← All regulations

Regulation · CELEX 32024R1689

Regulation (EU) 2024/1689 — artificial intelligence

View official text on EUR-Lex →

5 obligations

AI-ACT-004 · Regulation (EU) 2024/1689 — artificial intelligence, Article 4

AI literacy

Take measures to ensure staff and other people operating or using AI systems on the organisation's behalf have a sufficient level of AI literacy, proportionate to their role, technical knowledge and the AI systems in use.

Applicable now
Applies to
All in-scope organisations
Severity if failed
Medium
Applies from
2 Feb 2025
Source
AI-ACT.txt:1186

How this is verified

  • Training records exist for all staff who operate or use AI systems, refreshed on a defined cycle, mapped to the AI Register

    The AI Register and shadow-AI discovery (§1) are what identify who needs this training in the first place — pending that feature, evidence collection here is manual declaration only.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

AI-ACT-005 · Regulation (EU) 2024/1689 — artificial intelligence, Article 5

Prohibited AI practices

Do not place on the market, put into service, or use AI systems that deploy prohibited practices — including manipulative/subliminal techniques, exploitation of vulnerabilities, and social scoring that causes significant harm.

Applicable now
Applies to
All in-scope organisations
Severity if failed
Critical
Applies from
2 Feb 2025
Source
AI-ACT.txt:1196

How this is verified

  • The AI Register shows no in-use AI system flagged against any Article 5(1) prohibited-practice category

    Determining whether a given system falls into a prohibited category is a legal judgment call — pending compliance-expert review, not something to automate from a keyword match.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

AI-ACT-050 · Regulation (EU) 2024/1689 — artificial intelligence, Article 50

Transparency obligations for certain AI systems

Ensure people are informed when interacting with an AI system, label AI-generated or manipulated audio/image/video/text content as such, and disclose deepfakes and AI-generated public-interest text.

Not yet applicable
Applies to
All in-scope organisations
Severity if failed
Medium
Applies from
2 Aug 2026
Source
AI-ACT.txt:2574

How this is verified

  • AI-generated/manipulated content is machine-readably marked, and chatbot/emotion-recognition/deepfake disclosures are in place before first interaction

    Not yet applicable — evidence collection for this obligation shouldn't start until closer to 2 Aug 2026.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

AI-ACT-053 · Regulation (EU) 2024/1689 — artificial intelligence, Article 53

General-purpose AI model provider obligations

Maintain up-to-date technical documentation of the model, provide integration documentation to downstream AI-system providers, maintain a copyright-compliance policy, and publish a training-content summary.

Applicable now
Applies to
All in-scope organisations
Severity if failed
High
Applies from
2 Aug 2025
Source
AI-ACT.txt:2642

How this is verified

  • Technical documentation, downstream integration documentation, a copyright policy, and a public training-content summary all exist and are current

    The free/open-source exemption (Art 53(2)) doesn't apply to models with systemic risk — scoping which of DMS's models this covers is expert/legal review, not automatable yet.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

AI-ACT-055 · Regulation (EU) 2024/1689 — artificial intelligence, Article 55

Systemic-risk GPAI provider obligations

For general-purpose AI models with systemic risk: perform standardised model evaluation and adversarial testing, assess and mitigate systemic risk, report serious incidents to the AI Office, and secure the model and its infrastructure.

Applicable now
Applies to
All in-scope organisations
Severity if failed
Critical
Applies from
2 Aug 2025
Source
AI-ACT.txt:2720

How this is verified

  • Adversarial testing, systemic-risk assessment, and serious-incident reporting to the AI Office are current, on top of the Article 53 obligations

    Only applies if DMS is designated as providing a GPAI model with systemic risk — that designation itself isn't modelled yet.

Draft — pending expert review

Last verified against primary law 23 Jul 2026