The EU AI Act articles that might apply to you, and where to read them
6 July 2026 · 6 min read

The EU AI Act runs to more than a hundred articles, but only a handful of them touch a small team. This is a map of the ones our free check can flag for you, in plain language, each with a link to the exact text of the law. Every link opens in a new tab, so you can read the source without losing your place here.
One thing to keep in mind before you click through. The linked pages show the original 2024 Regulation. The 2026 Digital Omnibus later amended some of the application dates, most importantly moving the heavy high-risk obligations from 2 August 2026 to 2 December 2027. Where the source text still shows an older date, the date we give below is the one that now applies.
This is the one that already applies to almost everyone. If your team uses or oversees AI on your behalf, the people involved need a sufficient, role-appropriate understanding of it. There is no prescribed course and no fixed fine, but it is binding law and has been in force since 2 February 2025. The practical duty is to give your people a short, relevant briefing and keep dated evidence that you did. Read it here: Article 4, AI literacy.
A short list of uses you simply cannot deploy, such as social scoring, most untargeted biometric identification, and emotion recognition of staff in the workplace. These carry the heaviest penalties in the Act and have been banned since 2 February 2025. For most small teams the honest answer is that none of these apply, but it is worth reading the list once to be sure: Article 5, prohibited AI practices.
This is the next real deadline, 2 August 2026. If people interact with your AI, for example a chatbot, or you publish AI-generated or edited content, you have to make that clear and mark synthetic media as AI-generated. It only bites if you are public-facing. The detail is here: Article 50, transparency obligations.
This is the heavy part of the Act, and thanks to the Digital Omnibus it now applies from 2 December 2027, not 2 August 2026. It only matters if you use or build AI in a high-risk area. Annex III is the list of those areas: hiring and worker evaluation, access to essential services like credit and insurance, biometrics, education, law enforcement and a few more. If nothing you do lands in that list, this whole chapter passes you by.
If it does apply, your duties depend on your role. Deployers, the organisations using a high-risk system, have to keep a human in the loop, use the system as instructed, monitor it, keep logs and inform the people affected. Those obligations are in Article 26. Providers, the ones building or selling a high-risk system, carry the far heavier load: a risk-management system, technical documentation, a conformity assessment, registration and post-market monitoring, set out in Article 16. The full structure sits in Chapter III.
If you do not build the AI but move it along the chain, you still have duties, and they bite once the system is high-risk. If you bring a high-risk AI system into the EU from outside, Article 23 makes you the importer: check that the provider did the conformity assessment and technical documentation, that the system carries CE marking and names its provider, and keep those records. If you make a high-risk system available on the market without being its provider or importer, Article 24 puts a lighter checking duty on you as distributor: confirm the CE marking and documentation are there, and do not pass it on if you have reason to think it is not compliant.
One trap worth knowing: if you put your own name or trademark on a high-risk system, substantially change one already on the market, or repurpose it into a high-risk use, Article 25 treats you as its provider, and the heavier provider obligations above become yours. That is the same rule the check flags when it asks whether you have modified a system.
These only apply if you train or substantially fine-tune a general-purpose or foundation model, which most teams do not. If you do, Article 53 sets the base obligations, technical documentation, a copyright policy and a training-data summary, and Article 55 adds systemic-risk measures for the most capable models. These have applied since 2 August 2025.
If you ever want to understand the stakes, the fine schedule is Article 99. The headline figures, up to 35 million euro or 7 percent of turnover, attach to the prohibited practices in Article 5, not to the literacy duty. For a small team the real risk is rarely a fine, it is being unable to show a client, insurer or regulator that you made a reasonable effort.
That is exactly what our free check answers. Two minutes of plain questions and it tells you which of these articles are in scope for your situation, where you are on the timeline, and how long you have to act. Take the check here, no account needed.
Klaar walks you through inventory, training, policy and the dated evidence.