IAPP AIGP · Domain II/IV · Exam Module

The EU AI Act — Risk, Roles & Deadlines

Regulation (EU) 2024/1689, updated for the Digital Omnibus. The exam tests three things: which tier a system falls into, who owes what, and when it applies. This module makes all three interactive.

8-scenario classifier 8 prohibited practices Penalty calculator Omnibus timeline 6-role matcher
Fresh for 2026: the Digital Omnibus (in force 27 July 2026) pushed Annex III high-risk obligations from 2 Aug 2026 to 2 Dec 2027. Timeline relief, not repeal — prohibitions and GPAI duties are unchanged. This is exactly the kind of update the exam loves.
Scroll to begin ↓
1
Interactive · Risk-tier classifier

Which Tier Does It Fall Into?

The AI Act is a risk pyramid: prohibited, high-risk, limited (transparency), minimal. The exam's favourite question is classification — here are eight scenarios to drill it. Answer, get instant feedback, and the reasoning sticks.

The four tiers at a glance

TierWhat it coversKey obligationsStatus
Prohibited (Art. 5)Eight practices deemed unacceptable: manipulation, exploitation, social scoring, certain biometricsBanned outright — cannot be placed on market, put into service, or usedIn force since 2 Feb 2025
High-risk (Art. 6 + Annexes I & III)AI in products under EU safety law (Annex I) + eight listed use areas (Annex III): employment, credit, education, law enforcement, migration, essential services, biometrics, justiceRisk management, data governance, technical documentation, conformity assessment, CE marking, registration in EU database, human oversight, accuracy/robustness/cybersecurityAnnex III: 2 Dec 2027 (Omnibus); Annex I: 2 Aug 2028
Limited / transparency (Art. 50)Chatbots, deepfakes, emotion recognition, biometric categorisation, synthetic contentDisclosure duties: tell users they are interacting with AI; label deepfakes and synthetic contentIn force since 2 Aug 2026
Minimal riskEverything else — spam filters, games, most enterprise toolsVoluntary codes of conduct; AI literacy (Art. 4) applies to allIn force
Exam anchor — the two high-risk routesHigh-risk comes from two annexes: Annex I (AI embedded in products already regulated by EU safety law — toys, medical devices, cars, machinery) and Annex III (standalone AI in eight listed areas). A system is high-risk if it is either a safety component of an Annex I product or falls in an Annex III area and poses a significant risk to health, safety or fundamental rights. The Digital Omnibus also added a narrowing of Annex III scope — the exam may test that the list is not automatic.
2
Article 5 · The eight banned practices

The 8 Prohibited AI Practices

In force since 2 February 2025 — the first obligations to bite. Learn each with its letter (a)–(h) and its exam tell. Fines: up to €35M or 7% of worldwide turnover.

(a) Subliminal manipulation

Deploying subliminal, manipulative or deceptive techniques to distort behaviour, causing or likely causing significant harm.

Tell: "imperceptible" or "exploits vulnerabilities" + harm.

(b) Exploitation of vulnerabilities

Exploiting vulnerabilities of persons due to age, disability or socio-economic situation to distort behaviour, causing significant harm.

Tell: children, elderly, disabled, or economically vulnerable groups.

(c) Social scoring

Evaluation or classification of natural persons based on social behaviour or inferred personal characteristics, where the score leads to detrimental treatment in unrelated contexts, or is unjustified/disproportionate.

Tell: public or private "trustworthiness" scores with harmful consequences.

(d) Predictive policing (individual risk)

Assessing or predicting the risk of a person committing a criminal offence based solely on profiling or personality traits/characteristics.

Tell: "solely on profiling" — the key qualifier. Risk assessment of crime patterns is NOT banned.

(e) Untargeted facial scraping

Creating or expanding facial recognition databases by untargeted scraping of facial images from the internet or CCTV footage.

Tell: Clearview-style scraping — no consent, no targeting.

(f) Emotion inference in work/education

Inferring emotions of a natural person in the workplace or in educational institutions (with narrow exceptions: medical/safety reasons).

Tell: workplace or classroom emotion detection.

(g) Biometric categorisation (sensitive)

Categorising individuals based on biometric data to infer race, political opinions, religious beliefs, sexual orientation — with narrow law-enforcement exceptions.

Tell: biometrics + sensitive attributes inference.

(h) Real-time remote biometric ID in public (law enforcement)

Real-time remote biometric identification in publicly accessible spaces for law enforcement — banned except for three narrow cases: victims (incl. missing persons), credible threats (terrorism), and serious crimes, each with judicial authorisation.

Tell: the three exceptions + prior judicial approval.

Exam trap — the qualifiersEach prohibition has a narrowing qualifier the exam tests: (a) and (b) require significant harm; (d) requires solely on profiling; (h) has three narrow exceptions with judicial authorisation. A practice that looks banned may be lawful if the qualifier is missing — and vice versa.[EU AI Act Art. 5]
3
Interactive · Article 99 penalty calculator

What Does Non-Compliance Cost?

Three fine tiers under Art. 99 — plus the SME lower-of rule. Pick the violation, set the turnover, and see the ceiling. The exam tests the tiers and the SME carve-out, not the arithmetic — but the arithmetic makes it stick.

€500M
SME or start-up (Art. 99(6) — lower of the two figures applies)
Maximum fine ceiling
€15,000,000 or 3%
3% of €500M = €15M — the percentage figure is higher, so it sets the ceiling.
Art. 99(4) · breach of operator obligations
TierViolationCeilingArticle
TopProhibited practices (Art. 5); non-compliant training data for GPAI€35M or 7% of worldwide turnover — whichever higherArt. 99(3)
MidMost other obligations: high-risk duties, Art. 50 transparency, GPAI provider duties€15M or 3% — whichever higherArt. 99(4)
LowSupplying incorrect, incomplete or misleading information to authorities€7.5M or 1% — whichever higherArt. 99(5)
SME ruleFor SMEs and start-ups, the lower of the two figures applies (not the higher)Cap effectively halved for SMEsArt. 99(6)
GPAI finesGPAI model providers: infringement of GPAI obligations, incorrect info, non-compliance with AI Office requests€15M or 3% (GPAI); systemic-risk GPAI: €15M or 3%Art. 101
Exam memory hook — 35 / 15 / 7.5Think "7% for the seven deadly practices" (prohibited), "3% for the three letters of Art. 50" (transparency), "1% for the one thing you should have just told them" (misleading info). And the SME rule: lower of the two — the exam loves flipping "whichever is higher" to "whichever is lower" for SMEs.[EU AI Act Art. 99]
4
Phased application · updated for the Digital Omnibus

When Does Each Obligation Bite?

The Act applies in phases. The Digital Omnibus (Council approval 29 June 2026, in force 27 July 2026) shifted the high-risk dates — but left the early milestones untouched. Know which dates moved and which didn't.

Entry into force UNCHANGED
1 August 2024
Regulation (EU) 2024/1689 published in the Official Journal on 12 July 2024; entered into force 20 days later. The countdown clock starts here.
Prohibited practices apply UNCHANGED
2 February 2025
Article 5 prohibitions bite — the first enforceable obligations. Also: AI literacy (Art. 4) and the Commission's GPAI codes of practice process.
GPAI transparency obligations UNCHANGED
2 August 2025
Chapter V GPAI model obligations apply: documentation, copyright policy, training-data summaries. Systemic-risk GPAI duties follow later.
General application + Art. 50 transparency + GPAI enforcement UNCHANGED
2 August 2026
The bulk of the Act applies: Art. 50 transparency duties (chatbots, deepfakes), GPAI enforcement powers for the AI Office, and the general governance machinery. This is the date that just passed.
Annex III high-risk obligations SHIFTED BY OMNIBUS
2 August 20262 December 2027
Standalone high-risk systems in the eight Annex III areas (employment, credit, education, law enforcement, migration, essential services, biometrics, justice) now comply from 2 Dec 2027 — a 16-month extension. The Omnibus also narrowed Annex III scope in places.
Annex I high-risk (embedded in regulated products) SHIFTED BY OMNIBUS
2 August 20272 August 2028
AI as a safety component of products under EU safety law (medical devices, machinery, toys, vehicles) — now 2 Aug 2028. The last major milestone.
What the Omnibus did NOT changeProhibitions (2 Feb 2025), GPAI transparency (2 Aug 2025), general application and Art. 50 (2 Aug 2026) all stand. The delay is timeline relief, not repeal — and the exam will test that distinction.[Digital Omnibus, Council approval 29 Jun 2026]
5
Who owes what

Roles & Obligations — The Matcher

The Act assigns duties by role: provider, deployer, importer, distributor, product manufacturer, authorised representative. Six scenarios — match the role to the obligation. This is the other favourite exam format.

Role cheat-sheet

RoleCore dutiesExam tell
ProviderDesign, conformity assessment, CE marking, technical documentation, EU database registration, post-market monitoring"Develops" or "places on the market under own name"
DeployerUse in accordance with instructions, human oversight, monitoring, DPIA/FRIA where applicable, inform workers"Uses" the system in a professional capacity
ImporterVerify provider compliance before placing on market, own-name fallback, cooperation with authorities"Imports from outside the EU"
DistributorVerify CE marking and documentation before making available, withdraw non-compliant products"Makes available on the market" without placing
Product manufacturerFor Annex I systems: manufacturer of the product is treated as provider"Puts its name on the product"
Authorised representativeMandatory for non-EU providers; liaison with authorities, holds documentation"Non-EU provider's EU representative"
6
Easily confused — exam differentiators

Compare & Contrast

Four pairs the exam loves to blur. If you can fill these from memory, the EU AI Act section is yours.

6.1 Prohibited vs high-risk

Prohibited (Art. 5)High-risk (Art. 6)
StatusBanned outright — no compliance pathLawful, but heavily regulated
Since2 Feb 20252 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I)
Fine tier€35M / 7%€15M / 3%
Exam tellManipulation, social scoring, scraping, emotion inferenceEmployment, credit, education, biometric ID, essential services

6.2 Provider vs deployer

ProviderDeployer
WhoDevelops or places on market under own nameUses the system professionally
Core dutyConformity assessment, CE marking, technical fileHuman oversight, monitoring, instructions compliance
DocumentationTechnical documentation, EU database registrationLogs, DPIA/FRIA where applicable
Exam tell"Develops", "places on the market""Uses", "operates", "deploys"

6.3 Annex I vs Annex III high-risk

Annex IAnnex III
RouteAI as safety component of regulated productsStandalone AI in eight listed use areas
ExamplesMedical devices, machinery, toys, vehiclesHiring, credit scoring, education, law enforcement
Deadline2 Aug 2028 (Omnibus)2 Dec 2027 (Omnibus)
ConformityOften via existing sectoral regimes + AI ActSelf-assessment (most) or notified body (some)

6.4 GPAI vs systemic-risk GPAI

GPAI modelSystemic-risk GPAI
DefinitionGeneral-purpose AI model (e.g., foundation models)GPAI with high-impact capabilities — presumed at ≥ 10^25 FLOPs training compute
ObligationsDocumentation, copyright policy, training-data summariesAll GPAI duties + risk assessment, adversarial testing, incident reporting, cybersecurity
Fines€15M / 3% (Art. 101)€15M / 3% (Art. 101)
Exam tell"General-purpose", "foundation model""10^25 FLOPs", "systemic risk", "high-impact"
Exam memory hook — the numbers10^25 FLOPs = systemic-risk presumption. 35/15/7.5 = fine tiers. 2 Feb 25 / 2 Aug 25 / 2 Aug 26 / 2 Dec 27 / 2 Aug 28 = the five dates. 8 = prohibited practices and Annex III areas. 3 = real-time biometric exceptions.[EU AI Act; Digital Omnibus]
7
Self-test · Exam traps

Eight Exam Traps

TRUE / FALSE — instant feedback per question, score tallied at the bottom. Best score persists in this browser.

8
Exam-day readiness

Before Thursday — The Checklist

Tap each item as you master it. The goal: fill every box from memory, not recognition.

§
Citation ledger

Sources