
One regulation, staggered start dates
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024. Rather than a single effective date, the regulation phases in its obligations: it entered into force on 1 August 2024, the ban on prohibited practices applied from 2 February 2025, the governance rules for general-purpose AI models applied from 2 August 2025, and most high-risk system obligations apply on later dates running out to 2027 and 2028, according to the European Commission's regulatory framework page. A reader checking whether the Act 'applies' to a given system needs the specific provision's date, not a single headline date for the whole regulation.
Risk tiers, and a separate track for general-purpose models
The Act sorts AI systems into unacceptable-risk practices that are banned outright, including certain social-scoring and manipulative systems, high-risk systems subject to documentation, oversight and monitoring duties, limited-risk systems subject to disclosure obligations, and everything else. General-purpose AI models sit outside this system-level ladder: any provider owes baseline duties, including technical documentation, information for downstream developers, a published summary of training content, and respect for EU copyright rules, regardless of what a downstream deployer builds with the model. A narrower band of 'systemic risk' models carries extra duties again: adversarial testing, systemic risk assessment, incident tracking to the EU's AI Office, and cybersecurity controls. The Act presumes systemic risk once a model's training compute exceeds 10^25 floating-point operations, according to the explainer site artificialintelligenceact.eu, though the Commission can also designate a model as systemically risky below that threshold, and a provider can argue against the presumption above it.
What a deployer owes, separate from a provider
The Act distinguishes the provider that builds a system from the deployer that puts it into use. A deployer of a high-risk system owes human oversight of its operation, monitoring for and reporting of serious incidents, and awareness of the capability and compliance information the provider must supply, a narrower set of duties than the provider carries, but not a free pass for downstream use. This provider and deployer split, and the separate general-purpose track, mean a single product can trigger obligations under more than one part of the Act depending on whether an organisation built the underlying model, fine-tuned it, or only deployed it inside an application.
- Which specific provision's application date governs this system, and has that date already passed?
- Is the organisation a provider, a deployer, or both, for this particular AI system, and does its compliance file reflect that role correctly?
- If a general-purpose model is involved, has anyone checked its declared or estimated training compute against the systemic-risk threshold?
The Act's complexity is largely a function of trying to regulate models, systems and roles with a single instrument; treating it as one uniform rule with one start date will misstate most organisations' actual obligations.
Sources & reading trail
Official Journal text and publication date, and the source for the Act's risk-tier structure.
Source published: 12 July 2024 · Retrieved: 16 September 2026
European Commission page giving the phased application dates and deployer obligations for high-risk systems.
Source published: Not established · Retrieved: 16 September 2026
Third-party explainer used only for the 10^25 FLOP systemic-risk threshold and general-purpose model obligations.
Source published: Not established · Retrieved: 16 September 2026
Papers and official documents establish the record; the reading and the questions are Model Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.