European Union Artificial Intelligence Act

· About European Union Artificial Intelligence Act

Key Takeaways

  • The EU AI Act is Regulation (EU) 2024/1689, the EU’s first comprehensive AI law, and it entered into force on 1 August 2024 with phased application dates through 2027 and 2028.[2][4]
  • Prohibited AI practices and the AI literacy obligation apply from 2 February 2025, so providers and deployers that use banned systems face immediate compliance risk and enforcement exposure.[2][4]
  • General-purpose AI (GPAI) rules apply from 2 August 2025, including documentation, transparency, and copyright-related summary obligations for GPAI model providers, with stronger duties for systemic-risk models.[1][2]
  • The Act’s general transparency obligations for many AI systems apply from 2 August 2026, including disclosure when users interact with an AI system and labeling of certain synthetic or manipulated content.[4]
  • As amended in 2026, high-risk AI obligations for many standalone Annex III systems were pushed to 2 December 2027, and embedded product-regulated systems to 2 August 2028, reflecting a delay introduced by the 2026 “Digital Omnibus on AI.”[10][11]
  • Maximum fines under the AI Act reach €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for other infringements, and €7.5 million or 1.5% for incorrect information, whichever is higher.[2][4]

What It Is

The EU AI Act is a harmonised EU regulation that lays down rules for the development, placing on the market, putting into service, and use of AI systems, with a risk-based structure covering unacceptable-risk, high-risk, limited-risk, and minimal-risk uses.[2][4] It is enforced primarily by national market surveillance authorities, with coordination at EU level through the European Commission and the AI Office established under the Act.[4][6]

The regulation was adopted on 13 June 2024, published in the Official Journal on 12 July 2024, and entered into force on 1 August 2024.[2][4] The Commission’s official AI policy page states that the Act became applicable on 2 August 2026 “with some exceptions,” reflecting the staged rollout rather than a single start date.[4]

Key phase-in milestones are set by Article 113 and related provisions. Prohibitions and AI literacy started on 2 February 2025; GPAI rules started on 2 August 2025; general transparency duties started on 2 August 2026; and the 2026 omnibus delayed some high-risk obligations to 2 December 2027 and 2 August 2028.[2][4][10][11]

Who Must Comply

The Act applies to providers, deployers, importers, distributors, product manufacturers, authorised representatives, and certain other actors in the AI supply chain when they place AI systems on the EU market, put them into service in the EU, or use output generated by AI in the EU.[2][4] A provider outside the EU can still fall in scope if it places an AI system on the EU market or its output is used in the EU, giving the law clear extraterritorial reach.[2][4]

Applicability depends on the role and the system’s risk category. High-risk obligations apply where an AI system is listed in Annex III or is a safety component of a regulated product listed in Annex I.[2][8] GPAI model providers are separately regulated, including providers of models distributed under open-source terms if they place them on the EU market or make them available in the EU in scope terms under the Act.[2][4]

Exemptions are limited. The Act does not apply to AI systems used exclusively for military, defence, or national security purposes, and it contains specific carve-outs for certain scientific research, personal non-professional use, and narrowly defined law-enforcement or public-security contexts, subject to the Act’s detailed articles.[2] Small and medium-sized enterprises are not exempt, but the Act and its implementing ecosystem are designed to provide some proportionality and support measures.[4]

Core Requirements

  1. Ban prohibited practices. Providers and deployers must not place on the market or use AI systems that fall under the Act’s prohibited practices, including manipulative, exploitative, social-scoring, and certain biometric and emotion-recognition uses, subject to the exact statutory exceptions.[2][4]
  1. Maintain AI literacy. Providers and deployers must take measures to ensure that personnel and relevant users have an adequate level of AI literacy appropriate to their technical knowledge, experience, education, and the context of use.[2][4]
  1. Meet GPAI documentation and transparency duties. GPAI model providers must prepare technical documentation, provide information to downstream providers, and publish a sufficiently detailed summary of training content used under the Act’s copyright-related requirements.[2][4]
  1. Apply special duties for systemic-risk GPAI. Providers of GPAI models with systemic risk must conduct evaluations, assess and mitigate risks, document serious incidents, ensure cybersecurity protections, and notify the AI Office and relevant authorities where required.[2][4]
  1. Run a high-risk compliance management system. High-risk AI providers must implement risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, and cybersecurity controls, and they must maintain conformity assessment evidence before placing the system on the market.[2][4]
  1. Give user transparency notices. When users interact with AI systems, when emotion recognition or biometric categorisation is used, or when synthetic or manipulated content is generated, providers and deployers must provide the disclosures required by Article 50 and related provisions.[2][4]
  1. Use post-market monitoring and incident reporting. High-risk providers must monitor systems after deployment, report serious incidents and malfunctioning where required, and cooperate with market surveillance authorities throughout the lifecycle.[2][4]

Deadlines and Penalties

| Milestone | Date | What applies | |---|---:|---| | Regulation enters into force | 1 August 2024 | The AI Act becomes legally operative and its phased timetable begins.[2][4] | | Prohibited practices and AI literacy | 2 February 2025 | Chapter I and Chapter II rules start applying, including banned practices and AI literacy duties.[2][4] | | GPAI rules and AI Office governance | 2 August 2025 | Chapter V obligations for GPAI providers begin, alongside governance measures and related implementing structures.[2][4] | | General transparency duties | 2 August 2026 | Article 50-style transparency obligations apply to many AI uses, including certain AI interactions and synthetic content notices.[4] | | Delayed high-risk AI date for many Annex III systems | 2 December 2027 | Certain standalone high-risk obligations were extended by the 2026 omnibus.[10][11] | | Delayed high-risk AI date for many Annex I embedded systems | 2 August 2028 | Product-embedded high-risk AI obligations were also extended by the 2026 omnibus.[10][11] |

Maximum fines are set in tiers. The highest tier is €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited AI practices.[2][4] Other infringements can reach €15 million or 3% of global turnover, while supplying incorrect, incomplete, or misleading information to authorities can reach €7.5 million or 1.5% of turnover.[2][4]

Other sanctions include orders to stop placing systems on the market, withdrawal or recall measures, forced corrective action, and administrative penalties imposed by national authorities under the EU’s market surveillance framework.[2][4] For some public-sector and SME contexts, fines may be calibrated lower under the Act’s proportionality rules, but the statutory caps remain substantial.[2]

How to Comply

  1. Build an AI inventory. Map every AI use case, vendor, model, and deployment location, then classify each item by role and risk category under the AI Act.
  1. Create a governance baseline. Align controls with ISO 27001 for security management, NIST CSF 2.0 for enterprise risk governance, and ISO/IEC 42001 for AI management systems where AI is a repeatable business capability.
  1. Classify and screen for prohibitions. Check whether any use case falls into a prohibited practice or a special category requiring extra transparency or safeguards.
  1. Stand up GPAI vendor due diligence. Contract for technical documentation, model information, incident reporting, copyright-summary disclosure, and audit rights from any GPAI supplier.
  1. Implement high-risk controls. For Annex III or product-embedded uses, maintain a risk management file, data governance, logging, human oversight, validation testing, and cybersecurity evidence.
  1. Document transparency notices. Prepare user-facing disclosures for AI interaction, deepfake/synthetic content, and emotion-recognition or biometric categorisation where applicable.
  1. Set up post-market monitoring. Track performance drift, complaints, incidents, and misuse, and route serious issues to legal, compliance, and engineering owners for escalation.
  1. Test conformity before launch. Use pre-deployment assessments and, where required, conformity assessment procedures before placing a system on the EU market or putting it into service.

Related Regulations

  • The GDPR overlaps on automated decision-making, biometric data, profiling, and transparency, and it can apply in parallel where AI systems process personal data.
  • The Digital Services Act intersects with recommender systems, content moderation, and transparency in platform contexts, especially where AI is used to rank or recommend content.
  • The NIS2 Directive overlaps on cybersecurity governance, incident response, and supply-chain controls for in-scope entities that operate AI systems.
  • The Product Liability Directive and national liability rules may conflict or overlap with AI Act safety obligations where defective AI causes harm.
  • The Data Act can overlap with access, portability, and interoperability issues for connected products and services that embed AI.

FAQ

Does the EU AI Act apply to companies outside the EU?

Yes, if an outside-EU provider places an AI system on the EU market, puts it into service in the EU, or if the system’s output is used in the EU in the ways covered by the Act.[2][4] The law is therefore not limited to EU-incorporated entities. Vendors selling into the EU should assume coverage unless a specific exemption clearly applies.

Does the AI Act ban all biometric AI?

No. The Act bans only specific biometric uses, such as certain real-time remote biometric identification in public spaces and other high-risk or manipulative practices, subject to statutory exceptions.[2] Other biometric systems can still be allowed, but many will be high-risk and must meet strict controls.

When do most companies have to comply?

The first major compliance date was 2 February 2025 for prohibited practices and AI literacy, followed by 2 August 2026 for general transparency duties.[2][4] High-risk AI deadlines are later for many use cases because the 2026 omnibus delayed them to 2 December 2027 or 2 August 2028 depending on the category.[10][11]

What changed in 2025–2026?

The main 2025–2026 development is not a wholesale rewrite but a staged implementation plus a 2026 omnibus that delayed some high-risk obligations.[4][10][11] The Commission’s AI policy page still describes the Act as applicable from 2 August 2026 with exceptions, while implementation timelines now reflect later dates for certain high-risk systems.[4][10]

Are ISO 27001 or ISO 42001 enough to comply?

No. Those standards help structure controls, but they do not replace the AI Act’s legal duties on prohibited practices, documentation, transparency, conformity assessment, and market surveillance.[2] ISO 27001 and ISO 42001 are useful evidence frameworks, not legal safe harbours.

Sources

Put it into practice

More compliance guides