Regolamento · CELEX 32024R1689
Regulation (EU) 2024/1689 — artificial intelligence
Leggi il testo ufficiale su EUR-Lex →8 obblighi
AI-ACT-004 · Regulation (EU) 2024/1689 — artificial intelligence, Article 4
AI literacy
Take measures to ensure staff and other people operating or using AI systems on the organisation's behalf have a sufficient level of AI literacy, proportionate to their role, technical knowledge and the AI systems in use.
Applicable now
AI-ACT-004 · Regulation (EU) 2024/1689 — artificial intelligence, Article 4
AI literacy
Take measures to ensure staff and other people operating or using AI systems on the organisation's behalf have a sufficient level of AI literacy, proportionate to their role, technical knowledge and the AI systems in use.
- Applies to
- All in-scope organisations
- Severity if failed
- Medium
- Applies from
- 2 Feb 2025
- Source
- AI-ACT.txt:1186
How this is verified
Training records exist for all staff who operate or use AI systems, refreshed on a defined cycle, mapped to the AI Register
The AI Register and shadow-AI discovery (§1) are what identify who needs this training in the first place — pending that feature, evidence collection here is manual declaration only.
Last verified against primary law 23 Jul 2026
AI-ACT-005 · Regulation (EU) 2024/1689 — artificial intelligence, Article 5
Prohibited AI practices
Do not place on the market, put into service, or use AI systems that deploy prohibited practices — including manipulative/subliminal techniques, exploitation of vulnerabilities, and social scoring that causes significant harm.
Applicable now
AI-ACT-005 · Regulation (EU) 2024/1689 — artificial intelligence, Article 5
Prohibited AI practices
Do not place on the market, put into service, or use AI systems that deploy prohibited practices — including manipulative/subliminal techniques, exploitation of vulnerabilities, and social scoring that causes significant harm.
- Applies to
- All in-scope organisations
- Severity if failed
- Critical
- Applies from
- 2 Feb 2025
- Source
- AI-ACT.txt:1196
How this is verified
The AI Register shows no in-use AI system flagged against any Article 5(1) prohibited-practice category
Determining whether a given system falls into a prohibited category is a legal judgment call — pending compliance-expert review, not something to automate from a keyword match.
Last verified against primary law 23 Jul 2026
AI-ACT-011 · Regulation (EU) 2024/1689 — artificial intelligence, Article 11 and Annex IV
Technical documentation for high-risk AI systems
Draw up technical documentation before the system is placed on the market, keep it up to date, and cover at least the nine headings of Annex IV — what the system is, how it was built, how it is monitored and controlled, its risk management, its changes through the lifecycle, the standards applied, the declaration of conformity and the post-market monitoring plan.
Applicable now
AI-ACT-011 · Regulation (EU) 2024/1689 — artificial intelligence, Article 11 and Annex IV
Technical documentation for high-risk AI systems
Draw up technical documentation before the system is placed on the market, keep it up to date, and cover at least the nine headings of Annex IV — what the system is, how it was built, how it is monitored and controlled, its risk management, its changes through the lifecycle, the standards applied, the declaration of conformity and the post-market monitoring plan.
- Applies to
- Providers of high-risk AI systems
- Severity if failed
- High
- Applies from
- 2 Aug 2026
- Source
- AI-ACT.txt:1556
How this is verified
Technical documentation exists covering all nine Annex IV headings, was drawn up before the system was placed on the market, and is kept up to date
For high-risk systems that are safety components of Annex I products, Art 6(1) and its obligations apply from 2 August 2027 rather than 2026 — which date binds depends on how the system is classified.
Last verified against primary law 23 Jul 2026
AI-ACT-013 · Regulation (EU) 2024/1689 — artificial intelligence, Article 13
Transparency and instructions for use for deployers
Accompany a high-risk AI system with instructions for use a deployer can act on: who the provider is, what the system is for, how accurate and robust it is and against which metrics, the circumstances in which it can cause harm, the human oversight measures, the resources and maintenance it needs, and how to read its logs.
Applicable now
AI-ACT-013 · Regulation (EU) 2024/1689 — artificial intelligence, Article 13
Transparency and instructions for use for deployers
Accompany a high-risk AI system with instructions for use a deployer can act on: who the provider is, what the system is for, how accurate and robust it is and against which metrics, the circumstances in which it can cause harm, the human oversight measures, the resources and maintenance it needs, and how to read its logs.
- Applies to
- Providers of high-risk AI systems
- Severity if failed
- High
- Applies from
- 2 Aug 2026
- Source
- AI-ACT.txt:1606
How this is verified
Instructions for use accompany the system and contain all of Art 13(3)(a)-(f), in a form the target deployer can understand and in the required language
Whether the instructions are 'comprehensible to deployers' (Art 13(2)) is a judgement about the audience, which cannot be made from the text alone.
Last verified against primary law 23 Jul 2026
AI-ACT-047 · Regulation (EU) 2024/1689 — artificial intelligence, Article 47 and Annex V
EU declaration of conformity
Draw up a written, signed EU declaration of conformity for each high-risk AI system, keep it for ten years after the system is placed on the market, keep it up to date, and give it to a national competent authority on request. Its contents are fixed by Annex V.
Applicable now
AI-ACT-047 · Regulation (EU) 2024/1689 — artificial intelligence, Article 47 and Annex V
EU declaration of conformity
Draw up a written, signed EU declaration of conformity for each high-risk AI system, keep it for ten years after the system is placed on the market, keep it up to date, and give it to a national competent authority on request. Its contents are fixed by Annex V.
- Applies to
- Providers of high-risk AI systems
- Severity if failed
- High
- Applies from
- 2 Aug 2026
- Source
- AI-ACT.txt:2510
How this is verified
A signed EU declaration of conformity exists for each high-risk AI system, containing all eight Annex V items, kept at the disposal of national competent authorities for 10 years
The platform can check the declaration says what Annex V requires. Whether the system actually conforms is the conformity assessment's answer, not the declaration's.
Last verified against primary law 23 Jul 2026
AI-ACT-050 · Regulation (EU) 2024/1689 — artificial intelligence, Article 50
Transparency obligations for certain AI systems
Ensure people are informed when interacting with an AI system, label AI-generated or manipulated audio/image/video/text content as such, and disclose deepfakes and AI-generated public-interest text.
Applicable now
AI-ACT-050 · Regulation (EU) 2024/1689 — artificial intelligence, Article 50
Transparency obligations for certain AI systems
Ensure people are informed when interacting with an AI system, label AI-generated or manipulated audio/image/video/text content as such, and disclose deepfakes and AI-generated public-interest text.
- Applies to
- All in-scope organisations
- Severity if failed
- Medium
- Applies from
- 2 Aug 2026
- Source
- AI-ACT.txt:2574
How this is verified
AI-generated/manipulated content is machine-readably marked, and chatbot/emotion-recognition/deepfake disclosures are in place before first interaction
Not yet applicable — evidence collection for this obligation shouldn't start until closer to 2 Aug 2026.
Last verified against primary law 23 Jul 2026
AI-ACT-053 · Regulation (EU) 2024/1689 — artificial intelligence, Article 53
General-purpose AI model provider obligations
Maintain up-to-date technical documentation of the model, provide integration documentation to downstream AI-system providers, maintain a copyright-compliance policy, and publish a training-content summary.
Applicable now
AI-ACT-053 · Regulation (EU) 2024/1689 — artificial intelligence, Article 53
General-purpose AI model provider obligations
Maintain up-to-date technical documentation of the model, provide integration documentation to downstream AI-system providers, maintain a copyright-compliance policy, and publish a training-content summary.
- Applies to
- All in-scope organisations
- Severity if failed
- High
- Applies from
- 2 Aug 2025
- Source
- AI-ACT.txt:2642
How this is verified
Technical documentation, downstream integration documentation, a copyright policy, and a public training-content summary all exist and are current
The free/open-source exemption (Art 53(2)) doesn't apply to models with systemic risk — scoping which of DMS's models this covers is expert/legal review, not automatable yet.
Last verified against primary law 23 Jul 2026
AI-ACT-055 · Regulation (EU) 2024/1689 — artificial intelligence, Article 55
Systemic-risk GPAI provider obligations
For general-purpose AI models with systemic risk: perform standardised model evaluation and adversarial testing, assess and mitigate systemic risk, report serious incidents to the AI Office, and secure the model and its infrastructure.
Applicable now
AI-ACT-055 · Regulation (EU) 2024/1689 — artificial intelligence, Article 55
Systemic-risk GPAI provider obligations
For general-purpose AI models with systemic risk: perform standardised model evaluation and adversarial testing, assess and mitigate systemic risk, report serious incidents to the AI Office, and secure the model and its infrastructure.
- Applies to
- All in-scope organisations
- Severity if failed
- Critical
- Applies from
- 2 Aug 2025
- Source
- AI-ACT.txt:2720
How this is verified
Adversarial testing, systemic-risk assessment, and serious-incident reporting to the AI Office are current, on top of the Article 53 obligations
Only applies if DMS is designated as providing a GPAI model with systemic risk — that designation itself isn't modelled yet.
Last verified against primary law 23 Jul 2026