Regulations › European Union

EU AI Act

Artificial Intelligence Act, Regulation (EU) 2024/1689

In force ai
WhenIn effect since 1 August 2024
Who enforces itEU AI Office and national market surveillance authorities
Who it applies toProviders, deployers, importers and distributors of AI systems on the EU market or whose outputs are used in the EU.

Risk-based AI regulation with obligations assigned by role: prohibited practices, high-risk requirements, transparency duties and rules for general-purpose models.

The law in brief

The EU AI Act is the first comprehensive law on artificial intelligence. It sorts AI by risk: some practices are banned outright, high-risk systems must meet detailed requirements before and after they reach the market, some systems carry transparency duties, and general-purpose AI models have their own rules.

Most duties fall on providers, who develop a system or put it on the market, but deployers, the organizations that use AI in their work, carry real obligations too.

Who it applies to

  • Providers placing AI systems or general-purpose AI models on the EU market or putting them into service, wherever they are established.
  • Deployers using AI systems in the EU in a professional capacity.
  • Providers and deployers outside the EU where the system's output is used in the EU.
  • Importers, distributors and authorized representatives.
  • It does not apply to AI used only for military, defense or national security purposes, to pure scientific research and development, or to purely personal use.

What it requires

Banned practices

Do not place on the market or use AI for practices the Act prohibits, including manipulative techniques that cause harm, social scoring, untargeted scraping to build facial recognition databases, emotion recognition at work or in education, and most real-time remote biometric identification in public spaces for law enforcement.

AI literacy

Take measures to ensure a sufficient level of AI literacy among staff and others operating or using AI systems on your behalf.

Requirements for high-risk systems

Providers must run a risk management system, govern training data, keep technical documentation and logs, design for human oversight, meet accuracy, robustness and cybersecurity levels, operate a quality management system, and complete conformity assessment before placing the system on the market.

Deployer duties for high-risk systems

Use the system according to its instructions, assign competent human oversight, monitor its operation, keep automatically generated logs for at least six months, and inform workers before using it at work. Public bodies and some others must also assess the impact on fundamental rights.

Transparency for certain systems

Tell people when they are interacting with an AI system, mark synthetic content in a machine-readable way, and disclose deep fakes and AI-generated text published to inform the public.

General-purpose AI models

Providers of general-purpose AI models keep technical documentation, give information to downstream providers, respect EU copyright law and publish a summary of training content; models with systemic risk carry additional evaluation, incident and cybersecurity duties.

People's rights

People affected by AI have specific protections: the right to an explanation of certain decisions taken on the basis of a high-risk system's output (Art. 86), the right to be told when they are interacting with an AI system or seeing AI-generated or manipulated content (Art. 50), and the right to complain to a market surveillance authority (Art. 85).

Enforcement and penalties

Three tiers of fines (Art. 99): up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices; up to €15 million or 3% for most other obligations; up to €7.5 million or 1% for supplying incorrect information to authorities. For smaller businesses and start-ups the lower of the two amounts applies. Fines for general-purpose AI model providers are set by the Commission (Art. 101).

The highest fines, for prohibited practices

Up to €35 million or 7% of worldwide annual turnover, whichever is higher.

What's changing

Dates moved by Regulation (EU) 2026/1744. High-risk obligations for systems listed in Annex III now apply from 2 December 2027, and for AI in products under Annex I from 2 August 2028. The prohibitions have applied since 2 February 2025, general-purpose AI model rules since 2 August 2025, and the Article 50 transparency duties since 2 August 2026. Regulatory Watch reports guidance and implementing acts as they arrive.

What to do first

  1. Inventory the AI you build, buy and use, and record your role for each: provider, deployer, importer or distributor.
  2. Screen every use against the prohibited practices in Article 5 and stop anything that falls inside.
  3. Classify each system: prohibited, high-risk, transparency-only or minimal.
  4. Give staff AI literacy training proportionate to their role (Art. 4).
  5. For high-risk systems, plan the provider requirements or, as a deployer, human oversight, log retention and monitoring.
  6. Label AI interactions and AI-generated content where Article 50 applies.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Sources