EU AI Act · Regulation (EU) 2024/1689

The EU AI Act, as a checklist you can complete

The EU AI Act asks three things of an organisation: know which AI systems you use, classify them by risk level, and document the obligations of that level.

Free assessment in 3 minutes: 12 questions based on the articles of Regulation (EU) 2024/1689. Score and action plan included.

Updated: · Jacobo González Jaspe

  1. Inventory

    Which AI systems you use

  2. Classification

    Their risk level (Art. 6)

  3. Documentation

    The obligations of that level

0/12
Entry offer

EU AI Act: deployer-ready in two weeks

For companies that already use AI (a chat assistant, a copilot, a chatbot on the website) and want to have in order what Regulation (EU) 2024/1689 asks today of whoever uses it: the "deployer".

  1. An inventory of your AI uses Which AI tools your team uses, for which task and with which data. Everything else builds on it.
  2. An AI literacy plan and one training session What Art. 4 asks, applicable since 2 February 2025: proportionate measures so the people using AI know how it works and where it fails.
  3. Labelling and transparency The Art. 50 notices that apply to you, applicable since 2 August 2026: saying a chatbot is an AI and labelling generated content where required.
  4. Risk classification Each use, at its risk level and in writing. If one is high-risk (Annex III), we tell you and explain what that means.
  5. A written scope, agreed on the call What is in, what is out, who on your team takes part and on which dates. A fixed written quote after the call.
Book a 15-minute call

Two weeks from the signed scope, if your team can make the interviews and the training session in that window. If a use is high-risk, two weeks are not enough: we tell you on the call and propose a different scope.

Compliance pack

All 17 EU AI Act and GDPR templates, in one file

DPIA, FRIA, system register, human oversight, transparency and the rest. One Markdown file you open in any editor and fill in with your own facts.

One email, no automatic newsletter. Privacy

What applies, and when

Dates from Regulation (EU) 2024/1689. Each one is a step on the checklist, not a countdown.

EU AI Act application timeline 2 Feb 2025: Prohibited practices (Art. 5) and AI literacy (Art. 4). 2 Aug 2025: General-purpose AI models (Arts. 53–55). 2 Aug 2026: Transparency (Art. 50), penalties and general application. 2 Dec 2027: Annex III high-risk systems (employment, credit, education...). 2 Aug 2028: Annex I high-risk systems (products with CE marking). in force upcoming Today 2 Feb 2025 Prohibited practices (Art. 5)and AI literacy (Art. 4) 2 Aug 2025 General-purpose AI models(Arts. 53–55) 2 Aug 2026 Transparency (Art. 50), penaltiesand general application 2 Dec 2027 Annex III high-risk systems(employment, credit, education...) 2 Aug 2028 Annex I high-risk systems(products with CE marking)

Since 2 February 2025

Prohibited practices (Art. 5) and AI literacy for staff (Art. 4) already apply. They are the first two items on the checklist.

2 August 2026

General application, including the Article 50 transparency duties (whoever offers a chatbot must make clear it is an AI). The transition period in Regulation (EU) 2026/1744 covers only Article 50(2) marking of generated content, for systems already on the market.

2 December 2027

Obligations for Annex III high-risk systems. If none of your systems falls there, this item does not apply to you.

The four risk levels of the EU AI Act Unacceptable: 8 banned practices, Art. 5. High risk: Annexes I and III · Arts. 6–49. Limited risk: Transparency · Art. 50. Minimal risk: No level-specific duties. Unacceptable 8 banned practices, Art. 5 High risk Annexes I and III · Arts. 6–49 Limited risk Transparency · Art. 50 Minimal risk No level-specific duties

Risk classification

The EU AI Act classifies AI systems into four risk levels: unacceptable, high, limited, and minimal. Each level carries different obligations. Our tool helps you identify where your systems fall.

If you want us to review your systems with you, our local AI consulting starts with that classification. The text of the Regulation and the rest of the law cited here are in the regulation index.

View classification templates →

EU AI Act: obligations and dates

What Regulation (EU) 2024/1689 asks of a Spanish SME, with the dates and the articles.

Does the AI Act apply to my SME if I only use ChatGPT?

Yes, as a "deployer" (Article 3(4)): since 2 February 2025 Article 4 applies to you, which asks you to take AI-literacy measures for your staff. High-risk obligations reach you only if you use AI for an Annex III use case, such as recruitment or creditworthiness assessment.

Using a third-party model does not make you a provider. Since Regulation (EU) 2026/1744, Article 4 asks for measures that support AI literacy, taking into account your staff's knowledge and the context of use, without requiring you to guarantee any individual's level. Article 50 adds transparency duties for deployers in specific cases: deep fakes, and AI-generated text published to inform the public without human review or editorial responsibility.

Reviewed: Read the full guide →

Which AI Act dates affect me?

Three have passed: prohibited practices and AI literacy since 2 February 2025, general-purpose AI models since 2 August 2025, and general application since 2 August 2026. Annex III high-risk obligations, originally due on that same date, apply from 2 December 2027: Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), adopted and in force since 27 July 2026, set that date.

The same Omnibus moves Annex I high-risk AI (AI inside Section A regulated products such as medical devices, lifts or toys; machinery moved to Section B and gets its AI requirements through delegated acts under Regulation (EU) 2023/1230 that must apply by 2 August 2028) from 2 August 2027 to 2 August 2028, and applies two new prohibited practices it adds to Article 5 from 2 December 2026. It was published in the Official Journal on 24 July 2026 and amends Article 113 of the Regulation.

Reviewed: Read the full guide →

Is my customer-service chatbot high-risk?

Usually not: answering enquiries is not listed in Annex III. What Article 50(1) does require is that the person knows they are talking to an AI, unless it is obvious; that duty falls on the system's provider, and if you put the chatbot into service under your own name or trademark, the provider may be you (Article 3(3)).

It becomes high-risk if the same system is used for one of the Annex III purposes, for example assessing people's creditworthiness or credit score, selecting candidates or deciding admission to an educational institution (points 3, 4 and 5). Article 50(5) requires the notice to be clear and distinguishable, at the latest at the first interaction.

Reviewed: Read the full guide →

What are the fines, and who enforces in Spain?

Article 99 sets three bands: up to EUR 35 million or 7% of worldwide turnover for prohibited practices; up to EUR 15 million or 3% for breaching the obligations listed in its paragraph 4, including those of deployers (Article 26) and the transparency duties (Article 50); and up to EUR 7.5 million or 1% for supplying incorrect, incomplete or misleading information to the authorities. For SMEs the lower figure of each pair applies. In Spain, the state agency for AI supervision is AESIA.

AESIA (the Spanish Agency for the Supervision of Artificial Intelligence) was created by Royal Decree 729/2023, which approves its statute, and is based in A Coruña. The 7% and 3% figures are calculated on the preceding financial year and, for larger companies, whichever is higher applies.

Reviewed: Read the full guide →

What is a "deployer"?

The natural or legal person, public authority or body that uses an AI system under its authority, except in a personal non-professional activity (Article 3(4)). If you buy an AI service and use it in your business, with your customers or staff, that is you.

The provider is whoever develops the system, or has it developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3)). A deployer's duties include AI literacy (Article 4), transparency in the cases of Article 50 and, for high-risk systems, assigning human oversight to people with the necessary competence, training and authority (Article 26(2)).

Reviewed: Read the full guide →

Local AI simplifies compliance

When AI runs on your own hardware, part of the checklist gets shorter: no data transfers, no third-party processing agreements, and the audit trail stays under your control. The rest of your EU AI Act obligations remain yours.

Book a 15-minute call

AESIA: Spain's AI Watchdog

Spain created AESIA, the agency that supervises AI, through Royal Decree 729/2023. It publishes guidance on applying the AI Act and coordinates the regulatory sandbox.

Compliance

EU AI Act Risk Classification

Answer 6 questions to classify your AI system and get a compliance checklist.

0%