Futura AI
it

Regulation (EU) 2024/1689

Whitepaper — The AI Act explained for those who must apply it

An operational guide to risk classification, obligations for high-risk systems, and what changes for public bodies, banks, insurers and regulated industry.

Operational guideBy Daniele Grotti (CEO)

What you’ll find in this guide

Risk classification

How to distinguish unacceptable risk, high risk, limited risk and minimal risk, and why the level depends on how the system is used, not on the technology itself.

Obligations for high-risk systems

Risk management, data governance, technical documentation, automatic logging and human oversight: what the Regulation requires before going into production.

Deployers, not only providers

The responsibilities of those who use a high-risk system, including the impact assessments required for public bodies and the financial sector.

A sector-by-sector operational checklist

Concrete steps for public administration, regions, banks, insurers and industry, covering deadlines already in force and those still ahead.

Risk classification: four tiers, not two

Regulation (EU) 2024/1689 does not classify technologies: it classifies uses. The same language model can be minimal risk in an internal research assistant and high risk if used to evaluate job applications. The question is never "what technology are we using", but "what decision does it contribute to".

The four tiers: unacceptable risk, banned outright (social scoring, subliminal manipulation, certain uses of real-time biometric identification in public spaces). High risk, subject to strict obligations before production: this is the Annex III category, covering credit scoring, life and health insurance risk assessment, personnel selection, and access to essential public services. Limited risk, with transparency obligations: a chatbot must disclose it is an AI system, synthetic content must be labeled as such. Minimal risk, with no specific obligations: most internal productivity systems fall here.

What the Regulation requires for a high-risk system

Before going into production, a system classified as high-risk requires: a risk management system maintained throughout the whole lifecycle, not just at the design stage; governance of training, validation and testing data, with controls on quality and representativeness; technical documentation that allows design choices and system limits to be reconstructed; automatic event logging sufficient to guarantee traceability of operation; human oversight measures that allow a person to intervene or halt the system; adequate levels of accuracy, robustness and cybersecurity, documented and verifiable.

On top of this comes conformity assessment before the system is placed on the market or put into service, and for some categories, registration in a public EU database. These are obligations designed to be verifiable by a third party, not just declared: it's why, in our projects, technical documentation and the audit trail are built alongside the system, not written up after the fact.

Deployers, not only providers: obligations for whoever uses the system

A common mistake is assuming obligations fall only on whoever builds the system (the "provider"). The Regulation explicitly distinguishes the role of deployer — the organization using a high-risk AI system as part of its own activity — and assigns it obligations of its own: use the system according to the provider's instructions, ensure human oversight by trained staff, monitor its operation and retain the logs it generates, inform workers and their representatives before introducing a high-risk system in the workplace.

For public bodies and for specific cases in the financial sector — in particular banks and insurers using AI for credit or insurance assessments — a more demanding obligation applies: the Fundamental Rights Impact Assessment, to be carried out before the system is put into use, not after an incident.

The Regulation’s deadlines

  1. 1 Aug 2024

    Regulation enters into force

  2. 2 Feb 2025

    Ban on unacceptable-risk practices

  3. 2 Aug 2025

    GPAI model obligations and governance rules

  4. 2 Aug 2026

    High-risk system obligations apply (Annex III)

  5. 2 Aug 2027

    Obligations for AI in regulated products (Annex I)

Sector-by-sector operational checklist

Not every item below applies to every organization: it depends on the AI systems actually in use and their specific application. These are the steps that, in our experience, take the longest if addressed late.

Public administration and local government

  • Inventory the AI systems already in use or under evaluation, including those introduced without a formal project (e.g. drafting assistants for administrative acts)
  • Check whether any system falls under the Annex III high-risk use cases tied to access to essential public services
  • Prepare the fundamental rights impact assessment for high-risk systems before they are put into use
  • Define who, internally, is responsible for human oversight of each system

Regional governments and PNRR/ERDF programs

  • Check the risk classification of the tools used for monitoring, reporting and ex-ante evaluation of policies
  • Ensure traceability of sources for every output used in audits toward national and European oversight bodies
  • Document the data governance behind simulation models covering population and businesses

Banks and insurers

  • Map where AI is involved in credit scoring, life/health insurance pricing and claims assessment: these are explicitly high-risk cases
  • Prepare the fundamental rights impact assessment required for these uses
  • Align AI system audit trails and logs with existing compliance and supervisory requirements
  • Vet third-party model or AI service providers: deployer obligations remain with whoever uses the system

Industry and Manufacturing

  • Check whether AI is integrated as a safety component in products already covered by EU harmonization legislation (machinery, devices): these cases fall under Annex I, with obligations from 2 August 2027
  • For internally used systems (predictive maintenance, quality control, technical support): check whether they affect personnel-related decisions, in which case they may fall under high risk
  • Document the technical sources (manuals, bills of materials, regulations) used by AI systems for internal knowledge retrieval

This guide does not replace legal advice on compliance with Regulation (EU) 2024/1689, nor a formal assessment specific to your organization: official interpretations, delegated acts and harmonized technical standards continue to be published and may refine the obligations described here. It is a technical foundation written by people who design AI systems meant for production, intended to help you orient yourselves before involving your legal, compliance and data protection teams.

Stay updated on regulatory developments

The Regulation is entering into force in phases and implementing texts continue to be published. Leave your email to receive an update whenever something relevant to your sector changes.

This whitepaper does not replace legal advice on compliance with the Regulation: it is a technical foundation to help you orient yourselves, written by people who design AI systems meant for production.

Frequently asked questions

What does Futura AI’s AI Act whitepaper cover?

An operational guide to Regulation (EU) 2024/1689: risk classification, obligations for high-risk systems, deployer responsibilities (not just providers), and a sector-by-sector operational checklist for public administration, regional governments, banks, insurers and regulated industry.

When do the AI Act obligations for high-risk systems take effect?

The Regulation entered into force on 1 August 2024. From 2 August 2026, the obligations for Annex III high-risk systems apply; from 2 August 2027, those for AI in regulated products under Annex I. The ban on unacceptable-risk practices has already been in force since 2 February 2025.

Under the AI Act, who has obligations — only whoever builds the AI system?

No. Deployers — anyone using a high-risk system, not just those who build it — have obligations of their own: public bodies and specific financial-sector cases must carry out a fundamental rights impact assessment.