⭐ Star on GitHub

Summary: Wiki pages for raw/AI-regulations/ — the full text of the EU AI Act (Regulation (EU) 2024/1689) plus an SME guide. Several EU AI Act explainers in raw/Laws/ are also drawn on here where they interpret specific articles.

Sources: raw/AI-regulations/ (2 files, ~108k words)

Last updated: 2026-07-28


Pages

PageArticles
eu-ai-actStructure, scope, risk architecture, roles, extraterritorial reach
prohibited-ai-practicesArt 5
high-risk-ai-systemsArts 6–7, Annex III
high-risk-requirementsArts 8–15
article-15-cybersecurityArt 15 — the security article
article-50-transparencyArt 50
gpai-and-systemic-riskArts 51–56
serious-incident-reportingArt 73 (+ Code of Practice Commitment 9)
enforcement-and-penaltiesArt 99, Chapter V enforcement
ai-act-timelineArts 112–113
provider-vs-deployerRoles, and how modification moves you
ai-act-and-smesSME provisions

If you only read three

  1. article-15-cybersecurity — names data poisoning, model poisoning, adversarial examples and confidentiality attacks in binding law, and requires “prevent, detect, respond to, resolve and control for.”
  2. gpai-and-systemic-risk — Art 55(1) is four lines and constitutes the entire binding cybersecurity and red-teaming requirement for frontier models in the EU.
  3. serious-incident-reporting — Art 73(6) constrains what your IR team is allowed to do before notifying authorities.

Dates at a glance

  • 2 Feb 2025 — prohibitions live
  • 2 Aug 2025 — GPAI obligations live (enforcement powers not until 2026)
  • 2 Aug 2026 — the main body: high-risk requirements, Art 15, Art 50, Art 73
  • 2 Aug 2027 — Art 6(1) product-safety-route high-risk systems

Full detail and the Commission’s own deadlines: ai-act-timeline.

Observations from this ingest

  • The Act’s security list predates the agentic threat model. Art 15(5)‘s five named attack classes come from the adversarial-ML literature. Prompt injection, indirect injection and tool poisoning are not named and must be read into the general clause. The Code of Practice covers that ground far better than the Regulation does.
  • The heavy lifting is in soft law. Art 55(1)(d) says “adequate level of cybersecurity protection.” What that means is set by the Code of Practice, not the Regulation.
  • Two reporting regimes with different clocks. Art 73 tiers by harm type (2/10/15 days). The Code of Practice adds a 5-day cybersecurity-breach tier with no Article 73 equivalent.
  • The GPAI enforcement gap — obligations from Aug 2025, Commission powers from Aug 2026 — is real but not total: MSA requests, downstream complaints and scientific-panel alerts operate throughout.

Log

See log.