EU AI Act
AI-generated text. This page was generated using artificial intelligence.
Artificial Intelligence Act[1]
European Union[1]
EU regulation[1]
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744[2]
In force; phased application[3]
Entered into force August 1, 2024. Key application dates: 2025–2028; see timeline.[3]
September 7, 2026 — consolidated law and official implementation sources reviewed.[1]
Overview
The EU AI Act establishes EU-wide rules for developing, supplying and using AI. It combines prohibitions on specified practices, duties for high-risk systems, transparency requirements for certain uses, and a separate regime for general-purpose AI (GPAI) models. Its legal citation is Regulation (EU) 2024/1689.[1]
Status as of September 7, 2026: the Act is in force and its general application date has passed. The July 2026 Digital Omnibus amendment changed the implementation schedule; major high-risk requirements apply later. An enacted rule and a rule already applicable to a particular system are therefore different questions.[3][2]
Jump to: Who is covered · Main duties · Application dates · Enforcement
Scope
- Providers develop an AI system or GPAI model, or have one developed, and supply it under their own name. Deployers use an AI system under their authority in a professional context. Importers, distributors, product manufacturers and authorized representatives also have specified roles.[4]
- Territorial reach: coverage includes providers supplying the EU market even when established elsewhere, EU-based deployers, and certain overseas providers and deployers where the system’s output is used in the EU.[4]
- Exclusions and limits: the Act contains exclusions for exclusively military, defense or national-security uses, specified research activity, and purely personal non-professional use by natural persons. Open-source systems are not universally exempt: Articles 5 and 50 and the high-risk rules can still apply; GPAI models have their own narrower exception.[4][5]
- Other law still matters: the Act preserves the application of EU data-protection, consumer-protection and product-safety law. See related EU laws.[4]
Requirements
Prohibited practices and AI literacy
Article 5 prohibits specified harmful manipulation and exploitation, social scoring, certain predictive-policing uses, untargeted facial-image scraping, certain sensitive biometric categorization, and workplace or educational emotion recognition subject to the medical/safety exception. Real-time remote biometric identification for law enforcement in publicly accessible spaces is subject to a prohibition with narrow statutory exceptions and authorization safeguards. These are defined prohibitions, not a general ban on every use of biometrics.[6]
The 2026 amendment adds prohibitions concerning systems used to generate or manipulate non-consensual intimate material and child sexual abuse material, applicable from December 2, 2026. The amended text specifies the covered provider conduct, foreseeable misuse and safeguards, and prohibited deployer use.[6]
Article 4, as amended, requires providers and deployers to support the AI literacy of people operating AI on their behalf, taking account of their experience and context of use. It expressly does not require guaranteeing each individual a particular literacy level.[6]
High-risk AI systems
There are two main classification routes:[7]
- Regulated products — Article 6(1) and Annex I: an AI product or safety component covered by listed product legislation, where the relevant third-party conformity-assessment condition is met. Sector-specific limits also matter.
- Listed uses — Article 6(2) and Annex III: specified applications in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes. A field label alone does not classify every system in that field.
Article 6(3) permits a limited exception for certain Annex III systems that do not pose the specified significant risk, subject to its conditions. Within Annex III, systems that profile natural persons remain high-risk. A provider relying on the exception must document the assessment and register the system.[7]
When the relevant requirements apply, providers must address risk management, data governance, technical documentation, logging, user instructions, human oversight, accuracy, robustness and cybersecurity, alongside the applicable quality-management, conformity-assessment, registration and post-market duties.[8]
Deployers must use high-risk systems according to instructions, assign competent human oversight and monitor their operation. Article 27 adds a fundamental-rights impact assessment for specified public-sector/public-service deployers and certain creditworthiness and life/health-insurance uses; it is not imposed on every deployer. The phased dates and existing-system rules below remain important.[8][3]
Transparency: chatbots, synthetic content and deepfakes
Article 50 separates several duties:[9]
- Direct interaction: providers must make people aware that they are interacting with AI, unless that is obvious in context, with a specified law-enforcement exception.
- Machine-readable marking: providers of systems generating synthetic text, images, audio or video must make outputs detectably artificial, subject to technical feasibility and statutory exceptions, including standard assistive editing.
- Disclosure by users of AI: deployers must disclose deepfakes and certain AI-generated public-interest text. Artistic works have an adapted disclosure rule; public-interest text can be excepted where human review/editorial control and editorial responsibility are present.
- Emotion recognition and biometric categorization: deployers must inform exposed people, subject to the specified law-enforcement exception.
Most Article 50 duties apply from August 2, 2026. The December 2, 2026 transition for systems already marketed before August 2 concerns provider marking under Article 50(2), not a blanket postponement of all transparency duties.[9][3]
General-purpose AI models
GPAI is a model-level regime, separate from classifying a downstream application as high-risk. Article 53 requires technical documentation, information for downstream system providers, an EU copyright-compliance policy, and a public summary of training content. Qualifying open-source models have a limited documentation exception; copyright and training-summary duties remain, and the exception does not extend to models with systemic risk.[5]
Providers of GPAI models with systemic risk have additional evaluation and adversarial-testing, risk-mitigation, serious-incident reporting and cybersecurity obligations. The GPAI Code of Practice offers a voluntary way to demonstrate compliance; providers using another route must demonstrate adequate compliance with the binding Act.[5][10]
The GPAI obligations began applying on August 2, 2025. Models placed on the market before that date have a transition until August 2, 2027. The start of Commission fining powers under Article 101 in August 2026 is a separate milestone.[5][11]
Enforcement
- National authorities supervise AI systems within their remit; the European Data Protection Supervisor supervises EU institutions’ use. The Commission/AI Office supervises GPAI models and, under amended Article 75, specified GPAI-based systems and systems forming part of designated very large platforms/search engines, subject to the statutory exceptions.[11]
- Powers and complaints: the Act provides for information requests, evaluations, corrective measures and penalties. Article 85 permits complaints to the relevant market-surveillance authority. An investigation or information request is not itself a finding of infringement.[11]
- Maximum fines: Article 99 provides ceilings of €35 million/7% of worldwide annual turnover for prohibited practices, €15 million/3% for the other listed breaches, and €7.5 million/1% for specified misleading-information breaches. For undertakings the higher ceiling generally applies, with lower-of-the-two treatment for SMEs and specified small mid-cap breaches. Article 101 separately governs GPAI-provider fines; Article 100 governs EU institutions. These are ceilings, not automatic penalties.[11]
Timeline
The table summarizes key dates in the amended Act. Article 111 contains additional rules for existing systems, including significant design changes, public-authority systems and large-scale IT systems; the table is not a substitute for those transitional provisions.[3]
| Date | Milestone |
|---|---|
| August 1, 2024 | Original Act entered into force.[1] |
| February 2, 2025 | Initial prohibitions and AI-literacy provisions began applying.[3] |
| August 2, 2025 | GPAI and governance provisions began applying, with specified exceptions and transitions.[5] |
| July 27, 2026 | Digital Omnibus amendment entered into force.[2] |
| August 2, 2026 | General application date, including Article 50 transparency and Article 101 GPAI fining powers, subject to exceptions.[3] |
| December 2, 2026 | New intimate-material/CSAM prohibitions apply; Article 50(2) marking transition ends for qualifying pre-existing systems.[3] |
| August 2, 2027 | Pre-August 2025 GPAI models must comply; revised national AI-sandbox deadline.[3] |
| December 2, 2027 | Main high-risk requirements for Annex III systems apply.[3] |
| August 2, 2028 | Main high-risk requirements for Annex I product-related systems apply, subject to sectoral rules.[3] |
Original parliamentary development
Brando Benifei and Dragoș Tudorache served as Parliament’s co-rapporteurs for the original AI Act. Their joint work is recorded in legislative procedure 2021/0106(COD).[12]
Amendment history and related coverage
The Digital Omnibus is now adopted legislation, not a pending negotiating proposal. Regulation (EU) 2026/1744 amended the Act’s deadlines, AI-literacy wording, specified prohibitions, supervision and product-law interaction. Earlier negotiating positions should be read as legislative history.[2]
Use these links for the wiki’s dated reporting:
- July 27, 2026 — amendment coverage
- July 31, 2026 — implementation coverage
- August 2, 2026 — application coverage
- August 10, 2026 — provider implementation coverage
- September 1, 2026 — supervisory coverage
- European Union AI law directory · AI law by topic
Related organizations
References
- ↑ 1.0 1.1 1.2 1.3 1.4 1.5 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 1–3 and 113. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 2.0 2.1 2.2 2.3 Regulation (EU) 2026/1744, Digital Omnibus on AI, July 8, 2026; Official Journal, July 24, 2026, Articles 1 and 4. Reviewed September 7, 2026.
- ↑ 3.00 3.01 3.02 3.03 3.04 3.05 3.06 3.07 3.08 3.09 3.10 3.11 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 57, 111 and 113. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 4.0 4.1 4.2 4.3 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 2 and 3. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 5.0 5.1 5.2 5.3 5.4 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 51–55, 111(3) and 113. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 6.0 6.1 6.2 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 4, 5 and 113. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 7.0 7.1 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Article 6 and Annexes I and III. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 8.0 8.1 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 9–17, 26, 27, 43, 49, 72 and 73. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ 9.0 9.1 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 50 and 111(4). Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ European Commission, The General-Purpose AI Code of Practice, reviewed September 7, 2026.
- ↑ 11.0 11.1 11.2 11.3 Regulation (EU) 2024/1689, consolidated text of July 27, 2026, Articles 70, 74, 75–75c, 85, 88–94 and 99–101. Reviewed September 7, 2026. The consolidated text is a documentation aid; the Official Journal acts are authoritative.
- ↑ European Parliament Legislative Observatory, Artificial Intelligence Act, procedure 2021/0106(COD). Accessed September 12, 2026.