The AI Act, in one sentence
L'AI Act is the European regulation on artificial intelligence, Regulation (EU) 2024/1689, which entered into force on 1 August 2024. It is the world's first comprehensive legal framework on AI. It does not regulate a technology: it regulates uses, with a simple rule: the more a use can harm people, the heavier the obligations.
It applies on top of the GDPR, without replacing it. The GDPR protects personal data; the AI Act governs what AI systems do, and how they influence decisions about people.
Provider or deployer: what is your role?
The whole regulation rests on a distinction between two roles, which do not carry the same obligations.
| Role | Who it is | Examples |
|---|---|---|
| Provider | Develops an AI system, or has it developed, and places it on the market under its own name. | Mistral, OpenAI, or the publisher of a tool such as Opti'. |
| Deployer | Uses an AI system under its authority, in a professional context. | Your organisation, as soon as its teams use an AI tool for work. |
An NGO is almost always a deployer: it uses tools designed by others. It therefore has its own obligations, which cannot be delegated to the provider.
Is your organisation concerned?
The scope is set by Article 2. For an organisation working in Africa, there are three situations.
- Your organisation is established in the European Union, for example an international NGO headquartered in Europe: it is a deployer within the meaning of the regulation, including for what its teams do.
- The output produced by the AI is used in the Union: the regulation then also applies to providers and deployers established outside the Union.
- A national organisation with no link to the Union is not directly subject to it. But its European donors and partners are, and they pass these requirements on in their contracts, as they did for the GDPR.
In every case, national data protection laws already apply, whatever tool is used.
Four levels of risk, four regimes
| Level | Regime | What it means |
|---|---|---|
| Unacceptable risk | Prohibited | Practices contrary to fundamental rights. No humanitarian exemption. |
| High risk | Regulated | Allowed, with heavy obligations before and during use. |
| Transparency risk | Disclosed | Allowed, provided it is made clear that it is AI. |
| Minimal risk | Free | No specific obligation. This covers the vast majority of everyday uses. |
Separately, general-purpose AI models, the ones behind conversational assistants, have their own obligations since 2 August 2025. These fall on their providers, not on the organisations that use them.
What has been prohibited since 2 February 2025
Article 5 prohibits eight practices. The first two directly concern the humanitarian sector.
- Exploiting vulnerabilities linked to age, disability or a specific social or economic situation, to distort a person's behaviour in a way that harms them.
- Social scoring: evaluating or classifying people based on their social behaviour or personality, leading to unfavourable treatment.
- Manipulation through subliminal or deliberately deceptive techniques.
- Emotion recognition in the workplace and in educational institutions, except for medical or safety reasons.
- Biometric categorisation aimed at inferring race, political opinions, religious beliefs or sexual orientation.
- Untargeted scraping of facial images to build facial recognition databases.
- Predicting criminal offences based solely on profiling or personality traits.
- Real-time remote biometric identification in public spaces for law enforcement, save for strict exceptions.
From 2 December 2026, the AI omnibus regulation adds a ban on systems that generate non-consensual intimate images or child sexual abuse material.
High risk: where humanitarian work is directly targeted
Annex III lists the high-risk uses. Several of them exist in our sector:
- Access to essential benefits: assessing people's eligibility for essential public assistance and services, or deciding to grant, reduce or revoke them, by or on behalf of a public authority.
- Emergencies: triaging emergency calls, dispatching emergency services, triaging patients in emergency healthcare.
- Migration, asylum and borders: assessing a risk posed by a person, examining an application for asylum, a visa or a residence permit.
- Employment: recruiting, screening applications, evaluating, deciding on a promotion or a dismissal.
The provider must then set up risk management, ensure data quality, document and log, provide for human oversight, and ensure accuracy and robustness. The deployer, for its part, uses the system according to its instructions, assigns oversight to competent people, keeps the logs and informs the people concerned. Public bodies and private entities providing public services must also carry out a fundamental rights impact assessment.
These obligations were due to apply on 2 August 2026. The AI omnibus regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July, postponed them to 2 December 2027, and to 2 August 2028 for AI embedded in regulated products. The postponement is not a cancellation: the obligations themselves are unchanged.
Transparency, applicable since 2 August 2026
Article 50 is the part of the regulation that affects the most everyday uses. The European Commission published its guidelines on 20 July 2026, together with a code of practice on marking generated content.
| Obligation | Who | What it requires |
|---|---|---|
| Say that people are talking to an AI | Provider | A system that interacts directly with people, a chatbot for example, must tell them so, unless it is obvious. |
| Mark generated content | Provider | Generated text, images, audio and video carry machine-readable marking. Systems already on the market have until 2 December 2026. |
| Disclose deepfakes | Deployer | An image, audio or video that imitates a real person or event is disclosed as generated. |
| Disclose published text | Deployer | Generated text published to inform the public on matters of public interest is disclosed, unless it has been reviewed by a human who takes editorial responsibility for it. |
People exposed to an emotion recognition or biometric categorisation system must also be informed.
AI literacy: the obligation that concerns everyone
Article 4 has applied since 2 February 2025 to every organisation that provides or deploys AI. It was reworded by the omnibus on 27 July 2026:
- before, providers and deployers had to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff;
- since then, they must take measures to support the development of that literacy, without being required to guarantee a given level for each person. The Commission and the Member States must support this effort.
It moves from an obligation of result to an obligation of means. It still falls on the organisation that puts AI in the hands of its teams, not on the person using it. In practice, it means being able to show what has been done: written guidance, training adapted to roles, a way to report problems.
The timeline, as of 21 September 2026
| Date | What applies |
|---|---|
| 1 August 2024 | Entry into force of the regulation |
| 2 February 2025 | Prohibited practices and AI literacy |
| 2 August 2025 | General-purpose AI models, governance, penalties |
| 27 July 2026 | Entry into force of the AI omnibus, Regulation (EU) 2026/1744 |
| 2 August 2026 | General application of the regulation, including transparency |
| 2 December 2026 | New prohibitions, end of the marking grace period for existing systems |
| 2 December 2027 | High risk, Annex III |
| 2 August 2028 | High risk embedded in regulated products |
Fines can reach EUR 35 million or 7% of worldwide turnover for a prohibited practice, EUR 15 million or 3% for other obligations, and EUR 7.5 million or 1% for incorrect information supplied to authorities. For small and medium-sized enterprises, the lower of the two amounts applies.
Where to start
- Take stock of the AI tools your teams really use, including personal accounts and AI features added to existing software.
- Classify each use: prohibited, high risk, transparency or minimal. It is the use that gets classified, not the tool.
- Train and guide: written guidance, training adapted to roles, a way to report problems. That is Article 4.
- Disclose AI: tell people when they are interacting with an AI, and review what you publish. That is Article 50.
- Require from your suppliers what they are obliged to do, and put it in the contract.
The AI Act and the SAFE AI framework
The law sets a floor. It says nothing about what matters most in humanitarian work: humanitarian principles, community participation, people's right to know when AI is making decisions about them. For that, the sector has given itself a more demanding standard, published in May 2026: the SAFE AI framework, explained, with its three risk tiers and its four-stage journey.
For the reasons specific to AI in our sector, and how Opti' responds to them, see also ethical AI in humanitarian work and AI for MEAL.
What Opti' does with these requirements
Opti' is a provider within the meaning of the regulation. Its everyday uses, drafting a questionnaire, analysing a dataset, writing a report, fall under minimal risk or transparency: the tool does not assess anyone's eligibility. Compliance, however, always depends on how your organisation uses it.
- The figures in a report never come from the model: they come from a register calculated from the data, which the writing only references.
- Before writing, the AI submits its readings to the user, who validates, corrects or rejects them: this is the human review that Article 50 asks for.
- Servers in Europe, application-level encryption of content before it is written to the database, and a private AI option, OptIA, with no third-party provider.
Frequently asked questions
My organisation is not in Europe: does the AI Act apply?
Not directly, if it is not established in the Union and if the AI's outputs are not used there. It does however apply to an NGO headquartered in Europe, and European donors pass its requirements on in their contracts.
Is it allowed to use ChatGPT to write a report?
Yes, it is generally a minimal-risk use. If the text is published to inform the public on matters of public interest, it must be disclosed as AI-generated, unless it has been reviewed by a person who takes editorial responsibility for it. The main risk lies elsewhere: pasting beneficiary data into it.
Does the Article 4 training obligation still exist?
Yes. Since 27 July 2026, it requires taking measures to support the development of staff AI literacy, without guaranteeing a given level. It is an obligation of means, which falls on the organisation.
Does the high-risk postponement mean we can wait until 2027?
No. The obligations are unchanged; only their application date has been postponed to 2 December 2027. The prohibitions, AI literacy and transparency already apply.
Is an aid targeting tool high risk?
It is if it assesses people's eligibility for essential public benefits, by or on behalf of a public authority. In other cases, it still falls under the highest tier of the SAFE AI framework, which applies to any use that directly affects access to aid.