Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages: prohibited practices and the AI literacy duty from 2 February 2025, obligations for general purpose AI models from 2 August 2025, the bulk of the high risk regime from 2 August 2026, and high risk systems embedded in already regulated products from 2 August 2027. The Commission has since proposed adjustments to parts of that calendar, so a compliance plan should be dated against the text in force when it is written.
The tiers
Unacceptable risk, prohibited outright: social scoring, untargeted scraping of facial images, emotion inference in the workplace and in education, and certain biometric categorisation and predictive policing uses. High risk: the use cases listed in Annex III, covering areas such as employment, education, essential services, law enforcement and critical infrastructure, plus safety components of products already regulated. These carry the heavy obligations, among them risk management, data governance, technical documentation, logging, human oversight and conformity assessment. Limited risk: transparency duties, telling a person they are dealing with a machine and marking synthetic content. Minimal risk: no specific obligation.
The point that gets missed
Classification depends on the use, not on the technology. The same model can sit in a minimal risk product and in a high risk one, and the obligations follow the use case. So the inventory that matters is an inventory of uses, and it has to be maintained as new ones appear.