At a glance
This is the heaviest-weighted competency in Domain II, and the EU AI Act — Regulation (EU) 2024/1689 — is its centre of gravity. The Act is built on two organising ideas you must hold at once:
- A risk-tier pyramid — obligations scale with risk (prohibited → high → limited → minimal). (II.C.1)
- A role matrix — who you are (provider, deployer, importer, distributor) determines which obligations you carry. (II.C.6)
Layered on top are the substantive requirements (II.C.2–II.C.3), the separate GPAI model regime (II.C.4), and enforcement/penalties (II.C.5). You should also be able to contrast the EU’s comprehensive risk-based model with the South Korean AI Basic Act and the Colorado AI Act.
II.C.1 — Risk classification framework
| Tier | What it is | Representative examples | Obligation |
|---|---|---|---|
| Unacceptable / Prohibited (Art. 5) | Uses deemed a clear threat to rights | Government social scoring; manipulative or exploitative systems; untargeted scraping of facial images; emotion recognition in workplace/education; most real-time remote biometric ID in public by law enforcement | Banned |
| High-risk (Arts. 6, Annex III) | Significant risk to health, safety, fundamental rights | AI in employment/hiring, credit/lending, education, essential services, biometric ID, critical infrastructure, law enforcement, migration; safety components of regulated products | Full requirements + conformity assessment |
| Limited / Transparency risk | Interacts with or generates content for people | Chatbots, deepfakes / synthetic media, AI-generated content | Disclosure/labelling duties only |
| Minimal risk | Everything else | Spam filters, AI in video games, inventory optimisation | No mandatory obligations (voluntary codes) |
II.C.2 — Risk management, data governance, documentation, conformity, records
For high-risk systems, providers must establish (Arts. 9–18):
- Risk management system — a continuous, iterative process across the lifecycle to identify, evaluate and mitigate risks (Art. 9).
- Data and data governance — training/validation/test data must be relevant, representative and, as far as possible, error-free and complete; examine for bias (Art. 10).
- Technical documentation — drawn up before market and kept up to date, demonstrating compliance (Art. 11, Annex IV).
- Record keeping / logging — automatic logs for traceability over the system’s lifetime (Art. 12).
- Accuracy, robustness and cybersecurity — appropriate levels declared and maintained (Art. 15).
- Conformity assessment + CE marking + registration — verify conformity (often self-assessment), affix CE marking, register in the EU database before placing on the market.
Certain deployers must also perform a Fundamental Rights Impact Assessment (FRIA, Art. 27) before putting a high-risk system into use (notably public bodies and some private actors).
II.C.3 — Human oversight, transparency and quality management
- Human oversight (Art. 14) — high-risk systems must be designed so humans can effectively oversee them: understand outputs, intervene, override, and use a “stop” function. Includes guarding against automation bias (over-trusting the machine).
- Transparency to deployers (Art. 13) — high-risk systems ship with instructions for use so deployers can operate them properly.
- Transparency to people (Art. 50) — the limited-risk layer: tell people when they interact with AI (chatbots), label deepfakes / synthetic media and AI-generated text on matters of public interest, and disclose emotion-recognition/biometric-categorisation use.
- Quality management system (Art. 17) — providers of high-risk AI must operate a documented QMS covering compliance strategy, design, testing, data management and post-market monitoring.
II.C.4 — General-purpose AI (GPAI) models
The Act regulates GPAI models separately from AI systems. All GPAI providers must:
- Maintain technical documentation and information for downstream providers.
- Put in place a policy to respect EU copyright (including TDM opt-outs).
- Publish a sufficiently detailed summary of training content.
A GPAI model with systemic risk carries extra duties. Systemic risk is presumed where cumulative training compute exceeds 10^25 FLOPs (or by Commission designation). Those providers must additionally: perform model evaluations and adversarial testing (red-teaming), assess and mitigate systemic risks, report serious incidents, and ensure adequate cybersecurity.
II.C.5 — Enforcement and penalties
Enforcement runs through national market-surveillance authorities and, for GPAI, the European AI Office. Fines are tiered to the severity of the breach (whichever is higher of a euro amount or a percentage of global annual turnover):
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Art. 5) | €35M or 7% of global turnover |
| Most other obligations (high-risk, transparency, GPAI duties) | €15M or 3% |
| Supplying incorrect/misleading information to authorities | €7.5M or 1% |
Phased application (from entry into force, 1 Aug 2024): prohibitions apply from Feb 2025; GPAI obligations from Aug 2025; most high-risk obligations from Aug 2026; high-risk systems that are safety components of regulated products from Aug 2027.
Watch item: the Commission has floated “simplification” / digital-omnibus proposals that could adjust some AI Act timelines and duties. Learn the dates above as enacted, and check for adopted amendments close to your exam date — but expect the exam to test the enacted framework, not pending proposals.
II.C.6 — Role-based obligations
The Act assigns duties by operator role. The same organisation can hold several roles, and a deployer can become a provider (inheriting heavier duties) if it puts its name on a high-risk system or substantially modifies one.
| Role | Definition | Core obligations (high-risk) |
|---|---|---|
| Provider | Develops the system/model and places it on the market under its own name | The full set: risk management, data governance, documentation, conformity assessment, CE marking, registration, QMS, post-market monitoring |
| Deployer | Uses the system under its own authority (professional use) | Use per instructions, ensure human oversight, monitor operation, ensure input data relevance, keep logs, inform affected persons, FRIA where required |
| Importer | Places a non-EU provider’s system on the EU market | Verify the provider did conformity assessment, documentation and CE marking before import |
| Distributor | Makes a system available in the chain (not provider/importer) | Check CE marking and documentation; do not supply non-conforming systems |
| Authorized representative | EU-established agent appointed in writing by a non-EU provider (Art. 22) | Verify conformity documentation exists, keep it available for authorities, cooperate with regulators — the provider’s mandatory EU point of contact |
Territorial scope — who is caught
Like the GDPR, the AI Act reaches beyond the EU’s borders (Art. 2). It applies to:
- Providers placing systems on the EU market or putting them into service in the EU — wherever the provider is established;
- Deployers established or located in the EU; and
- Providers and deployers in third countries where the output of the system is used in the EU.
So a US company with no EU office is still in scope if its AI system’s output is used in the Union. Conversely, an EU company’s system built and used entirely outside the EU (no EU market placement, no EU output use) is not caught.
The wider landscape: US states, China and other regimes
US state laws cluster into four models — recognising which model a statute follows is more useful than memorising every state:
| Model | What it regulates | Examples |
|---|---|---|
| Consequential-decision | Algorithmic discrimination in high-stakes decisions (employment, credit, housing, healthcare) | Colorado AI Act; Illinois’ employment-AI amendments |
| Frontier-model safety | The largest foundation models: safety frameworks, incident reporting, whistleblower protection | California SB 53 (frontier AI transparency) |
| Transparency / disclosure | Documentation of training data and AI-generated content | California AB 2013 (training-data transparency) |
| Interaction / chatbot | Telling people they’re dealing with an AI | Utah AI Policy Act; chatbot-disclosure laws |
China regulates by application, iteratively — three key instruments: algorithm-recommendation provisions (2022), deep-synthesis rules (2023, mandatory labeling of synthetic media), and the Interim Measures for Generative AI Services (2023 — content moderation, training-data legality, labeling duties for public-facing GenAI). Distinctive features: algorithm registration/filing with the regulator and content-alignment requirements.
Other approaches worth one line each: the UK has no horizontal AI statute — existing regulators apply five cross-sector principles (pro-innovation, principles-based). Canada’s federal AIDA bill died with prorogation in early 2025, leaving provincial/privacy law to do the work. Japan follows a light-touch, soft-law-first promotion approach. The spectrum runs: EU (comprehensive, product-safety style) → South Korea (comprehensive but lighter) → China (application-specific, state-led) → UK/Japan (principles/soft law) → US (sectoral + state patchwork).
Contrast: South Korea and Colorado
South Korean AI Basic Act (Asia’s first comprehensive AI law; effective Jan 2026). Like the EU, it is risk-tinged and horizontal, but lighter-touch:
- Special duties for “high-impact” AI (areas like healthcare, energy, public services) — risk management, human oversight, user protection.
- Generative-AI transparency — label/notify users of AI-generated content.
- A domestic representative requirement for large foreign providers above thresholds.
Colorado AI Act (SB 24-205) — the leading U.S. state AI law. It targets “algorithmic discrimination” in consequential decisions (employment, lending, housing, insurance, education, healthcare, legal/government services) by imposing a duty of reasonable care on developers and deployers of high-risk AI (impact assessments, risk-management policy, consumer notice, attorney-general enforcement — no private right of action).
How this shows up later
- The AI Act’s conformity assessment, technical documentation and post-market monitoring become concrete deliverables in Domain III (release readiness, model cards) and Domain IV (deployment, monitoring).
- Role-based duties drive the build-vs-buy and vendor-contract analysis in Domain IV (a deployer who modifies a model may inherit provider obligations).
- The risk tiers operationalise the harm taxonomy from I.A.2 and align with the impact-assessment tooling in II.D.