AI Governance Library

Top 10 operational impacts of the EU AI Act

A compiled ten-part IAPP article series on the operational impacts of the EU AI Act, covering scope and definitions, risk categories, obligations for providers and non-providers of high-risk systems, general-purpose AI models, governance, assurance, enforcement and GDPR alignment.
Cover of Top 10 operational impacts of the EU AI Act

⚡ Quick Summary

Published by the IAPP, this compiled ten-part article series examines the operational impacts of the EU AI Act, whose final text was published in the Official Journal of the European Union on 12 July 2024 and entered into force 20 days later. Jointly written by European legal experts, it translates the act's provisions into actionable terms for providers, deployers, importers, distributors, authorised representatives and providers of general-purpose AI models, and places the act alongside the GDPR, NIS2, the Digital Services Act and the Digital Markets Act.

The series follows the act's structure: the 68 definitions and operator roles; the risk-based approach and its categories — prohibited practices, high-risk systems, transparency risks and general-purpose AI models, with systemic risk presumed above 10^25 floating point operations of training compute; the Chapter III requirements for high-risk providers; obligations on non-providers, including fundamental rights impact assessments; Chapter V obligations for general-purpose AI models; the EU and national governance architecture; assurance and conformity assessment; post-market monitoring and incident reporting; and fines of up to 35 million euros or 7% of worldwide annual turnover.

Its message is that the act is in force and being phased in while harmonised standards and guidance remain pending, so organisations need governance programmes that anticipate overlapping obligations across member states and regulatory regimes.

🧩 What’s Covered

The ten articles follow the act's structure, each covering one operational theme.

  • Scope, definitions and actors: subject matter, the 68 definitions, the operator roles of provider, deployer, importer, distributor, product manufacturer and authorised representative, and the exclusions for traditional software, open-source, research and military AI.
  • Understanding and assessing risk: the definition of risk at Article 3(2) and the categories of prohibited practices (Article 5), high-risk systems (Article 6, Annex III), transparency risks (Article 50) and general-purpose AI models.
  • Provider obligations: Articles 8-22 — risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, quality management, ten-year document and six-month log retention, and corrective action.
  • Non-provider obligations: deployer duties (AI literacy, monitoring, oversight, incident reporting, Article 27 impact assessments), importer and distributor due diligence, authorised representatives, and Article 25 role shifts along the value chain.
  • General-purpose AI models: Chapter V's separation of models from systems, systemic risk, Articles 53-55 obligations, Annex XI and XII documentation, codes of practice, open-source carve-outs, and the dates 2 Aug. 2025 and 2 Aug. 2027.
  • Governance: the AI Office, AI Board, Advisory Forum, Scientific Expert Panel, EDPS and standardisation bodies at EU level; member states, market surveillance, notifying, notified and data protection authorities nationally; plus an annex mapping competences.
  • Assurance and conformity assessment: assurance versus compliance, internal (Annex VI) and external (Annex VII) assessment procedures, harmonised standards, common specifications and private assurance tools.
  • Monitoring, enforcement and related regimes: post-market monitoring (Article 72), serious incident reporting (Article 73), fragmented supervision, limited remedies, fines of up to 35 million euros or 7% of turnover, and links to the GDPR, DORA, CRA and NIS2.

💡 Why it matters?

For organisations that place, use or handle AI in the EU, the series turns the act's articles into an operational map: which operator role they hold, which risk category applies, which documents, logs, oversight measures and assessments are required, and when each obligation bites. It is specific about deadlines and figures, from the six-month log retention and ten-year documentation periods to the two general-purpose AI compliance dates. It also flags where the act leaves organisations exposed — pending harmonised standards, absent templates, fragmented national supervision and limited remedies — so governance teams can plan for uncertainty rather than wait for guidance.

❓ What’s Missing

Ten articles cannot cover the whole act, and the series is explicitly selective: it states that indicating every task of each governance body is beyond its scope and defers some topics to later parts. Several central items are described as unavailable at the time of writing: the Article 72 post-market monitoring plan template, the AI Office training-content template, Commission guidance on serious incident reporting and the harmonised standards. The pieces are dated July to November 2024 and describe a phased implementation with open questions, such as how systemic-risk incident reporting will be operationalised. Practical detail on conformity assessment in practice, sectoral application and costs is not provided.

👥 Best For

Best for compliance, privacy and legal teams mapping the act's obligations onto their own organisation, especially providers and deployers of high-risk AI systems and providers of general-purpose AI models. It also serves AI governance and assurance functions designing conformity assessment and post-market monitoring processes, and risk or policy staff who need a structured overview of the EU governance architecture and its links to the GDPR.

📄 Source Details

The full title as printed is Top 10 operational impacts of the EU AI Act; the cover describes it as an article series. It is published by the IAPP, and the individual articles carry bylines and publication dates running from July 2024 to November 2024, with the closing page marked "Published November 2024." It runs to 79 pages. The input was a text extraction covering all 79 pages; the footer shows iapp.org, but no URL for the document itself and no reference number are printed.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.