EU AI Act summary: what the law requires, and when #
Regulation (EU) 2024/1689 is the first comprehensive law governing artificial intelligence. It does not regulate AI as a technology. It regulates what a given system is used for, and it scales its demands to the harm that use could cause.
The Act in brief #
- It applies to AI systems placed on the EU market or whose output is used in the EU, wherever the company behind them is established.
- It sorts AI systems into four risk levels: unacceptable, high, limited and minimal. General-purpose AI models sit outside that ladder, under their own rules.
- Your duties depend on your role. Providers who develop and place a system on the market carry most of them. Deployers who use a system professionally carry fewer, but not none.
- A handful of practices are banned outright, and have been since February 2025.
- High-risk systems carry the heavy obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity.
- Certain systems must disclose themselves whatever their risk level, including chatbots and generators of synthetic content.
- Everyone deploying AI professionally owes an AI literacy duty to their staff.
- Fines reach 35 million euro or 7% of worldwide annual turnover.
- Obligations phase in across several years, and the high-risk dates moved in 2026.
Who it applies to #
Territorial reach is deliberately broad. The Act catches you if you are established in the EU, if you place a system on the EU market, or if the output of your system is used in the EU, regardless of where you sit. Importers, distributors, product manufacturers and authorised representatives are all pulled in.
Three exclusions matter in practice: individuals using AI for purely personal, non-professional purposes; systems developed and used solely for scientific research and development; and research, testing and development activity before a system is placed on the market, unless the testing happens in real-world conditions.
Note that a role is not fixed. A deployer, distributor or importer becomes a provider, with a provider’s full obligations, if it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system so that it becomes high-risk. Repurposing a general-purpose model into a high-risk application is the most common way a company becomes a provider without meaning to.
The four risk levels #
The Act sorts AI systems by the harm their use could cause, and scales its demands accordingly.
Unacceptable: prohibited #
Eight practices are banned, judged unacceptable rather than merely risky: manipulative or subliminal techniques that materially distort behaviour; exploitation of vulnerability due to age, disability or social and economic situation; social scoring; predicting criminal offending from profiling or personality traits alone; untargeted scraping of facial images to build recognition databases; emotion inference in workplaces and schools; biometric categorisation that infers sensitive attributes such as race, political opinion or sexual orientation; and real-time remote biometric identification in public by law enforcement, subject to narrow exceptions.
High risk #
Two routes into this level. A system is high-risk if it is a safety component of a product already covered by EU product legislation, or if it falls in one of the Annex III use cases: biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services including creditworthiness and life or health insurance pricing, law enforcement, migration and border control, and the administration of justice and democratic processes.
Annex III is not automatic. A listed system escapes the classification if it only performs a narrow procedural task, improves the result of a completed human activity, detects decision patterns without replacing human judgment, or performs a preparatory task. Two conditions attach: profiling of individuals never qualifies for the exemption, and the provider must document the assessment and produce it on request. Registration remains required either way.
Limited risk: transparency duties #
Independent of the rest of the ladder. Systems interacting directly with people must say they are AI. Synthetic audio, image, video and text must be marked machine-readably. Emotion recognition and biometric categorisation must be disclosed to the people exposed to them. Deepfakes and AI-generated text on matters of public interest must be labelled as artificial. These duties overlap with the levels above: a high-risk system can carry transparency duties too.
Minimal risk #
Everything else, and it is the large majority of AI in use. Spam filters, recommendation engines, most internal productivity tools. No specific obligations under the Act, though the AI literacy duty still applies to the people using them.
General-purpose AI models: a separate regime #
GPAI models sit outside the risk ladder. A model is not a system, and the same model can end up inside a high-risk system, a limited-risk one, or neither. Obligations centre on technical documentation, information for downstream providers, a copyright policy and a training-data summary, with additional duties where the model presents systemic risk.
If you build on someone else’s model, note where the line falls: the model provider carries the GPAI duties, and you carry the system duties for whatever you build with it. Change the intended purpose so the result is high-risk and you become a provider in your own right.
What you actually have to do #
Every business using AI professionally owes an AI literacy duty: staff dealing with the system need a level of understanding matched to their role and context. This one has applied since February 2025 and is widely overlooked.
Providers of high-risk systems carry the core programme: a risk management system across the lifecycle; data governance covering quality, representativeness and bias; technical documentation; automatic logging; instructions that let a deployer use the system correctly; human oversight designed into the system; and appropriate accuracy, robustness and cybersecurity. Conformity assessment, registration and post-market monitoring sit on top.
Deployers of high-risk systems carry a lighter but real set: use the system according to its instructions, assign competent human oversight, keep logs, inform workers where the system is used in an employment context, and in some cases run a fundamental rights impact assessment.
Key dates #
| Date | What applies |
|---|---|
| 1 August 2024 | The Act enters into force |
| 2 February 2025 | Prohibited practices, and the AI literacy duty |
| 2 August 2025 | General-purpose AI model obligations |
| 2 August 2026 | Transparency duties under Article 50 |
| 2 December 2027 | High-risk obligations for standalone Annex III systems |
| 2 August 2028 | High-risk obligations for AI embedded in regulated products |
Providers of general-purpose models already on the market before 2 August 2025 have until 2 August 2027 to bring them into line.
What changed in 2026 #
Most summaries of the AI Act still show 2 August 2026 as the date high-risk obligations begin. That is no longer correct. Implementation had fallen behind, largely because the harmonised standards the regime depends on were not ready, and the EU amended the timetable through the Digital Omnibus on AI, in force since July 2026.
The effect is a deferral, not a repeal. Standalone Annex III high-risk systems move to 2 December 2027 and AI embedded in regulated products to 2 August 2028. Nothing else moved: the prohibitions, the AI literacy duty, the general-purpose model regime and the Article 50 transparency rules all apply on their original dates.
Read that as more time to do the work properly, not permission to stop. Classifying a portfolio, building the documentation and standing up the risk management system is a multi-year programme for most organisations, and the deferred date assumes you started.
Penalties #
| Infringement | Maximum |
|---|---|
| Prohibited practices | 35 million euro or 7% of worldwide annual turnover |
| Most other obligations | 15 million euro or 3% |
| Incorrect or misleading information to authorities | 7.5 million euro or 1% |
Whichever is higher, in each case. Providers of general-purpose models face a separate Commission power to fine up to 15 million euro or 3%. Member States may add their own penalties on top, so the national implementing rules matter. And because AI systems generally process personal data, the same conduct can attract a GDPR fine in parallel.