The question: Who does it apply to, and in what capacity?
The AI Act does not classify technologies, it classifies uses
People often look for whether a given model “is compliant”. The question has no answer, because the Regulation does not look at the technology employed: it looks at what you make it decide, and from that it draws four levels of obligation.
One and the same model can therefore be prohibited, tightly governed or free depending on the use made of it. And one and the same organisation does not carry the same obligations depending on whether it provides the system or uses it.
Screening job applicationsHigh risk · Permitted, under heavy obligations
What triggers the level
The system takes part in a decision about access to employment: one of the areas expressly listed as high-risk.
What has to be done
A full programme: risk analysis, quality and representativeness of the data, documentation, logging, real human oversight, measurement of accuracy and of the gaps between groups.
In what capacity you are concerned
You are a deployer if you use a tool from the market. You become a provider if you place it on the market under your own name, or if you modify it substantially.
In what capacity
Provider
You develop a system, or you place it on the market under your own name.
Carries: The conformity of the system itself: design, documentation, assessment, marking.
Deployer
You use a system under your own authority, in the course of your activity.
Carries: The use: human oversight, informing people, monitoring in service, following the instructions for use.
The switch that surprises people most: a deployer becomes a provider if they put their name on the system, or if they substantially modify what it is for. Many organisations believe themselves safe because they “only use it”, and change rank without noticing.
A second regime, which is not read on the scale
General-purpose AI models are governed separately, not according to the risk of the use but because they serve every purpose: technical documentation, information for those who integrate them, a policy for complying with copyright law, and a sufficiently detailed summary of the content used for training. Those that present a systemic risk carry reinforced obligations of evaluation and reporting. This regime weighs on the provider of the model, not on you: what you expect from it is that it gives you what you need to meet your own obligations.
Dated snapshot
2026-08
1 August 2024Entry into force of the Regulation.
2 February 2025Prohibited practices become applicable, along with the AI literacy obligation.
2 August 2025Obligations for general-purpose AI models, and governance put in place.
2 August 2026General application, including high-risk systems in the listed areas.
2 August 2027High-risk systems built into products already covered by harmonisation legislation.
This calendar is the one in the text as adopted. Adjustments to the calendar and to implementation have been put up for discussion at European level, and the technical standards that will make the high-risk obligations precise were not all published at the date of this infographic. Check the state of the law in force before committing yourself: that is precisely what an infographic cannot guarantee on your behalf.
The Regulation does not ask which technology you employ, it asks what you make it decide, and in what capacity you act. Two organisations using the same model therefore do not carry the same obligations, and one organisation does not carry the same ones from one use to the next. That is why an inventory of uses is always a useful thing to draw up before a policy.
The SVG embeds its fonts: it opens identically in a browser and in a recent office suite. For a tool that does not read vector files, take the PNG.
Reuse this infographic
CC BY 4.0
You can embed this infographic in an article, an intranet or teaching material. It stays interactive, and its cartouche links back here: that is the only thing asked in return.