Executive Summary — TL;DR

The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive AI law. Here are the three things every organisation must know:

  • 1 Risk determines your obligations. The Act classifies all AI systems into four tiers — from Unacceptable Risk (banned outright since February 2025) to Minimal Risk (no mandatory rules). If your AI is in HR, credit scoring, education, or biometrics, you are almost certainly in the high-risk tier.
  • 2 The primary deadline is 2 August 2026. From this date, high-risk AI systems must have completed conformity assessments, full technical documentation, EU database registration, and human oversight mechanisms. Conformity assessments take up to 12 months — organisations must act now.
  • 3 It applies globally, not just in the EU. Any company — US, UK, or otherwise — that provides or deploys AI affecting EU users is in scope. The maximum fine for violations is €35 million or 7% of global annual turnover, whichever is higher.
Regulation EU 2024/1689

EU AI Act Summary: The Complete Guide for 2025–2026

The EU AI Act is the world’s first comprehensive legal framework governing artificial intelligence. Formally adopted on 13 March 2024 and entering into force on 1 August 2024, it establishes binding obligations for AI providers, deployers, and importers operating in or affecting the European Union market.

This guide covers everything organisations need to understand: the Act’s scope, risk classification system, compliance obligations, key deadlines, and enforcement regime — with direct references to the official regulation text.

Last updated: March 2026 · Sources: EUR-Lex Official Text · European Commission

1. What Is the EU AI Act?

The EU AI Act (officially Regulation (EU) 2024/1689 of the European Parliament and of the Council) is landmark legislation that creates a uniform legal framework for artificial intelligence across all 27 EU member states. It was proposed by the European Commission in April 2021, underwent three years of legislative negotiation, and was formally adopted on 21 May 2024.

The Act takes a risk-based approach: the stricter the potential harm an AI system could cause, the heavier its regulatory requirements. It does not regulate AI as a technology in the abstract — it regulates specific applications and use cases of AI systems based on the context in which they operate.

Crucially, the EU AI Act is a product safety regulation, not primarily a data protection law. It operates alongside — not instead of — the General Data Protection Regulation (GDPR) and other existing EU law. Organisations dealing with AI systems that process personal data must comply with both simultaneously.

458
Articles in the regulation
13
Annexes covering specific use cases
4
Risk tiers from minimal to prohibited
36
Months from entry into force to full application

Source: EUR-Lex — Regulation (EU) 2024/1689

2. Who Does the EU AI Act Apply To?

The EU AI Act has broad territorial scope. It applies to organisations and individuals who:

  • Place AI systems on the EU market or put them into service in the EU — regardless of where they are established
  • Use AI systems within the EU (deployers)
  • Are importers or distributors of AI systems in the EU
  • Are located outside the EU, but whose AI system’s output is used within the EU

In practice, this means any US, UK, Asian, or other non-EU company offering AI-powered products or services to EU residents is potentially subject to the Act. This extraterritorial reach mirrors the GDPR’s approach and makes the EU AI Act a de-facto global compliance standard for organisations with EU market exposure.

Key Actors Defined by the Act

ActorArticleDefinitionExample
ProviderArt. 3(3)Develops and places an AI system on the market or into service under their own nameAI software companies, model developers
DeployerArt. 3(4)Uses an AI system under their own authority in a professional contextHR dept using AI screening tool; bank using credit scoring API
ImporterArt. 3(6)An EU-established person who places a non-EU AI system on the EU marketEU distributor of US-built AI software
DistributorArt. 3(7)Supply chain entity that makes an AI system available without modifying itResellers, marketplaces, app stores
Authorised RepresentativeArt. 3(5)EU-established entity mandated by a non-EU provider to act on their behalfRequired for all non-EU providers of high-risk AI

Who Is Exempt?

The Act does not apply to AI systems used exclusively for military, national security, or defence purposes; AI for scientific research and development (before it enters the market); and AI systems used by individuals purely for personal, non-professional use. Open-source AI models may qualify for partial exemptions in certain conditions, but remain subject to prohibited practice rules regardless.

Reference: Article 2 — Scope, EU AI Act Official Reference Site

3. The Risk Classification System

The EU AI Act’s central mechanism is its four-tier risk pyramid. Compliance obligations scale with risk — the more severe the potential harm, the more stringent the requirements. Understanding where your AI system sits in this hierarchy is the first and most critical step in any compliance programme.

UNACCEPTABLE RISK — Prohibited
Article 5 · Banned from 2 February 2025
~1% of AI systems
AI systems that pose an unacceptable threat to fundamental rights, safety, or democratic values. Prohibited outright — no conformity path available. Examples: social scoring by governments, real-time biometric surveillance in public spaces (outside narrow exceptions), manipulation of vulnerable individuals.
HIGH RISK — Strict Obligations
Annex III + Annex I products · Deadline: 2 August 2026
~8–10% of AI systems
AI systems posing significant risk to health, safety, or fundamental rights. Subject to comprehensive conformity assessment, technical documentation, human oversight, and registration requirements. Covers HR, credit, education, biometrics, law enforcement, and more.
LIMITED RISK — Transparency Obligations
Article 50 · Deadline: 2 August 2026
~15–20% of AI systems
AI systems with limited risk — primarily chatbots, deepfake generators, and AI-content generators. Must disclose AI nature to users and label AI-generated content. No conformity assessment required, but transparency duties are mandatory and enforceable.
MINIMAL RISK — Largely Unregulated
No mandatory requirements · Voluntary codes of conduct encouraged
~70% of AI systems
The vast majority of AI applications — spam filters, AI in video games, recommendation engines, basic automation — fall here. No mandatory obligations. The Commission encourages providers to adopt voluntary codes of conduct based on the high-risk framework.

Source: European Parliament — EU AI Act explainer

Visual Overview
EU AI Act Summary Infographic — Risk pyramid, key deadlines, penalties and Annex III high-risk categories at a glance
EU AI Act at a Glance — risk tiers, penalties, key deadlines and Annex III categories. View full size ↗ · Download PDF version

4. Prohibited AI Practices (Article 5)

Article 5 bans eight categories of AI practices that the EU legislature determined pose unacceptable risks. These bans took effect on 2 February 2025 — meaning organisations should already have ceased any of the following activities. There is no conformity pathway; the practices are prohibited absolutely.

#Prohibited PracticeKey Detail
1Subliminal ManipulationAI that uses techniques beyond conscious perception to materially distort behaviour in ways that cause or are likely to cause harm
2Exploitation of VulnerabilitiesAI that exploits age, disability, or social/economic situation to distort behaviour in harmful ways
3Social Scoring by Public AuthoritiesAI used by public bodies to evaluate or classify people based on social behaviour or personality characteristics, leading to unjustified or disproportionate detrimental treatment
4Real-Time Remote Biometric ID in Public SpacesLimited law-enforcement exceptions exist with prior judicial authorisation for specific crimes only
5Untargeted Facial Image ScrapingBuilding or expanding facial recognition databases by scraping the internet or CCTV footage without targeted purpose
6Emotion Inference in Workplaces & EducationAI that infers emotions from biometric data in workplace or educational institution contexts (narrow medical and safety exceptions apply)
7Biometric Categorisation by Sensitive AttributesCategorising individuals based on biometric data to deduce race, political opinions, religion, trade union membership, sexual orientation
8Predictive Policing Based Solely on ProfilingAI that assesses the risk of individuals committing future criminal offences based solely on personality traits or profiling without a prior criminal act
⚠ Enforcement Note: These prohibitions have been in force since 2 February 2025. Organisations still operating any of the above AI systems are already in violation and face the highest penalty tier (up to €35M or 7% of global turnover). Immediate legal review is recommended.

5. High-Risk AI System Obligations

High-risk AI systems face the Act’s most comprehensive compliance requirements. There are two routes to being classified as high-risk: being listed in Annex III (standalone high-risk AI use cases), or being an AI component that is a safety component of a product already regulated under Annex I product safety legislation (medical devices, machinery, aviation equipment, etc.).

Providers of high-risk AI systems must fulfil the following obligations before placing a system on the EU market:

ObligationArticleWhat Is RequiredApplies To
Risk Management SystemArt. 9Continuous, iterative process identifying and mitigating risks throughout the AI lifecycleProviders
Data GovernanceArt. 10Training, validation, and test data must meet quality criteria; bias detection and correction requiredProviders
Technical DocumentationArt. 11Full documentation before market placement; kept up to date for entire system lifecycleProviders
Record-Keeping / LoggingArt. 12Automatic logging of operations to the extent technically feasible; enables post-incident analysisProviders
Transparency & InstructionsArt. 13Clear instructions for use enabling deployers to understand and operate the system correctlyProviders
Human OversightArt. 14Design must enable humans to monitor, understand, intervene, override, or halt the systemProviders (design) / Deployers (operation)
Accuracy, Robustness & CybersecurityArt. 15Systems must achieve appropriate accuracy levels and be resilient to errors, faults, and adversarial attacksProviders
Quality Management SystemArt. 17Documented QMS covering strategy, design, development, testing, and post-market monitoringProviders
Conformity AssessmentArt. 43Self-assessment for most Annex III systems; third-party assessment required for biometric ID and certain othersProviders
EU Database RegistrationArt. 49Register in the EU AI Act database before market placement; publicly accessibleProviders (+ some deployers)
Post-Market MonitoringArt. 72Active monitoring of system performance; report serious incidents to authorities within 15 daysProviders

Deployer Obligations for High-Risk AI

Deployers of high-risk AI systems (organisations using them in operations) also carry significant obligations, including: using systems only within the scope documented by the provider; implementing human oversight measures as specified; ensuring staff have AI literacy; conducting Fundamental Rights Impact Assessments (FRIAs) before deploying in regulated sectors; maintaining use logs for at least 6 months; and reporting serious incidents to the provider and national authorities.

See also: IBM — EU AI Act Requirements Overview · Our Provider vs. Deployer Guide

6. General Purpose AI (GPAI) Models

Chapter V of the EU AI Act introduces a separate regulatory framework specifically for General Purpose AI (GPAI) models — large foundation models (such as GPT, Gemini, Claude, Llama) that can be adapted for a wide range of downstream tasks. These obligations applied from 2 August 2025.

All GPAI Providers Must:
  • Maintain technical documentation of training methodology
  • Provide information and documentation to downstream deployers
  • Comply with EU copyright law (Article 53(1)(c))
  • Publish a summary of training data content
  • Implement an AI policy to respect intellectual property
Systemic Risk GPAI Models (Additional):
Applies to models trained with >1025 FLOPs (currently: GPT-4 class and above)
  • Adversarial testing (red-teaming) before release
  • Report serious incidents to the AI Office
  • Cybersecurity protection measures
  • Energy efficiency reporting
  • Ongoing model evaluations

Organisations that integrate GPAI models into their own applications must obtain the required documentation from the model provider. If the GPAI is integrated into a high-risk AI system, the downstream provider becomes responsible for the combined system’s conformity assessment.

Reference: EU AI Act Chapter V — GPAI Model Obligations · OECD AI Governance Framework

7. Transparency and AI Labeling Requirements

Article 50 creates transparency obligations that apply broadly — including to AI systems that are not classified as high-risk. These take effect from 2 August 2026 and affect any business producing AI-generated content or operating AI interfaces that interact with the public.

ObligationWho Must ComplyRequirementExceptions
Chatbot DisclosureProviders / Deployers of conversational AIInform users they are interacting with AI, not a humanWhere AI nature is obvious from context
Deepfake LabelingAny provider generating synthetic audio/video/imageMachine-readable disclosure that content is AI-generatedAuthorised law enforcement; artistic satire with clear disclosure
AI-Generated Text DisclosurePublishers of AI-generated text on public-interest topicsDisclose AI-generated nature clearly to readers/audienceMinor AI-assisted editing of human-authored text
Emotion Recognition DisclosureDeployers of emotion recognition AINotify individuals that emotion recognition is operatingMedical devices; certain research applications

Reference: Our Article 50 Deep-Dive Guide · Article 50 Official Reference

8. EU AI Act Governance Structure

The Act establishes a multi-level governance system with distinct roles at EU and national levels.

EU AI Office
Central EU-level body within the European Commission. Oversees GPAI models, develops technical standards, coordinates with national authorities, and enforces cross-border violations. Operational from 2024.
EC AI Office ↗
National Competent Authorities
Each member state designates at least one national supervisory authority responsible for market surveillance, enforcement of Annex III obligations, and handling complaints within their jurisdiction.
AI Board
Advisory body comprising representatives from all member states’ national competent authorities. Provides guidance on consistent application of the Act across the EU and advises the Commission.
Advisory Forum & Scientific Panel
The Advisory Forum provides stakeholder input (industry, civil society, academia). The Scientific Panel of independent experts advises on GPAI model assessments and technical questions.

Reference: NIST AI Risk Management Framework (complementary international standard)

9. EU AI Act Timeline and Key Deadlines

The Act uses a phased implementation with obligations rolling in across three years. The table below shows every key milestone.

DateMilestoneWho Is AffectedStatus
1 Aug 2024Act enters into force; 36-month countdown beginsAll organisationsPassed
2 Feb 2025Prohibited AI practices (Article 5) take effectAll organisations using banned AIPassed
2 Feb 2025AI literacy obligations for providers and deployers beginAll providers & deployersPassed
2 Aug 2025GPAI model obligations (Chapter V) apply; AI Office Code of Practice liveGPAI model providersPassed
2 Aug 2025National competent authorities must be designated by member statesEU Member StatesPassed
⚡ 2 Aug 2026HIGH-RISK AI (Annex III) fully compliant · Article 50 transparency live · EU database openAll high-risk AI providers & deployers; all AI content producersPrimary Deadline
2 Aug 2027High-risk AI in Annex I legacy products (medical devices, machinery, etc.) must complyManufacturers of regulated products with AI componentsUpcoming
View Full Interactive Timeline →

10. EU AI Act Penalties and Enforcement

The EU AI Act’s penalty structure is explicitly designed to make compliance less costly than non-compliance for organisations of any size. The fines are calculated as the higher of a fixed cap or a percentage of global annual turnover — ensuring large multinationals face penalties proportionate to their scale.

Violation TypeMaximum FineGlobal Turnover CapGDPR Comparison
Prohibited AI (Article 5)€35,000,0007%2× higher than GDPR max (4%)
High-Risk AI / GPAI Obligations€15,000,0003%≈ GDPR mid-tier
Misleading Authorities€7,500,0001.5%Lower tier
SME / Startup MitigationLower of fixed cap or percentage applies. Regulators must consider proportionality, company size, and cooperation with authorities when setting fines.

Beyond financial penalties, national authorities can order market withdrawal of non-compliant AI systems, impose temporary or permanent bans on operation in the EU, and require public disclosure of violations. For non-EU providers, this can effectively mean total loss of EU market access.

Reference: IAPP EU AI Act Resource Centre · Our Full Penalties Guide

11. Quick Reference Tables

Use these tables to quickly locate key articles, understand obligations by actor, and identify your compliance priorities.

Table A: Key Articles at a Glance

ArticleTopicKey Provision
Art. 3Definitions48 defined terms including AI system, provider, deployer, GPAI model
Art. 5Prohibited PracticesEight banned AI use cases; effective 2 Feb 2025
Art. 6High-Risk ClassificationRules for classifying AI systems as high-risk; references to Annex I and III
Art. 9Risk ManagementMandatory risk management system for high-risk AI; iterative lifecycle requirement
Art. 10Data GovernanceTraining data quality, bias testing, data management practices
Art. 11Technical DocumentationDocumentation requirements; Annex IV specifies content
Art. 13TransparencyClear instructions for use; information to deployers
Art. 14Human OversightDesign requirements enabling human monitoring and override
Art. 17Quality ManagementQMS requirements covering full development and deployment lifecycle
Art. 25Deployer ReclassificationConditions under which a deployer becomes a provider (substantial modification)
Art. 43Conformity AssessmentSelf-assessment vs third-party assessment rules
Art. 49EU Database RegistrationMandatory registration before market placement
Art. 50Transparency ObligationsChatbot disclosure, deepfake labeling, AI-generated content rules
Art. 53GPAI Provider ObligationsDocumentation, copyright compliance, downstream transparency
Art. 72Incident ReportingSerious incident reporting; 15-day notification window

Table B: Compliance Obligations by Actor Type

ObligationProviderDeployerImporterDistributorGPAI Provider
Risk Management System
Technical Documentation✅ (verify)
Conformity Assessment✅ (verify)
EU AI Database Registration✅ (some)
Human Oversight Design✅ (operate)
AI Literacy Training for Staff
Fundamental Rights Impact Assessment
Maintain Use Logs (6 months)
Incident Reporting
Copyright & Training Data Disclosure

Table C: Annex III High-Risk Categories — Common Affected Products

CategoryCommon Products / SystemsWho Is Typically Affected
Biometric IDFace recognition, fingerprint systems, gait analysisSecurity companies, access control vendors, law enforcement tech
Critical InfrastructureGrid management AI, traffic control, flood predictionUtilities, smart city platforms, transport operators
EducationAdmissions AI, automated grading, proctoring toolsEdTech companies, universities, exam boards
Employment / HRCV screening, interview analysis AI, performance monitoringHR software vendors, enterprises using these tools
Essential ServicesCredit scoring, insurance underwriting AI, benefits eligibilityBanks, insurers, fintech companies, public sector
Law EnforcementPredictive policing tools, AI lie detectors, evidence analysisLegal tech vendors, police technology suppliers
Migration & BorderRisk profiling tools, document verification, asylum processing AIBorder tech vendors, immigration authorities
Justice AdministrationLegal research AI, sentencing recommendation toolsLegal tech companies, court administration bodies

Source: Annex III, Regulation EU 2024/1689 · Our Full Annex III Guide

EU AI Act Summary — PDF Guide
Download the complete EU AI Act Summary as a formatted PDF. Includes all key articles, obligation tables, deadlines, and the Annex III checklist. Free to download and share.
↓ Download PDF

12. EU AI Act Summary — FAQ

Comprehensive answers to the most-searched questions about the EU AI Act, structured for fast reference by legal, compliance, and technical teams.

What is the EU AI Act in simple terms? +
The EU AI Act is a law that sets rules for how AI systems can be used in Europe. Think of it as a safety rating system for AI: the more dangerous the AI could be, the stricter the rules. Some AI applications are banned entirely (like using AI to manipulate people subliminally). Others need extensive safety checks before they can be used (like AI in hiring or credit decisions). Most AI — like spam filters or video game AI — faces no mandatory requirements at all.
Is the EU AI Act in force now? +
Yes — the Act entered into force on 1 August 2024. However, not all obligations apply immediately. The Act uses a phased approach: the ban on prohibited AI practices applies from 2 February 2025; GPAI obligations from 2 August 2025; and the main high-risk AI and transparency obligations from 2 August 2026. Some legacy product obligations do not apply until 2027. As of March 2026, organisations should be in active compliance preparation for the August 2026 deadline.
How does the EU AI Act define an “AI system”? +
Article 3(1) defines an AI system as a machine-based system designed to operate with varying levels of autonomy that may exhibit adaptiveness, and that — for explicit or implicit objectives — infers from the inputs it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This deliberately broad definition is aligned with the OECD AI Principles definition. It covers most machine learning systems, neural networks, and large language models — but not traditional rule-based software or simple search algorithms.
Does a UK or US company need to comply with the EU AI Act? +
Yes — if they place AI systems on the EU market or their AI outputs are used in the EU. The Act has full extraterritorial effect. A UK or US SaaS company that provides an HR screening tool, a credit scoring API, or any other Annex III system to EU-based customers is a Provider under the Act and must comply with all provider obligations — including conformity assessment, technical documentation, and EU AI database registration. Non-EU providers must appoint an EU-based Authorised Representative (Article 22). Brexit does not exempt UK companies; they are treated identically to companies from any other third country.
What is a “conformity assessment” and how long does it take? +
A conformity assessment is the formal process by which a provider verifies that their high-risk AI system meets all the requirements in Articles 8 to 15. For most Annex III systems, this is an internal self-assessment based on the provider’s own documentation and testing. Third-party assessment by an accredited Notified Body is mandatory for biometric identification systems and AI components in safety-critical regulated products (Annex I). In practice, a full self-conformity assessment for a complex high-risk AI system (including risk management documentation, data governance review, and technical documentation preparation) typically takes 4 to 12 months depending on organisation size and starting maturity. Organisations aiming for the August 2026 deadline should begin immediately.
What is the EU AI Act database and who needs to register? +
The EU AI Act database (Article 71) is a publicly accessible registry managed by the EU AI Office. Providers of high-risk AI systems listed in Annex III must register before placing their system on the EU market. The registration captures: the provider’s identity and contact details, a description of the AI system and its intended purpose, a summary of the conformity assessment, the declaration of conformity reference, and the AI system’s technical specifications. Certain deployers of high-risk AI systems used by public bodies must also register their deployment. The database is designed to enable transparency, allowing downstream deployers and regulators to verify that a system has undergone the required conformity process.
Can open-source AI models be exempt from the EU AI Act? +
Partially. The Act provides some accommodation for open-source AI — in particular for GPAI models: providers of open-source GPAI models released under open licences may benefit from reduced documentation obligations compared to closed-model providers. However, this does not create a blanket exemption. If an open-source AI system falls under a prohibited practice (Article 5), those prohibitions still apply. If an organisation fine-tunes or adapts an open-source model and deploys it as a high-risk system, they become a Provider and all high-risk obligations apply. The open-source accommodation is a nuance, not a loophole.
How does the EU AI Act relate to GDPR? +
The EU AI Act and GDPR operate in parallel and are complementary. GDPR governs the processing of personal data — including when AI systems process personal data. The EU AI Act governs the development and deployment of AI systems, regardless of whether they involve personal data. An AI recruitment screening tool, for example, creates obligations under both laws: GDPR applies because it processes candidates’ personal data; the EU AI Act applies because it is an Annex III high-risk AI system. Where there is overlap, organisations must comply with both. The European Data Protection Board (EDPB) has issued guidance on the interaction between the two frameworks.
What is a Fundamental Rights Impact Assessment (FRIA)? +
A Fundamental Rights Impact Assessment (FRIA) is a mandatory pre-deployment assessment required for certain deployers of high-risk AI systems — specifically bodies governed by public law and private entities providing public services. It must be completed before deploying a high-risk AI system. The FRIA assesses: the purpose and geographic scope of deployment; who might be affected; the potential impact on fundamental rights (as defined in the EU Charter); the likelihood and severity of that impact; and mitigation measures. Deployers must notify their national market surveillance authority upon completion. The FRIA is similar in concept to a GDPR Data Protection Impact Assessment (DPIA) but specifically focused on AI-driven fundamental rights implications.
What counts as a “serious incident” that must be reported? +
Article 3(49) defines a serious incident as any incident or malfunction of a high-risk AI system that: results in the death of a person; results in serious injury; causes significant disruption in the management of critical infrastructure; causes significant property damage; or leads to an infringement of obligations under EU law protecting fundamental rights. Providers must report serious incidents to the national market surveillance authority of the member state where the incident occurred within 15 days of becoming aware of it. If the incident is life-threatening or fatal, reporting must occur immediately. This mirrors the incident reporting approach in the NIS2 Directive for cybersecurity incidents.
What are the AI literacy requirements? +
Article 4 requires all providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff and other persons dealing with AI systems on their behalf. This obligation applied from 2 February 2025. The Act does not prescribe a specific training curriculum or certification — it requires organisations to assess what level of AI literacy is appropriate for their context and ensure their teams can understand and critically evaluate AI outputs, recognise limitations, and fulfil their oversight obligations. In practice, this means deployers need to train HR teams, credit officers, judges, or any other staff operating high-risk AI tools to understand how those tools work and how to exercise meaningful human oversight.
Where can I find the full official text of the EU AI Act? +
The full official text is published in all EU official languages on EUR-Lex: Regulation (EU) 2024/1689 — EUR-Lex. The EU AI Act reference site provides a more navigable article-by-article version. The European Commission’s digital strategy page provides policy summaries and links to guidance documents from the AI Office. For practical compliance guidance, see our 2026 Compliance Guide.
MF
Martina Fowler
EU AI Act Expert
Senior AI Regulatory Counsel & Lead Author, EU AI Act Guide

Martina Fowler is a senior AI regulatory counsel with over a decade of experience advising multinational organisations on technology law, data governance, and EU digital policy. She has closely tracked the EU AI Act since the Commission’s initial proposal in April 2021 and has guided dozens of enterprises through risk classification, conformity assessment design, and cross-border compliance strategy. Martina holds an LL.M. in European Law from KU Leuven and is a frequent speaker at EU policy forums on AI regulation and fundamental rights. Her work at EU AI Act Guide focuses on translating complex legislative text into actionable compliance frameworks for legal, technical, and business audiences.

martina.fowler@euaiactguide.com