EU AI Act 2026 Flashcards: Timeline, Roles & Risk Rules

A 140-card, source-linked review of the amended EU AI Act timeline, roles, risk structure, GPAI, transparency, high-risk duties, and enforcement.

Về bộ thẻ này

EU AI Act 2026 Flashcards: Timeline, Roles & Risk Rules

Build reliable recall of the amended EU AI Act with 140 focused, source-linked cards. The deck covers implementation dates, scope and exclusions, prohibited practices, provider and deployer roles, GPAI, Article 50 transparency, high-risk duties, governance, and penalty ceilings.

What you will practise

  • Separate entry into force, general applicability, and later high-risk dates.
  • Distinguish providers, deployers, importers, distributors, authorised representatives, and affected persons.
  • Recall the risk gateways, prohibited practices, GPAI duties, and Article 50 disclosure rules.
  • Recognise when a fact needs a fresh official-source check or fact-specific legal analysis.

Recall map and exclusions

The deck practises milestone → date and selected date → milestone recall, term or role → definition or duty, and rule or fact pattern → legal status, exception, or consequence. Composite prompts are limited to tests whose parts work together, including the Article 6 high-risk gateways and the role-specific triggers for the two 2026 prohibitions. Mechanical reversals of every definition, citation, exception, penalty ceiling, and multi-answer duty list are excluded because they would duplicate existing prompts or allow several correct answers.

Freshness

Official sources were checked on 26 August 2026. The deck incorporates Regulation (EU) 2026/1744 and the amended implementation timeline. Every card links to an official EU source and carries its retrieval date. Recheck EUR-Lex and the Commission timeline for later changes.

Important boundary

This deck is educational material, not legal advice. It does not classify any real AI system, decide whether an exception applies, or resolve a fact-specific compliance question. Consult qualified counsel and the competent authority for an actual system.

Sources and method

The primary source is the 27 July 2026 consolidated text of Regulation (EU) 2024/1689, read with Regulation (EU) 2026/1744. Commission timeline, FAQ, regulatory-framework, enforcement, GPAI, prohibited-practice, and Article 50 pages provide current implementation context. Commission guidance is useful but non-binding; courts and competent authorities give authoritative interpretations.

Cards use one root tag, EU AI Act, plus one learning group. The final order rotates across groups so related rules and exceptions are separated for stronger retrieval practice.

Independent study aid

This independently authored deck is unofficial. It is not affiliated with, endorsed by, or official material from the European Union, the European Commission, or any other EU institution.

Thẻ trong bộ này

  1. Thẻ 1

    Câu hỏi

    When did the EU AI Act enter into force?

    Câu trả lời

    Answer. 1 August 2024, twenty days after publication in the Official Journal. Most duties did not apply immediately; the Act uses a phased timetable.

    Source: European Commission implementation timeline. Retrieved 2026-08-26.

  2. Thẻ 2

    Câu hỏi

    When can the EU AI Act apply to a provider outside the EU?

    Câu trả lời

    Answer. When the provider places an AI system or GPAI model on the EU market, puts an AI system into service in the EU, or when the output of its AI system is used in the EU. The exact facts still matter.

    Source: Regulation (EU) 2024/1689, Article 2. Retrieved 2026-08-26.

  3. Thẻ 3

    Câu hỏi

    Who is a provider under the EU AI Act?

    Câu trả lời

    Answer. A person, public authority, agency, or other body that develops an AI system or GPAI model, or has one developed, and places it on the market or puts the system into service under its own name or trademark, whether paid or free.

    Source: Regulation (EU) 2024/1689, Article 3(3). Retrieved 2026-08-26.

  4. Thẻ 4

    Câu hỏi

    What is a general-purpose AI model?

    Câu trả lời

    Answer. An AI model with significant generality that can competently perform a wide range of distinct tasks and can be integrated into many downstream systems or applications. Models used only for research, development, or prototyping before market placement are excluded from this definition.

    Source: Regulation (EU) 2024/1689, Article 3(63). Retrieved 2026-08-26.

  5. Thẻ 5

    Câu hỏi

    When must people be told they are interacting with AI?

    Câu trả lời

    Answer. Providers must design direct-interaction AI systems so people are informed that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant, and circumspect person in the circumstances.

    Source: Regulation (EU) 2024/1689, Article 50(1). Retrieved 2026-08-26.

  6. Thẻ 6

    Câu hỏi

    What is the core purpose of high-risk AI risk management?

    Câu trả lời

    Answer. To establish a continuous, iterative lifecycle process that identifies, analyses, evaluates, and treats known and reasonably foreseeable risks to health, safety, and fundamental rights, then tests whether controls work.

    Source: Regulation (EU) 2024/1689, Article 9. Retrieved 2026-08-26.

  7. Thẻ 7

    Câu hỏi

    Who enforces most EU AI Act rules?

    Câu trả lời

    Answer. National competent authorities, including market-surveillance authorities, enforce most AI-system rules in Member States. The Commission’s AI Office has central responsibilities, especially for GPAI.

    Source: European Commission enforcement framework. Retrieved 2026-08-26.

  8. Thẻ 8

    Câu hỏi

    Which EU AI Act rules began applying on 2 February 2025?

    Câu trả lời

    Answer. The AI-system definition and scope-related provisions, AI-literacy duty, and most original prohibited-practice rules began applying on 2 February 2025.

    Source: European Commission implementation timeline. Retrieved 2026-08-26.

  9. Thẻ 9

    Câu hỏi

    Does the EU AI Act apply to an EU-based deployer?

    Câu trả lời

    Answer. Yes. The Act applies to deployers that have their place of establishment or are located in the EU, subject to the Act’s specific exclusions and transitions.

    Source: Regulation (EU) 2024/1689, Article 2(1)(b). Retrieved 2026-08-26.

  10. Thẻ 10

    Câu hỏi

    Who is a deployer under the EU AI Act?

    Câu trả lời

    Answer. A person, public authority, agency, or other body using an AI system under its authority, except where the system is used in a personal, non-professional activity.

    Source: Regulation (EU) 2024/1689, Article 3(4). Retrieved 2026-08-26.

  11. Thẻ 11

    Câu hỏi

    Which baseline duties apply to all GPAI-model providers?

    Câu trả lời

    Answer. Keep technical documentation current, give downstream providers information needed for integration and compliance, maintain an EU-copyright-compliance policy, publish a sufficiently detailed training-content summary, and cooperate with authorities.

    Source: Regulation (EU) 2024/1689, Article 53. Retrieved 2026-08-26.

  12. Thẻ 12

    Câu hỏi

    Who must machine-mark AI-generated content under Article 50?

    Câu trả lời

    Answer. Providers of AI systems that generate synthetic audio, image, video, or text content must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.

    Source: Regulation (EU) 2024/1689, Article 50(2). Retrieved 2026-08-26.

  13. Thẻ 13

    Câu hỏi

    What data quality does Article 10 require for high-risk AI?

    Câu trả lời

    Answer. Training, validation, and testing datasets must be governed appropriately and, for their intended purpose, be relevant, sufficiently representative, and as far as possible free of errors and complete, with suitable statistical properties.

    Source: Regulation (EU) 2024/1689, Article 10. Retrieved 2026-08-26.

  14. Thẻ 14

    Câu hỏi

    What is the European AI Office’s main EU AI Act role?

    Câu trả lời

    Answer. It supports implementation and enforcement at EU level, including central supervision of GPAI obligations and coordination, guidance, evaluations, and investigations within its legal remit.

    Source: European Commission enforcement framework. Retrieved 2026-08-26.

  15. Thẻ 15

    Câu hỏi

    Which EU AI Act rules began applying on 2 August 2025?

    Câu trả lời

    Answer. The GPAI obligations and much of the governance framework began applying on 2 August 2025, alongside Member State penalty-notification and authority-designation steps.

    Source: European Commission implementation timeline. Retrieved 2026-08-26.

  16. Thẻ 16

    Câu hỏi

    When can EU output-use bring a non-EU actor into scope?

    Câu trả lời

    Answer. When a provider or deployer is outside the EU but the output produced by its AI system is used in the EU. This is a territorial hook, not an automatic conclusion about every remote service.

    Source: Regulation (EU) 2024/1689, Article 2(1)(c). Retrieved 2026-08-26.

  17. Thẻ 17

    Câu hỏi

    Who is an importer under the EU AI Act?

    Câu trả lời

    Answer. An EU-located or EU-established person that places on the market an AI system bearing the name or trademark of a person established outside the EU.

    Source: Regulation (EU) 2024/1689, Article 3(6). Retrieved 2026-08-26.

  18. Thẻ 18

    Câu hỏi

    When is a GPAI model presumed to have systemic risk?

    Câu trả lời

    Answer. When cumulative training compute exceeds 10^25 floating-point operations, the model is presumed to have high-impact capabilities and therefore systemic risk, unless the legal classification is successfully rebutted.

    Source: Regulation (EU) 2024/1689, Articles 51–52. Retrieved 2026-08-26.

  19. Thẻ 19

    Câu hỏi

    How strong must Article 50 machine marking be?

    Câu trả lời

    Answer. The technical solution must be effective, interoperable, robust, and reliable as far as technically feasible, considering the content’s nature, implementation costs, and generally acknowledged state of the art.

    Source: Regulation (EU) 2024/1689, Article 50(2). Retrieved 2026-08-26.

  20. Thẻ 20

    Câu hỏi

    When must high-risk technical documentation exist?

    Câu trả lời

    Answer. It must be drawn up before the high-risk system is placed on the market or put into service and kept up to date throughout the relevant lifecycle.

    Source: Regulation (EU) 2024/1689, Article 11. Retrieved 2026-08-26.

  21. Thẻ 21

    Câu hỏi

    What does the European AI Board do?

    Câu trả lời

    Answer. It advises and assists the Commission and Member States to support consistent and effective application of the Act, including coordination among national authorities and sharing technical and regulatory expertise.

    Source: Regulation (EU) 2024/1689, Articles 65–66. Retrieved 2026-08-26.

  22. Thẻ 22

    Câu hỏi

    What was the EU AI Act’s general applicability date?

    Câu trả lời

    Answer. 2 August 2026. Important exceptions and later dates remain, especially for certain prohibitions, high-risk categories, and legacy GPAI models.

    Source: European Commission implementation timeline. Retrieved 2026-08-26.

  23. Thẻ 23

    Câu hỏi

    Which national-security activity is outside the EU AI Act?

    Câu trả lời

    Answer. The Act does not apply to areas outside EU law and does not affect Member State competences concerning national security, regardless of the entity carrying out the national-security tasks.

    Source: Regulation (EU) 2024/1689, Article 2(3). Retrieved 2026-08-26.

  24. Thẻ 24

    Câu hỏi

    Who is a distributor under the EU AI Act?

    Câu trả lời

    Answer. A supply-chain person, other than the provider or importer, that makes an AI system available on the EU market.

    Source: Regulation (EU) 2024/1689, Article 3(7). Retrieved 2026-08-26.

  25. Thẻ 25

    Câu hỏi

    Can the Commission classify a GPAI model as systemic risk below 10^25 FLOPs?

    Câu trả lời

    Answer. Yes. The Commission may designate a model when it has high-impact capabilities evaluated through appropriate technical tools and criteria, even without crossing the compute presumption.

    Source: Regulation (EU) 2024/1689, Article 51. Retrieved 2026-08-26.

  26. Thẻ 26

    Câu hỏi

    Who must disclose AI-generated deepfakes?

    Câu trả lời

    Answer. Deployers of AI systems that generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content was artificially generated or manipulated.

    Source: Regulation (EU) 2024/1689, Article 50(4). Retrieved 2026-08-26.

  27. Thẻ 27

    Câu hỏi

    What logging capability must a high-risk AI system have?

    Câu trả lời

    Answer. It must technically allow automatic recording of events over its lifetime to support traceability, monitoring, post-market work, and investigation appropriate to the system’s purpose.

    Source: Regulation (EU) 2024/1689, Article 12. Retrieved 2026-08-26.

  28. Thẻ 28

    Câu hỏi

    What is the Scientific Panel’s governance role?

    Câu trả lời

    Answer. The independent Scientific Panel supports enforcement with technical expertise, including alerts and advice on GPAI models, systemic risks, evaluations, and other technically complex matters.

    Source: Regulation (EU) 2024/1689, Articles 68 and 90. Retrieved 2026-08-26.

  29. Thẻ 29

    Câu hỏi

    What did Regulation (EU) 2026/1744 do to the AI Act timetable?

    Câu trả lời

    Answer. It amended Regulation (EU) 2024/1689, including deferred dates for Annex III and Annex I high-risk obligations and targeted Article 50 and prohibited-practice transitions.

    Source: Regulation (EU) 2026/1744. Retrieved 2026-08-26.

  30. Thẻ 30

    Câu hỏi

    Are exclusively military or defence AI systems covered?

    Câu trả lời

    Answer. No. The Act excludes AI systems placed on the market, put into service, or used exclusively for military, defence, or national-security purposes, regardless of the actor. Mixed or changed uses need separate analysis.

    Source: Regulation (EU) 2024/1689, Article 2(3). Retrieved 2026-08-26.

  31. Thẻ 31

    Câu hỏi

    Who is an authorised representative under the EU AI Act?

    Câu trả lời

    Answer. An EU-located or EU-established person that receives and accepts a written mandate from a provider to perform specified obligations and procedures on the provider’s behalf.

    Source: Regulation (EU) 2024/1689, Article 3(5). Retrieved 2026-08-26.

  32. Thẻ 32

    Câu hỏi

    When must a GPAI provider notify the Commission of a systemic-risk threshold?

    Câu trả lời

    Answer. Without delay and, in any event, within two weeks after the provider knows or has reasonable grounds to believe the model meets the systemic-risk condition.

    Source: Regulation (EU) 2024/1689, Article 52(1). Retrieved 2026-08-26.

  33. Thẻ 33

    Câu hỏi

    How does Article 50 treat artistic deepfakes?

    Câu trả lời

    Answer. For evidently artistic, creative, satirical, fictional, or analogous works, disclosure may be made in an appropriate way that does not hamper display or enjoyment of the work. The disclosure duty still exists.

    Source: Regulation (EU) 2024/1689, Article 50(4). Retrieved 2026-08-26.

  34. Thẻ 34

    Câu hỏi

    What information must accompany a high-risk AI system?

    Câu trả lời

    Answer. Concise, complete, correct, and clear instructions for use with the provider’s identity, capabilities and limits, intended purpose, performance, risks, human-oversight measures, input-data specifications, logging, maintenance, and other legally required details.

    Source: Regulation (EU) 2024/1689, Article 13. Retrieved 2026-08-26.

  35. Thẻ 35

    Câu hỏi

    What is the Advisory Forum’s role?

    Câu trả lời

    Answer. It supplies stakeholder expertise and advice to the AI Board and Commission through a balanced group representing industry, startups, civil society, academia, and other affected interests.

    Source: Regulation (EU) 2024/1689, Article 67. Retrieved 2026-08-26.

  36. Thẻ 36

    Câu hỏi

    When did Regulation (EU) 2026/1744 enter into force?

    Câu trả lời

    Answer. 27 July 2026. The amendment changed the then-current consolidated AI Act and must be considered when studying implementation dates.

    Source: Regulation (EU) 2026/1744, Article 4. Retrieved 2026-08-26.

  37. Thẻ 37

    Câu hỏi

    Is pure scientific research and development covered?

    Câu trả lời

    Answer. The Act does not apply to AI systems or models, including outputs, specifically developed and put into service for the sole purpose of scientific research and development. Other uses need separate analysis.

    Source: Regulation (EU) 2024/1689, Article 2(6). Retrieved 2026-08-26.

  38. Thẻ 38

    Câu hỏi

    Which actors count as operators under the EU AI Act?

    Câu trả lời

    Answer. Providers, product manufacturers, deployers, authorised representatives, importers, and distributors. “Operator” is the Act’s umbrella term for these value-chain roles.

    Source: Regulation (EU) 2024/1689, Article 3(8). Retrieved 2026-08-26.

  39. Thẻ 39

    Câu hỏi

    Can a GPAI provider challenge the systemic-risk presumption?

    Câu trả lời

    Answer. Yes. With the threshold notification, the provider may present sufficiently substantiated arguments that the model exceptionally does not present systemic risks despite meeting the compute presumption. The Commission decides.

    Source: Regulation (EU) 2024/1689, Article 52(2). Retrieved 2026-08-26.

  40. Thẻ 40

    Câu hỏi

    When must AI-generated public-interest text be disclosed?

    Câu trả lời

    Answer. A deployer must disclose artificial generation or manipulation when publishing AI-generated or manipulated text to inform the public on matters of public interest, unless a stated exception applies.

    Source: Regulation (EU) 2024/1689, Article 50(4). Retrieved 2026-08-26.

  41. Thẻ 41

    Câu hỏi

    What must human oversight enable for high-risk AI?

    Câu trả lời

    Answer. Effective oversight by competent people who can understand capabilities and limits, detect anomalies and automation bias, interpret outputs, decide not to use or override them, and safely interrupt the system where appropriate.

    Source: Regulation (EU) 2024/1689, Article 14. Retrieved 2026-08-26.

  42. Thẻ 42

    Câu hỏi

    Can a person complain about an alleged AI Act infringement?

    Câu trả lời

    Answer. Yes. Any natural or legal person with grounds to consider that the Act was infringed may lodge a complaint with the relevant market-surveillance authority, without prejudice to other remedies.

    Source: Regulation (EU) 2024/1689, Article 85. Retrieved 2026-08-26.

  43. Thẻ 43

    Câu hỏi

    When do the two new 2026 prohibited practices begin applying?

    Câu trả lời

    Answer. 2 December 2026. They concern specified non-consensual intimate or sexually explicit deepfakes and specified child-sexual-abuse material or performances.

    Source: Regulation (EU) 2026/1744, Article 1 and transition provisions. Retrieved 2026-08-26.

  44. Thẻ 44

    Câu hỏi

    Is pre-market AI research, testing, or development covered?

    Câu trả lời

    Answer. Generally no, before placement on the market or putting into service, if the activity respects applicable EU law. Testing in real-world conditions is not part of this exclusion.

    Source: Regulation (EU) 2024/1689, Article 2(8). Retrieved 2026-08-26.

  45. Thẻ 45

    Câu hỏi

    Is an affected person an operator?

    Câu trả lời

    Answer. No. “Operator” covers specified supply-chain and use roles. An affected person is someone in the EU affected by an AI system and may hold rights such as complaint or explanation rights where their conditions are met.

    Source: Regulation (EU) 2024/1689, Articles 2, 3(8), 85–86. Retrieved 2026-08-26.

  46. Thẻ 46

    Câu hỏi

    What must GPAI technical documentation cover?

    Câu trả lời

    Answer. The model’s development, training, testing, evaluation, architecture, design specifications, capabilities, limitations, and other information required by Annex XI, kept current and available to the AI Office and national authorities on request.

    Source: Regulation (EU) 2024/1689, Article 53(1)(a) and Annex XI. Retrieved 2026-08-26.

  47. Thẻ 47

    Câu hỏi

    What is the public-interest text disclosure exception for human review?

    Câu trả lời

    Answer. Disclosure is not required when the AI-generated content underwent human review or editorial control and a natural or legal person holds editorial responsibility for publication.

    Source: Regulation (EU) 2024/1689, Article 50(4). Retrieved 2026-08-26.

  48. Thẻ 48

    Câu hỏi

    Which performance qualities must high-risk AI maintain?

    Câu trả lời

    Answer. An appropriate level of accuracy, robustness, and cybersecurity throughout the lifecycle, consistent with the system’s intended purpose and the acknowledged state of the art.

    Source: Regulation (EU) 2024/1689, Article 15. Retrieved 2026-08-26.

  49. Thẻ 49

    Câu hỏi

    When does Article 86 give an explanation right?

    Câu trả lời

    Answer. When a deployer takes a decision about an affected person on the basis of output from an Annex III high-risk system, except point 2 systems, and the decision produces legal effects or similarly significantly affects that person in a way they consider adverse to their health, safety, or fundamental rights, subject to the Article’s conditions and exceptions.

    Source: Regulation (EU) 2024/1689, Article 86. Retrieved 2026-08-26.

  50. Thẻ 50

    Câu hỏi

    What is the Article 50 transition for older synthetic-content systems?

    Câu trả lời

    Answer. A system placed on the market before 2 August 2026 that generates or manipulates synthetic content has until 2 December 2026 to comply with Article 50(2)’s machine-readable marking duty.

    Source: Regulation (EU) 2026/1744, Article 1 transition amendment. Retrieved 2026-08-26.

  51. Thẻ 51

    Câu hỏi

    Does personal non-professional AI use fall under deployer duties?

    Câu trả lời

    Answer. No. A natural person using AI in a purely personal, non-professional activity is excluded from the deployer definition and the Act does not apply to that use. Other applicable law can still matter.

    Source: Regulation (EU) 2024/1689, Articles 2(10) and 3(4). Retrieved 2026-08-26.

  52. Thẻ 52

    Câu hỏi

    When does a downstream actor become the provider of an AI system?

    Câu trả lời

    Answer. If it places its name or trademark on a high-risk system, makes a substantial modification, or changes the intended purpose so a previously non-high-risk system becomes high-risk.

    Source: Regulation (EU) 2024/1689, Article 25. Retrieved 2026-08-26.

  53. Thẻ 53

    Câu hỏi

    What must GPAI providers tell downstream system providers?

    Câu trả lời

    Answer. They must provide and maintain information and documentation enabling downstream providers to understand the model’s capabilities and limitations and comply with the Act, without disclosing protected intellectual property unnecessarily.

    Source: Regulation (EU) 2024/1689, Article 53(1)(b) and Annex XII. Retrieved 2026-08-26.

  54. Thẻ 54

    Câu hỏi

    Who must be informed about emotion-recognition use?

    Câu trả lời

    Answer. Deployers of emotion-recognition systems must inform the natural persons exposed to the system and process personal data consistently with EU data-protection law.

    Source: Regulation (EU) 2024/1689, Article 50(3). Retrieved 2026-08-26.

  55. Thẻ 55

    Câu hỏi

    What is a high-risk provider’s basic compliance duty?

    Câu trả lời

    Answer. Ensure the system complies with the Chapter III Section 2 requirements, identify itself, operate quality and documentation controls, complete conformity steps, register where required, take corrective action, and cooperate with authorities.

    Source: Regulation (EU) 2024/1689, Article 16. Retrieved 2026-08-26.

  56. Thẻ 56

    Câu hỏi

    What must an Article 86 explanation contain?

    Câu trả lời

    Answer. Clear and meaningful explanations of the AI system’s role in the decision-making procedure and the main elements of the decision taken. It is not a general right to source code or every model detail.

    Source: Regulation (EU) 2024/1689, Article 86. Retrieved 2026-08-26.

  57. Thẻ 57

    Câu hỏi

    When do Annex III high-risk duties begin applying after the 2026 amendment?

    Câu trả lời

    Answer. 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, subject to the Act’s detailed transitions and any applicable exceptions.

    Source: Regulation (EU) 2026/1744. Retrieved 2026-08-26.

  58. Thẻ 58

    Câu hỏi

    Does open-source release create a blanket EU AI Act exemption?

    Câu trả lời

    Answer. No. The free-and-open-source exception does not cover systems placed on the market or put into service as high-risk systems or systems falling under Article 5 or Article 50. Other conditions also matter.

    Source: Regulation (EU) 2024/1689, Article 2(12). Retrieved 2026-08-26.

  59. Thẻ 59

    Câu hỏi

    What happens to the original provider after a downstream actor becomes provider?

    Câu trả lời

    Answer. For that specific system, the original provider is no longer treated as provider under Article 25, but must cooperate and supply reasonably expected technical access and information unless it clearly prohibited the conversion into a high-risk system.

    Source: Regulation (EU) 2024/1689, Article 25. Retrieved 2026-08-26.

  60. Thẻ 60

    Câu hỏi

    What copyright policy must a GPAI provider maintain?

    Câu trả lời

    Answer. A policy to comply with EU copyright and related-rights law, including identifying and respecting rights reservations expressed under Article 4(3) of the Digital Single Market Copyright Directive.

    Source: Regulation (EU) 2024/1689, Article 53(1)(c). Retrieved 2026-08-26.

  61. Thẻ 61

    Câu hỏi

    Who must be informed about biometric-categorisation use?

    Câu trả lời

    Answer. Deployers of biometric-categorisation systems must inform the natural persons exposed to the system and process personal data under applicable EU data-protection rules. Article 5 separately prohibits certain sensitive-trait categorisation.

    Source: Regulation (EU) 2024/1689, Article 50(3). Retrieved 2026-08-26.

  62. Thẻ 62

    Câu hỏi

    What must a high-risk provider’s quality-management system cover?

    Câu trả lời

    Answer. A documented, proportionate system covering compliance strategy, design and development, testing, data, technical specifications, verification, records, accountability, post-market monitoring, incident reporting, communications, and continuous improvement.

    Source: Regulation (EU) 2024/1689, Article 17. Retrieved 2026-08-26.

  63. Thẻ 63

    Câu hỏi

    What is the top fine tier for prohibited AI practices?

    Câu trả lời

    Answer. Up to €35 million or, for undertakings, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, subject to the Act’s penalty rules and case-specific assessment.

    Source: Regulation (EU) 2024/1689, Article 99(3). Retrieved 2026-08-26.

  64. Thẻ 64

    Câu hỏi

    How do the AI Act’s application rules differ for Annex I Section A and Section B high-risk systems?

    Câu trả lời

    Answer. Section A systems enter the Chapter III, Sections 1–3 regime on 2 August 2028. Section B systems do not take on that full regime: Article 2(2) limits the AI Act to Articles 6(1), 60a, and 102–112, with Articles 57–59 applying only when high-risk requirements are integrated into the relevant sectoral law. Articles 102–110 have applied since 27 July 2026.

    Source: Regulation (EU) 2024/1689, Articles 2(2) and 113. Retrieved 2026-08-26.

  65. Thẻ 65

    Câu hỏi

    Does the EU AI Act replace privacy law?

    Câu trả lời

    Answer. No. EU data-protection, privacy, communications-confidentiality, and consumer-protection law continue to apply. AI Act compliance does not by itself establish compliance with those rules.

    Source: Regulation (EU) 2024/1689, Article 2 and recitals. Retrieved 2026-08-26.

  66. Thẻ 66

    Câu hỏi

    When is a product manufacturer treated as an AI-system provider?

    Câu trả lời

    Answer. For a high-risk AI system that is a safety component of a product covered by Section A of Annex I, the product manufacturer becomes the provider and takes on Article 16 duties if either: (1) the system is placed on the market together with the product under the manufacturer’s name or trademark; or (2) the system is put into service under that name or trademark after the product has already been placed on the market.

    Source: Regulation (EU) 2024/1689, Article 25(3). Retrieved 2026-08-26.

  67. Thẻ 67

    Câu hỏi

    What training-content disclosure must a GPAI provider publish?

    Câu trả lời

    Answer. A sufficiently detailed summary of the content used to train the model, using the template provided by the AI Office. It is a public transparency duty, not a requirement to publish every training item.

    Source: Regulation (EU) 2024/1689, Article 53(1)(d). Retrieved 2026-08-26.

  68. Thẻ 68

    Câu hỏi

    When must an Article 50 disclosure be presented?

    Câu trả lời

    Answer. In a clear and distinguishable manner no later than the first interaction with or exposure to the AI system or its output, while satisfying applicable accessibility requirements.

    Source: Regulation (EU) 2024/1689, Article 50(5). Retrieved 2026-08-26.

  69. Thẻ 69

    Câu hỏi

    How long must high-risk providers keep core compliance documents?

    Câu trả lời

    Answer. Generally ten years after the AI system is placed on the market or put into service, including technical documentation, quality-system documentation, changes approved by notified bodies, notified-body decisions, and the EU declaration of conformity.

    Source: Regulation (EU) 2024/1689, Article 18. Retrieved 2026-08-26.

  70. Thẻ 70

    Câu hỏi

    What is the main fine tier for listed operator and Article 50 violations?

    Câu trả lời

    Answer. Up to €15 million or, for undertakings, up to 3% of total worldwide annual turnover for the preceding year, whichever is higher, subject to the exact provision and case-specific penalty assessment.

    Source: Regulation (EU) 2024/1689, Article 99(4). Retrieved 2026-08-26.

    Abstract blue and gold pathways converging around a balanced circular framework on a deep navy background.

    140 thẻ

    EU AI Act 2026 Flashcards: Timeline, Roles & Risk Rules

    Học bộ thẻ này miễn phí

    Nibomo sẽ mở ra để bạn bắt đầu học.

  71. Thẻ 71

    Câu hỏi

    When must Member States have at least one AI regulatory sandbox operational?

    Câu trả lời

    Answer. By 2 August 2027, either nationally or through joint participation with other Member States, according to the Commission’s current implementation timeline.

    Source: European Commission implementation timeline. Retrieved 2026-08-26.

  72. Thẻ 72

    Câu hỏi

    What makes software an AI system under the Act?

    Câu trả lời

    Answer. It must be machine-based, operate with varying autonomy, possibly adapt after deployment, infer from inputs how to generate outputs such as predictions, content, recommendations, or decisions, and influence physical or virtual environments.

    Source: Regulation (EU) 2024/1689, Article 3(1). Retrieved 2026-08-26.

  73. Thẻ 73

    Câu hỏi

    Must a provider’s identity be visible on a high-risk AI system?

    Câu trả lời

    Answer. Yes. The provider must place its name, registered trade name or trademark, and contact address on the system or, when that is not possible, on packaging or accompanying documentation.

    Source: Regulation (EU) 2024/1689, Article 16(b). Retrieved 2026-08-26.

  74. Thẻ 74

    Câu hỏi

    Which GPAI duties may an open-source provider avoid?

    Câu trả lời

    Answer. If the model meets the qualifying free-and-open-source conditions and is not systemic-risk, Article 53(1)(a) and (b) technical and downstream documentation duties do not apply. Copyright policy, training summary, and cooperation duties remain.

    Source: Regulation (EU) 2024/1689, Article 53(2). Retrieved 2026-08-26.

  75. Thẻ 75

    Câu hỏi

    Must Article 50 disclosures be accessible?

    Câu trả lời

    Answer. Yes. The information must meet applicable accessibility requirements in addition to being clear, distinguishable, and timely. The right format depends on the surface and audience.

    Source: Regulation (EU) 2024/1689, Article 50(5). Retrieved 2026-08-26.

  76. Thẻ 76

    Câu hỏi

    Must high-risk providers keep automatically generated logs?

    Câu trả lời

    Answer. Yes, when the logs are under their control. Providers must retain them for a period appropriate to the system’s intended purpose and generally at least six months unless other law provides otherwise.

    Source: Regulation (EU) 2024/1689, Article 19. Retrieved 2026-08-26.

  77. Thẻ 77

    Câu hỏi

    What is the fine tier for misleading information to authorities?

    Câu trả lời

    Answer. Up to €7.5 million or, for undertakings, up to 1% of total worldwide annual turnover for the preceding year, whichever is higher, for supplying incorrect, incomplete, or misleading information to notified bodies or authorities in response to a request.

    Source: Regulation (EU) 2024/1689, Article 99(5). Retrieved 2026-08-26.

  78. Thẻ 78

    Câu hỏi

    When did most AI Act enforcement powers start operating?

    Câu trả lời

    Answer. 2 August 2026 for the provisions applicable then. Later-applying obligations cannot be enforced as if already in force, and transitions must be checked provision by provision.

    Source: European Commission implementation timeline. Retrieved 2026-08-26.

  79. Thẻ 79

    Câu hỏi

    Which manipulation practice does Article 5 prohibit?

    Câu trả lời

    Answer. Placing on the market, putting into service, or using AI that deploys subliminal, purposefully manipulative, or deceptive techniques with the objective or effect of materially distorting a person’s or group’s behaviour by appreciably impairing informed decision-making, thereby causing a decision they would not otherwise have taken in a manner that causes, or is reasonably likely to cause, significant harm to that person or another person or group.

    Source: Regulation (EU) 2024/1689, Article 5(1)(a). Retrieved 2026-08-26.

  80. Thẻ 80

    Câu hỏi

    What must a provider do after discovering high-risk non-conformity?

    Câu trả lời

    Answer. Immediately take corrective action to bring the system into conformity, withdraw it, disable it, or recall it as appropriate, inform relevant downstream actors, and notify authorities when the risk conditions are met.

    Source: Regulation (EU) 2024/1689, Article 20. Retrieved 2026-08-26.

  81. Thẻ 81

    Câu hỏi

    What qualifies a model as open source for the GPAI documentation exception?

    Câu trả lời

    Answer. Its parameters, including weights, architecture information, and information on model usage, must be publicly accessible under a free-and-open-source licence that permits access, use, modification, and distribution.

    Source: Regulation (EU) 2024/1689, Article 53(2). Retrieved 2026-08-26.

  82. Thẻ 82

    Câu hỏi

    Does obvious AI interaction remove every Article 50 duty?

    Câu trả lời

    Answer. No. Obviousness is specific to the direct-interaction notice in Article 50(1). Separate marking and deployer-disclosure duties can still apply to synthetic content, deepfakes, public-interest text, or covered biometric uses.

    Source: Regulation (EU) 2024/1689, Article 50. Retrieved 2026-08-26.

  83. Thẻ 83

    Câu hỏi

    How must high-risk providers cooperate with authorities?

    Câu trả lời

    Answer. On a reasoned request, provide information and documentation necessary to demonstrate conformity, grant access to automatically generated logs under their control, and otherwise cooperate in actions concerning the system.

    Source: Regulation (EU) 2024/1689, Article 21. Retrieved 2026-08-26.

  84. Thẻ 84

    Câu hỏi

    How are SME fines treated under the AI Act?

    Câu trả lời

    Answer. For undertakings that are SMEs, each Article 99 fine must not exceed the lower of the stated percentage or fixed amount. Penalties must still be effective, proportionate, and dissuasive.

    Source: Regulation (EU) 2024/1689, Article 99(6). Retrieved 2026-08-26.

  85. Thẻ 85

    Câu hỏi

    By when must legacy GPAI models comply with GPAI duties?

    Câu trả lời

    Answer. Providers of GPAI models placed on the market before 2 August 2025 must comply with the applicable GPAI obligations by 2 August 2027.

    Source: European Commission GPAI provider guidelines. Retrieved 2026-08-26.

  86. Thẻ 86

    Câu hỏi

    Which vulnerability exploitation does Article 5 prohibit?

    Câu trả lời

    Answer. AI that exploits vulnerability due to age, disability, or a specific social or economic situation to materially distort behaviour in a way causing, or reasonably likely to cause, significant harm.

    Source: Regulation (EU) 2024/1689, Article 5(1)(b). Retrieved 2026-08-26.

  87. Thẻ 87

    Câu hỏi

    When must a non-EU high-risk provider appoint an authorised representative?

    Câu trả lời

    Answer. Before making the high-risk AI system available in the EU, when the provider is established outside the EU, it must appoint an EU-established authorised representative by written mandate.

    Source: Regulation (EU) 2024/1689, Article 22. Retrieved 2026-08-26.

  88. Thẻ 88

    Câu hỏi

    Do systemic-risk GPAI models receive the open-source documentation exception?

    Câu trả lời

    Answer. No. A GPAI model with systemic risk remains subject to the full applicable Article 53 baseline and Article 55 systemic-risk duties even if released under an open-source licence.

    Source: Regulation (EU) 2024/1689, Articles 53(2) and 55. Retrieved 2026-08-26.

  89. Thẻ 89

    Câu hỏi

    Is the direct-interaction notice required when AI use is obvious?

    Câu trả lời

    Answer. Not under Article 50(1), if AI interaction is obvious to a reasonably well-informed, observant, and circumspect person, considering the circumstances and context. This is a contextual test, not a broad product label.

    Source: European Commission Article 50 FAQ. Retrieved 2026-08-26.

  90. Thẻ 90

    Câu hỏi

    What must an authorised representative verify for high-risk AI?

    Câu trả lời

    Answer. That the EU declaration of conformity and technical documentation exist and that an appropriate conformity-assessment procedure was completed, then retain specified documents and support authority access and cooperation.

    Source: Regulation (EU) 2024/1689, Article 22. Retrieved 2026-08-26.

  91. Thẻ 91

    Câu hỏi

    When did Article 50’s transparency duties begin applying?

    Câu trả lời

    Answer. 2 August 2026, with a targeted transition to 2 December 2026 for Article 50(2) marking by qualifying synthetic-content systems already on the market before that date.

    Source: European Commission Article 50 guidelines. Retrieved 2026-08-26.

  92. Thẻ 92

    Câu hỏi

    Which social-scoring practice is prohibited?

    Câu trả lời

    Answer. Evaluating or classifying people over time by social behaviour or known, inferred, or predicted traits when this causes detrimental treatment in unrelated contexts or unjustified or disproportionate treatment.

    Source: Regulation (EU) 2024/1689, Article 5(1)(c). Retrieved 2026-08-26.

  93. Thẻ 93

    Câu hỏi

    When must an authorised representative end its mandate?

    Câu trả lời

    Answer. If it considers or has reason to consider the provider is acting contrary to the Act, it must terminate the mandate and immediately inform the relevant market-surveillance authority and, where applicable, the notified body.

    Source: Regulation (EU) 2024/1689, Article 22(4). Retrieved 2026-08-26.

  94. Thẻ 94

    Câu hỏi

    What evaluations must systemic-risk GPAI providers perform?

    Câu trả lời

    Answer. State-of-the-art model evaluations, including documented adversarial testing, to identify and mitigate systemic risks. The evaluations must follow standardised protocols and reflect the model’s capabilities and risks.

    Source: Regulation (EU) 2024/1689, Article 55(1)(a). Retrieved 2026-08-26.

  95. Thẻ 95

    Câu hỏi

    What is Article 50’s law-enforcement exception for interaction notices?

    Câu trả lời

    Answer. Systems authorised by law to detect, prevent, investigate, or prosecute criminal offences can be exempt from the notice when appropriate safeguards protect third-party rights and freedoms. Systems available for public crime reporting remain subject to the notice.

    Source: Regulation (EU) 2024/1689, Article 50(1). Retrieved 2026-08-26.

  96. Thẻ 96

    Câu hỏi

    What must a high-risk importer verify before market placement?

    Câu trả lời

    Answer. That the provider completed the correct conformity assessment, drew up technical documentation, affixed required CE marking, supplied the EU declaration and instructions, and appointed an authorised representative where required.

    Source: Regulation (EU) 2024/1689, Article 23. Retrieved 2026-08-26.

  97. Thẻ 97

    Câu hỏi

    What date should this deck’s legal summaries be checked against?

    Câu trả lời

    Answer. 26 August 2026. Later amendments, delegated acts, standards, court decisions, or guidance can change how the rules should be understood.

    Source: European Commission AI regulatory framework. Retrieved 2026-08-26.

  98. Thẻ 98

    Câu hỏi

    Is criminal-risk prediction based solely on profiling allowed?

    Câu trả lời

    Answer. No. Article 5 prohibits assessing or predicting an individual’s risk of committing an offence solely from profiling or personality traits. AI may support a human assessment already based on objective, verifiable facts linked to criminal activity.

    Source: Regulation (EU) 2024/1689, Article 5(1)(d). Retrieved 2026-08-26.

  99. Thẻ 99

    Câu hỏi

    What identity information must a high-risk importer provide?

    Câu trả lời

    Answer. Its name, registered trade name or trademark, and contact address. The importer must put them on the high-risk AI system and, where applicable, on its packaging or accompanying documentation.

    Source: Regulation (EU) 2024/1689, Article 23(3). Retrieved 2026-08-26.

  100. Thẻ 100

    Câu hỏi

    Which systemic risks must GPAI providers assess and mitigate?

    Câu trả lời

    Answer. EU-level risks arising from the model’s development, market placement, or use, including sources and propagation pathways. Measures must be proportionate, documented, and kept current.

    Source: Regulation (EU) 2024/1689, Article 55(1)(b). Retrieved 2026-08-26.

  101. Thẻ 101

    Câu hỏi

    Does Article 50 machine marking apply to ordinary editing?

    Câu trả lời

    Answer. Not when the AI performs an assistive function for standard editing or does not substantially alter input data or its semantics. The exception is narrow and depends on what the system actually does.

    Source: Regulation (EU) 2024/1689, Article 50(2). Retrieved 2026-08-26.

  102. Thẻ 102

    Câu hỏi

    What must a high-risk distributor check before availability?

    Câu trả lời

    Answer. The distributor must verify the required CE marking; a copy of the EU declaration and instructions for use; the provider’s Article 16(b) identity marking and Article 16(c) quality-management system; and, where applicable, the importer’s Article 23(3) identity marking.

    Source: Regulation (EU) 2024/1689, Article 24(1). Retrieved 2026-08-26.

  103. Thẻ 103

    Câu hỏi

    Which official text should be the default legal source for this deck?

    Câu trả lời

    Answer. The EUR-Lex consolidated Regulation (EU) 2024/1689 version dated 27 July 2026, read together with Regulation (EU) 2026/1744 and later official updates. Consolidation is a study aid; the Official Journal acts remain legally authoritative.

    Source: EUR-Lex consolidated Regulation (EU) 2024/1689. Retrieved 2026-08-26.

  104. Thẻ 104

    Câu hỏi

    Is untargeted facial-image scraping for a recognition database allowed?

    Câu trả lời

    Answer. No. Article 5 prohibits creating or expanding facial-recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

    Source: Regulation (EU) 2024/1689, Article 5(1)(e). Retrieved 2026-08-26.

  105. Thẻ 105

    Câu hỏi

    What must an importer do if it suspects high-risk non-conformity?

    Câu trả lời

    Answer. If the system is non-conforming, falsified, or accompanied by falsified documentation, the importer must not place it on the market until conformity is restored. Separately, if the system presents an Article 79(1) risk, the importer must inform the provider, authorised representative, and market-surveillance authorities.

    Source: Regulation (EU) 2024/1689, Article 23(2). Retrieved 2026-08-26.

  106. Thẻ 106

    Câu hỏi

    What serious incidents must systemic-risk GPAI providers report?

    Câu trả lời

    Answer. Relevant serious incidents and possible corrective measures must be tracked, documented, and reported without undue delay to the AI Office and, where appropriate, national competent authorities.

    Source: Regulation (EU) 2024/1689, Article 55(1)(c). Retrieved 2026-08-26.

  107. Thẻ 107

    Câu hỏi

    Does authorised law-enforcement use remove machine-marking duties?

    Câu trả lời

    Answer. Article 50(2) does not require synthetic-content marking where the AI system is authorised by law to detect, prevent, investigate, or prosecute criminal offences. The authorising law and its conditions still control the use.

    Source: Regulation (EU) 2024/1689, Article 50(2). Retrieved 2026-08-26.

  108. Thẻ 108

    Câu hỏi

    What storage and transport duties apply to high-risk importers?

    Câu trả lời

    Answer. While responsible for the system, an importer must ensure storage and transport conditions do not jeopardise compliance with high-risk-system requirements.

    Source: Regulation (EU) 2024/1689, Article 23(4). Retrieved 2026-08-26.

  109. Thẻ 109

    Câu hỏi

    What does 2 August 2028 mark, and which Article 111 transitions come later?

    Câu trả lời

    Answer. It is the selected main application milestone for Chapter III, Sections 1–3 for Article 6(1) high-risk systems tied to Annex I Section A products. It is not the Act’s last operative transition. Article 111 requires providers and deployers of high-risk systems intended to be used by public authorities to comply by 2 August 2030. It also requires AI systems that are components of large-scale IT systems established by the legal acts in Annex X, if placed on the market or put into service before 2 August 2027, to comply by 31 December 2030. Annex I Section B systems remain under Article 2(2)’s limited regime, not the full Chapter III regime.

    Sources: Regulation (EU) 2024/1689, Articles 2(2), 111 and 113 and European Commission implementation timeline. Retrieved 2026-08-26.

  110. Thẻ 110

    Câu hỏi

    Is workplace or school emotion inference allowed?

    Câu trả lời

    Answer. Generally no. Inferring emotions of natural persons in workplaces or educational institutions is prohibited, except where use is intended for medical or safety reasons.

    Source: Regulation (EU) 2024/1689, Article 5(1)(f). Retrieved 2026-08-26.

  111. Thẻ 111

    Câu hỏi

    How long must a high-risk importer keep conformity records?

    Câu trả lời

    Answer. For ten years after the system is placed on the market or put into service, the importer must keep a copy of the relevant certificate, where applicable, the instructions, and the EU declaration of conformity.

    Source: Regulation (EU) 2024/1689, Article 23(5). Retrieved 2026-08-26.

  112. Thẻ 112

    Câu hỏi

    What cybersecurity duty applies to systemic-risk GPAI models?

    Câu trả lời

    Answer. Providers must ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, proportionate to systemic risk and the state of the art.

    Source: Regulation (EU) 2024/1689, Article 55(1)(d). Retrieved 2026-08-26.

  113. Thẻ 113

    Câu hỏi

    Is there a law-enforcement exception to deepfake disclosure?

    Câu trả lời

    Answer. Yes, for use authorised by law to detect, prevent, investigate, or prosecute criminal offences, with the relevant legal safeguards. The exception should not be generalized to ordinary public communications.

    Source: Regulation (EU) 2024/1689, Article 50(4). Retrieved 2026-08-26.

  114. Thẻ 114

    Câu hỏi

    What must a distributor do if a high-risk system seems non-compliant?

    Câu trả lời

    Answer. Withhold it from the market until conformity is restored. Separately, if the system presents an Article 79(1) risk, inform the provider or importer. Article 24(2) does not add an authority-notification duty at this pre-market stage.

    Source: Regulation (EU) 2024/1689, Article 24(2). Retrieved 2026-08-26.

  115. Thẻ 115

    Câu hỏi

    What must be rechecked before relying on an AI Act date?

    Câu trả lời

    Answer. The current consolidated regulation, any amending regulation, and the Commission implementation timeline. A date in an older course or card set may have been superseded.

    Source: European Commission AI Act FAQ. Retrieved 2026-08-26.

  116. Thẻ 116

    Câu hỏi

    Which biometric categorisation is prohibited?

    Câu trả lời

    Answer. Biometric categorisation that individually categorises people to deduce or infer race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation, subject to narrow dataset and law-enforcement carve-outs.

    Source: Regulation (EU) 2024/1689, Article 5(1)(g). Retrieved 2026-08-26.

  117. Thẻ 117

    Câu hỏi

    What must a distributor do after a high-risk system is already available?

    Câu trả lời

    Answer. If it becomes non-compliant, take or ensure the corrective action needed to bring it into conformity, withdraw it, or recall it. Separately, if the system presents an Article 79(1) risk, immediately inform the provider or importer and competent authorities, with details of the non-compliance and corrective action.

    Source: Regulation (EU) 2024/1689, Article 24(4). Retrieved 2026-08-26.

  118. Thẻ 118

    Câu hỏi

    Can a GPAI code of practice demonstrate compliance?

    Câu trả lời

    Answer. Yes. Until harmonised standards are available, providers may rely on approved codes of practice to demonstrate compliance. A provider choosing another route must show alternative adequate means of compliance.

    Source: Regulation (EU) 2024/1689, Article 56. Retrieved 2026-08-26.

  119. Thẻ 119

    Câu hỏi

    Does Article 50 replace other transparency law?

    Câu trả lời

    Answer. No. Article 50 adds AI-specific duties without displacing stricter or overlapping obligations under consumer, media, electoral, platform, accessibility, privacy, or other applicable law.

    Source: European Commission Article 50 guidelines. Retrieved 2026-08-26.

  120. Thẻ 120

    Câu hỏi

    What storage and transport duties apply to high-risk distributors?

    Câu trả lời

    Answer. While responsible for the system, a distributor must ensure storage and transport conditions do not jeopardise compliance with high-risk-system requirements.

    Source: Regulation (EU) 2024/1689, Article 24(3). Retrieved 2026-08-26.

  121. Thẻ 121

    Câu hỏi

    When is an Annex I product-linked AI system high-risk?

    Câu trả lời

    Answer. Only when the Article 6(1) gateway remains satisfied after paragraphs 1a–1c: the AI is a safety component of an Annex I product, is itself such a product, or its failure or malfunction would endanger health and safety; and the product must undergo third-party conformity assessment before market placement or service. AI used solely for non-safety assistance, optimisation, efficiency, automation, convenience, or quality control is not a safety component unless its failure or malfunction would endanger health or safety. An assessment required solely for non-health-and-safety risks does not satisfy the second condition.

    Source: Regulation (EU) 2024/1689, Article 6(1)–(1c). Retrieved 2026-08-26.

  122. Thẻ 122

    Câu hỏi

    How must high-risk distributors cooperate with authorities?

    Câu trả lời

    Answer. They must provide relevant information and documentation on a reasoned request and cooperate in actions concerning the high-risk system, including measures to reduce or mitigate risks.

    Source: Regulation (EU) 2024/1689, Article 24(5)–(6). Retrieved 2026-08-26.

  123. Thẻ 123

    Câu hỏi

    Are the Commission’s Article 50 guidelines legally binding?

    Câu trả lời

    Answer. No. They are practical interpretive guidance. The AI Act’s text is binding, and authoritative interpretation belongs to competent authorities and ultimately the Court of Justice of the European Union.

    Source: European Commission Article 50 guidelines. Retrieved 2026-08-26.

  124. Thẻ 124

    Câu hỏi

    What input-data duty applies to high-risk deployers?

    Câu trả lời

    Answer. When a deployer controls input data, it must ensure that the input is relevant and sufficiently representative for the system’s intended purpose.

    Source: Regulation (EU) 2024/1689, Article 26(4). Retrieved 2026-08-26.

  125. Thẻ 125

    Câu hỏi

    Which non-consensual intimate deepfake practice is prohibited?

    Câu trả lời

    Answer. For providers, placing the system on the market or putting it into service is prohibited only if generating or manipulating the covered realistic intimate or sexually explicit material of an identifiable person without freely given, specific, informed, unambiguous, and explicit consent is intended, or is reasonably foreseeable and reproducible without significant technical modification and reasonable, adequate safeguards are absent. For deployers, use is prohibited only when they use the system for that purpose. The rule applies from 2 December 2026; manipulation counts only if it increases intimate-part exposure or alters the nature of the sexually explicit activity.

    Source: Regulation (EU) 2026/1744, Article 1 (AI Act Article 5(1)(ba) and 5(1a)–(1b)). Retrieved 2026-08-26.

  126. Thẻ 126

    Câu hỏi

    How must a high-risk deployer use the system?

    Câu trả lời

    Answer. According to the accompanying instructions, while assigning human oversight to natural persons with the necessary competence, training, authority, and support.

    Source: Regulation (EU) 2024/1689, Article 26(1)–(2). Retrieved 2026-08-26.

  127. Thẻ 127

    Câu hỏi

    What is the safest Article 50 disclosure design?

    Câu trả lời

    Answer. Put a clear, distinguishable, accessible notice at the first interaction or exposure, close to the relevant AI experience or content, while also meeting any machine-marking duty. Exact design remains context-specific.

    Source: European Commission Article 50 FAQ. Retrieved 2026-08-26.

  128. Thẻ 128

    Câu hỏi

    Who must complete a fundamental-rights impact assessment?

    Câu trả lời

    Answer. Before first use, deployers that are public bodies, private entities providing public services, and deployers of specified Annex III creditworthiness and life or health-insurance systems, subject to Article 27’s exact scope and exceptions.

    Source: Regulation (EU) 2024/1689, Article 27. Retrieved 2026-08-26.

  129. Thẻ 129

    Câu hỏi

    How does Annex III create high-risk status?

    Câu trả lời

    Answer. Article 6(2) classifies systems in Annex III’s listed use cases as high-risk, unless Article 6(3)’s limited no-significant-risk conditions apply. A use-case label alone is not the full analysis.

    Source: Regulation (EU) 2024/1689, Article 6(2)–(3) and Annex III. Retrieved 2026-08-26.

  130. Thẻ 130

    Câu hỏi

    What must a deployer do when high-risk use may create a risk?

    Câu trả lời

    Answer. If use in accordance with the instructions may present an Article 79(1) risk, the deployer must, without undue delay, inform the provider or distributor and the relevant market-surveillance authority, and suspend use. A serious incident triggers a separate immediate chain: inform the provider first, then the importer or distributor and the relevant market-surveillance authorities; if the provider cannot be reached, Article 73 applies mutatis mutandis.

    Source: Regulation (EU) 2024/1689, Article 26(5). Retrieved 2026-08-26.

  131. Thẻ 131

    Câu hỏi

    Can a high-risk FRIA reuse a data-protection impact assessment?

    Câu trả lời

    Answer. Yes. If a DPIA already addresses relevant elements, the deployer should complement it with the additional Article 27 information rather than duplicate the work.

    Source: Regulation (EU) 2024/1689, Article 27(4). Retrieved 2026-08-26.

  132. Thẻ 132

    Câu hỏi

    When may law enforcement use real-time remote biometric identification in public?

    Câu trả lời

    Answer. Only for narrow listed objectives and under strict necessity, proportionality, temporal, geographic, and personal limits, generally with prior judicial or independent administrative authorisation. The default rule is prohibition.

    Source: Regulation (EU) 2024/1689, Article 5(1)(h) and 5(2)–(7). Retrieved 2026-08-26.

  133. Thẻ 133

    Câu hỏi

    How long must a high-risk deployer keep logs under its control?

    Câu trả lời

    Answer. For a period appropriate to the intended purpose and generally at least six months, unless applicable EU or national law provides otherwise, particularly on personal-data protection.

    Source: Regulation (EU) 2024/1689, Article 26(6). Retrieved 2026-08-26.

  134. Thẻ 134

    Câu hỏi

    What conformity steps precede high-risk market placement?

    Câu trả lời

    Answer. The provider must complete the applicable conformity assessment, draw up the EU declaration of conformity, affix CE marking, and register the system where required before placement or service. The exact route depends on the system.

    Source: Regulation (EU) 2024/1689, Articles 43, 47–49. Retrieved 2026-08-26.

  135. Thẻ 135

    Câu hỏi

    When can an Annex III system be treated as not high-risk?

    Câu trả lời

    Answer. Only when both parts of Article 6(3) are met: it poses no significant risk of harm to health, safety, or fundamental rights—including, for example, by not materially influencing decision-making—and it satisfies at least one listed task condition: a narrow procedural task; improvement of the result of a previously completed human activity; detection of decision-making patterns or deviations without being meant to replace or influence the previously completed human assessment without proper human review; or a preparatory task for an Annex III assessment. Profiling systems remain high-risk, and the provider must document the assessment.

    Source: Regulation (EU) 2024/1689, Article 6(3)–(4). Retrieved 2026-08-26.

  136. Thẻ 136

    Câu hỏi

    When must workers be told about workplace high-risk AI?

    Câu trả lời

    Answer. Before putting the system into service or using it at work, the deployer that is an employer must inform worker representatives and affected workers that they will be subject to the system, following applicable information rules.

    Source: Regulation (EU) 2024/1689, Article 26(7). Retrieved 2026-08-26.

  137. Thẻ 137

    Câu hỏi

    What ongoing monitoring must high-risk providers run?

    Câu trả lời

    Answer. A documented post-market monitoring system proportionate to the technology and risks, actively collecting and analysing performance data throughout the system’s lifetime to evaluate continuous compliance.

    Source: Regulation (EU) 2024/1689, Article 72. Retrieved 2026-08-26.

  138. Thẻ 138

    Câu hỏi

    Which child-sexual-abuse AI practice is prohibited from 2 December 2026?

    Câu trả lời

    Answer. From 2 December 2026, providers may not place the system on the market or put it into service if generating or manipulating the covered child-sexual-abuse material or performances is intended, or is reasonably foreseeable and reproducible without significant technical modification and reasonable, adequate safeguards are absent. Deployers are prohibited only when they use the system for that purpose. A ‘without right’ defence under national law remains possible.

    Source: Regulation (EU) 2026/1744, Article 1 (AI Act Article 5(1)(bb) and 5(1a)). Retrieved 2026-08-26.

  139. Thẻ 139

    Câu hỏi

    Who must be told when high-risk AI informs a decision about them?

    Câu trả lời

    Answer. The deployer must inform the affected natural person that the relevant Annex III high-risk system is being used, where Article 26’s notice condition applies. Other explanation and data-protection rights may also be relevant.

    Source: Regulation (EU) 2024/1689, Article 26(11). Retrieved 2026-08-26.

  140. Thẻ 140

    Câu hỏi

    Does Article 6(3) ever exclude profiling systems from high-risk status?

    Câu trả lời

    Answer. No. An Annex III system that performs profiling of natural persons is always considered high-risk, even if another Article 6(3) task description might appear narrow.

    Source: Regulation (EU) 2024/1689, Article 6(3). Retrieved 2026-08-26.

Abstract blue and gold pathways converging around a balanced circular framework on a deep navy background.

140 thẻ

EU AI Act 2026 Flashcards: Timeline, Roles & Risk Rules

Học bộ thẻ này miễn phí

Nibomo sẽ mở ra để bạn bắt đầu học.