Practical answers for engineering and product teams — timelines, classification, Article 50, GPAI roles and what to document first.
Yes, but different provisions apply on different dates. Prohibited practices and AI literacy obligations have applied since 2 February 2025. GPAI obligations started applying on 2 August 2025. Article 50 transparency obligations apply from 2 August 2026. Current European Commission guidance places Annex III high-risk rules at 2 December 2027 and product-embedded high-risk rules at 2 August 2028.
No. Risk classification depends primarily on the intended purpose and use context of the AI system. A general internal summarisation tool is not automatically high-risk simply because it uses a powerful foundation model.
Examples include certain systems used for recruitment and employment, education, essential services, biometrics, critical infrastructure, migration and asylum, and specific justice or democratic-process use cases. The exact classification depends on the system's intended purpose and the Regulation's criteria.
Article 50 introduces transparency obligations for certain AI systems. Examples include informing users when they are interacting with AI and disclosure obligations around specific AI-generated or manipulated content such as deepfakes.
Start with an AI inventory. Record the system owner, intended purpose, model or models used, data sources, deployment location, affected users, risk classification, evaluation evidence, logging and human-oversight controls.
No. Model licensing and AI Act classification are different questions. Open-weight deployment can improve control and sovereignty, but the resulting AI system still needs to be assessed based on its role and intended use.
A GPAI model provider places a general-purpose model on the market. A downstream integrator builds an AI system using such a model together with application logic, data, retrieval, tools or interfaces. Their obligations are not identical, but downstream teams still need enough model information and their own system-level evidence.
For high-risk systems, logging and traceability are core parts of the compliance framework. Even outside the high-risk category, operational logs are useful for incident investigation, evaluation, human oversight and change management.
Human oversight means more than placing a person somewhere in the workflow. The system should give authorised people enough information and control to monitor behaviour, intervene, override or stop operation where appropriate.
Do not wait for the high-risk application date to build the evidence layer. Establish inventory, classification, model governance, evaluations, logging, security testing, documentation and change-management processes now so new systems inherit them by default.
Next step. If you want this to ship, LMXAI scopes the integration as a system — not a workshop series.