All rules under the EU AI Act
Common specifications, harmonised standards, administrative templates, guidelines and codes — filter by role, topic, or instrument type.
Common specifications, harmonised standards, administrative templates, guidelines and codes — filter by role, topic, or instrument type.
Level 1
Primary legislation
Examples: AI Act (Reg. 2024/1689)
Drafted by: European Commission proposal
Adopted by: European Parliament & Council (ordinary legislative procedure)
Effect: Legally binding across the EU. Staggered application from Feb 2025 (prohibited practices) through Aug 2027 (full high-risk product safety scope).
Level 2
Delegated & implementing acts · harmonised standards
Examples: Common specifications · administrative templates · hEN (CEN/CENELEC)
Drafted by: European Commission · European standardisation organisations
Adopted by: Delegated/implementing regulations adopted by the Commission. Harmonised standards published in the OJEU — presumption of conformity when cited.
Effect: Legally binding technical detail — conformity assessment procedures, CE marking templates, GPAI transparency rules, post-market monitoring formats.
Level 3
Guidelines · codes of practice
Examples: Commission guidelines · AI Office codes of practice for GPAI
Drafted by: European Commission · European AI Office
Adopted by: Published directly — no further adoption step
Effect: Not legally binding but shape enforcement and supervisory expectations. GPAI providers may demonstrate compliance via approved codes of practice.
Track live developments on the AI Act implementation page and AI Act consultations.
Mandates tracked
22
Specs · templates · guidelines
Adopted
6
live instruments
Outstanding
16
not yet adopted
In dataset
22
curated mandates
Regulation (EU) 2024/1689 — harmonised rules on artificial intelligence
Timeline note: Statutory Aug 2026 / Aug 2027 dates may shift under the Digital Omnibus (COM(2025) 836) while negotiations continue. See proposed backstops
AI Act enters into force
Regulation (EU) 2024/1689 published in the Official Journal on 12 July 2024.
Prohibited AI practices apply
Art. 5 bans (e.g. social scoring, manipulative techniques, real-time remote biometric identification in public spaces) become enforceable.
GPAI obligations · AI Office governance
Chapters III (high-risk) and V (GPAI models) apply for general-purpose AI; AI Office, Board and scientific panel operational; penalties for prohibited AI.
High-risk AI (Annex III) applies
Most Annex III high-risk use cases and transparency obligations for certain AI (chatbots, emotion recognition) become applicable.
Full application — Annex I product safety
High-risk AI embedded in products under Union harmonisation legislation (Annex I) and all remaining obligations fully applicable.
Guidelines on the practical implementation of Art. 5 — prohibited manipulative techniques, social scoring, and real-time remote biometric identification.
Why it matters: First enforcement boundary — determines whether your AI system is outright banned before any conformity assessment.
AI Office-facilitated codes of practice for GPAI providers — copyright, transparency, systemic risk mitigation for models above 10²⁵ FLOPs.
Why it matters: GPAI providers can demonstrate compliance through approved codes instead of (or alongside) direct Art. 53 obligations.
Implementing act establishing the template for the EU declaration of conformity required before placing high-risk AI on the market.
Why it matters: Every high-risk AI provider must complete this declaration — the paperwork gate before CE marking.
Implementing act on the form and content of CE marking for high-risk AI systems placed on the Union market.
Why it matters: Defines how CE marking must appear on your product, packaging, or documentation.
Registration requirements and template for GPAI models in the EU database — including training compute and modality information.
Why it matters: Mandatory for all GPAI providers — registration is live via the AI Act Service Desk.
Common specifications where harmonised standards for GPAI transparency and copyright policy are insufficient.
Why it matters: Fallback conformity route for GPAI when cited standards do not cover your model architecture or training pipeline.
Common specifications where harmonised standards are insufficient or unavailable — criteria for determining high-risk status under Art. 6.
Why it matters: If no hEN covers your use case, these specs become the conformity benchmark for classification decisions.
European standardisation requests to CEN/CENELEC for presumption-of-conformity standards covering risk management, data governance, transparency, and human oversight.
Why it matters: Following cited hENs is the main route to presumed conformity — your QMS and technical documentation will map to these.
Implementing act establishing the template for reporting serious incidents and malfunctioning of high-risk AI and GPAI models.
Why it matters: Providers and deployers must report within prescribed timelines — this template defines the required fields.
Implementing act on the template for post-market monitoring plans required under Art. 72 for high-risk AI systems.
Why it matters: Part of your conformity assessment file — defines how you will collect and analyse performance data after deployment.
Implementing act on the template for real-world testing plans in AI regulatory sandboxes and limited pre-market testing.
Why it matters: Enables structured testing outside the lab before full conformity — relevant for deployers running sandbox pilots.
Implementing act on registration in the EU database for high-risk AI systems before placement on the market.
Why it matters: Public register of high-risk AI — providers must register with prescribed information before going live.
Draft guidelines on whether an AI system is high-risk under Art. 6 — Annex I product safety and Annex III use cases, with practical examples.
Why it matters: Determines whether Chapter III obligations apply at all — the gateway before requirements-and-conformity guidelines under Art. 96.
Guidelines on the practical implementation of Chapter III requirements — risk management, data governance, transparency, human oversight, accuracy, and robustness (Art. 96(1)(a)).
Why it matters: Primary interpretive guide for Chapter III conformity once published — distinct from the Art. 6 classification consultation now open.
Guidelines on how Chapter III requirements apply to each category of high-risk AI listed in Annex III.
Why it matters: Maps abstract obligations to concrete use cases — essential for deployers in HR, credit, insurance, and biometrics.
Guidelines on transparency for AI interacting with natural persons, emotion recognition, biometric categorisation, and deepfakes (Art. 50).
Why it matters: Applies even when your AI is not high-risk — chatbots and synthetic content need disclosure from Aug 2026.
Guidelines for Member States on establishing and operating AI regulatory sandboxes under Art. 57–58.
Why it matters: Framework for testing innovative AI under supervisory oversight before full market placement.
Guidelines on AI literacy measures required under Art. 4 — ensuring staff and operators have sufficient AI competence.
Why it matters: Baseline organisational duty for every provider and deployer from Feb 2025 — often overlooked in technical compliance programmes.
Guidelines on proportionate application of requirements for SMEs, including simplified quality management and documentation.
Why it matters: May reduce conformity burden for smaller providers — check whether your entity qualifies.
Guidelines on conducting fundamental rights impact assessments before deploying high-risk AI — required for deployers of Annex III systems (except where exempt).
Why it matters: Deployer-side obligation distinct from provider conformity — critical for banks, insurers, and public bodies using third-party AI.
Guidelines for market surveillance authorities on coordinated enforcement, cross-border cases, and measures under Art. 79.
Why it matters: Explains how national authorities will inspect and sanction — informs your compliance monitoring strategy.
Technical and procedural means for marking AI-generated text, audio, image, or video content as artificially generated or manipulated.
Why it matters: Deepfake and synthetic media disclosure — deployers of generative AI in marketing and media must implement detectable marking.
Mandate list extracted from Regulation (EU) 2024/1689; deadlines are statutory. Statuses are curated — cross-check the AI Act implementation page for live developments.