Map your AI applications, roles and risks and determine which obligations under the European AI Act are relevant.
Start with your role and use case
The rules differ for providers, deployers, importers and distributors. An organisation may have different roles for different applications.
For each AI system, describe its purpose, user, data involved, supplier, impact and the decisions it supports or makes.
- prohibited applications
- high-risk AI systems
- transparency obligations
- rules for general-purpose AI models
- other AI involving general governance and due care considerations
Which application dates apply?
The general application date is 2 August 2026, subject to exceptions. The original prohibited practices and AI literacy provisions have applied since 2 February 2025; rules for general-purpose AI models since 2 August 2025, subject to transitional provisions. Following amending Regulation (EU) 2026/1744, the relevant high-risk rules in Chapter III, Sections 1–3, apply from 2 December 2027 for Article 6(2) / Annex III and from 2 August 2028 for Article 6(1) / Annex I. Article 6(5) is excluded from this postponement. New prohibitions introduced by the amendment apply from 2 December 2026. Also check the transitional provisions for existing systems in each case.
Providers and deployers must take measures to support AI literacy among relevant staff and others using AI systems on their behalf. The amended provision does not require a guarantee of any specific individual level of knowledge. Tailor guidance and training to people’s knowledge, the application and those affected.
Create a workable AI register
The internal AI register below is a practical way to maintain oversight. It is not a general statutory registration requirement for every AI application. Registration in the EU database, where required, is a separate obligation for specific systems and roles.
A spreadsheet can be a starting point, but agree who reports new applications and who assesses them. Include built-in AI features in existing software and informal use of generative AI.
Record at least the owner, purpose, supplier, data, users, risk category, decision-making and agreed controls.
What do you need to organise now?
Create one straightforward approval process proportionate to the risk. Not every application needs an extensive file, but every application must be identifiable and used responsibly.
The AI Act, GDPR and other rules alongside one another
The AI Act does not replace privacy, employment or consumer law. An AI application may also require a DPIA, an information security assessment, corporate governance decisions or a sector-specific assessment.
Use a single intake process that involves the relevant disciplines early, rather than separate checks afterwards.
Frequently asked questions
Does the AI Act apply only to developers?+
No. Organisations using AI systems may also have obligations.
Must every AI application be prohibited or certified?+
No. The obligations depend on the role and risk category.
What is AI literacy?+
Appropriate knowledge and skills to understand and use AI responsibly, tailored to the context and risks.
Sources and further reading
We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.
- EUR-Lex: AI Act, consolidated version of 27 July 2026Accessed on 20 September 2026
- European Commission: official informationAccessed on 20 September 2026
- EUR-Lex: amending Regulation (EU) 2026/1744Accessed on 20 September 2026
Related articles
This is general guidance and does not replace a legal assessment or the official standard.
