Article 9
Risk management system for high-risk AI
Article 9 requires providers of high-risk AI systems to establish, implement, document, and maintain a risk management system that runs as a continuous, iterative process across the entire lifecycle: identify foreseeable risks to health, safety, and fundamental rights, estimate and evaluate them including under reasonably foreseeable misuse, and adopt targeted risk management measures, with testing to confirm the residual risk is acceptable.
Fundamental rights include data protection, so the flow of personal data into and through an AI system is squarely inside the Article 9 analysis. Reasonably foreseeable misuse is the clause that catches everyday behaviour: employees feeding personal or confidential data into AI tools in ways the provider or deployer never intended is foreseeable, well documented, and therefore something the risk management system must anticipate and mitigate. IBM's 2025 breach study found 97% of organizations that suffered an AI-related breach lacked proper AI access controls, which is precisely the gap a functioning Article 9 process is supposed to close before an incident, not after.
Article 14
Human oversight
Article 14 requires high-risk AI systems to be designed so natural persons can effectively oversee them while in use: understand the system's capacities and limits, monitor its operation, remain aware of automation bias, correctly interpret output, and be able to intervene, override, or stop the system. Oversight measures can be built into the system or organized by the deployer.
Oversight is only effective if a person can actually see and act on what the AI is doing, including what data goes in. An organization where AI use happens invisibly in browser tabs cannot claim effective oversight: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage, and 71% of GenAI connections go through personal, non-corporate accounts. Making AI interactions visible to accountable humans, and putting a control at the point where data enters, is the operational substance behind Article 14's design requirement.
Article 2
Scope and extraterritorial reach
Article 2 sets the Act's reach: it applies to providers placing AI systems or GPAI models on the EU market regardless of where they are established, to deployers located in the EU, and to providers and deployers located outside the EU where the output produced by the AI system is used in the EU.
This is the provision that makes the Act relevant in Toronto and Texas. A Canadian firm whose AI-assisted analysis, screening decisions, or generated content is used by clients in the EU can be within scope without any EU office. Even organizations that never trigger scope directly encounter the Act through contracts: EU customers and partners increasingly require evidence of AI governance, including controls on what data employees expose to AI tools, as a condition of doing business.
Articles 5 and 113 (timeline)
Prohibited practices and phased application
The Act entered into force on August 1, 2024, and applies in phases: prohibitions on unacceptable-risk practices (such as social scoring and certain biometric uses) and AI literacy duties from February 2, 2025; general-purpose AI model obligations from August 2, 2025; most remaining obligations, including the bulk of the high-risk regime, from August 2, 2026; and high-risk systems embedded in regulated products under Annex I from August 2, 2027.
The phase-in is a compliance calendar, not a grace period: the governance work behind Articles 9 and 14 (inventories, risk assessments, oversight design, data controls) takes quarters to build, and evidence of a functioning system cannot be backdated. Organizations that map their AI usage and put data controls in place now will meet the 2026 and 2027 deadlines with documentation already in hand; those that wait will be reconstructing what their employees did with AI after the fact.