AI Act · Deadline imminent
Article 50 transparency obligations become applicable for AI systems interacting with humans, emotion-recognition and biometric categorisation systems.
What the AI Act is
The AI Act is a horizontal, risk-based regulation that classifies AI systems by the level of risk they pose to health, safety, fundamental rights and the environment. It entered into force on 1 August 2024. The obligations that apply to a system depend on its classification, its role in the supply chain and whether it is a general-purpose AI model.
The four risk tiers
- Prohibited AI practices. Systems that are considered unacceptable are banned outright. This includes social scoring by public authorities, subliminal techniques that materially distort behaviour, exploitation of vulnerabilities of specific groups, and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions.
- High-risk AI systems. These are AI systems used in safety-critical products or in specific areas listed in Annex III, such as critical infrastructure, education, employment, essential services, law enforcement, migration and administration of justice. They must comply with a full set of requirements: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity.
- Transparency obligations. AI systems that interact with humans, generate synthetic content, or recognise emotions or biometric categories must meet disclosure requirements so users know they are dealing with AI. These are the Article 50 obligations.
- General-purpose AI models. GPAI models with systemic risk are subject to obligations including model evaluation, systemic-risk mitigation, incident reporting, and cybersecurity safeguards. Other GPAI models have lighter transparency and documentation obligations.
Key dates
The AI Act applies in stages:
- Prohibited practices were banned from 2 February 2025.
- General-purpose AI obligations, including certain systemic-risk requirements, applied from 2 August 2025.
- Article 50 transparency obligations apply from 2 August 2026.
- High-risk obligations for stand-alone Annex III systems apply from 2 December 2027 [VERIFY].
- AI embedded in Annex I regulated products applies from 2 August 2028 [VERIFY].
Deferred high-risk dates
How CYBERVETTER helps
We help organisations determine whether an AI system is in scope, classify it correctly, and build the evidence required by its tier. Our work includes:
- AI system inventory and classification against the AI Act tiers.
- Risk management, technical documentation and data governance reviews for high-risk systems.
- Human oversight, transparency and record-keeping procedures.
- Security and robustness assessments aligned with the AI Act's cybersecurity expectations.
- Readiness for conformity assessment and notified-body engagement where required.