Overview & scope
The EU AI Act is a horizontal regulation: it governs AI systems generally rather than sector by sector, and it is built to be risk-based — the heavier the potential harm, the heavier the obligation.
Published in the Official Journal on 12 July 2024 and in force since 1 August 2024, the Act establishes a single legal framework for the development, supply and use of AI across all member states. Core transparency, governance and penalty provisions apply from 2 August 2026; several obligations are already live, and the high-risk regime was deferred to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) by the Digital Omnibus (see Timeline). It sits within the EU's New Legislative Framework for product safety and is designed to keep AI safe and respectful of fundamental rights while still supporting innovation.
The Act provides, at a high level:
- Harmonised rules for the supply and use of AI systems in all member states, with extraterritorial reach over operators based outside the EU.
- Prohibitions of a small set of AI practices deemed unacceptable.
- Technical and operator requirements for high-risk AI systems that present a significant risk of harm.
- A dedicated regime for providers of general-purpose AI (GPAI) models, with extra duties where systemic risk is present.
- Transparency duties for systems that interact with people or generate synthetic content.
- Rules for governance, market surveillance and enforcement, plus measures — notably regulatory sandboxes — to support SMEs and start-ups.
Entry into force & the compliance timeline
The Act came into force on 1 August 2024, but its obligations switch on in waves under Art 113. The dates below are operative law, including the amendments made by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), which deferred the high-risk deadlines and added two new prohibitions (see §15).
Regulation enters into force
The clock starts. Staggered application dates follow under Article 113.
Prohibited practices banned · AI literacy duty begins
The original eight Article 5 prohibitions apply outright; providers and deployers must take measures to support the development of AI literacy among staff (Art 4, recast by the Digital Omnibus with effect from 27 Jul 2026 — no specific level of literacy is guaranteed).
GPAI model rules · penalties (mostly) · governance
Obligations for GPAI model providers apply; the penalty regime applies (except Art 101 GPAI-provider fines, delayed 12 months). The AI Office, AI Board and advisory forum become operational.
Transparency · GPAI enforcement · penalties
Art 50 transparency for systems placed on the market from this date, and the Commission's enforcement powers and fines for GPAI providers (Arts 99–101). Not deferred by the Digital Omnibus — but the high-risk Annex III regime that originally started today has moved to 2 Dec 2027.
New Art 5 prohibitions · legacy synthetic-content marking
Two new prohibitions added by the Digital Omnibus apply — AI that generates or manipulates realistic non-consensual intimate imagery, and child sexual abuse material (Art 5(1)(ba)–(bb)). Providers of synthetic-content systems placed on the market before 2 Aug 2026 must meet the Art 50(2) machine-readable marking duty by this date (new Art 111(4)).
Legacy GPAI compliance · sandboxes operational
GPAI models placed on the market before 2 Aug 2025 must be brought into compliance (Art 111(3) — unchanged by the Omnibus). National regulatory sandboxes must be operational (Art 57).
High-risk (Annex III) obligations apply
The full high-risk regime for Art 6(2) / Annex III systems — risk management, data governance, technical documentation, human oversight, conformity assessment, EU-database registration and deployer duties including the FRIA — deferred from 2 Aug 2026. Backstop date: it can bite earlier, six months after a Commission decision that the supporting standards and measures are available.
High-risk safety components (Annex I) apply
Obligations for high-risk AI that is a safety component of a product already covered by Annex I product-safety law (Art 6(1)) — deferred from 2 Aug 2027 (or 12 months after the Commission support-measures decision, if earlier).
High-risk AI used by public bodies
Systems already on the market and used by public authorities must comply by this date (Art 111(2)).
Large-scale EU IT systems (Annex X)
Systems such as those handling visas or Schengen information, put into service before their application date, must comply by end-2030 (Art 111(1)).
Risk classification
Risk = the probability of harm × its severity. The Act sorts AI into four bands, plus a parallel track for GPAI models. Select a tier to see what it means and where the obligations sit.
General-purpose AI models (e.g. large language models) are regulated separately from the four-tier system. All GPAI providers carry documentation, copyright and transparency duties; those crossing the systemic-risk threshold (presumed above 10²⁵ training FLOPs) take on evaluation, incident-reporting and cybersecurity obligations on top. See §8 →
Prohibited AI practices
Article 5 bans a closed set of practices judged incompatible with fundamental EU values and rights. These have been prohibited outright since 2 February 2025, and breach draws the highest fine tier (up to €35M or 7% of worldwide turnover).
- Subliminal or manipulative techniques that materially distort behaviour and are reasonably likely to cause significant harm.
- Exploiting vulnerabilities — of age, disability or economic situation — to distort behaviour and cause significant harm.
- Social scoring that leads to detrimental or disproportionate treatment out of context.
- Predictive policing of individuals — assessing the risk a person will commit a crime, based solely on profiling (except to support a human assessment grounded in verifiable facts).
- Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.
- Emotion recognition in the workplace or education (except for medical or safety reasons).
- Biometric categorisation inferring sensitive attributes such as race, political opinion or religion.
- Real-time remote biometric identification in public spaces for law enforcement — except within narrow, safeguarded exceptions (see Annex II offences).
High-risk AI systems
Article 6 defines high-risk AI via two routes, and it is here that the Act's technical and operator burden concentrates.
- Route 1 — safety components (Art 6(1)). AI that is, or is the safety component of, a product covered by the Annex I product-safety legislation and already requires third-party conformity assessment (e.g. medical devices, toys, lifts).
- Route 2 — Annex III use cases (Art 6(2)). AI intended for a listed high-stakes area — unless it does not pose significant harm (the Art 6(3) derogation).
Annex III — the high-risk use cases
- Biometrics — remote identification, sensitive-attribute categorisation, emotion recognition.
- Critical infrastructure — safety components in digital infrastructure, road traffic, utilities.
- Education & vocational training — admissions, evaluation of outcomes, exam-cheating detection.
- Employment — recruitment, targeted job ads, promotion/termination, performance monitoring.
- Essential services — public benefits, credit scoring (except fraud detection), life/health insurance pricing.
- Law enforcement — polygraphs, evidence reliability, re-offending / victim risk, profiling.
- Migration, asylum & border control — assisting visa and asylum examinations.
- Justice & democracy — assisting judicial fact-finding, or influencing elections and referenda.
Requirements for high-risk systems Arts 8–15
If a system is high-risk, it must satisfy a stack of granular requirements. In brief, it must:
- Operate a continuous risk-management system across the lifecycle Art 9.
- Use data & governance — training, validation and testing sets that are relevant, representative and, as far as possible, error-free and unbiased Art 10.
- Maintain technical documentation (at least the Annex IV elements) demonstrating conformity Art 11.
- Enable automatic record-keeping / logs, retained for at least six months Art 12.
- Provide transparency & instructions for use so deployers can interpret and use output correctly Art 13.
- Allow effective human oversight, including the ability to interrupt or stop the system safely Art 14.
- Achieve appropriate accuracy, robustness & cybersecurity — resilient to data poisoning and model evasion Art 15.
Operator obligations across the value chain
Requirements sit on top of every organisation in the high-risk supply chain — the bulk on the provider, with lighter duties down the chain. Select a role:
The provider carries the heaviest burden Arts 16–21. Before release it must:
- Ensure the system meets the technical requirements and affix CE marking with its identifying details.
- Operate a quality-management system Art 17 and complete the conformity assessment, drawing up the EU declaration of conformity.
- Register the system on the central EU database before placing it on the market.
- Retain technical documentation and the declaration for 10 years; retain auto-generated logs for at least six months.
- Appoint an authorised representative where relevant; take immediate corrective action and cooperate with authorities if the system ceases to conform.
Before placing a high-risk system on the market Art 23, an importer must verify the provider has:
- Completed the relevant conformity assessment and drawn up technical documentation.
- Appointed an authorised representative and affixed CE marking plus the EU certificate of conformity.
Importers add their name and address to the packaging, keep the certificate / declaration for 10 years, report risks, and cooperate with authorities.
Before making a system available Art 24, distributors verify that CE marking is applied, the declaration and instructions accompany the system, and upstream parties have met their duties. Once it is on the market they must monitor, take corrective action, and notify the provider/importer and authorities of non-compliance or risk.
Deployers use the system under their own authority Art 26. They must:
- Use it per the instructions for use and assign competent human oversight.
- Ensure input data (where in their control) is relevant and representative.
- Monitor operation, suspend use and report risks/serious incidents up the chain; retain logs for at least six months.
- Inform affected workers before workplace deployment; public-sector deployers must use only registered systems and register their own use.
- Complete a fundamental rights impact assessment (FRIA) where required Art 27.
Providers established outside the EU must appoint an authorised representative by written mandate before offering high-risk systems (Art 22) or GPAI models (Art 54). The representative verifies the declaration and documentation, confirms the conformity assessment, and — if it believes the provider is non-compliant — must terminate the mandate and report to the market-surveillance authority.
Transparency requirements
Article 50 applies to providers and deployers of systems that interact with people or create content people see — regardless of whether the system is also high-risk. Information must be given at the time of first interaction or exposure, be clear and identifiable, and meet accessibility rules (Art 50(5)). Likely the Act's most far-reaching duty, given chatbots and generative AI.
- Direct interaction (Art 50(1)). Providers must ensure people are told they're interacting with AI — unless it's obvious to a reasonably informed person.
- Synthetic content (Art 50(2)). Providers must mark AI-generated or manipulated audio, image, video or text as artificially generated, in a machine-readable, robust way.
- Emotion recognition / biometric categorisation (Art 50(3)). Deployers must inform the people subject to it and comply with data-protection law.
- Deepfakes (Art 50(4)). Deployers must disclose that image, audio or video content is artificially generated or manipulated — relaxed for evidently artistic or satirical work.
- Synthetic text on matters of public interest (Art 50(4)). Must be disclosed as AI-generated, unless a human reviewed it and holds editorial responsibility.
General-purpose AI (GPAI) models
The Act regulates GPAI models on their own track, with a baseline set of duties for all providers and a heavier layer where a model carries systemic risk.
All GPAI providers Art 53
- Maintain up-to-date technical documentation (at least Annex XI) for the model.
- Provide downstream information (Annex XII) so integrators can meet their own obligations.
- Put in place a copyright policy respecting EU law and a rights reservation, and publish a sufficiently detailed summary of training data using the AI Office template.
- Third-country providers must appoint an authorised representative (Art 54).
Open-source exception: most of these duties fall away for models released under a free and open-source licence with public architecture — but not for models with systemic risk (Art 53(2)).
Systemic-risk GPAI Arts 51–55
A model has systemic risk if it has high-impact capabilities (Art 51). High impact is presumed above 10²⁵ cumulative training FLOPs. Providers must notify the Commission within two weeks of meeting (or expecting to meet) the threshold, and additionally:
- Perform model evaluation and adversarial testing with state-of-the-art tools.
- Assess and mitigate systemic risk at EU level.
- Document and promptly report serious incidents to the AI Office and national authorities.
- Ensure adequate cybersecurity for the model and its physical infrastructure.
Evidencing conformity, CE marking & registration
Conformity assessment is a provider obligation for high-risk systems. Most can be done by self-assessment (Annex VI, internal control); where that isn't available the provider must use a notified body (Annex VII).
- Harmonised standards Art 40. Systems built to harmonised standards enjoy a presumption of conformity and can self-assess. Standards are still in development (2027 estimates) — hence the reliance on codes of practice and common specifications (Art 41).
- Notified-body route. Required where standards/common specs don't exist or aren't applied, or a standard carries a restriction — the notified body assesses the quality-management system and technical documentation and issues a certificate (valid up to 4–5 years).
- EU declaration of conformity Art 47. Prepared by the provider, kept up to date and retained for 10 years; one declaration can cover multiple applicable EU laws.
- CE marking Art 48. Affixed (physically or digitally) to indicate conformity; where a notified body was involved, its ID number is shown.
- EU database registration Art 49. Providers register Annex III high-risk systems before market; public-authority deployers register their use. Law-enforcement / migration systems register only limited data in a secure, non-public section.
Governance, monitoring & enforcement
A layered set of bodies oversees the Act Arts 64–70: the AI Office (EU-level expertise, guidance and GPAI enforcement), the European AI Board (one representative per member state), an Advisory Forum (industry, civil society, academia), a scientific panel of independent experts, and national competent authorities — each member state designates at least one notifying authority and one market-surveillance authority.
Post-market monitoring & serious-incident reporting
Providers must monitor high-risk systems in the field (Art 72). Serious incidents are reported to the market-surveillance authority immediately after a causal link is established, and no later than:
- 2 days — widespread infringement, or a serious incident that disrupts critical infrastructure.
- 10 days — death of a person.
- 15 days — any other serious incident (the default cap) Art 73.
Market surveillance
Authorities hold broad powers: they can require access to training data, and to source code where needed to assess conformity and other checks are exhausted (Art 74(13)); they can prohibit, withdraw or recall a non-compliant system (Art 79(5)). The Commission holds exclusive GPAI enforcement (Art 88), assisted by the AI Office. A whistleblower tool supports anonymous reports.
Penalties
Articles 99 & 101 set a tiered fine regime — the higher of a fixed cap or a percentage of worldwide annual turnover. Fines apply from 2 Aug 2025 (GPAI-provider fines from 2 Aug 2026).
Non-compliance with the Article 5 bans — the highest tier.
Art 99(3)Breach of most obligations on operators, including transparency duties.
Art 99(4)Supplying incorrect, incomplete or misleading information to authorities.
Art 99(5)Failure by GPAI-model providers to meet their obligations.
Art 101(1)Extraterritorial reach & action points for non-EU entities
Article 2 gives the Act significant extraterritorial effect. It applies to:
- Providers placing a system or GPAI model on the EU market — wherever they are established.
- Deployers located or established in the EU.
- Any provider or deployer outside the EU whose system output is used in the EU.
- Importers, distributors, product manufacturers and authorised representatives.
Definitions Art 3
The Act's obligations turn on defined terms. Filter the glossary:
AI system
"A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from input how to generate outputs — predictions, content, recommendations or decisions — that can influence physical or virtual environments."
GPAI model
An AI model — including one trained at scale with self-supervision — that displays significant generality, competently performs a wide range of tasks, and can be integrated into many downstream systems. Excludes models still used only for R&D or prototyping.
Provider
A person or organisation that develops (or has developed) an AI system or GPAI model and places it on the market or puts it into service under its own name or trade mark, for payment or free.
Deployer
Any person or organisation using an AI system under its authority — except purely personal, non-business use. Covers an employer deploying a system to its workforce, or a public authority to the public.
Operator
The umbrella term: a provider, product manufacturer, deployer, authorised representative, importer or distributor.
Placing on the market
The first making available of an AI system or GPAI model on the EU market.
Putting into service
Supply of a system for first use directly to the deployer, or for the provider's own use in the EU, for its intended purpose.
Intended purpose
The use for which the provider intends a system, as specified in its instructions, promotional material and technical documentation — a key yardstick for assessing risk and conformity.
Reasonably foreseeable misuse
Use not for the intended purpose, but which may result from reasonably foreseeable human behaviour.
Deepfake
AI-generated or manipulated image, audio or video content that resembles real persons, objects or events and would falsely appear authentic. Always subject to Art 50 transparency.
Systemic risk
A risk specific to the high-impact capabilities of GPAI models, with significant EU-market impact through reach or foreseeable negative effects that can propagate at scale.
High-impact capabilities
Capabilities matching or exceeding those of the most advanced GPAI models — presumed above 10²⁵ training FLOPs.
AI literacy
The skills and understanding that let providers, deployers and affected persons make informed use of AI and grasp its opportunities and risks (Art 4).
Instructions for use
Information from the provider on intended purpose and correct operation — also relevant to whether a system is high-risk.
The annexes
The operational detail lives in thirteen annexes. Expand any for a summary.
The Digital Omnibus on AI
The Digital Omnibus on AI is now law — Regulation (EU) 2026/1744 (CELEX 32026R1744), published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It amends Regulation (EU) 2024/1689; the dates below are operative law and are reflected in the timeline above. It began as Commission proposal COM(2025) 836 (19 Nov 2025) and was politically agreed on 7 May 2026. Key changes:
- Later high-risk deadlines — 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I safety components).
- Transitional transparency — generative systems already released get until 2 Dec 2026 for machine-readable marking (Art 50(2)).
- Two new Art 5 prohibitions — non-consensual intimate imagery and CSAM (Art 5(1)(ba)–(bb)) — applying 2 Dec 2026.
- Reduced overlap with sector-specific product-safety law, and a sector approach for AI-enabled machinery.
- Narrower "safety component" gateway (Art 6(1a)–(1c)); the Art 49 registration duty for Annex III systems self-assessed as not high-risk survives, with simplified content.
- Lighter AI-literacy obligation (measures to support literacy, not a guaranteed level); expanded bias-correction latitude; SMC (small mid-cap) privileges.
- Post-market monitoring flexibility (guidance and template by Sep 2027); sandboxes operational by 2 Aug 2027; wider real-world testing.
- AI Office supervision centralised (Art 75, new Arts 75a–75d) for GPAI-based systems and those embedded in designated VLOPs/VLOSEs, with new investigation and fining powers.