AI Act Made Simple2026 mini reference

A practical compliance kit

AI Act Made Simple 2026 guide

A clear, visual reference for understanding the roles, risk levels, dates and language that shape AI Act compliance.

Prepared by AAMS
AI Act compliance, made clear.
Current edition
August 2026

Navigate the guide

A short route through the essentials.

Use this mini reference guide to orient the first conversation around an AI system. It brings together the starting points that help turn a use case into a focused compliance plan.

Ready to map your own use case?

RRCS gives you a structured first reading of role, risk and compliance readiness.

Start RRCS assessment

01. AI Act risk matrix

The risk levels that matter.

A practical orientation map. The category follows the AI system’s intended purpose and use in context.

Unacceptable risk

Prohibited

AI practices listed in Article 5 are banned.Example: Social scoring by a public authority. Emotion recognition in a workplace or school is also generally prohibited.

High risk

High-risk AI

Systems can be high-risk as safety components or regulated products, or when they fall within listed Annex III use cases that can create significant risks.Example: AI used to rank job applicants.

Transparency risk

Limited risk

Specific transparency duties apply to certain AI systems and AI-generated content.Example: A customer-facing chatbot should make clear that the user is interacting with AI unless this is obvious from the context.

Minimal or no risk

Minimal risk

Most AI systems fall here. The AI Act does not introduce dedicated risk-management obligations for this category.Example: An AI-enabled video game or a spam filter where the intended use does not trigger another category.

Separate track

GPAI models

General-purpose AI models have their own provider obligations, and models with systemic risk have additional duties. GPAI is a regulatory track rather than a fifth risk level for an AI system.

02. AI Act role matrix

The roles that matter.

Start with the activity carried out for a specific AI system or general-purpose AI model.

Provider

Develops an AI system or GPAI model, or has it developed and places it on the market or puts it into service under its own name.Example: A company launches its own branded CV-screening tool.

Deployer

Uses an AI system under its authority, except for a purely personal and non-professional activity.Example: An employer uses AI to shortlist candidates.

Importer

An EU-established person that first places on the EU market an AI system bearing a non-EU person’s name or trademark.Example: An EU business brings a US-branded AI system to the EU market.

Distributor

A supply-chain actor, other than provider or importer, that makes an AI system available on the EU market.Example: A reseller supplies a third-party AI product to EU customers.

Authorised representative

An EU-established person appointed in writing by a provider to perform specified AI Act obligations and procedures.Example: An EU representative acts for a non-EU GPAI provider.

Product manufacturer

Can become responsible as a provider where it puts a high-risk AI system into service with its product under its own name.Example: A medical-device maker integrates a branded AI safety component.

Operator

An umbrella term covering provider, product manufacturer, deployer, authorised representative, importer and distributor.

03. AI Act application timeline

The dates that matter.

A clear view of the milestones currently in force and the obligations ahead after Regulation (EU) 2026/1744, the Digital Omnibus on AI.

2 February 2025

Definitions and prohibited AI practices started to apply.

2 August 2025

Governance rules and obligations for general-purpose AI model providers started to apply.

27 July 2026

Regulation (EU) 2026/1744 entered into force and revised parts of the implementation timetable.

2 August 2026

The AI Act became generally applicable, including Article 50 transparency obligations, subject to the revised high-risk timetable.

2 December 2026

Additional Digital Omnibus measures apply, including rules concerning machine-readable marking for relevant AI-generated content.

2 August 2027

National authorities must establish at least one AI regulatory sandbox.

2 December 2027

Requirements apply to standalone high-risk AI systems, including relevant Annex III use cases.

2 August 2028

Requirements apply to high-risk AI embedded in regulated products and safety components.

04. Essential glossary

The words that matter.

A practical alphabetised reference for the legal, technical and operational language of AI Act compliance.

AI compliance

Operational

The ongoing work of identifying obligations, implementing controls, retaining evidence and reviewing changes in the AI system and its use.

AI literacy

Operational

Knowledge and skills that help staff understand AI systems and use them responsibly. Regulation (EU) 2026/1744 kept the obligation for providers and deployers while removing the requirement to guarantee a specific or sufficient level for every individual.

AI model

Technical

A computational model used to produce outputs. It forms part of an AI system when combined with further components.

AI system

Legal

A machine-based system that infers from inputs how to generate outputs such as predictions, content, recommendations or decisions.

AI system lifecycle

Legal

The stages from design and development through market placement, use, monitoring, modification and withdrawal.

Annex III

Legal

The list of AI use cases that can be high-risk where the Article 6 classification rules are met.

Authorised representative

Legal

An EU-established person appointed in writing by a provider to carry out specified AI Act obligations.

Conformity assessment

Legal

The procedure used to demonstrate that a high-risk AI system meets relevant requirements before market placement or use.

Deployer

Legal

The person or organisation using an AI system under its authority, apart from purely personal and non-professional use.

Distributor

Legal

A supply-chain actor, other than provider or importer, that makes an AI system available on the EU market.

Downstream provider

Legal

A provider that integrates an AI model, including a GPAI model, into an AI system.

EU declaration of conformity

Legal

The declaration by which a provider states that a high-risk AI system complies with applicable requirements.

GPAI model

Legal

A general-purpose AI model with significant generality that can perform a wide range of distinct tasks.

GPAI system

Legal

An AI system based on a GPAI model that can serve a variety of purposes, directly or through integration in other systems.

High-risk AI system

Legal

An AI system classified as high-risk under Article 6, including certain regulated products and sensitive use cases.

Human oversight

Legal

Measures that enable people to understand, monitor and, where appropriate, intervene in an AI system’s operation.

Importer

Legal

An EU-established person that places on the EU market an AI system bearing a non-EU person’s name or trademark.

Intended purpose

Legal

The provider-specified use, including the context and conditions set out in documentation and materials.

Operator

Legal

An umbrella term covering provider, product manufacturer, deployer, authorised representative, importer and distributor.

Post-market monitoring

Legal

Monitoring after market placement or use, used to gather and analyse experience with a high-risk AI system’s performance.

Product manufacturer

Legal

A manufacturer that may become responsible as a provider when placing a high-risk AI system with its product under its own name.

Provider

Legal

The person or organisation that develops an AI system or GPAI model, or has it developed, and markets it under its name.

Reasonably foreseeable misuse

Legal

Use outside the intended purpose that can still be expected from foreseeable human behaviour or interaction with other systems.

Risk

Legal

The combination of the probability of harm occurring and the severity of that harm.

Risk management system

Legal

A continuous and iterative process for identifying, evaluating and mitigating high-risk AI system risks.

Role

Operational

The function an organisation performs for an AI system. The same organisation can hold more than one role.

Safety component

Legal

A component with a safety function, or whose failure or malfunction endangers health, safety or property.

Serious incident

Legal

An incident or malfunction linked to an AI system that leads, or may lead, to serious harm as defined by the AI Act.

Shadow AI

Operational

AI tools used inside an organisation without an approved route, documented assessment or clear governance.

Systemic risk

Legal

A risk tied to the high-impact capabilities of GPAI models that can have major effects and spread at scale across the value chain.

Technical documentation

Legal

The documented information required to show how a high-risk AI system was designed, developed and assessed.

Transparency obligation

Legal

A duty to give people clear information about certain AI interactions or AI-generated content, where Article 50 applies.

05. About AAMS

From reference point to compliance plan.

What is AI Act Made Simple?

AI Act Made Simple is AAMS’s practical AI compliance initiative. It makes the AI Act more legible for organisations that build, buy, deploy or govern AI, then helps them move from an initial question to an ordered plan.

Who we are

AAMS brings qualified EU lawyers and registered attorneys with professional AI specialisation into the compliance process. We combine legal analysis with an operational view of the system, its users, evidence and next actions.

RRiskWhat risk signals arise from the use case?
RRoleWhich AI Act role follows your activity?
CComplianceWhat obligations and controls should be prioritised?
SScoreHow ready is the organisation to act on the findings?

06. Your next step

Turn orientation into a focused compliance route.

Use this guide to start the conversation. Then bring the system, its intended purpose and its deployment context into the RRCS assessment. AAMS helps you turn that structured first reading into an actionable compliance plan.

Start with your RRCS assessment

Identify your likely AI Act role, the risk signals in your use case and the compliance actions to prioritise first.

Start RRCS assessment
This guide is a practical orientation resource. Read the official Regulation (EU) 2024/1689 and the amending Regulation (EU) 2026/1744 on EUR-Lex.
AI Act Made Simple · aiactmadesimple.eu