Vigilis

Knowledge base

The EU AI Act, explained clearly.

Plain-English guides to every part of the Act, who it applies to, the risk tiers, and each obligation by article. Every claim is sourced from the regulation text or official guidance, never invented.

22 guides

Who does the EU AI Act actually apply to?

Most companies assume the AI Act only affects AI developers. It doesn't. Any business deploying AI tools (including ChatGPT, AI-based HR tools, or predictive analytics) may have obligations.

Read guide

Understanding high-risk AI systems under Annex III

Annex III of the AI Act lists 12 specific categories of high-risk AI systems. If your AI system falls into one, you face strict obligations regardless of company size.

Read guide

Provider vs. deployer: what's the difference and why it matters

The obligations you face under the EU AI Act depend critically on whether your company is a provider (builds AI) or deployer (uses AI). Here's how to tell the difference.

Read guide

What documentation does a high-risk AI deployer need?

If you use a high-risk AI system, you need specific documentation. This guide covers exactly what's required under Articles 9, 12, 13, 14, and 26.

Read guide

Prohibited AI practices under Article 5: the 8 practices banned outright

Eight specific AI practices are banned outright, with no compliance pathway, from social scoring to real-time public biometric identification. Here's what each one actually covers.

Read guide

The EU AI Act's four risk tiers, explained

Unacceptable, high, limited, minimal, the Act sorts every AI system into one of four tiers, and the tier determines every obligation that follows.

Read guide

The risk management system required for high-risk AI (Article 9)

Article 9 requires a continuous, documented risk management process across a high-risk system's entire lifecycle, not a one-off document filed before launch.

Read guide

Data governance requirements for high-risk AI training data (Article 10)

Poor data governance is the most common root cause of discriminatory AI outputs. Here's exactly what Article 10 requires of training, validation, and testing data.

Read guide

Technical documentation and Annex IV, explained (Article 11)

Technical documentation is the first thing a market surveillance authority requests. Here's what Annex IV requires it to cover, and why it can't be reconstructed after the fact.

Read guide

Logging and record-keeping obligations under Article 12

Logs are the primary evidence of what a high-risk AI system actually did. Here's what providers must build in, and what deployers must retain and use.

Read guide

Human oversight requirements for high-risk AI systems (Article 14)

A named overseer on paper isn't the same as effective human oversight. Here's what Article 14 requires of system design and of the people who use it.

Read guide

Accuracy, robustness, and cybersecurity requirements (Article 15)

The technical backbone of the Act's safety guarantees, declared accuracy levels, resilience to errors, and defences against AI-specific attacks like data poisoning.

Read guide

CE marking, conformity assessment, and the EU declaration of conformity

Three separate steps stand between meeting the substantive requirements and lawfully placing a high-risk system on the market. Here's how they fit together.

Read guide

Registering a high-risk AI system in the EU database (Article 49)

An unregistered high-risk system is non-compliant on that basis alone. Here's who registers, what Annex VIII requires, and how to keep the entry current.

Read guide

Post-market monitoring and serious incident reporting (Articles 72-73)

Pre-launch testing only proves a system worked in controlled conditions. Here's what ongoing monitoring requires, and the tiered 2/10/15-day incident reporting deadlines.

Read guide

Transparency obligations for chatbots, deepfakes, and emotion recognition (Article 50)

A transparency floor that applies even to otherwise low-risk systems, disclosing AI interaction, labelling synthetic content, and flagging emotion recognition.

Read guide

Fundamental Rights Impact Assessments: who needs one and when (Article 27)

One of the few obligations that falls on the deployer, not the provider, required for public bodies, public-service operators, and credit/insurance risk scoring.

Read guide

Importer, distributor, and authorised representative obligations

You don't have to build or use an AI system to carry legal exposure under the Act. Here's what each supply-chain role is independently responsible for.

Read guide

General-purpose AI model obligations (Articles 51-56)

A distinct regime for GPAI model providers, technical documentation, downstream information duties, copyright policy, and extra rules for models with systemic risk.

Read guide

AI literacy: the Article 4 obligation everyone forgets

The broadest-reaching duty in the Act, live since February 2025, and not tied to any single document, here's what 'to their best extent' actually requires.

Read guide

Penalties and enforcement under the EU AI Act (Article 99)

Fines up to €35 million or 7% of global turnover for the most serious breaches. Here's the full tiered penalty structure, and the softer rule for SMEs.

Read guide

Key EU AI Act compliance deadlines: a phased timeline

The Act doesn't apply all at once. From the February 2025 prohibitions to the 2027 Annex I deadline, here's exactly which obligations activate on which date.

Read guide

Reading up is step one. Knowing your position is step two.

The free AI Act check turns all of this into your specific answer (applicability, role, and risk tier) in a few minutes.

Start the free AI Act check