Regulation (EU) 2024/1689, updated for the Digital Omnibus. The exam tests three things: which tier a system falls into, who owes what, and when it applies. This module makes all three interactive.
The AI Act is a risk pyramid: prohibited, high-risk, limited (transparency), minimal. The exam's favourite question is classification — here are eight scenarios to drill it. Answer, get instant feedback, and the reasoning sticks.
| Tier | What it covers | Key obligations | Status |
|---|---|---|---|
| Prohibited (Art. 5) | Eight practices deemed unacceptable: manipulation, exploitation, social scoring, certain biometrics | Banned outright — cannot be placed on market, put into service, or used | In force since 2 Feb 2025 |
| High-risk (Art. 6 + Annexes I & III) | AI in products under EU safety law (Annex I) + eight listed use areas (Annex III): employment, credit, education, law enforcement, migration, essential services, biometrics, justice | Risk management, data governance, technical documentation, conformity assessment, CE marking, registration in EU database, human oversight, accuracy/robustness/cybersecurity | Annex III: 2 Dec 2027 (Omnibus); Annex I: 2 Aug 2028 |
| Limited / transparency (Art. 50) | Chatbots, deepfakes, emotion recognition, biometric categorisation, synthetic content | Disclosure duties: tell users they are interacting with AI; label deepfakes and synthetic content | In force since 2 Aug 2026 |
| Minimal risk | Everything else — spam filters, games, most enterprise tools | Voluntary codes of conduct; AI literacy (Art. 4) applies to all | In force |
In force since 2 February 2025 — the first obligations to bite. Learn each with its letter (a)–(h) and its exam tell. Fines: up to €35M or 7% of worldwide turnover.
Deploying subliminal, manipulative or deceptive techniques to distort behaviour, causing or likely causing significant harm.
Tell: "imperceptible" or "exploits vulnerabilities" + harm.
Exploiting vulnerabilities of persons due to age, disability or socio-economic situation to distort behaviour, causing significant harm.
Tell: children, elderly, disabled, or economically vulnerable groups.
Evaluation or classification of natural persons based on social behaviour or inferred personal characteristics, where the score leads to detrimental treatment in unrelated contexts, or is unjustified/disproportionate.
Tell: public or private "trustworthiness" scores with harmful consequences.
Assessing or predicting the risk of a person committing a criminal offence based solely on profiling or personality traits/characteristics.
Tell: "solely on profiling" — the key qualifier. Risk assessment of crime patterns is NOT banned.
Creating or expanding facial recognition databases by untargeted scraping of facial images from the internet or CCTV footage.
Tell: Clearview-style scraping — no consent, no targeting.
Inferring emotions of a natural person in the workplace or in educational institutions (with narrow exceptions: medical/safety reasons).
Tell: workplace or classroom emotion detection.
Categorising individuals based on biometric data to infer race, political opinions, religious beliefs, sexual orientation — with narrow law-enforcement exceptions.
Tell: biometrics + sensitive attributes inference.
Real-time remote biometric identification in publicly accessible spaces for law enforcement — banned except for three narrow cases: victims (incl. missing persons), credible threats (terrorism), and serious crimes, each with judicial authorisation.
Tell: the three exceptions + prior judicial approval.
Three fine tiers under Art. 99 — plus the SME lower-of rule. Pick the violation, set the turnover, and see the ceiling. The exam tests the tiers and the SME carve-out, not the arithmetic — but the arithmetic makes it stick.
| Tier | Violation | Ceiling | Article |
|---|---|---|---|
| Top | Prohibited practices (Art. 5); non-compliant training data for GPAI | €35M or 7% of worldwide turnover — whichever higher | Art. 99(3) |
| Mid | Most other obligations: high-risk duties, Art. 50 transparency, GPAI provider duties | €15M or 3% — whichever higher | Art. 99(4) |
| Low | Supplying incorrect, incomplete or misleading information to authorities | €7.5M or 1% — whichever higher | Art. 99(5) |
| SME rule | For SMEs and start-ups, the lower of the two figures applies (not the higher) | Cap effectively halved for SMEs | Art. 99(6) |
| GPAI fines | GPAI model providers: infringement of GPAI obligations, incorrect info, non-compliance with AI Office requests | €15M or 3% (GPAI); systemic-risk GPAI: €15M or 3% | Art. 101 |
The Act applies in phases. The Digital Omnibus (Council approval 29 June 2026, in force 27 July 2026) shifted the high-risk dates — but left the early milestones untouched. Know which dates moved and which didn't.
The Act assigns duties by role: provider, deployer, importer, distributor, product manufacturer, authorised representative. Six scenarios — match the role to the obligation. This is the other favourite exam format.
| Role | Core duties | Exam tell |
|---|---|---|
| Provider | Design, conformity assessment, CE marking, technical documentation, EU database registration, post-market monitoring | "Develops" or "places on the market under own name" |
| Deployer | Use in accordance with instructions, human oversight, monitoring, DPIA/FRIA where applicable, inform workers | "Uses" the system in a professional capacity |
| Importer | Verify provider compliance before placing on market, own-name fallback, cooperation with authorities | "Imports from outside the EU" |
| Distributor | Verify CE marking and documentation before making available, withdraw non-compliant products | "Makes available on the market" without placing |
| Product manufacturer | For Annex I systems: manufacturer of the product is treated as provider | "Puts its name on the product" |
| Authorised representative | Mandatory for non-EU providers; liaison with authorities, holds documentation | "Non-EU provider's EU representative" |
Four pairs the exam loves to blur. If you can fill these from memory, the EU AI Act section is yours.
| Prohibited (Art. 5) | High-risk (Art. 6) | |
|---|---|---|
| Status | Banned outright — no compliance path | Lawful, but heavily regulated |
| Since | 2 Feb 2025 | 2 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I) |
| Fine tier | €35M / 7% | €15M / 3% |
| Exam tell | Manipulation, social scoring, scraping, emotion inference | Employment, credit, education, biometric ID, essential services |
| Provider | Deployer | |
|---|---|---|
| Who | Develops or places on market under own name | Uses the system professionally |
| Core duty | Conformity assessment, CE marking, technical file | Human oversight, monitoring, instructions compliance |
| Documentation | Technical documentation, EU database registration | Logs, DPIA/FRIA where applicable |
| Exam tell | "Develops", "places on the market" | "Uses", "operates", "deploys" |
| Annex I | Annex III | |
|---|---|---|
| Route | AI as safety component of regulated products | Standalone AI in eight listed use areas |
| Examples | Medical devices, machinery, toys, vehicles | Hiring, credit scoring, education, law enforcement |
| Deadline | 2 Aug 2028 (Omnibus) | 2 Dec 2027 (Omnibus) |
| Conformity | Often via existing sectoral regimes + AI Act | Self-assessment (most) or notified body (some) |
| GPAI model | Systemic-risk GPAI | |
|---|---|---|
| Definition | General-purpose AI model (e.g., foundation models) | GPAI with high-impact capabilities — presumed at ≥ 10^25 FLOPs training compute |
| Obligations | Documentation, copyright policy, training-data summaries | All GPAI duties + risk assessment, adversarial testing, incident reporting, cybersecurity |
| Fines | €15M / 3% (Art. 101) | €15M / 3% (Art. 101) |
| Exam tell | "General-purpose", "foundation model" | "10^25 FLOPs", "systemic risk", "high-impact" |
TRUE / FALSE — instant feedback per question, score tallied at the bottom. Best score persists in this browser.
Tap each item as you master it. The goal: fill every box from memory, not recognition.