Regulation · (EU) 2024/1689 · as amended by 2026/1744

REGULATION (EU) 2024/1689

A practical selection of articles of the AI Act as amended by the July 2026 omnibus. Each provision comes with a summary, a note and a link to the official text.

Official text (EUR-Lex) ↗
What this page is and what it is not In its original form the Regulation had 113 articles and 13 annexes; Regulation (EU) 2026/1744 added Articles 4a, 60a and 75a to 75d and a new Annex XIV. What follows is a practical selection of some thirty provisions that companies operating in the Czech Republic actually deal with — scope, definitions, prohibited practices, high-risk classification, provider obligations, transparency, general-purpose models, penalties and deadlines. What we leave out, and why, is set out in the opening card of each part. This is neither the official text nor a complete one. Paragraphs marked as summaries are written in our own words; the verbatim wording is deliberately not reproduced here, because official translations change over time and EUR-Lex is always the authority. We work with the consolidated text as of 27 July 2026, that is, after Regulation (EU) 2026/1744 (the digital omnibus on AI) — for every provision the omnibus changed, we state what applied before and what applies now. Consolidated texts on EUR-Lex are a working aid with no legal force; what is binding is the text published in the Official Journal and its amending Regulation 2026/1744. The “CypherOn note” blocks are our reading, not the text of the Regulation, and they do not replace legal advice.

Žádný paragraf neodpovídá hledanému výrazu.

Chapter I

General provisions and definitions

Selection

What made it onto this page from Chapter I and what did not

Chapter I sets out the subject matter of the Regulation, its scope, the definitions and AI literacy. Our selection covers Article 2, the four definitions in Article 3 that decide how a tool is classified, Article 4 and the new Article 4a. We left out Article 1, because it describes the purpose and the objectives and no standalone obligation follows from it, and the remaining definitions in Article 3 — there are more than sixty of them and in practice they get looked up one at a time, depending on which word in a particular provision is the sticking point.

CypherOn note
The order of work with the Regulation never changes: first use Article 2 to find out whether it applies to you at all, then use the definitions in Article 3 to determine your role for a given tool, and only then ask which risk category it falls into. Whoever starts with the obligations usually ends up working through somebody else's. Classification is done per tool, not per company — you can be a deployer for one tool and a provider for another. Official text: consolidated text as of 27 July 2026.
Art. 2

Scope and the main exclusions

The Regulation covers providers who place AI systems or general-purpose models on the market or put them into service in the Union, wherever they are established, deployers established in the Union, and providers and deployers in third countries where the output of the system is used in the Union. Alongside them it names importers, distributors, product manufacturers, authorised representatives and affected persons. Outside the scope fall national security and exclusively military or defence use (paragraph 3), research, testing and development prior to placing on the market, with an express carve-out for testing in real world conditions (paragraph 8), purely personal non-professional activity of a natural person (paragraph 10) and systems released under free and open-source licences, unless they amount to a prohibited practice, a high-risk system or a case under Article 50 (paragraph 12). The omnibus inserted a new paragraph 2 here: for high-risk systems under Article 6(1) relating to products covered by Annex I, Section B, only Article 6(1), Article 60a and Articles 102 to 112 of the whole Regulation apply.

CypherOn note
Two things trip companies up most often. First, extraterritoriality — if the supplier sits in the US but you use the output of its system in the Union, the supplier is in scope too, which means you as the deployer are not out of the game either. Second, an open-source licence is no blanket pardon: as soon as the model or system is a prohibited practice, is high-risk or falls under the transparency rules in Article 50, the exemption in paragraph 12 does not apply. The new paragraph 2 matters mainly for engineering and transport: for Section B products the substantive requirements reach you through the sectoral act, not directly from the AI Act. Official text: Article 2, amended by Regulation 2026/1744.
Art. 3(1)

What counts as an AI system

The definition is deliberately broad and technology-neutral. An AI system is a machine-based system designed to operate with varying levels of autonomy after deployment, which may exhibit adaptiveness and which infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. The key words are autonomy and inference, not any particular technology.

CypherOn note
Nowhere does the definition say “neural network” or “large language model”. What decides is whether the system infers the output itself or merely computes deterministically from rules somebody wrote into it. In practice that means two things: a classic script with fixed rules is usually not an AI system, whereas a scoring model built on data may well be one, even if the developer sees it as “just statistics”. If you are unsure, do not open with an argument about the definition — write down what the system decides and what happens when it decides wrongly. That is also the input for a risk assessment. Official text: Article 3.
Art. 3(3), (4) and (8)

Provider, deployer, operator

A provider is whoever develops an AI system or a general-purpose model, or has one developed, and places it on the market or puts it into service under its own name or trade mark, whether for payment or free of charge. A deployer is whoever uses an AI system under its authority, except where the use is a personal non-professional activity. Operator is the umbrella term: provider, product manufacturer, deployer, authorised representative, importer and distributor taken together.

CypherOn note
For bought-in tools most companies are deployers, not providers — they run no conformity assessment, draw up no declaration of conformity and register nothing in the EU database. Mind the word operator: when it turns up in a provision on market surveillance or on penalties, it means anyone from that list, so “this does not concern us, we do not develop anything” will not hold in such a sentence. Roles belong in the inventory of tools: one role, one owner and one classification per tool. Without that you cannot say who has to do what and for which tool. Official text: Article 3.
Art. 3(14)

Safety component — the new wording after the omnibus

Amended by the omnibus. A safety component is a component of a product or of an AI system which fulfils a safety function for that product or system, or a component whose failure or malfunctioning endangers the health and safety of persons or property. It is now added that a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. The earlier definition contained no such link to the intended purpose and stopped at the “fulfils a safety function” test.

CypherOn note
It looks cosmetic, but it is one of the most important shifts in the whole omnibus. The safety component is the gateway into high risk under Article 6(1) — and tying it to the intended purpose has narrowed that gateway. At the same time it hands the product provider both a tool and a responsibility: you set the intended purpose yourself and it has to match the instructions for use, the technical documentation and the sales materials. A marketing promise along the lines of “keeps your operation safe” in a leaflet can flip the classification straight back. The link to the new paragraphs of Article 6 is a little further down. Official text: Article 3, amended by Regulation 2026/1744.
Art. 4

AI literacy after the omnibus

Amended by the omnibus. Providers and deployers take measures to promote the improvement of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their knowledge, experience and education and the context in which the systems are used. The new wording expressly adds that the obligation does not require guaranteeing a specific level of AI literacy for individual persons. The earlier wording spoke of measures to ensure a sufficient level of AI literacy and carried no such qualifier. The Commission and the Member States are to support these efforts, the Commission publishes practical examples of compliance and the Council will adopt a recommendation on the matter.

CypherOn note
Do not read that as the obligation having disappeared — what moved is what you evidence. You do not prove the level of knowledge of a particular person, you prove the measures: that you know who uses AI in the company and for what, that you have rules for it and that you have briefed people on the risks of the tools they actually use. The easiest way to evidence this is an AI usage policy, but only where it describes the real tools and the real data in your company. A version downloaded off the internet has no such link and proves nothing in an inspection. Article 4 has applied since 2 February 2025 and it catches companies that merely use AI. Official text: Article 4, amended by Regulation 2026/1744.
Art. 4a

Special categories of data for bias detection

A new article, inserted by the omnibus. It allows special categories of personal data to be processed by way of exception where this is strictly necessary to detect and correct bias in high-risk systems. The conditions are cumulative and demanding: the bias must not be addressable with other data, including synthetic or anonymised data; the data are subject to technical limitations on re-use, to pseudonymisation and to state-of-the-art security measures; access is strictly controlled and documented; the data are not transmitted to other parties; they are deleted once the bias has been corrected or the retention period has expired; and the reason why the processing was necessary is recorded in the records of processing activities. Paragraph 2 opens a narrower variant for other systems and models and for deployers of high-risk systems.

CypherOn note
This is not a licence to collect sensitive data “for the fairness of the model”. It is a narrow exception with conditions you have to be able to evidence, and anyone who wants to rely on it needs the GDPR roles, the retention period and the access records sorted out in advance — otherwise an AI Act problem comes with a data protection problem attached. Practical advice: before you get into this article, verify that the bias really cannot be detected on anonymised or synthetic data. The Regulation puts that question first and an inspection will put it first too. Official text: Article 4a.

Chapter II

Prohibited AI practices

Art. 5(1)

The prohibitions at a glance

Prohibited are subliminal and purposefully manipulative techniques that materially distort the behaviour of a person and cause significant harm (point (a)), exploitation of vulnerabilities due to age, disability or a social or economic situation (point (b)), social scoring leading to detrimental treatment in contexts unrelated to the original one or to disproportionate treatment (point (c)), predicting criminal offences solely on the basis of profiling or personality traits (point (d)), untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases (point (e)), inferring emotions in the workplace and in education institutions (point (f)), biometric categorisation that infers sensitive attributes (point (g)) and real-time remote biometric identification in publicly accessible spaces for law enforcement purposes outside narrowly defined cases with prior authorisation (point (h)). The prohibitions have applied since 2 February 2025.

CypherOn note
The prohibitions carry the harshest penalty band — up to EUR 35 million or 7 % of worldwide turnover, whichever is higher. Not all of them are relevant to an ordinary company; the ones that come up in practice are points (f) and (g), which get a card of their own. The rest lands mainly on the public sector and on law enforcement. One frequent misconception: the prohibition attaches to a practice, not to a type of tool — the same tool can be perfectly fine in one deployment and prohibited in another. Official text: Article 5.
Art. 5(1)(f) and (g)

Emotions in the workplace and biometric categorisation

Point (f) prohibits placing on the market, putting into service for this purpose and using systems that infer the emotions of a natural person in the workplace and in education institutions; the only exception is where the use is intended to be put in place or placed on the market for medical or safety reasons. Point (g) prohibits biometric categorisation that categorises individual persons on the basis of their biometric data in order to deduce their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. The prohibition in point (g) does not cover the labelling or filtering of lawfully acquired biometric datasets, nor the categorisation of biometric data in the area of law enforcement.

CypherOn note
This is the most frequent real breach we come across in Czech companies, and it almost never arrives labelled as an “emotion tool”. It arrives as a module in an HR system (a candidate score from a video interview), as contact centre analytics (call sentiment, agent “satisfaction”) or as an engagement dashboard fed by cameras in a training room. The exception for medical and safety reasons is narrow and it goes to the purpose of the system, not to how the customer chooses to read it. Recommendation: go through the modules of the HR and analytics tools already running and have the supplier confirm in writing, for each of them, whether it infers emotions or sensitive categories. This is typically part of the AI tool assessment we run both before deployment and retrospectively. Official text: Article 5.
Art. 5(1)(ba) and (bb)

Two new prohibitions — applicable from 2 December 2026

Added by the omnibus. Point (ba) prohibits systems that create or manipulate realistic material depicting the intimate parts of an identifiable person, or that person engaged in sexually explicit conduct, without their freely given, specific, informed and explicit consent. Point (bb) prohibits systems that create or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU. The new paragraphs 1a and 1b draw the boundaries: placing on the market and putting into service are prohibited where producing such material is the intended purpose of the system, or where it is a reasonably foreseeable and reproducible outcome without significant technical modification and the system has no reliable safeguards; use is prohibited where the deployer actually uses the system to produce such material. Under Article 113, both points and both new paragraphs apply only from 2 December 2026, that is, later than the other prohibitions.

CypherOn note
For providers of generative tools, paragraph 1a is the crucial one: what decides is the intended purpose and the quality of the safeguards, not good intentions. If the model can produce non-consensual intimate content without a jailbreak and the filters are weak, “we did not mean it that way” does not hold up against the text. For companies that merely deploy tools, point (b) of paragraph 1a leads to a simple conclusion: the prohibition targets use for that purpose, so the risk lies in what people do — and that is handled by usage rules and monitoring, not by a technical audit of the model. There is time until 2 December 2026 to adjust filters and contractual terms. Official text: Article 5, amended by Regulation 2026/1744.

Chapter III · Section 1

When a system is high-risk

Selection

Two routes into high risk and what we left out

There are two independent routes into high risk: through a product regulated by a harmonisation act listed in Annex I (Article 6(1)) and through a use case listed in Annex III (Article 6(2)). Add to that the derogation in paragraph 3, with documentation and registration under paragraph 4. We work through both routes, both annexes, the new paragraphs 1a to 1c and the derogation. We left out Article 6(5) to (8) and Article 7, because they govern how the Commission issues guidelines and amends Annex III by delegated act — nothing follows from them for classifying a specific tool.

CypherOn note
This is the most expensive spot in the whole Regulation, because the deadline hangs off it as well. Chapter III, Sections 1 to 3 apply to Annex III systems from 2 December 2027 and to Annex I systems from 2 August 2028 — originally 2 August 2026 and 2 August 2027 respectively, moved by the omnibus. Section 4 (notified bodies) has applied since 2 August 2025 and Section 5 (conformity assessment and registration) since 2 August 2026; neither of those was moved. Our own quick pass through classification is in the AI Act calculator. Official text: Article 6.
Art. 6(1)

The route through an Annex I product

A system is high-risk where both conditions are met at the same time: it is intended to be used as a safety component of a product covered by one of the harmonisation acts listed in Annex I, or it is itself such a product, and that product is required to undergo a third-party conformity assessment under the same act. It makes no difference whether the system is placed on the market on its own or as part of the product.

CypherOn note
What decides is the combination of safety component plus third-party assessment. Where the product does fall under Annex I but the conformity assessment module chosen requires no third party, this route stays shut. So the first question to put to a manufacturing company is not “do we have AI?” but “which act do we certify the product under, and under which module”. The certification department usually knows the answer, not IT. Official text: Article 6.
Art. 6(1a) to (1c)

The new paragraphs that narrowed the safety component

Added by the omnibus, not in the Regulation before. Paragraph 1a says that systems used solely for user support, performance optimisation, service efficiency, automation, convenience or quality control unrelated to safety are not considered safety components. Paragraph 1b balances that immediately: systems whose failure or malfunctioning would endanger health and safety are safety components regardless of paragraph 1a. Paragraph 1c takes out of the condition in paragraph 1(b) those products for which a third-party conformity assessment is required exclusively on grounds other than risks to health and safety — the Regulation names, for example, radio spectrum allocation or electromagnetic interference with no bearing on health and safety.

CypherOn note
The practical effect: a chatbot in the user support of a machine, predictive maintenance aimed at availability, or an optical quality control system that does not sort safety-relevant defects will not reach high risk by this route after the omnibus. Mind paragraph 1b, though — as soon as a loss of function has consequences for health and safety, the narrowing falls away and you are back in high risk. Paragraph 1c helps mainly manufacturers of radio equipment, where the third party came into play because of spectrum rather than safety. Recommendation: write the decision down and file it together with the reasoning. When somebody asks, you will need to show why you did not classify the system as a safety component. Official text: Article 6, amended by Regulation 2026/1744.
Art. 6(2)

The route through an Annex III use case

Besides the systems under paragraph 1, the systems listed in Annex III are high-risk. Here it is not about a product or a certificate but about the area and the manner of use — the same technology can sit outside the Regulation in one deployment and be high-risk in another.

CypherOn note
For ordinary companies this is the more relevant route. It is entered most often through recruitment and worker management, creditworthiness assessment and pricing in insurance, and sometimes through access to education. Crucially, you can enter it without a single line of your own code: build a CV screening tool on top of a general-purpose model and you are in Annex III. The deadline for this branch is 2 December 2027. Official text: Article 6, the list in Annex III.
Art. 6(3) and (4)

The derogation for Annex III systems and what it costs

A system listed in Annex III is not considered high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. At least one of four conditions has to be met: a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns without replacing the human assessment, or a preparatory task to an assessment. The derogation never applies where the system performs profiling of natural persons. A provider relying on it has to document the assessment before placing the system on the market or putting it into service, register under Article 49(2) and submit the documentation to the authority on request.

CypherOn note
The derogation is not self-service — it is a documented conclusion, not an opinion. Where your supplier relies on it, ask for the assessment documentation and for proof of registration; if they have neither, treat the tool as high-risk, because the moment the derogation fails, Article 25 can shift the provider role onto you. And mind profiling: once the system profiles natural persons the discussion is over, however small the task it performs. Official text: Article 6.
Annex I

Section A and Section B — and machinery moving between them

Annex I has two sections. Section A lists the harmonisation acts based on the New Legislative Framework — toys, recreational craft, lifts, equipment for potentially explosive atmospheres, radio equipment, pressure equipment, cableway installations, personal protective equipment, appliances burning gaseous fuels, medical devices and in vitro diagnostic medical devices. Section B lists the other harmonisation acts: civil aviation security, two- and three-wheel vehicles, agricultural and forestry vehicles, marine equipment, rail system interoperability, motor vehicle type-approval and general vehicle safety, and civil aviation. The omnibus deleted Regulation (EU) 2023/1230 on machinery from Section A and inserted it into Section B as point 21.

CypherOn note
That move is the most important thing the omnibus did for Czech engineering. For Section B products, Article 2(2) means that only Article 6(1), Article 60a and Articles 102 to 112 of the AI Act apply directly — the substantive requirements reach practice through the sectoral act, not straight from the Regulation. Section A products, by contrast, stay under the full Chapter III regime with a deadline of 2 August 2028. Practical step: find out which section holds the act you certify your product under. That single piece of information changes both the scope of the obligations and the deadline. Official text: Annex I, amended by Regulation 2026/1744.
Annex III

Eight areas of use

Annex III lists eight areas: biometrics, where its use is permitted at all; critical infrastructure, specifically safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating and electricity; education and vocational training; employment and worker management; access to essential private and public services and benefits; law enforcement; migration, asylum and border control management; and the administration of justice together with democratic processes. Inside each area there is a specific list of use cases — belonging to the sector is not enough on its own.

CypherOn note
The most common mistake is reading the headings instead of the items. “Employment” does not mean that every HR tool is high-risk — the Annex targets recruitment and selection, decisions on terms of work, promotion and termination, task allocation, and monitoring and evaluation of performance. An attendance system or payroll records usually fall outside it. The same goes for services: what is covered is eligibility for benefits, creditworthiness assessment other than fraud detection, risk pricing in life and health insurance, and the triage of emergency calls. If you are unsure, run the items through the calculator and file the conclusion. Official text: Annex III.

Chapter III · Sections 2 and 3

Requirements and provider obligations

Selection

What Articles 8 to 15 contain and why they are not here one by one

Section 2 holds the requirements for high-risk systems themselves: the risk management system (Article 9), data and data governance (Article 10), technical documentation (Article 11), automatically generated logs (Article 12), transparency and information for the deployer (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15). Setting them out one by one would turn this page into a second version of the legal text; anyone actually working with them needs them in a project, not in an overview. From Section 3 we take Articles 16, 17 and 25 — the provider obligations and the shift of the role. Deployer obligations (Article 26) and the fundamental rights impact assessment (Article 27) are covered in the AI Act guide.

CypherOn note
The cybersecurity layer in Article 15(5) is unusually concrete: it speaks of measures against manipulation of training data and of pre-trained components, against inputs designed to make the model err, and against attacks on confidentiality. What you will not find in the Regulation is prompt injection, data leakage through model outputs and tools procured outside IT — that taxonomy has to come from elsewhere, typically from the OWASP Top 10 for applications with large language models. And one shortcut on top: under Article 42(3), added by the omnibus, a system covered by the Cyber Resilience Act that meets the conditions of its Article 12(1) is presumed to meet the cybersecurity requirements of Article 15. Anyone dealing with the CRA does not have to do this twice. Official text: Article 15 and Article 42.
Art. 16

Obligations of the provider of a high-risk system

The provider ensures that the system complies with the requirements of Section 2, indicates its identification and contact details on the system or in the accompanying documentation, has a quality management system in place under Article 17, keeps the documentation under Article 18, retains the automatically generated logs under Article 19, carries out the conformity assessment under Article 43 before placing the system on the market, draws up the EU declaration of conformity under Article 47, affixes the CE marking, complies with the registration obligation under Article 49(1), takes corrective actions under Article 20, demonstrates conformity upon a reasoned request from an authority, and ensures that the accessibility requirements are met.

CypherOn note
Article 16 is a signpost: on its own it says almost nothing, but it refers to everything else and it is precisely the article the penalty band of up to EUR 15 million or 3 % of turnover attaches to. For a company that becomes a provider unintentionally — typically by changing the intended purpose of a tool built on a general-purpose model — this is an unpleasant surprise: the obligations arrive all at once, and some of them, above all the technical documentation and the conformity assessment, are hard to catch up on retrospectively. Which is why it pays to confirm the role before the tool goes live. Official text: Article 16.
Art. 17

The quality management system and the new proportionality

The provider puts in place a quality management system documented in writing which covers, among other things, the regulatory compliance strategy, the design and development procedures, examination and testing, technical specifications and standards, data management, the risk management system under Article 9, post-market monitoring under Article 72, serious incident reporting, communication with authorities and the accountability framework of management. The omnibus added a new paragraph 2: the implementation of those aspects is proportionate to the size of the provider organisation, in particular where it is an SME including a start-up or a small mid-cap enterprise; the degree of rigour and the level of protection required for compliance must nevertheless be preserved. Before that, the article contained no express proportionality rule. A provider that already has a quality management system under sectoral law may incorporate these aspects into it (paragraph 3), and a special regime applies to financial institutions (paragraph 4).

CypherOn note
The new paragraph 2 is relief in form, not in substance — a smaller provider can keep thinner documentation and simpler processes, but must not drop what makes the system compliant. In practice this means ISO 9001 or an existing ISMS is a good base; you only have to add the parts they are missing: risk management under Article 9, post-market monitoring and incident reporting. Companies that already run an ISMS under Act No. 264/2025 Coll. or ISO/IEC 27001 usually need an extension, not a new system. Official text: Article 17, amended by Regulation 2026/1744.
Art. 25

When you become the provider

A distributor, importer, deployer or other third party is considered to be the provider of a high-risk system, with all the obligations under Article 16, where it puts its name or trade mark on a system already on the market, makes a substantial modification to it such that it remains high-risk, or modifies the intended purpose of a system — including a system built on a general-purpose model — such that it becomes high-risk. The omnibus rewrote paragraph 2: the initial provider ceases to be the provider of that system, but has to cooperate closely with the new provider and hand over what is needed to meet the obligations — in particular technical documentation sufficient to assess compliance with Article 16, information on known limitations and failure modes, and reasonable technical access. This does not apply where the initial provider has clearly specified that its system is not to be changed into a high-risk one.

CypherOn note
Point (c) is a trap you can fall into without a single line of your own code — a system prompt, an API connection and a decision that the tool will screen CVs are enough. The new cooperation duty is good news for the acquiring side and awkward for suppliers: without documentation from the initial provider, a conformity assessment was practically impossible. The omnibus added enforceability too — a breach of Article 25(2) and (4) is now expressly listed in the penalty band of up to EUR 15 million or 3 % of turnover (Article 99(4)(da)). Practical advice: write into your AI supplier contracts who the provider is, what happens if the intended purpose changes and what documentation you will receive. Official text: Article 25, amended by Regulation 2026/1744.

Chapter III · Section 5

Conformity assessment, declaration and registration

Art. 43

Conformity assessment

For systems under point 1 of Annex III (biometrics), a provider that has applied harmonised standards or common specifications chooses between internal control under Annex VI and an assessment involving a notified body under Annex VII; without those standards, or where they have been applied only in part, the Annex VII procedure is mandatory. For points 2 to 8 of Annex III, internal control without a notified body applies. The omnibus rewrote paragraph 3, which governs systems covered by the harmonisation acts in Annex I, Section A: the procedure under the sectoral act applies, and it includes an assessment of the requirements in Section 2 of Chapter III and of the quality management system under Article 17. Notified bodies notified under the Section A acts may assess that conformity and have until 28 January 2028 to apply for designation under the AI Act. The new wording also states that a manufacturer does not have to choose a third-party procedure merely because the product contains a high-risk AI system as a safety component, unless the sectoral act requires it. A fresh conformity assessment is required upon a substantial modification (paragraph 4).

CypherOn note
The last sentence of paragraph 3 is the substantive one — before, there was a risk that adding an AI component would by itself pull the product into a regime with a notified body. After the omnibus that no longer follows automatically and the sectoral act decides. The second thing worth watching is paragraph 4: for systems that continue to learn, changes in performance that are pre-determined and described in the technical documentation are not a substantial modification. In other words, what you define and document up front will not force you to repeat the conformity assessment. Section 5 has been applicable since 2 August 2026, earlier than the requirements for high-risk systems themselves. Official text: Article 43, amended by Regulation 2026/1744.
Art. 47

EU declaration of conformity

For each high-risk system the provider draws up a written, machine-readable EU declaration of conformity signed physically or electronically and keeps it for ten years from the placing of the system on the market or its putting into service, at the disposal of the national authorities. The declaration states that the system meets the requirements of Section 2, contains the information set out in Annex V and is translated into a language that the authorities of the Member States where the system is made available can readily understand. Where several harmonisation acts cover the system, a single declaration is drawn up for all of them. By drawing up the declaration the provider assumes responsibility for compliance and keeps the declaration up to date.

CypherOn note
The declaration of conformity is a formal act, but it carries something substantial — with it you assume responsibility for compliance, including for what you took over from a supplier. Ten years of archiving means you also have to secure the underlying evidence; after ten years nobody will get to the original version of the model, the data and the tests unless it is stored today. Official text: Article 47.
Art. 49

Registration in the EU database

Before a high-risk system from Annex III is placed on the market or put into service, both the provider and the system are registered in the EU database under Article 71; the exception is point 2 of Annex III (critical infrastructure), which is registered at national level. A provider that has concluded that its Annex III system is not high-risk also registers (paragraph 2, in conjunction with Article 6(3)). Deployers that are public authorities or Union institutions register themselves and the use of the system. For systems in law enforcement, migration, asylum and border control, registration takes place in a secure non-public section of the database.

CypherOn note
Registration concerns providers and the public sector — an ordinary company acting as a deployer registers nothing. The most overlooked part is paragraph 2: relying on the derogation in Article 6(3) does not remove the registration duty, it only means you register a different conclusion. When you ask a supplier to confirm that its tool is not high-risk, ask for proof of that registration in the same breath. Official text: Article 49.

Chapter IV

Transparency (Article 50)

Art. 50(1) and (2)

Provider obligations: recognising AI and marking the output

The provider designs systems intended to interact directly with people so that a person knows they are communicating with an AI system — unless this is obvious to a reasonably well-informed and observant person in the given context. The provider of a system that generates synthetic audio, image, video or text ensures that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as this is technically feasible. The marking obligation does not apply to the extent that the system performs an assistive function for standard editing or does not substantially alter the input data or their meaning.

CypherOn note
This is the part of the Regulation that lands on the largest number of organisations, and it has been applicable since 2 August 2026. The key phrase is “machine-readable” — a visual watermark or a line in the footer is not enough on its own, because the obligation is about detectability by a machine. Anyone who placed a generative system on the market before 2 August 2026 has until 2 December 2026 under Article 111(4). The exception for assistive editing is narrower than it reads: it helps with proofreading and formatting, not with a tool that writes the text. Official text: Article 50.
Art. 50(3) and (4)

Deployer obligations: deepfakes and matters of public interest

Whoever deploys an emotion recognition or biometric categorisation system where such use is not prohibited informs the persons exposed to it that the system is in operation. Whoever uses a system to generate or manipulate image, audio or video content constituting a deepfake has to disclose that the content has been artificially generated or manipulated; for evidently artistic, creative, satirical or fictional works the obligation narrows to an appropriate disclosure of the existence of such content in a way that does not hamper the enjoyment of the work. Whoever publishes AI-generated text in order to inform the public on matters of public interest has to disclose it — this does not apply where the content has undergone human review or editorial control and somebody carries editorial responsibility for the publication. The information is provided clearly and distinguishably at the latest at the time of the first interaction or exposure and has to meet the accessibility requirements (paragraph 5).

CypherOn note
For ordinary companies the most frequent practical impact is in marketing and communications: an AI visual in a campaign, a synthetic voice in an ad, generated text on the company blog about matters of public interest. The exception for editorial control is usable, but it needs a name attached — a specific person carries editorial responsibility, and that has to be described in an internal process, not merely asserted. Recommendation: write short rules for labelling AI content and build them into the content approval process. That is cheaper than arguing with a supervisory authority over whether a particular post was “public interest”. Official text: Article 50.

Chapter V

General-purpose AI models

Art. 51

When a model has systemic risk

A general-purpose AI model is classified as a model with systemic risk where it has high-impact capabilities evaluated with appropriate technical tools and methodologies, or where the Commission so decides on its own initiative or following a qualified alert from the scientific panel, on the basis of the criteria in Annex XIII. A presumption applies: a model has high-impact capabilities where the cumulative amount of computation used for its training exceeded 10 to the power of 25 floating point operations. The Commission may amend the thresholds and indicators by delegated act.

CypherOn note
This article concerns providers of models, not the companies that use them. For a deployer it is relevant only indirectly — with models carrying systemic risk you can expect more documentation, evaluation and safeguards on the supplier side, and that is worth using when choosing. Practical advice: do not base a supplier decision on whether the model is “big”. Ask about what you have to be able to evidence — what the model does with your data, how long it keeps them and what happens to them during training. Chapter V has applied since 2 August 2025. Official text: Article 51.
Art. 53

Obligations of the provider of a general-purpose model

The provider of a general-purpose model draws up and keeps up to date the technical documentation of the model, including the training and testing process and the evaluation results, to the extent set out in Annex XI, makes information and documentation available to downstream providers who integrate the model into their systems, to the extent set out in Annex XII, puts in place a policy to comply with Union copyright law, including respecting a reservation of rights expressed under Article 4(3) of Directive (EU) 2019/790, and publishes a sufficiently detailed summary of the content used for training, following the template provided by the AI Office. The first two obligations do not apply to models released under a free and open-source licence with publicly available parameters, architecture and information on use — but that carve-out does not extend to models with systemic risk.

CypherOn note
Two things here are useful to buyers as well. First, documentation for downstream providers is not a courtesy but an obligation — if you are building your own system on top of a model and the supplier refuses to give you the materials, cite Article 53(1)(b). Second, the training data summary and the copyright policy are public signals of a supplier's quality; where they are missing, that is a relevant input into your supplier assessment, whether under your own supplier policy or under Act No. 264/2025 Coll. Official text: Article 53.
Art. 55

Models with systemic risk — what comes on top

On top of the obligations in Articles 53 and 54, providers of models with systemic risk perform model evaluation in accordance with standardised protocols, including documented adversarial testing, assess and mitigate systemic risks at Union level, keep track of, document and report serious incidents together with corrective measures to the AI Office and, where appropriate, to national authorities without undue delay, and ensure an adequate level of cybersecurity protection for the model and for its physical infrastructure. Until a harmonised standard is published, they may demonstrate compliance by relying on a code of practice under Article 56.

CypherOn note
Point (d) is the only place in the whole Regulation that speaks of the cybersecurity of a model and of its physical infrastructure — and it applies to a narrow group of providers. Everyone else gets an indirect benefit: serious incidents reported to the AI Office mean that large problems with models become known sooner. Nothing follows from it for your own operations, though; incidents involving an AI tool in your company are handled under your own regime and, where applicable, under the Czech Cybersecurity Act. Official text: Article 55.

Chapter VI

Testing in real world conditions

Art. 60a

A new article for Annex I, Section B products

A new article, inserted by the omnibus. Member States may allow providers or prospective providers of AI-based products covered by the harmonisation acts in Annex I, Section B to test high-risk systems in real world conditions outside regulatory sandboxes, in order to verify compliance with the requirements of Articles 8 to 15. A Member State that decides to do so adopts, alone or together with other Member States, a framework for such testing and notifies the Commission before putting it in place. The framework has to include a mandatory testing plan agreed with the competent authority, ensure compliance with selected paragraphs of Article 60, contain effective governance and liability mechanisms and ensure a high level of protection of health, safety and fundamental rights. Alongside Article 6(1) and Articles 102 to 112, this is the only provision of the AI Act that applies directly to Section B systems.

CypherOn note
In practice this points at transport and engineering — autonomous vehicle functions, agricultural and forestry machinery, rail, marine equipment, aviation and, after the move, machinery as well. For Czech manufacturers it means two things. First, real world testing depends on whether the Czech Republic adopts such a framework; until one exists, this route does not open here. Second, the general regime for testing in real world conditions under Article 60 and informed consent under Article 61 remain unchanged for other high-risk systems. Anyone planning a pilot in live operation should establish up front which of the two regimes applies. Official text: Article 60a, inserted by Regulation 2026/1744.

Chapters XII and XIII

Penalties, transitional provisions and application

Art. 99

Penalties and the three fine bands

The rules on penalties are laid down by the Member States; they have to be effective, proportionate and dissuasive. The Regulation sets the ceilings: up to EUR 35 million or 7 % of total worldwide annual turnover for non-compliance with the prohibitions in Article 5, up to EUR 15 million or 3 % for breaches of the other obligations of operators and notified bodies — among them the provider obligations under Article 16, importer obligations under Article 23, distributor obligations under Article 24, deployer obligations under Article 26 and the transparency obligations under Article 50 — and up to EUR 7.5 million or 1 % for incorrect, incomplete or misleading information supplied to authorities. The higher of the two figures always applies. For SMEs, including start-ups, the lower of them applies instead (paragraph 6). The omnibus rewrote paragraph 1 so that Member States take into account the interests and the economic viability of smaller enterprises, added a new point (da) to the 3 % band (obligations under Article 25(2) and (4)) and inserted paragraph 6a, which extends the lower-of-the-two rule to small mid-cap enterprises.

CypherOn note
The chapter on penalties has been applicable since 2 August 2025, but the procedural rules are for the Member States to set — and the Czech implementing act is not in the Collection of Laws as of the date this page was last verified. That does not mean the obligations do not apply: the Regulation is directly applicable and applies regardless of the state of Czech law. It only means the national framework for imposing fines is missing. For providers of general-purpose models the Commission is competent directly under Article 101. Anyone planning compliance today should reckon with supervisory practice still taking shape — and with the simplest things always being the easiest to verify: an inventory of tools, roles, and content labelling. Official text: Article 99, amended by Regulation 2026/1744.
Art. 111

Systems and models already on the market

Systems that are components of the large-scale IT systems listed in Annex X and were placed on the market before 2 August 2027 have to be brought into compliance by 31 December 2030 (paragraph 1). Other high-risk systems placed on the market before the date of application of Chapter III are covered only where their designs undergo significant changes from that date onwards; for systems intended to be used by public authorities, however, compliance has to be achieved by 2 August 2030 (paragraph 2, rewritten by the omnibus). Providers of general-purpose models placed on the market before 2 August 2025 have until 2 August 2027 (paragraph 3). A new paragraph 4 gives providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2).

CypherOn note
Paragraph 2 is the most useful sentence for companies with legacy systems: a high-risk system that is on the market and does not change does not fall into the full regime. The weak spot is the phrase “significant changes in their designs” — with systems that are continuously tuned, the line is easy to cross and nobody notices. Recommendation: keep a change log for such systems with the date and scope of each change, so that you can show you never went as far as a significant change. The public sector does not get this relief — for it, 2 August 2030 is a hard ceiling. Official text: Article 111, amended by Regulation 2026/1744.
Art. 113

Application — when things actually start to apply

The Regulation applies generally from 2 August 2026, but individual parts have dates of their own. Chapters I and II have applied since 2 February 2025 — except for the new prohibitions in Article 5(1)(ba) and (bb) and paragraphs 1a and 1b, which apply from 2 December 2026. Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 have applied since 2 August 2025, with the exception of Article 101. Chapter III Sections 1, 2 and 3 apply, with the exception of Article 6(5), from 2 December 2027 to systems under Article 6(2) and Annex III and from 2 August 2028 to systems under Article 6(1) and Annex I. Articles 102 to 110 have applied since 27 July 2026. The omnibus rewrote points (a), (c) and (d) — originally the high-risk obligations were to start on 2 August 2026 and 2 August 2027 respectively.

CypherOn note
This article is the quickest credibility test for any text about the AI Act: if it claims that obligations for high-risk systems start on 2 August 2026, it was written before the omnibus and its timeline is out of date. Individual substantive statements in it may still be correct — the shift touched the deadlines, not the content of most requirements. What was not moved: transparency under Article 50 (2 August 2026), the prohibited practices (2 February 2025), general-purpose models (2 August 2025) and conformity assessment and registration in Section 5 (2 August 2026). We set out the whole timeline, including what changed, in the guide. Official text: Article 113, amended by Regulation 2026/1744.
Content valid as of 8 August 2026

From article to decision

The text of the Regulation
answers no questions.
A classification does.

Two questions come up most often from this page: are we the provider or the deployer for this tool, and from when does what apply to us. Both can be settled over a list of tools in a few hours. Tell us which tools you are dealing with and we will go through them with you.