EU AI Act · Compliance

AI Act: Why Articles 1–4 Are the Real Starting Point (and Where Most Compliance Work Goes Wrong)

Before classifying an AI system as high-risk or building a compliance programme, there is a more fundamental question: does the EU AI Act apply, to whom, and in what capacity? Articles 1–4 provide the legal starting point. Getting these first steps wrong can distort everything that follows.

AI Act: Why Articles 1–4 Are the Real Starting Point (and Where Most Compliance Work Goes Wrong)

Reviewed by Oleksandr Sobovyi, Founder & CEO of CORVUS AI — editorial responsibility statement below.

Complex law. Clear action.

When clients first come with an AI system and ask “what do we need to do under the AI Act?”, the instinct is often to jump straight to high-risk classification, conformity assessment, or the new GPAI rules. That is almost always a mistake.

The EU AI Act (Regulation (EU) 2024/1689) is deliberately built as a risk-based framework. You can find the official text here. It consists of 13 chapters, 113 articles, 180 recitals and 13 annexes. The architecture is not accidental. It is sequential. And Chapter I (Articles 1–4) sits at the very front for a reason: it is the filter that decides whether the Regulation applies at all, to whom it applies, and on what terms.

The overall logic of the Regulation

  • Chapter I (Arts. 1–4) — subject matter, territorial and material scope, definitions, and AI literacy. This is the foundation. Without a correct reading of Articles 2 and 3, nothing that follows can be applied properly.

  • Chapter II (Art. 5) — prohibited AI practices (the absolute bans).

  • Chapter III (Arts. 6–49) — the high-risk regime: classification, obligations of providers and deployers, conformity assessment, registration.

  • Chapter IV (Art. 50) — transparency obligations for specific categories (chatbots, deepfakes, emotion recognition systems, etc.).

  • Chapter V (Arts. 51–56) — general-purpose AI models, including those presenting systemic risk.

  • Chapters VI–XIII — governance (AI Office, national competent authorities), post-market monitoring, enforcement, penalties, and final provisions.

In practice, this means that every serious AI compliance review begins with the same two questions: Does the Regulation apply? And if so, to which economic operator, in which role?

Why Articles 1–4 matter more than most people realise

Article 1 sets out the subject matter and objectives. Article 2 draws the territorial and material boundaries — who is caught when the system is placed on the market, put into service, or used in the Union, including the extraterritorial reach that many non-EU companies still underestimate. Article 3 contains the definitions that determine everything downstream: what counts as an “AI system”, who is a “provider”, who is a “deployer”, what constitutes “placing on the market”, and so on. Article 4 introduces the AI literacy obligation — an under-discussed but practically important requirement that already has implications for training, documentation and governance.

Get any of these wrong and the rest of the analysis collapses. We regularly see clients who have spent months mapping obligations under Articles 9, 10 or 16, only to discover that they were looking at the wrong role entirely — treating themselves as a deployer when they were in fact a provider, or assuming the system fell outside the material scope when a careful reading of Article 2 brought it back in.

That is not a theoretical risk. It is the difference between a manageable compliance programme and a fundamental misallocation of legal, technical and commercial resources.

Practical takeaway

Chapter I is the entry filter. Every AI Act analysis that does not begin with a rigorous scope and definitional assessment is, at best, incomplete and, at worst, actively misleading. Before you open Annex III, before you debate whether your system is high-risk, and before you start drafting technical documentation, answer the preliminary questions properly:

  • Does the AI Act apply to this system and these activities at all?

  • Who is the provider and who is the deployer in this specific configuration?

  • Are there any carve-outs or special regimes that change the picture?

Only once those answers are solid does it make sense to move to the substantive obligations.

In our experience, the clients who treat Articles 1–4 as a formality are the ones who later face the most expensive corrections. The ones who treat them as the foundation tend to build cleaner, more defensible compliance programmes from the outset.

That is where the real work starts.

What matters. What’s next.

Disclaimer

This article has been prepared by CORVUS AI for general informational and educational purposes only. It is intended to make complex legal and regulatory developments easier to understand.

It does not constitute legal advice and does not create a professional adviser–client relationship. The information should not be relied upon as a substitute for advice based on the specific facts, circumstances and applicable law relevant to your organisation or project.

The article reflects our understanding of the law and regulatory framework as of the date of publication. Legislation, case law, regulatory guidance and administrative practice may subsequently change. While reasonable care has been taken in preparing this article, CORVUS AI does not warrant that the information is complete or remains current after the date of publication. We do not undertake to update this content.

To the fullest extent permitted by applicable law, CORVUS AI excludes liability for loss arising from reliance on this article. Nothing in this article constitutes an offer or solicitation to provide regulated legal services in any jurisdiction where doing so would be unlawful.

AI-assisted preparation: This article was prepared with the assistance of AI tools. Its legal analysis, conclusions and final text were subject to human review and editorial control and were reviewed and approved prior to publication by Oleksandr Sobovyi, Founder & CEO of CORVUS AI. CORVUS AI retains editorial responsibility for the published content.

For advice tailored to your organisation, project or specific circumstances, please contact CORVUS AI.

Official text of the AI Act: Regulation (EU) 2024/1689

logo