Prohibited
AI practices listed in Article 5 are banned.Example: Social scoring by a public authority. Emotion recognition in a workplace or school is also generally prohibited.
A practical compliance kit
A clear, visual reference for understanding the roles, risk levels, dates and language that shape AI Act compliance.
Navigate the guide
Use this mini reference guide to orient the first conversation around an AI system. It brings together the starting points that help turn a use case into a focused compliance plan.
RRCS gives you a structured first reading of role, risk and compliance readiness.
01. AI Act risk matrix
A practical orientation map. The category follows the AI system’s intended purpose and use in context.
AI practices listed in Article 5 are banned.Example: Social scoring by a public authority. Emotion recognition in a workplace or school is also generally prohibited.
Systems can be high-risk as safety components or regulated products, or when they fall within listed Annex III use cases that can create significant risks.Example: AI used to rank job applicants.
Specific transparency duties apply to certain AI systems and AI-generated content.Example: A customer-facing chatbot should make clear that the user is interacting with AI unless this is obvious from the context.
Most AI systems fall here. The AI Act does not introduce dedicated risk-management obligations for this category.Example: An AI-enabled video game or a spam filter where the intended use does not trigger another category.
General-purpose AI models have their own provider obligations, and models with systemic risk have additional duties. GPAI is a regulatory track rather than a fifth risk level for an AI system.
02. AI Act role matrix
Start with the activity carried out for a specific AI system or general-purpose AI model.
Develops an AI system or GPAI model, or has it developed and places it on the market or puts it into service under its own name.Example: A company launches its own branded CV-screening tool.
Uses an AI system under its authority, except for a purely personal and non-professional activity.Example: An employer uses AI to shortlist candidates.
An EU-established person that first places on the EU market an AI system bearing a non-EU person’s name or trademark.Example: An EU business brings a US-branded AI system to the EU market.
A supply-chain actor, other than provider or importer, that makes an AI system available on the EU market.Example: A reseller supplies a third-party AI product to EU customers.
An EU-established person appointed in writing by a provider to perform specified AI Act obligations and procedures.Example: An EU representative acts for a non-EU GPAI provider.
Can become responsible as a provider where it puts a high-risk AI system into service with its product under its own name.Example: A medical-device maker integrates a branded AI safety component.
An umbrella term covering provider, product manufacturer, deployer, authorised representative, importer and distributor.
03. AI Act application timeline
A clear view of the milestones currently in force and the obligations ahead after Regulation (EU) 2026/1744, the Digital Omnibus on AI.
Definitions and prohibited AI practices started to apply.
Governance rules and obligations for general-purpose AI model providers started to apply.
Regulation (EU) 2026/1744 entered into force and revised parts of the implementation timetable.
The AI Act became generally applicable, including Article 50 transparency obligations, subject to the revised high-risk timetable.
Additional Digital Omnibus measures apply, including rules concerning machine-readable marking for relevant AI-generated content.
National authorities must establish at least one AI regulatory sandbox.
Requirements apply to standalone high-risk AI systems, including relevant Annex III use cases.
Requirements apply to high-risk AI embedded in regulated products and safety components.
04. Essential glossary
A practical alphabetised reference for the legal, technical and operational language of AI Act compliance.
The ongoing work of identifying obligations, implementing controls, retaining evidence and reviewing changes in the AI system and its use.
Knowledge and skills that help staff understand AI systems and use them responsibly. Regulation (EU) 2026/1744 kept the obligation for providers and deployers while removing the requirement to guarantee a specific or sufficient level for every individual.
A computational model used to produce outputs. It forms part of an AI system when combined with further components.
A machine-based system that infers from inputs how to generate outputs such as predictions, content, recommendations or decisions.
The stages from design and development through market placement, use, monitoring, modification and withdrawal.
The list of AI use cases that can be high-risk where the Article 6 classification rules are met.
An EU-established person appointed in writing by a provider to carry out specified AI Act obligations.
The procedure used to demonstrate that a high-risk AI system meets relevant requirements before market placement or use.
The person or organisation using an AI system under its authority, apart from purely personal and non-professional use.
A supply-chain actor, other than provider or importer, that makes an AI system available on the EU market.
A provider that integrates an AI model, including a GPAI model, into an AI system.
The declaration by which a provider states that a high-risk AI system complies with applicable requirements.
A general-purpose AI model with significant generality that can perform a wide range of distinct tasks.
An AI system based on a GPAI model that can serve a variety of purposes, directly or through integration in other systems.
An AI system classified as high-risk under Article 6, including certain regulated products and sensitive use cases.
Measures that enable people to understand, monitor and, where appropriate, intervene in an AI system’s operation.
An EU-established person that places on the EU market an AI system bearing a non-EU person’s name or trademark.
The provider-specified use, including the context and conditions set out in documentation and materials.
An umbrella term covering provider, product manufacturer, deployer, authorised representative, importer and distributor.
Monitoring after market placement or use, used to gather and analyse experience with a high-risk AI system’s performance.
A manufacturer that may become responsible as a provider when placing a high-risk AI system with its product under its own name.
The person or organisation that develops an AI system or GPAI model, or has it developed, and markets it under its name.
Use outside the intended purpose that can still be expected from foreseeable human behaviour or interaction with other systems.
The combination of the probability of harm occurring and the severity of that harm.
A continuous and iterative process for identifying, evaluating and mitigating high-risk AI system risks.
The function an organisation performs for an AI system. The same organisation can hold more than one role.
A component with a safety function, or whose failure or malfunction endangers health, safety or property.
An incident or malfunction linked to an AI system that leads, or may lead, to serious harm as defined by the AI Act.
AI tools used inside an organisation without an approved route, documented assessment or clear governance.
A risk tied to the high-impact capabilities of GPAI models that can have major effects and spread at scale across the value chain.
The documented information required to show how a high-risk AI system was designed, developed and assessed.
A duty to give people clear information about certain AI interactions or AI-generated content, where Article 50 applies.
05. About AAMS
AI Act Made Simple is AAMS’s practical AI compliance initiative. It makes the AI Act more legible for organisations that build, buy, deploy or govern AI, then helps them move from an initial question to an ordered plan.
AAMS brings qualified EU lawyers and registered attorneys with professional AI specialisation into the compliance process. We combine legal analysis with an operational view of the system, its users, evidence and next actions.
06. Your next step
Use this guide to start the conversation. Then bring the system, its intended purpose and its deployment context into the RRCS assessment. AAMS helps you turn that structured first reading into an actionable compliance plan.
Identify your likely AI Act role, the risk signals in your use case and the compliance actions to prioritise first.
Start RRCS assessment