All insights
FAQ · EU AI Act

EU AI Act FAQ for enterprise AI teams

Practical answers for engineering and product teams — timelines, classification, Article 50, GPAI roles and what to document first.

Is the EU AI Act already applicable?

Yes, but different provisions apply on different dates. Prohibited practices and AI literacy obligations have applied since 2 February 2025. GPAI obligations started applying on 2 August 2025. Article 50 transparency obligations apply from 2 August 2026. Current European Commission guidance places Annex III high-risk rules at 2 December 2027 and product-embedded high-risk rules at 2 August 2028.

Does every company using ChatGPT or another LLM become high-risk?

No. Risk classification depends primarily on the intended purpose and use context of the AI system. A general internal summarisation tool is not automatically high-risk simply because it uses a powerful foundation model.

What kinds of AI systems can be high-risk?

Examples include certain systems used for recruitment and employment, education, essential services, biometrics, critical infrastructure, migration and asylum, and specific justice or democratic-process use cases. The exact classification depends on the system's intended purpose and the Regulation's criteria.

What does Article 50 require?

Article 50 introduces transparency obligations for certain AI systems. Examples include informing users when they are interacting with AI and disclosure obligations around specific AI-generated or manipulated content such as deepfakes.

What should an enterprise document first?

Start with an AI inventory. Record the system owner, intended purpose, model or models used, data sources, deployment location, affected users, risk classification, evaluation evidence, logging and human-oversight controls.

Does using an open-source or open-weight model remove AI Act obligations?

No. Model licensing and AI Act classification are different questions. Open-weight deployment can improve control and sovereignty, but the resulting AI system still needs to be assessed based on its role and intended use.

What is the difference between a GPAI model provider and a downstream integrator?

A GPAI model provider places a general-purpose model on the market. A downstream integrator builds an AI system using such a model together with application logic, data, retrieval, tools or interfaces. Their obligations are not identical, but downstream teams still need enough model information and their own system-level evidence.

Are logs required for AI Act compliance?

For high-risk systems, logging and traceability are core parts of the compliance framework. Even outside the high-risk category, operational logs are useful for incident investigation, evaluation, human oversight and change management.

What is human oversight in engineering terms?

Human oversight means more than placing a person somewhere in the workflow. The system should give authorised people enough information and control to monitor behaviour, intervene, override or stop operation where appropriate.

How should we prepare before 2027?

Do not wait for the high-risk application date to build the evidence layer. Establish inventory, classification, model governance, evaluations, logging, security testing, documentation and change-management processes now so new systems inherit them by default.

Primary sources

Related reading

Next step. If you want this to ship, LMXAI scopes the integration as a system — not a workshop series.

Start a project