The EU AI Act is the European Union’s comprehensive, risk-based law governing how artificial intelligence may be built, sold and used — formally Regulation (EU) 2024/1689, the first law of its kind anywhere. If your product touches people in Europe, it draws the boundaries you work inside. And after an amendment that entered into force on 27 July 2026, several of its headline deadlines are no longer where most explainers say they are.

| Quick answer: The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive artificial intelligence law. It sorts AI into four risk tiers — unacceptable, high, limited and minimal — and applies to any organisation whose AI is used in the EU, wherever it is based. Fines reach €35 million or 7% of global annual turnover. |
Table of Contents
What is the EU AI Act?
The EU AI Act is a European Union regulation that classifies artificial intelligence systems by the risk they pose to health, safety and fundamental rights, then attaches obligations in proportion to that risk. It is a regulation, not a directive, so it applies directly in all 27 member states without national transposition. And it is horizontal, governing AI across every sector rather than writing separate rulebooks for healthcare, finance or recruitment.
The Act entered into force on 1 August 2024 and applies in phases. Like the GDPR, it is extraterritorial: a company in California or Bengaluru falls in scope if its AI system is placed on the EU market or its output is used in the EU. The authoritative text sits on EUR-Lex. Public appetite for oversight is real but not unanimous: Pew Research Center found that across 25 countries surveyed in spring 2025, a median of 53% of adults trust the EU to regulate AI effectively, against 34% who do not.
How does the risk-based approach work?
The organising idea is that AI should be regulated as a use, not a technology. The Act sorts systems into four tiers: unacceptable risk (banned), high risk (heavily conditioned), limited risk (transparency only) and minimal risk (no specific obligations).
So the same model can land in different tiers depending on deployment. An image classifier is minimal risk when it sorts holiday photos and high risk when it screens job applicants. This is where compliance gets hard: in an analysis of 106 enterprise AI systems by appliedAI, summarised in a Cloud Security Alliance research note, 40% could not be clearly classified under the Act’s tiers at all. These duties overlap with the goals of explainable AI: oversight is impossible if nobody can reconstruct why a system produced an output.
What is banned, and what is high-risk?
Article 5 lists the prohibitions: government social scoring, manipulative or subliminal techniques, untargeted scraping of facial images, emotion inference in workplaces and schools, certain biometric categorisation, and real-time remote biometric identification in public for law enforcement, with narrow exceptions. The 2026 amendment added a prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material, with a transition to 2 December 2026.
High-risk systems are conditioned, not banned. Annex III covers stand-alone uses — recruitment, credit scoring, essential services, education, law enforcement, migration. Annex I covers AI embedded in products already regulated for safety. Providers must run a risk management system, meet data governance standards, produce technical documentation, keep logs, enable human oversight, hit accuracy and cybersecurity thresholds, and pass a conformity assessment before market entry.
| Risk tier | Examples | Core obligation | Applies from |
| Unacceptable | Social scoring; facial scraping | Prohibited | 2 Feb 2025 |
| Unacceptable (new) | AI-generated intimate imagery; CSAM | Prohibited | 2 Dec 2026 |
| High (Annex III) | CV screening; credit scoring | Conformity regime plus oversight | 2 Dec 2027 |
| High (Annex I) | AI inside medical devices, vehicles | Conformity regime via product law | 2 Aug 2028 |
| Limited | Chatbots; deepfakes | Disclosure and content marking | 2 Aug 2026 |
| Minimal | Spam filters; game AI | None specific | — |
How we compare: these tiers are mapped from Regulation (EU) 2024/1689 plus the 2026 AI Omnibus amendments, cross-checked against the European Commission’s official timeline rather than secondary summaries; where a date moved, we cite the post-amendment one. Disclosure: TechieHub is reader-supported; some outbound links are affiliate links that may earn us a commission at no extra cost to you, and this never influences our assessment. This article is general information, not legal advice.

What rules apply to general-purpose AI?
Foundation models sit in their own chapter: they are not built for one purpose and resist use-based tiers. Since 2 August 2025, providers of general-purpose AI models must publish technical documentation, supply information to downstream developers, maintain a copyright policy respecting text-and-data-mining reservations, and publish a detailed summary of training content. Anyone integrating large language models into a product inherits part of that paper trail.
A stricter tier applies to foundation models with systemic risk, presumed when training compute exceeds 10^25 floating-point operations. Those providers must run model evaluations and adversarial testing, mitigate systemic risks, report serious incidents to the AI Office, and meet cybersecurity requirements. Frontier releases from the largest labs — Anthropic’s Claude Opus 5, launched 24 July 2026, is one — sit in this bracket. The AI Office published the final General-Purpose AI Code of Practice on 10 July 2025; the grace period for signatories ends on 2 August 2026, when the Commission can begin imposing fines.
Article 50 handles transparency for everyone else. People must be told when they interact with an AI system, deepfakes must be disclosed, and synthetic content machine-readably marked. These duties apply from 2 August 2026, with grace to 2 December 2026 for systems already on the market. That is a partial answer to the credibility problem created by AI hallucinations.
When do the deadlines apply now?
This is where most published guides are wrong. The Commission proposed a simplification package on 19 November 2025; negotiators agreed provisionally on 7 May 2026, Parliament adopted it on 16 June 2026, the Council on 29 June 2026, and the AI Omnibus entered into force on 27 July 2026.
High-risk obligations for stand-alone Annex III systems moved from 2 August 2026 to 2 December 2027 — a sixteen-month deferral. Annex I embedded systems moved to 2 August 2028, because harmonised technical standards were not ready in time. Three other changes matter: Article 4’s duty to ensure AI literacy became a duty to take measures to support it; database registration was simplified for systems self-assessed as non-high-risk; and innovation reliefs once reserved for SMEs now extend to small mid-caps, with broader sandbox access including an EU-level sandbox.
What did not move matters as much. Prohibitions have applied since 2 February 2025 and GPAI obligations since 2 August 2025. And that date held: enforcement began on 2 August 2026 for prohibitions, transparency rules, AI literacy and general-purpose models, so those duties are now live and penalties attach to them.
Who complies, and what are the fines?
The Act binds providers who develop AI systems, deployers who use them professionally, and importers, distributors and authorised representatives. Deployer duties are lighter, but a deployer who substantially modifies a high-risk system becomes a provider by law.
Penalties run in three bands under Article 99. Breaching the Article 5 prohibitions carries fines up to €35 million or 7% of worldwide annual turnover, whichever is higher. Most other operator obligations carry up to €15 million or 3%, and misleading authorities up to €7.5 million or 1%. For SMEs and start-ups each cap is the lower of the two figures, not the higher. National market surveillance authorities enforce; the AI Office supervises general-purpose models. Readiness lags the rules: the same Cloud Security Alliance analysis found more than half of organisations still lack a systematic inventory of the AI they run.
Why is the law still contested?
Supporters argue it does what no voluntary framework achieved: it bans the worst uses, forces auditability onto consequential decisions, and gives citizens enforceable rights against opaque systems. It is also expected to travel: the “Brussels effect” turns EU rules into de facto global standards. Critics counter that compliance costs fall hardest on small firms and that definitions lag a technology reinventing itself annually. The 2026 Omnibus became a proxy for that fight: industry read it as pragmatism, civil-society groups as deregulation by the back door.

A compliance lead’s classification project
Marta Kowalska is compliance lead at a 400-person HR-software company in Kraków selling applicant-tracking tools EU-wide. Her task in early 2026: build the AI inventory nobody had, then classify every feature.
She catalogued 23 AI-touching features. Nineteen were minimal risk — resume parsing, duplicate detection, calendar optimisation — needing nothing beyond documentation hygiene. Three were high risk under Annex III because they rank or score candidates, and now sit on a roadmap targeting conformity assessment ahead of 2 December 2027. One support chatbot needed an explicit “you are talking to an AI” disclosure before 2 August 2026. The most valuable outcome was a deletion: a proposed feature inferring candidate enthusiasm from video interviews was cancelled, because emotion inference at work is prohibited, not merely regulated. Caught in a planning document, that cost an afternoon.
Frequently Asked Questions
Is the EU AI Act already in force?
Yes. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases. Prohibitions have applied since 2 February 2025 and general-purpose AI obligations since 2 August 2025. High-risk obligations for Annex III systems now apply from 2 December 2027 following the 2026 AI Omnibus.
Does the EU AI Act apply to companies outside Europe?
Yes. The Act is extraterritorial. Any provider or deployer whose AI system is placed on the EU market, or whose system output is used within the EU, falls in scope regardless of where the organisation is established. This mirrors the GDPR and is why the law shapes global product design.
What are the four risk levels?
Unacceptable risk covers banned practices such as social scoring. High risk covers permitted but tightly conditioned uses such as CV screening and credit scoring. Limited risk covers systems needing transparency, such as chatbots and deepfakes. Minimal risk covers everything else, including spam filters, with no specific obligations.
How large are the fines?
Article 99 sets three bands. Using prohibited AI attracts up to €35 million or 7% of worldwide annual turnover, whichever is higher. Most other obligations attract up to €15 million or 3%. Misleading authorities attracts up to €7.5 million or 1%. SMEs and start-ups face the lower of each pair.
What changed under the 2026 AI Omnibus?
The AI Omnibus entered into force on 27 July 2026. It deferred Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 2028, softened the Article 4 AI-literacy duty, simplified EU database registration, extended SME reliefs to small mid-caps, and added a prohibition on AI-generated intimate imagery and CSAM.
Do AI chatbots have to disclose that they are AI?
Yes. Article 50 requires that people be informed when they interact with an AI system unless it is obvious from context, and that synthetic audio, image, video and text be marked in machine-readable form. These transparency duties apply from 2 August 2026, with watermarking grace for existing systems until 2 December 2026.
Does the EU AI Act apply to me if I just use AI tools at work?
Yes, but lightly — using AI professionally makes you a “deployer”, and deployer duties are far narrower than provider duties. If you use a chatbot for drafting or a summariser for meetings, your obligations are essentially transparency and AI literacy: tell people when they are interacting with AI, and take measures to ensure staff using these tools understand them well enough to use them sensibly. Minimal-risk uses like spam filters and game AI carry no specific obligations at all.
Two situations escalate that sharply. Deploying AI for a high-risk purpose under Annex III — screening CVs, scoring credit, allocating benefits — brings human-oversight, logging and monitoring duties even though you did not build the system. And if you substantially modify a high-risk system, or put your own name on it, the Act treats you as its provider with the full conformity regime that entails. The practical test is not how sophisticated your AI use is but what decision it touches: a model drafting your marketing copy is minimal risk, and the same model ranking job applicants is not. Teams working in regulated fields will also want to read our guide to the best AI agent for legal work, where oversight duties bite hardest.
Conclusion
The EU AI Act is the first serious attempt to govern artificial intelligence comprehensively, and its central bet — regulate the use, not the technology — survived its first major amendment. The 2026 AI Omnibus changed the clock, not the architecture: prohibitions, transparency duties and general-purpose model rules are live and enforceable, while the heaviest high-risk machinery lands in December 2027 and August 2028. For anyone shipping AI into Europe, the practical move is Marta’s — inventory first, classify second, treat the deferral as runway rather than reprieve.

