What the term means, which article supports it and from when it applies.
In Regulation (EU) 2024/1689 almost no term binds everyone in the same way. The same word changes consequence depending on who reads it — whoever builds the system or whoever deploys it in their organisation — and on when they read it, because the obligations did not all start to apply at once.
That is why each entry states the role and the date in words, inside the text. You will not see a loose label: a label is a status, and a status expires.
Not everything that is recommended binds, and not everything worth doing is mandated by a rule. Each entry separates four things that are usually presented mixed together: what the articles impose and already applies; what they impose with a future date already set; what is only recommended by frameworks such as ISO 42001, NIST AI RMF or the guidance of ENISA, the OECD and the Spanish AI supervisory agency (AESIA) — which guide, but do not bind —; and what no rule mandates but is needed to be able to demonstrate what you did.
And it says so tied to whom and to when, inside the sentence and not in a label: the same obligation may fall on whoever builds the system and not on whoever deploys it in their organisation. The AI Act dates, one by one, are in the calendar.
The definitions the Regulation lays down are quoted verbatim, with their article and point. The rest is explained in our own prose, with the article alongside so that anyone can go to the official text and check it.
It is one of the Regulation’s broadest horizontal obligations: it reaches any company using AI, whatever the risk of its tools, and it is a measures-based obligation, not one of result.
It is an organisational decision, not a legal requirement, and confusing the two is costly in both directions.
It is the gateway to the Regulation: everything else — categories, obligations, dates — starts from whether a tool meets this definition.
It is the role of almost any company that buys software with AI in it rather than developing it.
It is the assessment made by whoever decides what personal data are processed for, before starting to process them.
It is the assessment made by whoever uses the system, not whoever makes it, and only a few must do it.
It is the model underneath the tool, and its obligations belong to whoever makes it, not whoever uses it.
It is not “the important AI”: it is a list of areas of use, and being in one of them is not enough.
It is the obligation that what an AI generates carries a mark a machine can read, not a label the user sees.
It is where the vast majority of the tools a company uses sit, and where the obligations are few, but not zero.
The Regulation sets the maximum amounts of the fines (Article 99(3) to (5)); each Member State lays down the penalties regime and its enforcement, and whatever the Regulation does not cap.
It is the only part of the Regulation that admits no risk management: it is not mitigated, not documented — it is not done.
It is whoever develops the system, or has it developed, and puts it on the market under its own name or trademark.
It is one of the three acts that turn a deployer into a provider, and all three exist only on high-risk systems.
It is the only part of the Regulation that allocates obligations between whoever builds and whoever uses, paragraph by paragraph.