec 2026. | In force since 2 Aug 2026 |
| Art. 9 | Risk management system | High-risk | Establish, document and maintain a lifecycle risk management process - identification, evaluation, mitigation, residual-risk review. | 2 Dec 2027 (Annex III) ยท 2 Aug 2028 (Annex I) |
| Art. 10 | Data & data governance | High-risk | Ensure training, validation and test data are relevant, representative, and checked for bias; document data provenance and preparation. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 11 + Annex IV | Technical documentation | High-risk | Maintain Annex IV technical file - system description, design choices, datasets, metrics, risk controls, post-market plan. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 12 | Automatic logging | High-risk | Enable and retain automatic event logs sufficient to trace system behaviour and identify risks throughout the lifecycle. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 13 | Transparency to deployers | High-risk | Provide deployers with clear instructions for use: capabilities, limitations, expected accuracy, oversight measures, maintenance. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 14 | Human oversight | High-risk | Design and validate oversight measures so a human can understand, monitor, intervene in, or stop the system. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 15 | Accuracy, robustness, cybersecurity | High-risk | Meet appropriate levels of accuracy, robustness, and cybersecurity; document metrics and testing. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 16โ17 | Quality management system | High-risk (providers) | Operate a quality management system covering compliance strategy, design controls, testing, incident handling, and supplier management. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 26 | Deployer obligations | High-risk (deployers) | Use the system per instructions, assign qualified human oversight, monitor operation, log use, inform affected persons where required. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 27 | Fundamental rights impact assessment (FRIA) | High-risk (public bodies & specified deployers) | Complete and keep updated a FRIA before deploying the high-risk system; notify the market surveillance authority. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 43 | Conformity assessment | High-risk (providers) | Complete the applicable conformity assessment procedure and issue an EU declaration of conformity before placing on the market. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 49 | EU database registration | High-risk | Register the system (or its use, for deployers required to register) in the EU database before placing on the market or putting into service. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 72 | Post-market monitoring | High-risk (providers) | Actively and systematically collect and review data on system performance in the field; feed findings back into risk management. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 73 | Serious incident reporting | High-risk (providers) | Report serious incidents to the competent market surveillance authority within the required timeframe. | 2 Dec 2027 / 2 Aug 2028 |
| Art. 53 | GPAI model obligations | GPAI | Publish technical documentation, information for downstream providers, copyright policy, and a summary of training content. | In force since 2 Aug 2025 (existing models: 2 Aug 2027) |
| Art. 55 | GPAI with systemic risk | GPAI (systemic) | Perform model evaluation and adversarial testing, assess and mitigate systemic risks, ensure cybersecurity, report serious incidents. | In force since 2 Aug 2025 |
Dates reflect Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026): Article 50 transparency and Article 4 AI competency have applied since 2 August 2026; high-risk obligations under Annex III apply from 2 December 2027 and Annex I from 2 August 2028. GPAI obligations under Article 53 already apply to new models placed on the market after 2 August 2025.
Not sure which rows apply to you?
Answer a few questions and get a matrix filtered to your AI use - with the specific articles, actions, and deadlines that apply to your company.
Start free assessment