Chapter I sets out the subject matter of the Regulation, its scope, the definitions and AI literacy. Our selection covers Article 2, the four definitions in Article 3 that decide how a tool is classified, Article 4 and the new Article 4a. We left out Article 1, because it describes the purpose and the objectives and no standalone obligation follows from it, and the remaining definitions in Article 3 — there are more than sixty of them and in practice they get looked up one at a time, depending on which word in a particular provision is the sticking point.
Žádný paragraf neodpovídá hledanému výrazu.
Chapter I
General provisions and definitions
The Regulation covers providers who place AI systems or general-purpose models on the market or put them into service in the Union, wherever they are established, deployers established in the Union, and providers and deployers in third countries where the output of the system is used in the Union. Alongside them it names importers, distributors, product manufacturers, authorised representatives and affected persons. Outside the scope fall national security and exclusively military or defence use (paragraph 3), research, testing and development prior to placing on the market, with an express carve-out for testing in real world conditions (paragraph 8), purely personal non-professional activity of a natural person (paragraph 10) and systems released under free and open-source licences, unless they amount to a prohibited practice, a high-risk system or a case under Article 50 (paragraph 12). The omnibus inserted a new paragraph 2 here: for high-risk systems under Article 6(1) relating to products covered by Annex I, Section B, only Article 6(1), Article 60a and Articles 102 to 112 of the whole Regulation apply.
CypherOn note
The definition is deliberately broad and technology-neutral. An AI system is a machine-based system designed to operate with varying levels of autonomy after deployment, which may exhibit adaptiveness and which infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. The key words are autonomy and inference, not any particular technology.
CypherOn note
A provider is whoever develops an AI system or a general-purpose model, or has one developed, and places it on the market or puts it into service under its own name or trade mark, whether for payment or free of charge. A deployer is whoever uses an AI system under its authority, except where the use is a personal non-professional activity. Operator is the umbrella term: provider, product manufacturer, deployer, authorised representative, importer and distributor taken together.
CypherOn note
Amended by the omnibus. A safety component is a component of a product or of an AI system which fulfils a safety function for that product or system, or a component whose failure or malfunctioning endangers the health and safety of persons or property. It is now added that a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. The earlier definition contained no such link to the intended purpose and stopped at the “fulfils a safety function” test.
CypherOn note
Amended by the omnibus. Providers and deployers take measures to promote the improvement of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their knowledge, experience and education and the context in which the systems are used. The new wording expressly adds that the obligation does not require guaranteeing a specific level of AI literacy for individual persons. The earlier wording spoke of measures to ensure a sufficient level of AI literacy and carried no such qualifier. The Commission and the Member States are to support these efforts, the Commission publishes practical examples of compliance and the Council will adopt a recommendation on the matter.
CypherOn note
A new article, inserted by the omnibus. It allows special categories of personal data to be processed by way of exception where this is strictly necessary to detect and correct bias in high-risk systems. The conditions are cumulative and demanding: the bias must not be addressable with other data, including synthetic or anonymised data; the data are subject to technical limitations on re-use, to pseudonymisation and to state-of-the-art security measures; access is strictly controlled and documented; the data are not transmitted to other parties; they are deleted once the bias has been corrected or the retention period has expired; and the reason why the processing was necessary is recorded in the records of processing activities. Paragraph 2 opens a narrower variant for other systems and models and for deployers of high-risk systems.
CypherOn note
Chapter II
Prohibited AI practices
Prohibited are subliminal and purposefully manipulative techniques that materially distort the behaviour of a person and cause significant harm (point (a)), exploitation of vulnerabilities due to age, disability or a social or economic situation (point (b)), social scoring leading to detrimental treatment in contexts unrelated to the original one or to disproportionate treatment (point (c)), predicting criminal offences solely on the basis of profiling or personality traits (point (d)), untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases (point (e)), inferring emotions in the workplace and in education institutions (point (f)), biometric categorisation that infers sensitive attributes (point (g)) and real-time remote biometric identification in publicly accessible spaces for law enforcement purposes outside narrowly defined cases with prior authorisation (point (h)). The prohibitions have applied since 2 February 2025.
CypherOn note
Point (f) prohibits placing on the market, putting into service for this purpose and using systems that infer the emotions of a natural person in the workplace and in education institutions; the only exception is where the use is intended to be put in place or placed on the market for medical or safety reasons. Point (g) prohibits biometric categorisation that categorises individual persons on the basis of their biometric data in order to deduce their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. The prohibition in point (g) does not cover the labelling or filtering of lawfully acquired biometric datasets, nor the categorisation of biometric data in the area of law enforcement.
CypherOn note
Added by the omnibus. Point (ba) prohibits systems that create or manipulate realistic material depicting the intimate parts of an identifiable person, or that person engaged in sexually explicit conduct, without their freely given, specific, informed and explicit consent. Point (bb) prohibits systems that create or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU. The new paragraphs 1a and 1b draw the boundaries: placing on the market and putting into service are prohibited where producing such material is the intended purpose of the system, or where it is a reasonably foreseeable and reproducible outcome without significant technical modification and the system has no reliable safeguards; use is prohibited where the deployer actually uses the system to produce such material. Under Article 113, both points and both new paragraphs apply only from 2 December 2026, that is, later than the other prohibitions.
CypherOn note
Chapter III · Section 1
When a system is high-risk
There are two independent routes into high risk: through a product regulated by a harmonisation act listed in Annex I (Article 6(1)) and through a use case listed in Annex III (Article 6(2)). Add to that the derogation in paragraph 3, with documentation and registration under paragraph 4. We work through both routes, both annexes, the new paragraphs 1a to 1c and the derogation. We left out Article 6(5) to (8) and Article 7, because they govern how the Commission issues guidelines and amends Annex III by delegated act — nothing follows from them for classifying a specific tool.
CypherOn note
A system is high-risk where both conditions are met at the same time: it is intended to be used as a safety component of a product covered by one of the harmonisation acts listed in Annex I, or it is itself such a product, and that product is required to undergo a third-party conformity assessment under the same act. It makes no difference whether the system is placed on the market on its own or as part of the product.
CypherOn note
Added by the omnibus, not in the Regulation before. Paragraph 1a says that systems used solely for user support, performance optimisation, service efficiency, automation, convenience or quality control unrelated to safety are not considered safety components. Paragraph 1b balances that immediately: systems whose failure or malfunctioning would endanger health and safety are safety components regardless of paragraph 1a. Paragraph 1c takes out of the condition in paragraph 1(b) those products for which a third-party conformity assessment is required exclusively on grounds other than risks to health and safety — the Regulation names, for example, radio spectrum allocation or electromagnetic interference with no bearing on health and safety.
CypherOn note
Besides the systems under paragraph 1, the systems listed in Annex III are high-risk. Here it is not about a product or a certificate but about the area and the manner of use — the same technology can sit outside the Regulation in one deployment and be high-risk in another.
CypherOn note
A system listed in Annex III is not considered high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. At least one of four conditions has to be met: a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns without replacing the human assessment, or a preparatory task to an assessment. The derogation never applies where the system performs profiling of natural persons. A provider relying on it has to document the assessment before placing the system on the market or putting it into service, register under Article 49(2) and submit the documentation to the authority on request.
CypherOn note
Annex I has two sections. Section A lists the harmonisation acts based on the New Legislative Framework — toys, recreational craft, lifts, equipment for potentially explosive atmospheres, radio equipment, pressure equipment, cableway installations, personal protective equipment, appliances burning gaseous fuels, medical devices and in vitro diagnostic medical devices. Section B lists the other harmonisation acts: civil aviation security, two- and three-wheel vehicles, agricultural and forestry vehicles, marine equipment, rail system interoperability, motor vehicle type-approval and general vehicle safety, and civil aviation. The omnibus deleted Regulation (EU) 2023/1230 on machinery from Section A and inserted it into Section B as point 21.
CypherOn note
Annex III lists eight areas: biometrics, where its use is permitted at all; critical infrastructure, specifically safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating and electricity; education and vocational training; employment and worker management; access to essential private and public services and benefits; law enforcement; migration, asylum and border control management; and the administration of justice together with democratic processes. Inside each area there is a specific list of use cases — belonging to the sector is not enough on its own.
CypherOn note
Chapter III · Sections 2 and 3
Requirements and provider obligations
Section 2 holds the requirements for high-risk systems themselves: the risk management system (Article 9), data and data governance (Article 10), technical documentation (Article 11), automatically generated logs (Article 12), transparency and information for the deployer (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15). Setting them out one by one would turn this page into a second version of the legal text; anyone actually working with them needs them in a project, not in an overview. From Section 3 we take Articles 16, 17 and 25 — the provider obligations and the shift of the role. Deployer obligations (Article 26) and the fundamental rights impact assessment (Article 27) are covered in the AI Act guide.
CypherOn note
The provider ensures that the system complies with the requirements of Section 2, indicates its identification and contact details on the system or in the accompanying documentation, has a quality management system in place under Article 17, keeps the documentation under Article 18, retains the automatically generated logs under Article 19, carries out the conformity assessment under Article 43 before placing the system on the market, draws up the EU declaration of conformity under Article 47, affixes the CE marking, complies with the registration obligation under Article 49(1), takes corrective actions under Article 20, demonstrates conformity upon a reasoned request from an authority, and ensures that the accessibility requirements are met.
CypherOn note
The provider puts in place a quality management system documented in writing which covers, among other things, the regulatory compliance strategy, the design and development procedures, examination and testing, technical specifications and standards, data management, the risk management system under Article 9, post-market monitoring under Article 72, serious incident reporting, communication with authorities and the accountability framework of management. The omnibus added a new paragraph 2: the implementation of those aspects is proportionate to the size of the provider organisation, in particular where it is an SME including a start-up or a small mid-cap enterprise; the degree of rigour and the level of protection required for compliance must nevertheless be preserved. Before that, the article contained no express proportionality rule. A provider that already has a quality management system under sectoral law may incorporate these aspects into it (paragraph 3), and a special regime applies to financial institutions (paragraph 4).
CypherOn note
A distributor, importer, deployer or other third party is considered to be the provider of a high-risk system, with all the obligations under Article 16, where it puts its name or trade mark on a system already on the market, makes a substantial modification to it such that it remains high-risk, or modifies the intended purpose of a system — including a system built on a general-purpose model — such that it becomes high-risk. The omnibus rewrote paragraph 2: the initial provider ceases to be the provider of that system, but has to cooperate closely with the new provider and hand over what is needed to meet the obligations — in particular technical documentation sufficient to assess compliance with Article 16, information on known limitations and failure modes, and reasonable technical access. This does not apply where the initial provider has clearly specified that its system is not to be changed into a high-risk one.
CypherOn note
Chapter III · Section 5
Conformity assessment, declaration and registration
For systems under point 1 of Annex III (biometrics), a provider that has applied harmonised standards or common specifications chooses between internal control under Annex VI and an assessment involving a notified body under Annex VII; without those standards, or where they have been applied only in part, the Annex VII procedure is mandatory. For points 2 to 8 of Annex III, internal control without a notified body applies. The omnibus rewrote paragraph 3, which governs systems covered by the harmonisation acts in Annex I, Section A: the procedure under the sectoral act applies, and it includes an assessment of the requirements in Section 2 of Chapter III and of the quality management system under Article 17. Notified bodies notified under the Section A acts may assess that conformity and have until 28 January 2028 to apply for designation under the AI Act. The new wording also states that a manufacturer does not have to choose a third-party procedure merely because the product contains a high-risk AI system as a safety component, unless the sectoral act requires it. A fresh conformity assessment is required upon a substantial modification (paragraph 4).
CypherOn note
For each high-risk system the provider draws up a written, machine-readable EU declaration of conformity signed physically or electronically and keeps it for ten years from the placing of the system on the market or its putting into service, at the disposal of the national authorities. The declaration states that the system meets the requirements of Section 2, contains the information set out in Annex V and is translated into a language that the authorities of the Member States where the system is made available can readily understand. Where several harmonisation acts cover the system, a single declaration is drawn up for all of them. By drawing up the declaration the provider assumes responsibility for compliance and keeps the declaration up to date.
CypherOn note
Before a high-risk system from Annex III is placed on the market or put into service, both the provider and the system are registered in the EU database under Article 71; the exception is point 2 of Annex III (critical infrastructure), which is registered at national level. A provider that has concluded that its Annex III system is not high-risk also registers (paragraph 2, in conjunction with Article 6(3)). Deployers that are public authorities or Union institutions register themselves and the use of the system. For systems in law enforcement, migration, asylum and border control, registration takes place in a secure non-public section of the database.
CypherOn note
Chapter IV
Transparency (Article 50)
The provider designs systems intended to interact directly with people so that a person knows they are communicating with an AI system — unless this is obvious to a reasonably well-informed and observant person in the given context. The provider of a system that generates synthetic audio, image, video or text ensures that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as this is technically feasible. The marking obligation does not apply to the extent that the system performs an assistive function for standard editing or does not substantially alter the input data or their meaning.
CypherOn note
Whoever deploys an emotion recognition or biometric categorisation system where such use is not prohibited informs the persons exposed to it that the system is in operation. Whoever uses a system to generate or manipulate image, audio or video content constituting a deepfake has to disclose that the content has been artificially generated or manipulated; for evidently artistic, creative, satirical or fictional works the obligation narrows to an appropriate disclosure of the existence of such content in a way that does not hamper the enjoyment of the work. Whoever publishes AI-generated text in order to inform the public on matters of public interest has to disclose it — this does not apply where the content has undergone human review or editorial control and somebody carries editorial responsibility for the publication. The information is provided clearly and distinguishably at the latest at the time of the first interaction or exposure and has to meet the accessibility requirements (paragraph 5).
CypherOn note
Chapter V
General-purpose AI models
A general-purpose AI model is classified as a model with systemic risk where it has high-impact capabilities evaluated with appropriate technical tools and methodologies, or where the Commission so decides on its own initiative or following a qualified alert from the scientific panel, on the basis of the criteria in Annex XIII. A presumption applies: a model has high-impact capabilities where the cumulative amount of computation used for its training exceeded 10 to the power of 25 floating point operations. The Commission may amend the thresholds and indicators by delegated act.
CypherOn note
The provider of a general-purpose model draws up and keeps up to date the technical documentation of the model, including the training and testing process and the evaluation results, to the extent set out in Annex XI, makes information and documentation available to downstream providers who integrate the model into their systems, to the extent set out in Annex XII, puts in place a policy to comply with Union copyright law, including respecting a reservation of rights expressed under Article 4(3) of Directive (EU) 2019/790, and publishes a sufficiently detailed summary of the content used for training, following the template provided by the AI Office. The first two obligations do not apply to models released under a free and open-source licence with publicly available parameters, architecture and information on use — but that carve-out does not extend to models with systemic risk.
CypherOn note
On top of the obligations in Articles 53 and 54, providers of models with systemic risk perform model evaluation in accordance with standardised protocols, including documented adversarial testing, assess and mitigate systemic risks at Union level, keep track of, document and report serious incidents together with corrective measures to the AI Office and, where appropriate, to national authorities without undue delay, and ensure an adequate level of cybersecurity protection for the model and for its physical infrastructure. Until a harmonised standard is published, they may demonstrate compliance by relying on a code of practice under Article 56.
CypherOn note
Chapter VI
Testing in real world conditions
A new article, inserted by the omnibus. Member States may allow providers or prospective providers of AI-based products covered by the harmonisation acts in Annex I, Section B to test high-risk systems in real world conditions outside regulatory sandboxes, in order to verify compliance with the requirements of Articles 8 to 15. A Member State that decides to do so adopts, alone or together with other Member States, a framework for such testing and notifies the Commission before putting it in place. The framework has to include a mandatory testing plan agreed with the competent authority, ensure compliance with selected paragraphs of Article 60, contain effective governance and liability mechanisms and ensure a high level of protection of health, safety and fundamental rights. Alongside Article 6(1) and Articles 102 to 112, this is the only provision of the AI Act that applies directly to Section B systems.
CypherOn note
Chapters XII and XIII
Penalties, transitional provisions and application
The rules on penalties are laid down by the Member States; they have to be effective, proportionate and dissuasive. The Regulation sets the ceilings: up to EUR 35 million or 7 % of total worldwide annual turnover for non-compliance with the prohibitions in Article 5, up to EUR 15 million or 3 % for breaches of the other obligations of operators and notified bodies — among them the provider obligations under Article 16, importer obligations under Article 23, distributor obligations under Article 24, deployer obligations under Article 26 and the transparency obligations under Article 50 — and up to EUR 7.5 million or 1 % for incorrect, incomplete or misleading information supplied to authorities. The higher of the two figures always applies. For SMEs, including start-ups, the lower of them applies instead (paragraph 6). The omnibus rewrote paragraph 1 so that Member States take into account the interests and the economic viability of smaller enterprises, added a new point (da) to the 3 % band (obligations under Article 25(2) and (4)) and inserted paragraph 6a, which extends the lower-of-the-two rule to small mid-cap enterprises.
CypherOn note
Systems that are components of the large-scale IT systems listed in Annex X and were placed on the market before 2 August 2027 have to be brought into compliance by 31 December 2030 (paragraph 1). Other high-risk systems placed on the market before the date of application of Chapter III are covered only where their designs undergo significant changes from that date onwards; for systems intended to be used by public authorities, however, compliance has to be achieved by 2 August 2030 (paragraph 2, rewritten by the omnibus). Providers of general-purpose models placed on the market before 2 August 2025 have until 2 August 2027 (paragraph 3). A new paragraph 4 gives providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2).
CypherOn note
The Regulation applies generally from 2 August 2026, but individual parts have dates of their own. Chapters I and II have applied since 2 February 2025 — except for the new prohibitions in Article 5(1)(ba) and (bb) and paragraphs 1a and 1b, which apply from 2 December 2026. Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 have applied since 2 August 2025, with the exception of Article 101. Chapter III Sections 1, 2 and 3 apply, with the exception of Article 6(5), from 2 December 2027 to systems under Article 6(2) and Annex III and from 2 August 2028 to systems under Article 6(1) and Annex I. Articles 102 to 110 have applied since 27 July 2026. The omnibus rewrote points (a), (c) and (d) — originally the high-risk obligations were to start on 2 August 2026 and 2 August 2027 respectively.