Regulation · CELEX 32024R1689
Regulation (EU) 2024/1689 — artificial intelligence
View official text on EUR-Lex →5 obligations
AI-ACT-004 · Regulation (EU) 2024/1689 — artificial intelligence, Article 4
AI literacy
Take measures to ensure staff and other people operating or using AI systems on the organisation's behalf have a sufficient level of AI literacy, proportionate to their role, technical knowledge and the AI systems in use.
Applicable now
AI-ACT-004 · Regulation (EU) 2024/1689 — artificial intelligence, Article 4
AI literacy
Take measures to ensure staff and other people operating or using AI systems on the organisation's behalf have a sufficient level of AI literacy, proportionate to their role, technical knowledge and the AI systems in use.
- Applies to
- All in-scope organisations
- Severity if failed
- Medium
- Applies from
- 2 Feb 2025
- Source
- AI-ACT.txt:1186
How this is verified
Training records exist for all staff who operate or use AI systems, refreshed on a defined cycle, mapped to the AI Register
The AI Register and shadow-AI discovery (§1) are what identify who needs this training in the first place — pending that feature, evidence collection here is manual declaration only.
Last verified against primary law 23 Jul 2026
AI-ACT-005 · Regulation (EU) 2024/1689 — artificial intelligence, Article 5
Prohibited AI practices
Do not place on the market, put into service, or use AI systems that deploy prohibited practices — including manipulative/subliminal techniques, exploitation of vulnerabilities, and social scoring that causes significant harm.
Applicable now
AI-ACT-005 · Regulation (EU) 2024/1689 — artificial intelligence, Article 5
Prohibited AI practices
Do not place on the market, put into service, or use AI systems that deploy prohibited practices — including manipulative/subliminal techniques, exploitation of vulnerabilities, and social scoring that causes significant harm.
- Applies to
- All in-scope organisations
- Severity if failed
- Critical
- Applies from
- 2 Feb 2025
- Source
- AI-ACT.txt:1196
How this is verified
The AI Register shows no in-use AI system flagged against any Article 5(1) prohibited-practice category
Determining whether a given system falls into a prohibited category is a legal judgment call — pending compliance-expert review, not something to automate from a keyword match.
Last verified against primary law 23 Jul 2026
AI-ACT-050 · Regulation (EU) 2024/1689 — artificial intelligence, Article 50
Transparency obligations for certain AI systems
Ensure people are informed when interacting with an AI system, label AI-generated or manipulated audio/image/video/text content as such, and disclose deepfakes and AI-generated public-interest text.
Not yet applicable
AI-ACT-050 · Regulation (EU) 2024/1689 — artificial intelligence, Article 50
Transparency obligations for certain AI systems
Ensure people are informed when interacting with an AI system, label AI-generated or manipulated audio/image/video/text content as such, and disclose deepfakes and AI-generated public-interest text.
- Applies to
- All in-scope organisations
- Severity if failed
- Medium
- Applies from
- 2 Aug 2026
- Source
- AI-ACT.txt:2574
How this is verified
AI-generated/manipulated content is machine-readably marked, and chatbot/emotion-recognition/deepfake disclosures are in place before first interaction
Not yet applicable — evidence collection for this obligation shouldn't start until closer to 2 Aug 2026.
Last verified against primary law 23 Jul 2026
AI-ACT-053 · Regulation (EU) 2024/1689 — artificial intelligence, Article 53
General-purpose AI model provider obligations
Maintain up-to-date technical documentation of the model, provide integration documentation to downstream AI-system providers, maintain a copyright-compliance policy, and publish a training-content summary.
Applicable now
AI-ACT-053 · Regulation (EU) 2024/1689 — artificial intelligence, Article 53
General-purpose AI model provider obligations
Maintain up-to-date technical documentation of the model, provide integration documentation to downstream AI-system providers, maintain a copyright-compliance policy, and publish a training-content summary.
- Applies to
- All in-scope organisations
- Severity if failed
- High
- Applies from
- 2 Aug 2025
- Source
- AI-ACT.txt:2642
How this is verified
Technical documentation, downstream integration documentation, a copyright policy, and a public training-content summary all exist and are current
The free/open-source exemption (Art 53(2)) doesn't apply to models with systemic risk — scoping which of DMS's models this covers is expert/legal review, not automatable yet.
Last verified against primary law 23 Jul 2026
AI-ACT-055 · Regulation (EU) 2024/1689 — artificial intelligence, Article 55
Systemic-risk GPAI provider obligations
For general-purpose AI models with systemic risk: perform standardised model evaluation and adversarial testing, assess and mitigate systemic risk, report serious incidents to the AI Office, and secure the model and its infrastructure.
Applicable now
AI-ACT-055 · Regulation (EU) 2024/1689 — artificial intelligence, Article 55
Systemic-risk GPAI provider obligations
For general-purpose AI models with systemic risk: perform standardised model evaluation and adversarial testing, assess and mitigate systemic risk, report serious incidents to the AI Office, and secure the model and its infrastructure.
- Applies to
- All in-scope organisations
- Severity if failed
- Critical
- Applies from
- 2 Aug 2025
- Source
- AI-ACT.txt:2720
How this is verified
Adversarial testing, systemic-risk assessment, and serious-incident reporting to the AI Office are current, on top of the Article 53 obligations
Only applies if DMS is designated as providing a GPAI model with systemic risk — that designation itself isn't modelled yet.
Last verified against primary law 23 Jul 2026