# ActAI Compliance: full text of all guides > Verified 2026-10-11. Licence CC BY 4.0. Not legal advice. # The EU AI Act explained in plain English > What the EU AI Act is, who it applies to, how the risk tiers work, and which deadlines changed after the 2026 AI Omnibus. - Source: https://actaicompliance.com/guides/eu-ai-act-explained/ - Region: European Union - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice The EU AI Act (Regulation (EU) 2024/1689) is the first broad, binding law for artificial intelligence. It entered into force on 1 August 2024 and applies in stages. If you build or use AI and have any link to the EU market, it matters even if your company is based somewhere else. ## Who it applies to The Act reaches beyond Europe. It covers providers that place AI systems on the EU market, deployers (organisations that use AI) located in the EU, and in some cases providers and deployers outside the EU whose AI output is used in the EU. A startup in the US or Kenya selling to EU customers can be in scope. ## The four risk tiers - **Unacceptable risk:** banned outright, for example certain manipulative uses and social scoring. These bans have applied since 2 February 2025. - **High risk:** allowed, but with strict duties. This covers AI used in areas such as hiring, education, credit scoring, essential services, law enforcement and critical infrastructure. - **Transparency risk:** systems such as chatbots and AI-generated content must be disclosed as AI. - **Minimal risk:** most other AI, with no specific obligations beyond existing law. Separate rules apply to general-purpose AI models, and those obligations have applied since 2 August 2025. ## What changed in 2026 The EU adopted the AI Omnibus (Regulation (EU) 2026/1744), which entered into force on 27 July 2026. Its biggest effect is on the high-risk deadlines: - Stand-alone high-risk systems listed in Annex III now apply from **2 December 2027** instead of 2 August 2026. - AI built into regulated products (Annex I) now applies from **2 August 2028**. - Transparency duties under Article 50, such as telling people they are talking to an AI, still applied from 2 August 2026. Systems already on the market before that date got until 2 December 2026 to add machine-readable marking to AI-generated content. - Companies that decide an Annex III system is not high-risk must still register it, but with simpler information. The Omnibus also added new bans, including on certain AI tools that generate realistic intimate imagery or child sexual abuse material, and it widened some relief for smaller companies. Deferred does not mean cancelled. Providers of high-risk systems still need risk management, data governance, logging, human oversight and technical documentation in place. ## What high-risk providers must prepare - A risk management system that covers the whole lifecycle - Data governance and data quality controls - Technical documentation (its required content is set out in Annex IV) - Automatic logging of events - Instructions for deployers and human oversight measures - Accuracy, robustness and cybersecurity measures - A conformity assessment and registration before going to market ## Penalties Under the original text, fines can reach 35 million euros or 7% of worldwide annual turnover for banned practices, with lower tiers for other breaches. Check whether the 2026 changes affect the figures that apply to you. ## What to do now 1. List every AI system you build or use. 2. Work out which risk tier each one falls into. 3. Start keeping records and documentation now. It is far cheaper than rebuilding it later. ## Go deeper - [Is my AI system high-risk?](https://actaicompliance.com/guides/is-my-ai-system-high-risk/) - [Annex III: the high-risk use cases](https://actaicompliance.com/guides/eu-ai-act-annex-iii-high-risk-ai/) - [Annex IV technical documentation: what to include](https://actaicompliance.com/guides/eu-ai-act-annex-iv-technical-documentation/) - [Conformity assessment: how it works](https://actaicompliance.com/guides/eu-ai-act-conformity-assessment/) Good starting points are the official text on EUR-Lex and the European Commission pages on the AI Act. --- # US AI regulation: federal rules, state laws and what to watch > The US has no single federal AI law. This guide covers the federal picture, the state patchwork, and practical steps for companies operating across states. - Source: https://actaicompliance.com/guides/us-ai-regulation/ - Region: United States - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice The United States does not have one comprehensive AI law. Instead, companies face a mix of federal agency enforcement, executive actions that change with administrations, and a growing, fast-moving set of state laws. ## The federal picture Federal agencies apply laws that already exist. The FTC polices deceptive or unfair AI claims, the EEOC looks at discrimination in hiring tools, and financial regulators look at fair lending. Federal policy has also pushed back against some state AI laws. Reports say the federal government intervened in a legal challenge to Colorado's law, so state rules can change quickly. The NIST AI Risk Management Framework is voluntary, but it is widely used as a practical benchmark and is a sensible starting point for internal governance. ## State laws worth knowing - **Colorado:** the original 2024 Colorado AI Act was repealed and replaced in 2026 by a narrower automated decision-making law, reported to take effect on 1 January 2027. The state attorney general is still working on rules, so verify the current status before you act. - **California:** several AI-related laws and privacy-agency rules apply, including rules on automated decision-making technology and transparency duties for large frontier AI developers. - **Texas:** the Texas Responsible AI Governance Act took effect on 1 January 2026. - **New York City:** Local Law 144 requires bias audits and notices for automated employment decision tools. Other states have passed laws on deepfakes, chatbots, healthcare AI and government use, and the list keeps growing. ## Where scrutiny is highest Across states and agencies, the areas that draw the most attention are consequential decisions about people: employment, lending, housing, insurance, healthcare and education. If your AI touches these, expect more rules and more questions. ## Practical steps 1. Map where your users and customers are, because state law follows them. 2. Classify your AI uses and flag any consequential decisions. 3. Document how your system was built, tested and monitored. 4. Give clear notices when people interact with AI or are subject to automated decisions. 5. Set a reminder to re-check state laws every quarter, since they are changing fast. Official sources: your state attorney general pages, the FTC website and NIST. --- # UK AI regulation: how it works without an AI Act > The UK has no single AI law. Here is how existing regulators and laws apply to AI, and what UK companies selling into the EU still need to watch. - Source: https://actaicompliance.com/guides/uk-ai-regulation/ - Region: United Kingdom - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice Unlike the EU, the UK has not passed one broad AI law. Its approach has been to rely on existing regulators and existing laws, guided by a set of cross-sector principles. That is lighter on paper, but it does not mean AI is unregulated. ## The principles-based approach The government's 2023 white paper set out five principles for regulators to apply in their own areas: - Safety, security and robustness - Appropriate transparency and explainability - Fairness - Accountability and governance - Contestability and redress Regulators such as the ICO (data protection), the CMA (competition), the FCA (financial services), Ofcom (online safety and communications) and the MHRA (medical devices) apply these within their own remits. ## Laws that already apply to AI in the UK - **UK GDPR and the Data Protection Act 2018:** apply whenever AI processes personal data, including rules on automated decision-making. The Data (Use and Access) Act 2025 updated parts of this area, so check the current text. - **Equality Act 2010:** discrimination by an AI system can still be unlawful discrimination. - **Consumer and competition law:** misleading claims about AI are still misleading claims. - **Sector rules:** financial services, healthcare and other regulated sectors have their own expectations for AI. ## Is a UK AI law coming? The government has said several times that it may legislate, particularly for the most powerful AI models. Timing and scope have shifted, so check the latest government announcements rather than relying on older articles. ## If you sell into the EU UK companies are outside the EU, but the EU AI Act can still apply when your AI system is placed on the EU market or its output is used there. Many UK firms end up following the stricter EU standard for their whole product, because maintaining two sets of practices is costly. ## Practical steps 1. Identify which regulators oversee your sector and read their AI guidance. 2. Run a data protection impact assessment for AI that handles personal data. 3. Keep records of how your AI was built, tested and monitored. 4. Check whether any EU customers bring you into the EU AI Act. Official sources: GOV.UK AI regulation pages and the ICO guidance on AI and data protection. --- # Canada AI regulation: what applies now > Canada has no federal AI statute in force. Here are the privacy, provincial and public-sector rules that already apply to AI. - Source: https://actaicompliance.com/guides/canada-ai-regulation/ - Region: Canada - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice Canada's proposed federal AI law, the Artificial Intelligence and Data Act (AIDA), did not become law. It was part of Bill C-27, which died when Parliament was prorogued in January 2025. As far as we know, there is still no federal AI-specific statute in force, but several existing rules apply to AI. ## Privacy law is the main constraint - **PIPEDA** governs how private-sector organisations collect, use and disclose personal information in commercial activity across much of Canada. If your AI processes personal data, PIPEDA principles on consent, purpose and accountability apply. - **Quebec Law 25** adds stronger privacy duties, including transparency when a decision is made exclusively by automated processing, and rights to ask about it. - Other provinces such as Alberta and British Columbia have their own private-sector privacy laws. ## Public sector rules The federal Directive on Automated Decision-Making sets requirements for government use of automated systems, including impact assessments. Ontario has also passed legislation setting rules for AI use in its public sector. ## Voluntary codes Canada introduced a voluntary code of conduct for advanced generative AI systems in 2023. It is not law, but signing on can matter commercially and for reputation. ## Other laws still apply Human rights law, consumer protection law and sector rules (financial services, health) apply to AI-driven decisions just as they do to human ones. ## What may change The federal government has said it wants to take a different approach to AI policy than AIDA, but timing and form are uncertain. Check official announcements before assuming anything. ## Practical steps 1. Treat privacy compliance as your core AI compliance task in Canada. 2. If you serve Quebec, check Law 25 requirements on automated decisions. 3. Document your AI systems and decision logic so you can explain outcomes. 4. If you also serve EU customers, check the EU AI Act, because Canadian companies can fall under it. Official sources: the Office of the Privacy Commissioner of Canada and the Treasury Board Secretariat. --- # Which AI laws apply to my business? > A simple way to work out which countries' AI rules apply to you, based on where you sell, what your AI does, and your role. - Source: https://actaicompliance.com/guides/which-ai-laws-apply-to-you/ - Region: Global overview - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice There is no single global AI law. Which rules apply to you depends on four questions. Answer them in order and you will usually end up with a short list. ## 1. Where are your users and customers? Most AI laws follow the people affected, not where your company is registered. If you sell to customers in the EU, state by state in the US, or in Canada, those places' rules can apply to you. ## 2. What does your AI do? Use case matters more than the technology. AI that makes or supports decisions about people (jobs, credit, housing, insurance, healthcare, education) gets far more scrutiny than a spell checker. Chatbots and AI-generated content face disclosure rules in a growing number of places. ## 3. What is your role? Most laws separate the people who build an AI system (providers or developers) from the people who use it (deployers). The duties are different. If you build a product on top of someone else's model, you may count as both. ## 4. What data is involved? If personal data is involved, privacy laws such as GDPR, UK GDPR, PIPEDA and US state privacy laws apply on top of any AI-specific rules. ## Quick guide by region - **European Union:** the most detailed binding AI law. See [the EU AI Act explained](https://actaicompliance.com/guides/eu-ai-act-explained/). - **United Kingdom:** no AI Act, regulator-led. See [UK AI regulation](https://actaicompliance.com/guides/uk-ai-regulation/). - **United States:** federal agencies plus a patchwork of state laws. See [US AI regulation](https://actaicompliance.com/guides/us-ai-regulation/). - **Canada:** no federal AI statute in force, privacy law does the work. See [Canada AI regulation](https://actaicompliance.com/guides/canada-ai-regulation/). - **Elsewhere:** other countries are moving too, including South Korea, Japan, Brazil, China and Singapore, with very different approaches from binding law to voluntary frameworks. We will cover them in future guides, and you should check official sources in the meantime. ## A simple checklist 1. List each AI system and what it does. 2. List the countries and US states where its outputs reach people. 3. Note whether you are a provider, a deployer, or both. 4. Flag any use that affects people's jobs, money, housing, health or education. 5. Write down how each system was built, tested and monitored. Nearly every regime asks for this, in one form or another. If your list includes the EU, start there. It is the most demanding regime and a good benchmark for the rest. --- # EU AI Act Annex III: the high-risk AI use cases > The eight areas listed in Annex III of the EU AI Act, with examples, the exceptions in Article 6(3), and when the rules apply. - Source: https://actaicompliance.com/guides/eu-ai-act-annex-iii-high-risk-ai/ - Region: European Union - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice Annex III is the list of AI use cases that the EU AI Act treats as high-risk. If your AI system falls into one of these areas, strict obligations apply. This guide lists the eight areas with plain-English examples. ## What Annex III is Article 6(2) of the AI Act says that AI systems used in the areas listed in Annex III are high-risk. These are stand-alone systems, meaning AI that is not built into a physical product already covered by EU product-safety law. (AI built into those products is covered by Annex I instead.) ## When it applies After the 2026 AI Omnibus, the high-risk obligations for Annex III systems apply from **2 December 2027**, not 2 August 2026 as first planned. AI built into regulated products under Annex I applies from **2 August 2028**. ## The eight areas 1. **Biometrics.** Remote biometric identification, biometric categorisation by sensitive characteristics, and emotion recognition, where permitted. 2. **Critical infrastructure.** AI used as a safety component in managing critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. 3. **Education and vocational training.** Deciding who is admitted, evaluating learning outcomes, assessing the level of education a person should receive, and monitoring cheating in tests. 4. **Employment and worker management.** Recruitment and selection (for example filtering applications or evaluating candidates), decisions on promotion or termination, task allocation based on behaviour or personal traits, and monitoring or evaluating performance. 5. **Essential private and public services.** Deciding eligibility for public benefits, credit scoring, risk assessment and pricing in life and health insurance, and dispatching or prioritising emergency services. 6. **Law enforcement.** Certain uses such as assessing the risk of a person becoming a victim or an offender, and evaluating evidence. 7. **Migration, asylum and border control.** Certain uses such as risk assessment of people crossing borders and assisting with the examination of applications. 8. **Administration of justice and democratic processes.** AI used to help judicial authorities research and apply the law, and AI intended to influence the outcome of an election or referendum. These are summaries. The exact wording in Annex III decides what is covered, so read the official text for your use case. ## Not everything in these areas is high-risk Article 6(3) says an Annex III system is **not** high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights. Examples include systems that only do a narrow procedural task, improve the result of a human activity already completed, detect patterns without replacing human judgement, or do a preparatory task. There is an important limit: a system that performs **profiling of people** is always treated as high-risk. If you rely on this exception, you must document your assessment and still **register** the system in the EU database. The 2026 Omnibus kept this registration duty but simplified the information required. ## How to check your own system 1. Write down exactly what your system does and who it affects. 2. Compare that to the eight areas above. 3. If it matches, check whether the Article 6(3) exception honestly applies, and document why. 4. If it is high-risk, plan for [the conformity assessment](https://actaicompliance.com/guides/eu-ai-act-conformity-assessment/) and your [technical documentation](https://actaicompliance.com/guides/eu-ai-act-annex-iv-technical-documentation/). For a step-by-step version, see [Is my AI system high-risk?](https://actaicompliance.com/guides/is-my-ai-system-high-risk/) The official text is on EUR-Lex. --- # EU AI Act Annex IV technical documentation: what to include > A plain-English checklist of what Annex IV technical documentation must contain for high-risk AI systems, who needs it, and when it applies. - Source: https://actaicompliance.com/guides/eu-ai-act-annex-iv-technical-documentation/ - Region: European Union - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice If you build a high-risk AI system for the EU market, Annex IV is the part of the AI Act that tells you what your technical documentation must contain. This guide walks through each item in plain English, who needs it, and when. ## What Annex IV is Article 11 of the AI Act requires providers of high-risk AI systems to prepare technical documentation before the system is placed on the market or put into service, and to keep it up to date. Annex IV lists what that documentation must cover. Its job is to show that the system meets the high-risk requirements and to give regulators and notified bodies what they need to assess it. ## Who needs it and when It applies to **providers** of high-risk AI systems, meaning the organisations that develop a system, or have one developed, and place it on the market under their own name. Deployers (the organisations that use it) have different duties. After the 2026 AI Omnibus, the high-risk rules apply from **2 December 2027** for stand-alone systems in the Annex III areas (see [Annex III explained](https://actaicompliance.com/guides/eu-ai-act-annex-iii-high-risk-ai/)) and from **2 August 2028** for AI built into products covered by EU product-safety law. The AI Act also lets small and medium-sized enterprises, including start-ups, provide some Annex IV elements in a simplified way. Check the Commission's latest guidance, and whether the 2026 changes extend this to your company size. ## What Annex IV requires Annex IV has nine sections. In plain English: 1. **General description of the system.** Intended purpose, who provides it, the version, how it interacts with other software or hardware, the forms it is supplied in (for example an API or a downloadable package), and the instructions for deployers. 2. **Detailed description of its elements and development process.** How it was built, including any third-party or pre-trained components, the design logic and key choices and why you made them, the architecture and computing resources, and the data used for training, validation and testing: where it came from and how it was selected, labelled and cleaned. This section also covers human oversight measures, any changes planned in advance, your validation and testing procedures with dated and signed test reports, and your cybersecurity measures. 3. **Monitoring, functioning and control.** What the system can and cannot do, expected accuracy (including for specific groups of people), foreseeable unintended outcomes and risks to health, safety and fundamental rights, and the input data it expects. 4. **Why your performance metrics are appropriate** for this particular system. 5. **The risk management system** described in Article 9. 6. **Changes you make over the system's lifecycle.** 7. **Standards applied.** The harmonised standards you used or, if none, how else you met the requirements. 8. **A copy of the EU declaration of conformity.** 9. **The post-market monitoring system and plan** you will use to track performance once the system is in use. ## How long to keep it Providers must keep the technical documentation available to the authorities for 10 years after the system is placed on the market or put into service. ## Practical tips - **Write it as you build.** Reconstructing data provenance and test results after the fact is slow and error-prone. - **Keep evidence, not just prose.** Test reports should be dated and signed, and data decisions should be traceable. - **Version everything.** Section 6 expects a record of changes, so tie each document version to a system version. - **Be specific about intended purpose.** A vague purpose makes every later section harder to defend. - **Have a responsible person review it.** Whoever drafts the document, someone accountable for the system should read and approve it. ## A note on AI agents Systems built from AI agents generate a lot of operational data: traces, tool calls and logs. These are useful raw evidence for the monitoring, testing and change sections, but traces on their own are not technical documentation. They still need to be organised against the Annex IV headings and reviewed by a person. Always check the official text on EUR-Lex for the exact wording of Annex IV. Next, read how [the conformity assessment](https://actaicompliance.com/guides/eu-ai-act-conformity-assessment/) uses this documentation. --- # EU AI Act conformity assessment: how it works > What a conformity assessment is under the EU AI Act, the two routes (self-assessment or notified body), and the steps after it. - Source: https://actaicompliance.com/guides/eu-ai-act-conformity-assessment/ - Region: European Union - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice A conformity assessment is how a provider shows that a high-risk AI system meets the EU AI Act's requirements before it goes on the market. This guide explains what it is, the two routes, and what happens afterwards. ## What it is Article 43 of the AI Act requires a conformity assessment for high-risk AI systems before they are placed on the EU market or put into service. It is a structured check that the system meets the high-risk requirements, such as risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity. It is the provider's job. Deployers (the organisations that use the system) do not carry it out. ## The two routes - **Internal control (Annex VI).** The provider checks its own quality management system, technical documentation and the design and monitoring of the system, and records the result. No outside body is involved. - **Assessment with a notified body (Annex VII).** An independent organisation, designated by a national authority, reviews the quality management system and the technical documentation, and can test the system. ## Which route applies to you - **Most Annex III systems** (such as hiring, education, credit and essential services) use **internal control**. - **Biometric systems in Annex III** can use internal control only if the provider has applied the relevant harmonised standards in full. Otherwise a notified body is needed. - **AI built into regulated products** (Annex I, such as medical devices or machinery) follows the conformity procedure of that product law, with the AI requirements added. The rules on exactly when each route applies are detailed, so confirm your case against Article 43 in the official text. Notified bodies are listed in the Commission's NANDO database. ## What happens after the assessment 1. **EU declaration of conformity** (Article 47). A written statement that the system meets the requirements. 2. **CE marking** (Article 48). The visible mark that the system conforms. 3. **Registration in the EU database** (Article 49), before the system is placed on the market or put into service. ## When you need to do it again A new assessment is needed when you make a **substantial modification** to the system. Changes you planned in advance and documented in the technical documentation do not count as substantial. That is why recording planned changes properly matters. ## Timing After the 2026 AI Omnibus, high-risk obligations apply from **2 December 2027** for stand-alone Annex III systems and from **2 August 2028** for AI built into regulated products. Plan to finish the assessment before the system is placed on the market, not by the deadline itself. ## What to prepare - [Technical documentation](https://actaicompliance.com/guides/eu-ai-act-annex-iv-technical-documentation/) in the Annex IV format - A quality management system (Article 17) - A risk management system (Article 9) - Test and validation records, dated and signed Not sure whether you are high-risk at all? Start with [Is my AI system high-risk?](https://actaicompliance.com/guides/is-my-ai-system-high-risk/) The official text is on EUR-Lex. --- # Is my AI system high-risk under the EU AI Act? > A step-by-step EU AI Act risk check: work out whether your AI system is prohibited, high-risk, subject to transparency rules, or minimal risk. - Source: https://actaicompliance.com/guides/is-my-ai-system-high-risk/ - Region: European Union - Published: 2026-10-11 - Last reviewed: 2026-10-11 - Publisher: ActAI Compliance (https://actaicompliance.com) - Licence: CC BY 4.0 (please attribute and link to the source URL) - General information, not legal advice Whether your AI system counts as high-risk decides how much work the EU AI Act creates for you. This step-by-step check helps you place your system. It is a guide, not legal advice, and borderline cases deserve a lawyer's opinion. ## Step 1: Is it an AI system under the Act? The Act defines an AI system as a machine-based system that operates with some autonomy and infers from the input it receives how to produce outputs such as predictions, content, recommendations or decisions. Ordinary software that only follows fixed rules written by people is generally outside this definition. If your product uses machine learning or a general-purpose model to produce outputs, assume it is in scope. ## Step 2: Is the use prohibited? Some uses are banned outright, for example manipulative techniques that cause harm and social scoring. These bans have applied since 2 February 2025, and the 2026 Omnibus added further bans. If your use is on the list, it cannot be placed on the EU market. ## Step 3: Is it part of a regulated product? If your AI is a safety component of a product covered by EU product-safety law (such as medical devices or machinery), or is itself such a product, it may be high-risk through **Annex I**. These obligations apply from **2 August 2028**. ## Step 4: Is it used in an Annex III area? Check the eight areas in [Annex III](https://actaicompliance.com/guides/eu-ai-act-annex-iii-high-risk-ai/): biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and justice and democratic processes. If your use matches, it is presumed high-risk, with obligations applying from **2 December 2027**. ## Step 5: Does an exception apply? An Annex III system can fall outside high-risk if it poses no significant risk of harm, for example a narrow procedural task or a purely preparatory task. A system that profiles people never qualifies for the exception. If you rely on it, document your reasoning and register the system. ## Step 6: What is your role? - **Provider:** you develop the system or have it developed and place it on the market under your name. You carry most of the duties, including [technical documentation](https://actaicompliance.com/guides/eu-ai-act-annex-iv-technical-documentation/) and the [conformity assessment](https://actaicompliance.com/guides/eu-ai-act-conformity-assessment/). - **Deployer:** you use someone else's system. You have your own duties, such as human oversight and informing people. ## Step 7: Do transparency rules apply anyway? Even if a system is not high-risk, Article 50 transparency rules can apply. These include telling people they are interacting with an AI system and labelling AI-generated content. They have applied since 2 August 2026, with a grace period to 2 December 2026 for marking AI-generated content from systems already on the market. ## What your result means - **Prohibited:** stop or redesign. - **High-risk:** plan documentation, risk management, human oversight and a conformity assessment. - **Transparency only:** make sure users are informed and content is labelled. - **Minimal risk:** no specific AI Act duties, though other laws such as GDPR still apply. Want a quick automated first pass? Attestly (our product) has an [EU AI Act risk checker](https://www.attestly.online/eu-ai-act-risk-checker?utm_source=actaicompliance). Treat any tool result as a starting point and confirm it against the official text. ---