Herramienta · Reglamento (UE) 2024/1689

AI Act classifier: your role and your obligations, with dates

Tell us your role in the chain (provider, importer, distributor or deployer), the type of system and whether you use third-party generative AI. We tell you which obligations apply to you and the exact date in art. 113 when they start to bite.

NormaReglamento (UE) 2024/1689
Roles evaluados4 (art. 3)
Next milestone2 Aug 2026 · general application

2 August 2026 is the general date of application of Regulation (EU) 2024/1689; the Chapter III requirements for Annex III high-risk systems are deferred to 2 December 2027, and those of Annex I to 2 August 2028, by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026.

What it does:based on your role in the value chain (provider, importer, distributor or deployer), the type of system (prohibited, Annex III high risk, limited risk/transparency, minimal, or general-purpose AI model) and whether you use third-party generative AI, it returns the specific obligations of Regulation (EU) 2024/1689 that apply to you, article by article, with the exact date each one becomes enforceable under its art. 113.

Who it is for:management, legal and technical directors and compliance officers who need to know, before 2 August 2026, what they must do and when — without waiting for the fine to arrive.

This tool is indicative and does not constitute professional advice.It does not analyse your actual technical documentation, your contract with AI providers, whether your model exceeds the systemic risk threshold in art. 51, or the sector-specific exceptions of each case. Check your situation with the Cumplimiento AI Act service from Summum Consultoría (the legal angle: diagnosis, classification and compliance plan) or with a professional before acting.

Do you use ChatGPT, Copilot or Gemini in your company?AI literacy for your staff (art. 4) has been mandatory since 2 February 2025, and on 2 de agosto de 2026 the transparency duties of art. 50 and the general application of the Regulation are added. If you develop or deploy an Annex III high-risk system, the deadline is deferred to 2 de diciembre de 2027 (y al 2 de agosto de 2028 for Annex I) by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026. Check it in 1 minute right here ↓.

Check your obligations

How the classificationworks.

Method · four steps, in cascade
01

Lo prohibido gana siempre

If the system falls under art. 5, no compliance plan is possible: it stops there. That prohibition has been in force since 2 February 2025, together with the AI literacy duty of art. 4.

02

Cruzamos tipo de sistema y rol

Each type of system (high risk, limited risk, general-purpose model, minimal) has its own article of obligations, and that article names different roles: not all operators have the same duties over the same system.

03

We add what gets forgotten

If you use third-party generative AI, you are the deployer of THAT system even if you did not build it: we add the AI literacy duty of art. 4 and, if you publish or expose the output, the transparency duties of art. 50.

04

Dates from art. 113, not from memory

Each obligation carries the exact date it becomes enforceable: 2 Feb 2025, 2 Aug 2025, 2 Aug 2026 or 2 Dec 2027. And if you are an SME, art. 99.6 lowers the cap on the fine.

Fuentes

Verification note: the content of each article cited was checked on 30 July 2026 against the official text published in the Official Journal of the European Union of the two applicable rules — Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, which amends it — downloaded from EUR-Lex. The dates in art. 113 correspond to its wording in force after that amendment.

Preguntas frecuentes sobre AI Act roles and obligations.

What are the provider, the importer, the distributor and the deployer under the AI Act?

They are the four roles («operators») defined in art. 3 of Regulation (EU) 2024/1689. The provider (art. 3.3) develops the system or model and places it on the market under its own name or trademark. The deployer (art. 3.4) uses it under its own authority, except for personal non-professional use. The importer (art. 3.6) places on the EU market a system bearing a third-country trademark. The distributor (art. 3.7) makes it available in the Union without being the provider or the importer. Each one has different obligations.

What are the key application dates of Regulation (EU) 2024/1689?

Según el art. 113 en su redacción vigente: los capítulos I y II (disposiciones generales, alfabetización en IA y prácticas prohibidas) se aplican desde el 2 de febrero de 2025. El capítulo III sección 4, el capítulo V (modelos de uso general), el capítulo VII (gobernanza) y el capítulo XII (sanciones, salvo el art. 101) se aplican desde el 2 de agosto de 2025. El 2 de agosto de 2026 sigue siendo la fecha general de aplicación del resto del Reglamento, incluidas las obligaciones de transparencia del art. 50. El 2 de diciembre de 2026 entran en aplicación las dos prohibiciones nuevas del art. 5, apartado 1, párrafo primero (letras b bis y b ter) y los apartados 1 bis y 1 ter; en esa misma fecha vence, como supuesto distinto, el plazo del nuevo art. 111, apartado 4, para que los proveedores de sistemas que generen contenido sintético ya presentes en el mercado antes del 2 de agosto de 2026 cumplan el art. 50, apartado 2. Y el capítulo III, secciones 1, 2 y 3 —los requisitos de los sistemas de alto riesgo y las obligaciones de sus proveedores y responsables del despliegue—, con excepción del art. 6, apartado 5, se aplica desde el 2 de diciembre de 2027 para los sistemas del art. 6, apartado 2, y el anexo III, y desde el 2 de agosto de 2028 para los del art. 6, apartado 1, y el anexo I. Esas dos últimas fechas las fija el Reglamento (UE) 2026/1744 (Ómnibus digital sobre IA), en vigor desde el 27 de julio de 2026.

My system is unacceptable risk (art. 5): what do I do?

Stop its development, placing on the market or use: the prohibition in art. 5 has been in force since 2 February 2025 and admits no compliance plan. Breaches are fined up to 35 million euros or 7% of worldwide annual turnover (art. 99.3).

I use ChatGPT, Copilot or Gemini in my company: do I have obligations even though I did not build the system?

Yes. By using a third party's AI system under your own authority, you act as the deployer of THAT system (art. 3.4), with obligations of your own: AI literacy for your staff (art. 4, in force since 2 February 2025) and, if you expose the output to people or publish it, the transparency duties of art. 50 (disclosing the AI interaction, marking synthetic content) from 2 August 2026.

How large can the fine be if I breach my obligations?

Depende de qué se incumpla (art. 99): hasta 35 M€ o el 7% de la facturación mundial por prácticas prohibidas del art. 5; hasta 15 M€ o el 3% por incumplir las demás obligaciones (proveedor, importador, distribuidor, responsable del despliegue, transparencia); hasta 7,5 M€ o el 1% por facilitar información incorrecta o engañosa a las autoridades. Para pymes y empresas emergentes, el art. 99.6 permite que la multa sea por el porcentaje o por el importe, según cuál de ellos sea menor: su redacción es «podrá ser», es decir, una facultad de la autoridad y no un derecho automático a la cifra más baja. Calcula el importe exacto de tu caso en la AI Act fine calculator.

Does this classifier replace a legal audit of my AI systems?

No. It is indicative: it does not analyse your actual technical documentation, your contract with AI providers or whether your model exceeds the systemic risk threshold. Check your case with the AI Act Compliance service from Summum Consultoría (the diagnosis and the compliance plan) or with Summum IA (the technical layer: traceability, bias assessment, Annex IV) before acting.

Shall we classify and
adecuamos tus sistemas?

Diagnosis, risk classification and compliance plan for the European AI Regulation, coordinated with the technical layer of Summum IA.