The pillar guide

The EU AI Act, explained simply

Regulation (EU) 2024/1689 — the EU AI Act — is the world’s first comprehensive law for artificial intelligence. It sorts AI by risk and attaches duties to each level. Here is what it means for your business, without the legalese.

Last reviewed · 2026-06-24 · EU AI Act · Reg. (EU) 2024/1689

Does it apply to you?

The Act reaches beyond the EU’s borders. It applies if you place an AI system on the EU market or put it into service there, and also if you are based outside the EU but the system’s output is used inside it. Your location does not exempt you — what matters is where the AI, or its results, land. Two roles carry most of the weight: providers, who develop an AI system or have it built and place it on the market under their name; and deployers, who use an AI system under their own authority in the course of business. Many companies are both. Your role decides which obligations fall on you — so it is the first thing the free check establishes.

The four risk tiers

The Act is built as a risk pyramid. A small set of uses is banned outright. Below that sits high-risk AI, which carries the heaviest obligations. Then comes limited-risk AI, which mostly owes transparency. Everything else is minimal-risk and largely unregulated. Almost every duty you have flows from which tier your system lands in — so classification comes first.

Minimal
Limited
High
Prohibited
Minimal

Very limited risk — light obligations.

Limited

Mainly transparency obligations apply to you.

High

Extensive duties: documentation, risk, oversight.

Prohibited

This use is banned in the EU.

The deadlines that matter

The Act applies in phases. The prohibitions and AI-literacy duty are already in force; GPAI and high-risk rules follow.

2025-02-02Prohibited practices & AI-literacy apply
2025-08-02GPAI model rules apply
2026-08-02Transparency obligations apply (Art. 50)
2026-12-02Synthetic-content marking grace ends (provisional)
2027-12-02High-risk duties apply — Annex III (provisional)
2028-08-02High-risk duties apply — Annex I products (provisional)

What you must do

Whatever your tier, the obligations cluster into five areas: governance (naming who is accountable and setting your AI policy), risk (assessing and mitigating foreseeable harm), documentation (the technical file and model cards that prove diligence), transparency (telling people when they deal with AI), and data (quality and governance of training and input data). Tawsik maps the exact obligations that apply to your profile and turns each one into a clear step — what it means, why it matters, and what to do.

Governance
Risk
Documentation
Transparency
Data

The cost of getting it wrong

Penalties scale with the severity of the breach. The ceilings come straight from Article 99:

Prohibited practices (Art. 5)

Art. 99(3)

Up to €35M or 7% of global annual turnover

Most other breaches — provider / deployer duties, transparency

Art. 99(4)

Up to €15M or 3% of global annual turnover

Supplying incorrect or misleading information to authorities

Art. 99(5)

Up to €7.5M or 1% of global annual turnover

Fines are the higher of a fixed amount or a percentage of global annual turnover. For SMEs and start-ups, the cap is the lower of the two.

FAQ

Is this legal advice?

No. Tawsik is grounded in the official regulation and guides you toward compliance, but it isn’t legal advice.

How long does the free check take?

A few minutes. You answer a short series of questions and get your risk tier and the obligations that apply — no sign-up.

See what applies to you

Answer a few questions, get your risk tier and obligations — no sign-up.

Keep reading

Tawsik guides you toward compliance. It isn’t legal advice.