EU AI Act
The EU AI Act is the common name for Regulation (EU) 2024/1689, a directly applicable European Union law that sets horizontal rules for artificial intelligence. Its stated objectives combine a functioning internal market with protection of health, safety, fundamental rights, democracy, and the rule of law. The regulation entered into force on 1 August 2024.[1]
As of the research cutoff for this article, 28 July 2026, the governing text was Regulation 2024/1689 as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI. The amending regulation was published on 24 July 2026 and entered into force on 27 July 2026. It replaced several application dates, amended duties and enforcement powers, and added two prohibited-practice provisions. It was enacted law at the cutoff, not a proposal or provisional agreement.[2]
The Act does not create one universal statutory ladder of four named risk tiers. "Unacceptable, high, limited, and minimal risk" is useful explanatory shorthand, but the operative text instead combines specific prohibitions, two routes into the high-risk regime, transparency duties for certain systems, rules for general-purpose AI models, and mostly no AI Act-specific duties for other systems. Separate Union and national laws can still apply.[1]
Legal basis and legislative history
The European Commission proposed the original regulation on 21 April 2021 after earlier policy work on trustworthy AI. The proposal used the ordinary legislative procedure. It relied principally on Article 114 of the Treaty on the Functioning of the European Union, with Article 16 supporting its specific personal-data rules for real-time remote biometric identification in law enforcement.[3] During negotiation, the co-legislators added a dedicated regime for general-purpose AI models, among other changes.
The European Parliament approved the final text on 13 March 2024 by 523 votes to 46, with 49 abstentions.[4] The Council gave its final approval on 21 May 2024.[5] The act was signed on 13 June, published in the Official Journal on 12 July, and entered into force 20 days later on 1 August 2024.[1]
Regulation 2026/1744 later amended the Act. Its operative text fixed new calendar dates for high-risk duties, changed the AI literacy obligation, extended the national regulatory-sandbox deadline, revised transitional rules, and expanded the AI Office's supervisory architecture. Earlier documents describing the measure as a Commission proposal or a May 2026 political agreement are legislative history, not the law at the cutoff.[2]
Scope
Article 2 covers providers that place AI systems or general-purpose AI models on the Union market, wherever those providers are established. It also covers Union-based deployers, importers, distributors, certain product manufacturers and authorised representatives, and affected people located in the Union. Providers and deployers in third countries are covered where output produced by their AI system is used in the Union. That last rule is a defined jurisdictional trigger, not a claim that every foreign AI activity has effects in the EU.[1]
The Act contains significant exclusions and qualifications. It does not apply outside the scope of Union law or to systems used exclusively for military, defence, or national-security purposes. It excludes certain third-country public-authority cooperation, systems and models developed and put into service solely for scientific research and development, and pre-market research, testing, or development other than testing in real-world conditions. It also excludes purely personal, non-professional use by natural-person deployers. Systems released under free and open-source licences receive a general exclusion unless they are placed on the market or put into service as high-risk systems or fall under Article 5 or Article 50. Data-protection, consumer-protection, product-safety, employment, and other laws continue to apply.[1][2]
Regulatory structure
| Statutory route | Trigger | Main legal effect |
|---|---|---|
| Prohibited practices | A practice falls within Article 5 | Placing on the market, putting into service, or use is prohibited as specified |
| High-risk AI systems | Article 6(1) and Annex I product route, or Article 6(2) and Annex III use-case route | Chapter III requirements for providers, deployers, and other operators apply on the relevant phased date |
| Certain transparent-use cases | A system or content falls within Article 50 | Interaction notices, machine-readable marking, or disclosure duties apply, depending on the actor and use |
| General-purpose AI models | A model meets the Article 3 definition; additional rules apply if it has systemic risk | Documentation, downstream information, copyright-policy, training-content-summary, and possibly systemic-risk duties |
| Other systems | None of the above routes applies | Usually no system-specific duty under the AI Act, although Article 4, other AI Act provisions, and other law may still matter |
The same technology can engage more than one route. A general-purpose model can be integrated into a high-risk system, and an Article 50 transparency duty does not displace a high-risk requirement. Conversely, a model is not a high-risk AI system merely because it is general-purpose.[1]
Prohibited practices
Most of the original Article 5 prohibitions have applied since 2 February 2025. In condensed form, they cover:
- AI that uses subliminal, purposefully manipulative, or deceptive techniques to materially distort decision-making in a way that causes or is reasonably likely to cause significant harm;
- AI that exploits vulnerability due to age, disability, or a specific social or economic situation under the same significant-harm test;
- social scoring that leads to detrimental treatment in an unrelated context or to unjustified or disproportionate treatment;
- individual criminal-offence risk assessment based solely on profiling or personality traits, subject to a narrow rule for supporting a human assessment based on objective and verifiable facts linked to criminal activity;
- untargeted scraping of facial images from the internet or CCTV to create or expand facial-recognition databases;
- emotion inference in workplaces and educational institutions, except for medical or safety reasons;
- biometric categorisation that infers specified sensitive or protected characteristics, subject to limited exclusions; and
- law-enforcement use of real-time remote biometric identification in publicly accessible spaces, except within tightly specified objectives, safeguards, authorisation, necessity, and proportionality conditions.[1]
Two common summaries are inaccurate. The social-scoring prohibition is not limited to public authorities, and the vulnerability rule is not a general ban on persuasion aimed at broad demographic groups. Each prohibition has its own elements, responsible actors, and exceptions.[1][7]
Regulation 2026/1744 added Article 5 provisions addressing AI systems connected with non-consensual intimate or sexually explicit synthetic content and child sexual-abuse material. The amendment includes separate provider-side and use-side tests, intended-purpose and reasonably foreseeable-outcome concepts, safeguard conditions, and exceptions. These additions were in force at the cutoff but do not apply until 2 December 2026. The Commission's final prohibited-practices guidelines date from 29 July 2025 and therefore do not interpret the later additions. Those guidelines are non-binding, and authoritative interpretation belongs to the Court of Justice of the European Union.[2][7]
High-risk AI systems
Article 6 provides two routes into the high-risk regime. Under Article 6(1), an AI system is high-risk when it is a safety component of, or is itself, a product covered by Annex I Union harmonisation legislation and that product must undergo third-party conformity assessment. Under Article 6(2), specified use cases in Annex III are high-risk.[1][2]
Annex III covers defined uses in eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services and benefits; law enforcement; migration, asylum, and border control; and administration of justice and democratic processes. These headings are not blanket classifications. The detailed intended use in Annex III controls.[1]
Article 6(3) excludes an Annex III system where it does not pose a significant risk of harm to health, safety, or fundamental rights, including because it does not materially influence a decision, and one of four specified task conditions is met. The provider must document that assessment and register the system. An Annex III system that profiles natural persons is always high-risk. As of the cutoff, Commission guidance on these classification questions was still a consultation draft, not adopted guidance.[1][15]
When the relevant provisions apply, a high-risk provider must maintain a risk-management system; govern training, validation, and test data; prepare technical documentation; enable record-keeping; provide deployer information; design effective human oversight; and meet appropriate accuracy, robustness, and cybersecurity requirements. Providers also face quality-management, conformity-assessment, registration, corrective-action, and post-market duties. Deployers must follow instructions, assign competent human oversight, monitor operation, retain logs under specified conditions, and report relevant risks and serious incidents.[1]
A fundamental-rights impact assessment under Article 27 is not required from every deployer. It applies before first use of most Article 6(2) systems by bodies governed by public law, private entities providing public services, and deployers of the creditworthiness and life or health insurance systems listed in Annex III points 5(b) and 5(c). Critical-infrastructure systems in Annex III point 2 are excluded from that Article 27 rule. The assessment addresses the deployment context, affected groups, likely harms, human oversight, governance, and remedies, and it can complement a data-protection impact assessment under the GDPR.[1][19]
The Chapter III Sections 1 to 3 duties do not share a single start date. For Article 6(2) and Annex III systems they apply from 2 December 2027. For Article 6(1) and Annex I product-related systems they apply from 2 August 2028. Article 6(5), which concerns Commission classification guidance, is excluded from those postponements and falls under the general application date.[2]
General-purpose AI models
The Act defines a general-purpose AI model by its significant generality, ability to competently perform a wide range of distinct tasks, and capacity for integration into a variety of downstream systems or applications. A model used for research, development, or prototyping before market placement is excluded from that definition. The definition is functional and is not itself a parameter-count or compute threshold.[1]
All covered general-purpose model providers must maintain technical documentation, give specified information to downstream system providers, establish a policy for compliance with Union copyright law, and publish a sufficiently detailed summary of training content using the AI Office template. A qualifying free and open-source model is exempt from the Article 53(1)(a) and (b) documentation duties, but not the copyright-policy or training-summary duties; the exception does not apply to models with systemic risk.[1]
The Commission's non-binding GPAI guidelines use training compute greater than 10^23 FLOP, together with the ability to generate language or images, as an indicative criterion in its interpretation of significant generality. That is not a statutory presumption. By contrast, Article 51(2) expressly presumes high-impact capabilities when cumulative training compute exceeds 10^25 FLOP. A provider can submit substantiated arguments against classification, and the Commission can designate a model on other Article 51 and Annex XIII grounds.[1][9]
Providers of models with systemic risk must additionally perform and document evaluations and adversarial testing, assess and mitigate Union-level systemic risks, report serious incidents and corrective measures, and maintain adequate cybersecurity for the model and its physical infrastructure.[1]
Chapter V has applied since 2 August 2025. Providers of models placed on the market before that date have until 2 August 2027 to comply. The General-Purpose AI Code of Practice covers transparency, copyright, and safety and security. It is voluntary and can facilitate demonstration of compliance; providers may instead demonstrate alternative adequate means. Even after an adequacy assessment, adherence is not the same as the Article 40 presumption produced by compliance with a cited harmonised standard.[1][9][10][11]
Transparency duties for certain systems
Article 50 creates actor-specific duties rather than a general "limited-risk" category. From its applicable date:
- providers of systems intended to interact directly with people must make the AI interaction known unless it is obvious to a reasonably well-informed, observant, and circumspect person in context, subject to a law-enforcement exception;
- providers of systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text must make outputs machine-readable and detectable as artificially generated or manipulated, subject to technical-feasibility and stated exceptions;
- deployers of emotion-recognition and biometric-categorisation systems must inform exposed people, subject to a law-enforcement exception; and
- deployers must disclose qualifying deepfake content and certain AI-generated or manipulated text published to inform the public on matters of public interest, with tailored exceptions for law enforcement, artistic works, and human editorial control.[1]
These duties generally apply from 2 August 2026, four days after this article's cutoff. Regulation 2026/1744 added a narrow transition: providers of synthetic-content systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2). The enacted transition names only Article 50(2); it does not generally postpone Article 50(1), (3), (4), or (5).[2]
The Commission published final Article 50 guidelines on 20 July 2026. They are non-binding. The related Transparency Code of Practice is voluntary, and the Commission assessed it as an adequate practical tool. The code does not replace the Act or the guidelines, and code adherence is not conclusive proof of legal compliance.[12][13][14]
Application timeline
Entry into force and application are different. A provision can be part of enacted law before the date on which it imposes operative duties. The current Article 113 schedule, read with the transition rules in Article 111, is:
| Date | Legal effect |
|---|---|
| 1 August 2024 | Regulation 2024/1689 entered into force |
| 2 February 2025 | Chapters I and II applied, including definitions, the original Article 4 duty, and the original Article 5 prohibitions |
| 2 August 2025 | Chapter III Section 4, Chapter V, Chapter VII, Chapter XII, and Article 78 applied, except Article 101 |
| 27 July 2026 | Regulation 2026/1744 entered into force; its amended Article 4 and Article 99 text took effect, and Articles 102 to 110 became applicable |
| 2 August 2026 | General application date for provisions not specially excepted, including Article 50, Chapter IX, Article 6(5), and Article 101 |
| 2 December 2026 | New Article 5 intimate-content and child sexual-abuse-material provisions apply; legacy Article 50(2) provider transition ends |
| 2 August 2027 | Member States must have at least one national AI regulatory sandbox operational; pre-2 August 2025 GPAI models must comply |
| 2 December 2027 | Chapter III Sections 1 to 3 apply to Article 6(2) and Annex III high-risk systems |
| 2 August 2028 | Chapter III Sections 1 to 3 apply to Article 6(1) and Annex I product-related high-risk systems |
| 2 August 2030 | Public-authority high-risk systems covered by the Article 111(2) transition must comply |
| 31 December 2030 | Covered Annex X large-scale IT systems placed or put into service before 2 August 2027 must comply |
The high-risk dates are fixed calendar dates in the enacted amendment. The final law did not retain the earlier proposal's system of triggering those duties after the Commission confirmed availability of supporting standards and guidance.[2]
Article 4 deserves separate treatment. AI literacy duties have applied since 2 February 2025. From 27 July 2026, amended Article 4 requires providers and deployers to take measures supporting development of AI literacy among staff and other people operating or using systems on their behalf, taking account of their knowledge, experience, education, training, and context. It expressly says this does not require guaranteeing a particular level of literacy.[2]
Article 111 also limits retrospective application. Other than specified large-scale systems, a high-risk system placed or put into service before its relevant Chapter III application date is generally covered only if its design is significantly changed from that date, subject to the 2030 public-authority deadline. The rule for pre-2 August 2025 general-purpose models and the narrow Article 50(2) transition are separate.[2]
Governance and enforcement
The governance system divides functions between Union and national bodies. The European AI Office was established inside the European Commission in January 2024.[6] The AI Board coordinates and advises, the scientific panel supplies independent technical expertise, and the advisory forum represents a range of stakeholders. Member States designate national competent authorities, including at least one market-surveillance authority and at least one notifying authority.[1]
The AI Office supervises and enforces Chapter V duties for general-purpose model providers. Regulation 2026/1744 also revised Article 75 and added Articles 75a to 75d for specified AI systems, investigations, commitments, fines, and periodic penalty payments. Those Chapter IX provisions apply from the general date of 2 August 2026. They were enacted at the cutoff but not yet applicable. Claims of completed AI Office fines or formal enforcement under those provisions before that date require a different legal basis and should not be inferred from informal engagement.[1][2]
Article 99 sets maximum administrative fines, while requiring effective, proportionate, and dissuasive national rules and case-specific assessment. The principal ceilings are:
| Infringement | Maximum for an undertaking |
|---|---|
| Article 5 prohibited practices | EUR 35 million or 7% of preceding-year worldwide turnover, whichever is higher |
| Listed obligations in Article 99(4), including many provider, deployer, and Article 50 duties | EUR 15 million or 3%, whichever is higher |
| Incorrect, incomplete, or misleading information in reply to specified authority requests | EUR 7.5 million or 1%, whichever is higher |
| GPAI provider infringement under Article 101 | EUR 15 million or 3%, whichever is higher |
For small and medium-sized enterprises, each Article 99 fine is capped at the lower rather than the higher of the percentage and fixed amount. Article 101 applies from 2 August 2026. Article 4 is not named in Article 99(4)'s EUR 15 million or 3% list; its infringement instead falls within Member-State rules and other measures under the broader Article 99(1) framework as amended. No fine can attach to breach of a substantive obligation before that obligation applies.[1][2]
Guidance, codes, and standards
Implementation materials have different legal effects:
| Material at the cutoff | Status |
|---|---|
| Regulation 2024/1689 as amended by Regulation 2026/1744 | Binding, directly applicable law |
| Final Commission guidelines on prohibited practices, the AI-system definition, GPAI providers, and Article 50 | Non-binding Commission interpretations; authoritative interpretation remains with the Court of Justice |
| Draft high-risk classification guidelines published in May 2026 | Consultation draft, not adopted guidance |
| GPAI and Article 50 codes of practice | Voluntary tools that can facilitate demonstration of compliance; no presumption of conformity |
| Harmonised standards under Article 40 | Voluntary to use, but an applicable standard whose reference is published in the Official Journal can confer a presumption of conformity for requirements it covers |
The Commission issued final non-binding guidelines on the AI-system definition and prohibited practices on 29 July 2025, and final non-binding GPAI guidelines on 19 November 2025.[7][8][9] It published draft high-risk classification guidelines for consultation on 19 May 2026. Those documents explicitly label themselves draft and non-binding, and the consultation closed on 23 July 2026.[15]
The Commission replaced its original AI standardisation request with C(2025) 3871 in June 2025. Its standardisation page, updated on 27 July 2026, still described CEN and CENELEC work across ten areas as ongoing and placed Commission assessment and Official Journal citation in future steps. On that primary-source record, no identified AI Act harmonised standard had yet acquired an Article 40 presumption of conformity at the cutoff.[16][17]
This distinction matters. Codes may organise evidence and influence supervisory practice, but Regulation 2026/1744 explains that they have limited legal effect and do not grant a presumption of conformity. Only a qualifying Official Journal-cited harmonised standard can create the Article 40 presumption, and only for requirements it covers.[2][9][12][16]
Interpretation and debate
The Act's risk-based design remains contested. Martin Ebers argues that a genuinely risk-based implementation requires ongoing assessment across an AI system's lifecycle rather than treating initial classification as the end of the inquiry.[18] Johann Laux and coauthors separately distinguish trustworthiness from the political and legal acceptability of risk, warning that technical risk controls cannot by themselves settle every normative choice.[21]
Fundamental-rights impact assessment is another point of interpretation. Alessandro Mantelero treats Article 27 as an ex ante, iterative, expert-based process that is broader than a GDPR data-protection impact assessment, while also observing that the statutory duty applies only to specified deployers and systems.[19] This is scholarly analysis, not an expansion of Article 27's legal scope.
Standards can translate open-textured requirements into operational methods, but their governance is debated. Laux, Sandra Wachter, and Brent Mittelstadt argue that technical standard-setting can contain hard value choices and raise participation and democratic-legitimacy questions.[20] The Act responds in part through stakeholder-participation and fundamental-rights requirements for standardisation, but the resulting standards remain legally distinct from the regulation.
The likely global influence of the Act is also an interpretation, not a legal effect. Marco Almada and Anca Radu argue that the Act may generate a "Brussels Effect" while also exporting limitations of its product-safety framing. Their argument cautions against assuming that regulatory diffusion necessarily produces equivalent protection of fundamental rights in other legal systems.[22]
See also
- AI regulation
- EU AI Act Digital Omnibus
- General Data Protection Regulation
- Foundation models
- Large language model
- Generative AI
- Deepfake
References
- ^European Parliament and Council of the European Union. "Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence." *Official Journal of the European Union*, 12 July 2024. eur-lex.europa.eu/...oj
- ^European Parliament and Council of the European Union. "Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)." *Official Journal of the European Union*, 24 July 2026. eur-lex.europa.eu/...TXT
- ^European Commission. "Proposal for a Regulation laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), COM(2021) 206 final." 21 April 2021. eur-lex.europa.eu/...TXT
- ^European Parliament. "Artificial Intelligence Act: MEPs adopt landmark law." 13 March 2024. europarl.europa.eu/...-act-meps-adopt-landmark-law
- ^Council of the European Union. "Artificial intelligence (AI) act: Council gives final green light to the first worldwide rules on AI." 21 May 2024. consilium.europa.eu/...first-worldwide-rules-on-ai
- ^European Commission. "Commission Decision establishing the European AI Office, C(2024) 390 final." 24 January 2024. digital-strategy.ec.europa.eu/...uropean-ai-office
- ^European Commission. "Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689, C(2025) 5052 final." 29 July 2025. digital-strategy.ec.europa.eu/...es-defined-ai-act
- ^European Commission. "Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689, C(2025) 5053 final." 29 July 2025. digital-strategy.ec.europa.eu/...rules-application
- ^European Commission. "Commission Guidelines on the scope of the obligations for providers of general-purpose AI models, C(2025) 7719 final." 19 November 2025. digital-strategy.ec.europa.eu/...dels-under-ai-act
- ^European Commission. "The General-Purpose AI Code of Practice." 10 July 2025. digital-strategy.ec.europa.eu/...contents-code-gpai
- ^European Commission. "Commission Opinion on the assessment of the General-Purpose AI Code of Practice." 1 August 2025. digital-strategy.ec.europa.eu/...-ai-code-practice
- ^European Commission. "Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50, C(2026) 5054 final." 20 July 2026. digital-strategy.ec.europa.eu/...loyers-ai-systems
- ^European Commission. "Code of Practice on Transparency of AI-generated Content." 10 June 2026. digital-strategy.ec.europa.eu/...generated-content
- ^European Commission. "Commission Opinion on the assessment of the Code of Practice on Transparency of AI-generated content, C(2026) 4839 final." 8 July 2026. digital-strategy.ec.europa.eu/...generated-content
- ^European Commission. "Draft Commission guidelines on the classification of high-risk AI systems." 19 May 2026. digital-strategy.ec.europa.eu/...h-risk-ai-systems
- ^European Commission. "AI Act standardisation." Updated 27 July 2026. digital-strategy.ec.europa.eu/...t-standardisation
- ^European Commission. "Commission Implementing Decision on a standardisation request as regards artificial intelligence, C(2025) 3871 final." 23 June 2025. ec.europa.eu/...detail
- ^Martin Ebers. "Truly Risk-based Regulation of Artificial Intelligence: How to Implement the EU's AI Act." *European Journal of Risk Regulation* 16, no. 2 (2025): 684-703. doi.org/...err.2024.78
- ^Alessandro Mantelero. "The Fundamental Rights Impact Assessment (FRIA) in the AI Act: Roots, legal obligations and key elements for a model template." *Computer Law & Security Review* 54 (2024): 106020. doi.org/...j.clsr.2024.106020
- ^Johann Laux, Sandra Wachter, and Brent Mittelstadt. "Three pathways for standardisation and ethical disclosure by default under the European Union Artificial Intelligence Act." *Computer Law & Security Review* 53 (2024): 105957. doi.org/...j.clsr.2024.105957
- ^Johann Laux, Sandra Wachter, and Brent Mittelstadt. "Trustworthy artificial intelligence and the European Union AI Act: On the conflation of trustworthiness and acceptability of risk." *Regulation & Governance* 18, no. 1 (2024): 3-32. doi.org/...rego.12512
- ^Marco Almada and Anca Radu. "The Brussels Side-Effect: How the AI Act Can Reduce the Global Reach of EU Policy." *German Law Journal* 25, no. 4 (2024): 646-663. doi.org/...glj.2023.108
Improve this article
Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.
9 revisions · v10 · 4,013 words · full history
Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify
Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here
Reviewer note: Independent 2026-07-28 legal fact-check: 22 explicit legal, official, or scholarly references, 64 resolved citation calls, eight canonical internal targets, and 20 high-risk legal/source groups checked. Root inspected all 38 production captures and ten selected source pages. Corrected Regulation (EU) 2026/1744 to enacted law in force at the cutoff; verified the amended phased dates, scope, Article 4, Article 6, Article 27, GPAI, Article 50, governance, fine rules, SME ceilings, and transitions; and distinguished binding regulations, final guidance, consultation drafts, voluntary codes, and Official Journal-cited harmonised standards.
Cite this page: AI Wiki. "EU AI Act." aiwiki.ai, updated 30 Jul 2026, fact-checked 30 Jul 2026. CC BY 4.0. https://aiwiki.ai/wiki/eu_ai_act