Regulation (EU) 2024/1689
EU AI Act
The EU AI Act introduces risk-based obligations for providers and deployers of AI systems on the EU market. It covers transparency, documentation, human oversight, and prohibitions on unacceptable practices. EUCRAB includes **ClearSource (DPCEA)** for training data provenance and copyright exposure mapping.
Am I affected?
Do you place AI systems on the EU market or put them into service in the EU?
Yes - likely in scope as provider or deployer.
Do you use generative AI or automated decision-making affecting people?
Yes - check transparency and high-risk classification.
Are you a public-sector body or critical infrastructure operator using AI?
Yes - heightened obligations and governance expectations.
Fines & sanctions
| Jurisdiction | Maximum | Notes |
|---|---|---|
| EU (general) | Up to €35M or 7% global turnover | For prohibited AI practices. |
| EU (high-risk) | Up to €15M or 3% turnover | Documentation, monitoring, conformity. |
Key requirements
- Maintain an inventory of AI use cases with risk classification.
- Implement human oversight for high-risk deployments.
- Provide technical documentation and logging where required.
- Ensure AI literacy for staff operating AI-supported processes.
- Register certain high-risk systems in the EU database.
- Document training data provenance where generative or custom models are used (ClearSource DPCEA).
Deadlines
- Prohibited AI practicesFeb 2025
- GPAI obligations (general-purpose AI)Aug 2025
- High-risk system requirements (phased)2026–2027
Documents
Our services
EUCRAB offers audit, compliance, and full-service packages tailored to your assessment results.
View service packages