EU Regulation 2024/1689 · The AI Act

The EU AI Act, made clear.

What the AI Act is, who it applies to, what you must do and by when. A practical, plain-language overview for organisations in Denmark and across the EU, kept up to date.

Information only, not legal advice. Last updated 17 September 2026.
What it is

A risk-based rulebook for artificial intelligence

The AI Act is the EU's regulation on artificial intelligence. It applies directly in every member state, including Denmark, with no separate national law needed to take effect.

Rather than regulating the technology as such, the AI Act regulates the risk an AI system poses to people's safety and fundamental rights. The higher the risk, the stricter the requirements. It reaches organisations that build AI systems (providers) and organisations that use them (deployers), as well as importers and distributors, and it applies regardless of company size.

A common shortcut is to picture a simple "risk pyramid". In practice the Act runs four independent sets of obligations, and a single system can fall under more than one. Understanding which ones apply to you is the first real step.

The four sets of obligations

Which rules apply depends on what your AI does

These are assessed independently, not as a single ladder. Screen your systems against all four.

Article 5

Prohibited practices

A defined list of uses that are banned outright, such as social scoring and certain manipulative or exploitative systems. No compliance path exists; they are simply not allowed.

Article 6 + Annex I & III

High-risk systems

Systems in sensitive areas (for example hiring, credit, education, critical infrastructure or regulated products). Strict duties: risk management, data quality, documentation, human oversight, accuracy and logging.

Article 50

Transparency

Lighter duties for systems that interact with people or generate content. Users must be told they are dealing with AI, and AI-generated or manipulated content must be marked.

Chapter V

General-purpose AI

Providers of general-purpose AI models (the large foundation models) have their own transparency, documentation and, for the most capable models, systemic-risk obligations.

AI literacy (Article 4) applies to everyone using AI at work: organisations must ensure staff have a basic understanding of how their AI systems work and the risks involved. This duty is already in effect.

Deadlines

When the obligations apply

The Act entered into force on 1 August 2024 and applies in phases. The 2026 Digital Omnibus deferred the high-risk deadlines; the dates below reflect that change.

2 February 2025
Prohibited practices & AI literacy. The Article 5 bans and the Article 4 AI-literacy duty took effect.
2 August 2025
General-purpose AI. Obligations for providers of general-purpose AI models began to apply.
2 August 2026
Transparency (Article 50). Applied as originally scheduled; not deferred.
2 December 2027
High-risk, Annex III. Stand-alone high-risk systems (for example hiring, credit, education, critical infrastructure). Deferred from the original August 2026 date.
2 August 2028
High-risk, Annex I. AI embedded in already-regulated products (for example medical devices, machinery, toys).

Dates can change through further EU amendments. Always confirm against the official consolidated text on EUR-Lex before acting.

In Denmark

Who supervises the AI Act in Denmark

The regulation applies directly, and a Danish act (LOV nr. 467 of 14 May 2025) adds the supplementary national rules and names the competent authorities.

Digitaliseringsstyrelsen

Coordinating national authority and market surveillance for most areas.

Datatilsynet

Authority for areas involving law enforcement and fundamental rights.

Domstolsstyrelsen

Authority for AI used in the administration of justice.

The Danish supplementary act also sets out penalties and entry into force. You can read it in full, in a readable format, on danskret.dk.

Getting ready

What organisations should do now

You do not need to solve everything at once, but you do need to know where you stand.

1
Make an inventory. List the AI systems you build or use, including AI features inside other tools.
2
Classify the risk. Screen each system against the four sets of obligations to see which apply.
3
Build AI literacy. Give the people who use AI a basic, documented understanding of it. This is already required.
4
Document and oversee. For higher-risk uses, put risk management, human oversight and record-keeping in place, and keep the evidence current.
5
Keep it maintained. Compliance is ongoing, not a one-off document. Re-check as your systems and the rules change.
Related pages

Other rules, explained

Part of the same family of plain-language overviews of laws and regulations, maintained by CisScan.

How CisScan helps you comply

CisScan turns the AI Act from a document exercise into continuously maintained evidence. It helps you inventory and classify your AI systems, close the gaps, and keep audit-ready documentation, alongside GDPR, ISO 27001, NIS2 and more, from one place.

The free check shows which EU regulations apply to your company, based on public data.