Core Scope: Timelines and Role Definitions

The AI Act, Regulation (EU) 2024/1689, sets risk-based rules that fall differently on AI developers and deployers depending on the specific use of the system. This index functions as a navigation hub: each entry states a technical obligation in a single line, identifies the legally liable party, and routes directly to the operational guide covering its implementation.

Statutory Deadlines and Entity Qualification

The regulation establishes distinct enforcement milestones across different risk tiers, with amended application timelines established under Regulation (EU) 2026/1744. Determining whether an engineering team acts as a provider or a deployer governs which downstream operational controls must be implemented.

Regulatory DutyObligated RoleStatutory TimelineTechnical Implementation Guide
General AI Act enforcement across standard application tiersAll commercial entities2 August 2026See compliance timeline
Provider vs. deployer qualification test for API-based model consumptionEngineering leads and software architects2 August 2026AI Act: Provider vs. Deployer Role Test (publishing 24-25 September)
Substantial modification threshold triggering reclassification to provider statusDownstream engineering teams modifying upstream models2 August 2026AI Act: Provider vs. Deployer Role Test (publishing 24-25 September)

Downstream teams consuming hosted model endpoints operate as deployers by default, provided they do not alter model weights or place the system under their own trademark.

High-Risk Classification and Prohibitions

The framework bans certain AI practices outright under Article 5, including social scoring, untargeted scraping of facial images, emotion inference in workplaces and education institutions, and biometric categorisation that deduces protected characteristics, alongside strict controls for systems classified as high-risk under Annex III. Engineering teams must determine whether their workload touches banned categories before evaluating technical requirements.

Classification Gates and Prohibited Categories

Prohibitions on manipulative systems and workplace emotion recognition took effect in February 2025, while high-risk classifications dictate mandatory quality management systems and pre-deployment conformity checks.

Regulatory DutyObligated RoleStatutory BasisTechnical Implementation Guide
Verification that system architecture contains no prohibited practicesProviders and deployersArticle 5 (Enforced Feb 2025)See prohibited practices checklist
Annex III high-risk classification audit for critical infrastructure, HR, and essential servicesSystem architects and product teamsArticle 6 & Annex IIIAI Act: Annex III High-Risk Decision Tree (publishing 24-25 September)
High-risk safety component verification for regulated physical productsHardware and embedded ML teamsAnnex I harmonised legislationAI Act: Annex III High-Risk Decision Tree (publishing 24-25 September)

Systems falling outside Annex III categories generally avoid conformity assessment requirements, remaining subject only to horizontal transparency mandates.

General Purpose AI and Compute Thresholds

General Purpose AI (GPAI) models operate under dedicated rules for providers on technical documentation, copyright policy and a public training-content summary, with additional obligations where a model is classified as posing systemic risk. Upstream model developers carry the primary compliance burden, but teams executing large-scale fine-tuning runs risk inheriting provider status.

Foundation Models and Fine-Tuning Limits

Statutory duties scale based on whether a model presents systemic risk, measured by cumulative floating-point operations (FLOPs) utilized during training runs.

Regulatory DutyObligated RoleTrigger ThresholdTechnical Implementation Guide
GPAI technical documentation, training data summaries, and copyright complianceUpstream model providersAll GPAI foundation modelsSee foundation model obligations
Systemic risk notification and mandatory adversarial testing protocolsModel developersTraining compute exceeding 10^25 FLOPsSee foundation model obligations
Fine-tuning compute audit to prevent involuntary reclassification as a GPAI providerTeams fine-tuning open-weight modelsSubstantial retraining runsAI Act: Fine-Tuning Compute Thresholds (published 22 September)

Standard parameter-efficient fine-tuning (PEFT) and low-rank adaptation (LoRA) workflows remain well below systemic thresholds, preserving downstream deployer classification.

Article 50: Output Marking and Transparency

Article 50 enforces horizontal transparency mandates across generative AI systems, irrespective of their risk tier. Developers operating chatbots, synthetic media pipelines, or automated publication tools must implement programmatic disclosures and machine-readable provenance markers.

Synthetic Content Marking and User Disclosure

Mandates apply from 2 August 2026, requiring both visual user notifications and embedded provenance metadata across synthetic text, image, audio, and video streams.

Regulatory DutyObligated RoleTechnical MechanismTechnical Implementation Guide
Direct interaction disclosure informing end-users they are communicating with an AI systemProviders of conversational interfacesUI disclaimers at first interactionAI Act: Article 50 Output Marking and Watermarking (publishing 24-25 September)
Machine-readable marking and provenance encoding on synthetic audio, image, and video outputsProviders of generative AI systemsC2PA metadata and SynthID watermarkingAI Act: Article 50 Output Marking and Watermarking (publishing 24-25 September)
Labelling synthetic text published on matters of public interestDeployers publishing generated textEditorial review flags or visual labelsAI Act: Article 50 Output Marking and Watermarking (publishing 24-25 September)
Disclosure to individuals exposed to emotion recognition or biometric categorisationDeployers of biometric systemsPrior notice to affected individualsAI Act: Article 50 Output Marking and Watermarking (publishing 24-25 September)

Assistive editing systems that do not substantially alter underlying semantics remain exempt from machine-readable watermarking obligations.

Annex IV Documentation and DPIAs

High-risk AI systems must carry technical documentation drawn up before the system is placed on the market, giving national authorities the information needed to assess compliance, alongside a risk management system maintained across the lifecycle. Teams deploying models against personal data must simultaneously execute statutory Data Protection Impact Assessments.

Technical Files and Privacy Assessments

Engineering teams must assemble verifiable documentation covering model architecture, data lineage, algorithmic assumptions, and validation metrics.

Regulatory DutyObligated Role and Application DateStatutory ReferenceTechnical Implementation Guide
Assembly of Annex IV technical documentation files and system architecture recordsProvider; Annex III systems apply from 2 December 2027, Annex I product-embedded systems from 2 August 2028Article 11 & Annex IVAI Act: Annex IV Technical Documentation Guide (published 21 September)
Lifecycle risk management system implementation and residual risk monitoringProvider; Annex III systems apply from 2 December 2027, Annex I product-embedded systems from 2 August 2028Article 9AI Act: Annex IV Technical Documentation Guide (published 21 September)
Data Protection Impact Assessment (DPIA) for high-risk and LLM-driven inference pipelinesDeployer as controller; GDPR duty in application since 25 May 2018GDPR Article 35 / AI Act alignmentAI Act: Data Protection Impact Assessment for LLMs (published 21 September)

Annex IV records must be maintained and held available for national market surveillance authorities for ten years after placing the system on the market.

Article 26: Logging and Conformity Audits

Deployers of high-risk AI systems must keep the logs the system automatically generates where those logs are under their control, assign human oversight to competent persons, and monitor the system in operation. Logging architectures must guarantee data integrity while satisfying statutory retention windows.

Operational Traceability and Audit Integrity

Article 26 mandates minimum retention periods for operational logs generated by high-risk systems under the deployer's direct technical control.

Regulatory DutyObligated Role and Application DateRetention PeriodTechnical Implementation Guide
Automated logging of high-risk AI system execution events and inference metadataDeployer; Annex III systems apply from 2 December 2027Article 26(5) minimum retention windowAI Act: Deployer Logging and Retention Window (published 14 September)
Implementation of tamper-evident audit trails and cryptographic hash chains for event logsDeployer; Annex III systems apply from 2 December 2027Active lifecycle durationAI Act: Tamper-Evident Audit Trails and Hash Chains (publishing 24-25 September)
Conformity assessment execution and CE marking registration in the EU databaseProvider; Annex III systems apply from 2 December 2027, Annex I product-embedded systems from 2 August 2028Pre-deployment milestoneAI Act: Conformity Assessment Guide (published 18 September)

Inference logging pipelines must record prompt identifiers, execution timestamps, and model version strings without logging sensitive payload data unnecessarily.

Infrastructure Duties and GDPR Overlap

Deploying compliant AI workloads requires isolating infrastructure responsibilities between the cloud provider and the application layer. Infrastructure controls must reconcile EU AI Act governance with existing GDPR mandates GDPR overlap guide.

Compute Sovereignty and Platform Handoff

Technical teams must distinguish between legal data protection claims and physical hosting architectures when provisioning compute nodes.

Governance AreaInfrastructure ResponsibilityCompliance IntersectionTechnical Implementation Guide
Data residency and processing location of each model you callInfrastructure provider and deployerGDPR Chapter V transfers, not an AI Act dutySee infrastructure requirements guide
Dual-framework compliance mapping for data lineage and training setsEngineering and legal leadsGDPR Article 6 & AI Act Article 10See GDPR overlap guide
Retention of prompts and outputs at the inference layerInference platform, confirmed in writing in your DPAGDPR storage limitation (Art. 5(1)(e))Ask your provider for its retention terms in the DPA

Lyceum states zero data retention for Serverless Inference, meaning prompts and outputs are processed in volatile GPU memory rather than stored, a self-asserted position rather than an audited one. It holds no EU AI Act conformity statement or certification; engineering teams remain responsible for their own application-level compliance and should request the Data Processing Agreement, plus the processing region of every model they call, in writing.