The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive AI law. Here are the three things every organisation must know:
- 1 Risk determines your obligations. The Act classifies all AI systems into four tiers — from Unacceptable Risk (banned outright since February 2025) to Minimal Risk (no mandatory rules). If your AI is in HR, credit scoring, education, or biometrics, you are almost certainly in the high-risk tier.
- 2 The primary deadline is 2 August 2026. From this date, high-risk AI systems must have completed conformity assessments, full technical documentation, EU database registration, and human oversight mechanisms. Conformity assessments take up to 12 months — organisations must act now.
- 3 It applies globally, not just in the EU. Any company — US, UK, or otherwise — that provides or deploys AI affecting EU users is in scope. The maximum fine for violations is €35 million or 7% of global annual turnover, whichever is higher.
EU AI Act Summary: The Complete Guide for 2025–2026
The EU AI Act is the world’s first comprehensive legal framework governing artificial intelligence. Formally adopted on 13 March 2024 and entering into force on 1 August 2024, it establishes binding obligations for AI providers, deployers, and importers operating in or affecting the European Union market.
This guide covers everything organisations need to understand: the Act’s scope, risk classification system, compliance obligations, key deadlines, and enforcement regime — with direct references to the official regulation text.
Last updated: March 2026 · Sources: EUR-Lex Official Text · European Commission
1. What Is the EU AI Act?
The EU AI Act (officially Regulation (EU) 2024/1689 of the European Parliament and of the Council) is landmark legislation that creates a uniform legal framework for artificial intelligence across all 27 EU member states. It was proposed by the European Commission in April 2021, underwent three years of legislative negotiation, and was formally adopted on 21 May 2024.
The Act takes a risk-based approach: the stricter the potential harm an AI system could cause, the heavier its regulatory requirements. It does not regulate AI as a technology in the abstract — it regulates specific applications and use cases of AI systems based on the context in which they operate.
Crucially, the EU AI Act is a product safety regulation, not primarily a data protection law. It operates alongside — not instead of — the General Data Protection Regulation (GDPR) and other existing EU law. Organisations dealing with AI systems that process personal data must comply with both simultaneously.
2. Who Does the EU AI Act Apply To?
The EU AI Act has broad territorial scope. It applies to organisations and individuals who:
- Place AI systems on the EU market or put them into service in the EU — regardless of where they are established
- Use AI systems within the EU (deployers)
- Are importers or distributors of AI systems in the EU
- Are located outside the EU, but whose AI system’s output is used within the EU
In practice, this means any US, UK, Asian, or other non-EU company offering AI-powered products or services to EU residents is potentially subject to the Act. This extraterritorial reach mirrors the GDPR’s approach and makes the EU AI Act a de-facto global compliance standard for organisations with EU market exposure.
Key Actors Defined by the Act
| Actor | Article | Definition | Example |
|---|---|---|---|
| Provider | Art. 3(3) | Develops and places an AI system on the market or into service under their own name | AI software companies, model developers |
| Deployer | Art. 3(4) | Uses an AI system under their own authority in a professional context | HR dept using AI screening tool; bank using credit scoring API |
| Importer | Art. 3(6) | An EU-established person who places a non-EU AI system on the EU market | EU distributor of US-built AI software |
| Distributor | Art. 3(7) | Supply chain entity that makes an AI system available without modifying it | Resellers, marketplaces, app stores |
| Authorised Representative | Art. 3(5) | EU-established entity mandated by a non-EU provider to act on their behalf | Required for all non-EU providers of high-risk AI |
Who Is Exempt?
The Act does not apply to AI systems used exclusively for military, national security, or defence purposes; AI for scientific research and development (before it enters the market); and AI systems used by individuals purely for personal, non-professional use. Open-source AI models may qualify for partial exemptions in certain conditions, but remain subject to prohibited practice rules regardless.
Reference: Article 2 — Scope, EU AI Act Official Reference Site
3. The Risk Classification System
The EU AI Act’s central mechanism is its four-tier risk pyramid. Compliance obligations scale with risk — the more severe the potential harm, the more stringent the requirements. Understanding where your AI system sits in this hierarchy is the first and most critical step in any compliance programme.
4. Prohibited AI Practices (Article 5)
Article 5 bans eight categories of AI practices that the EU legislature determined pose unacceptable risks. These bans took effect on 2 February 2025 — meaning organisations should already have ceased any of the following activities. There is no conformity pathway; the practices are prohibited absolutely.
| # | Prohibited Practice | Key Detail |
|---|---|---|
| 1 | Subliminal Manipulation | AI that uses techniques beyond conscious perception to materially distort behaviour in ways that cause or are likely to cause harm |
| 2 | Exploitation of Vulnerabilities | AI that exploits age, disability, or social/economic situation to distort behaviour in harmful ways |
| 3 | Social Scoring by Public Authorities | AI used by public bodies to evaluate or classify people based on social behaviour or personality characteristics, leading to unjustified or disproportionate detrimental treatment |
| 4 | Real-Time Remote Biometric ID in Public Spaces | Limited law-enforcement exceptions exist with prior judicial authorisation for specific crimes only |
| 5 | Untargeted Facial Image Scraping | Building or expanding facial recognition databases by scraping the internet or CCTV footage without targeted purpose |
| 6 | Emotion Inference in Workplaces & Education | AI that infers emotions from biometric data in workplace or educational institution contexts (narrow medical and safety exceptions apply) |
| 7 | Biometric Categorisation by Sensitive Attributes | Categorising individuals based on biometric data to deduce race, political opinions, religion, trade union membership, sexual orientation |
| 8 | Predictive Policing Based Solely on Profiling | AI that assesses the risk of individuals committing future criminal offences based solely on personality traits or profiling without a prior criminal act |
5. High-Risk AI System Obligations
High-risk AI systems face the Act’s most comprehensive compliance requirements. There are two routes to being classified as high-risk: being listed in Annex III (standalone high-risk AI use cases), or being an AI component that is a safety component of a product already regulated under Annex I product safety legislation (medical devices, machinery, aviation equipment, etc.).
Providers of high-risk AI systems must fulfil the following obligations before placing a system on the EU market:
| Obligation | Article | What Is Required | Applies To |
|---|---|---|---|
| Risk Management System | Art. 9 | Continuous, iterative process identifying and mitigating risks throughout the AI lifecycle | Providers |
| Data Governance | Art. 10 | Training, validation, and test data must meet quality criteria; bias detection and correction required | Providers |
| Technical Documentation | Art. 11 | Full documentation before market placement; kept up to date for entire system lifecycle | Providers |
| Record-Keeping / Logging | Art. 12 | Automatic logging of operations to the extent technically feasible; enables post-incident analysis | Providers |
| Transparency & Instructions | Art. 13 | Clear instructions for use enabling deployers to understand and operate the system correctly | Providers |
| Human Oversight | Art. 14 | Design must enable humans to monitor, understand, intervene, override, or halt the system | Providers (design) / Deployers (operation) |
| Accuracy, Robustness & Cybersecurity | Art. 15 | Systems must achieve appropriate accuracy levels and be resilient to errors, faults, and adversarial attacks | Providers |
| Quality Management System | Art. 17 | Documented QMS covering strategy, design, development, testing, and post-market monitoring | Providers |
| Conformity Assessment | Art. 43 | Self-assessment for most Annex III systems; third-party assessment required for biometric ID and certain others | Providers |
| EU Database Registration | Art. 49 | Register in the EU AI Act database before market placement; publicly accessible | Providers (+ some deployers) |
| Post-Market Monitoring | Art. 72 | Active monitoring of system performance; report serious incidents to authorities within 15 days | Providers |
Deployer Obligations for High-Risk AI
Deployers of high-risk AI systems (organisations using them in operations) also carry significant obligations, including: using systems only within the scope documented by the provider; implementing human oversight measures as specified; ensuring staff have AI literacy; conducting Fundamental Rights Impact Assessments (FRIAs) before deploying in regulated sectors; maintaining use logs for at least 6 months; and reporting serious incidents to the provider and national authorities.
See also: IBM — EU AI Act Requirements Overview · Our Provider vs. Deployer Guide
6. General Purpose AI (GPAI) Models
Chapter V of the EU AI Act introduces a separate regulatory framework specifically for General Purpose AI (GPAI) models — large foundation models (such as GPT, Gemini, Claude, Llama) that can be adapted for a wide range of downstream tasks. These obligations applied from 2 August 2025.
- Maintain technical documentation of training methodology
- Provide information and documentation to downstream deployers
- Comply with EU copyright law (Article 53(1)(c))
- Publish a summary of training data content
- Implement an AI policy to respect intellectual property
- Adversarial testing (red-teaming) before release
- Report serious incidents to the AI Office
- Cybersecurity protection measures
- Energy efficiency reporting
- Ongoing model evaluations
Organisations that integrate GPAI models into their own applications must obtain the required documentation from the model provider. If the GPAI is integrated into a high-risk AI system, the downstream provider becomes responsible for the combined system’s conformity assessment.
Reference: EU AI Act Chapter V — GPAI Model Obligations · OECD AI Governance Framework
7. Transparency and AI Labeling Requirements
Article 50 creates transparency obligations that apply broadly — including to AI systems that are not classified as high-risk. These take effect from 2 August 2026 and affect any business producing AI-generated content or operating AI interfaces that interact with the public.
| Obligation | Who Must Comply | Requirement | Exceptions |
|---|---|---|---|
| Chatbot Disclosure | Providers / Deployers of conversational AI | Inform users they are interacting with AI, not a human | Where AI nature is obvious from context |
| Deepfake Labeling | Any provider generating synthetic audio/video/image | Machine-readable disclosure that content is AI-generated | Authorised law enforcement; artistic satire with clear disclosure |
| AI-Generated Text Disclosure | Publishers of AI-generated text on public-interest topics | Disclose AI-generated nature clearly to readers/audience | Minor AI-assisted editing of human-authored text |
| Emotion Recognition Disclosure | Deployers of emotion recognition AI | Notify individuals that emotion recognition is operating | Medical devices; certain research applications |
Reference: Our Article 50 Deep-Dive Guide · Article 50 Official Reference
8. EU AI Act Governance Structure
The Act establishes a multi-level governance system with distinct roles at EU and national levels.
Reference: NIST AI Risk Management Framework (complementary international standard)
9. EU AI Act Timeline and Key Deadlines
The Act uses a phased implementation with obligations rolling in across three years. The table below shows every key milestone.
| Date | Milestone | Who Is Affected | Status |
|---|---|---|---|
| 1 Aug 2024 | Act enters into force; 36-month countdown begins | All organisations | Passed |
| 2 Feb 2025 | Prohibited AI practices (Article 5) take effect | All organisations using banned AI | Passed |
| 2 Feb 2025 | AI literacy obligations for providers and deployers begin | All providers & deployers | Passed |
| 2 Aug 2025 | GPAI model obligations (Chapter V) apply; AI Office Code of Practice live | GPAI model providers | Passed |
| 2 Aug 2025 | National competent authorities must be designated by member states | EU Member States | Passed |
| ⚡ 2 Aug 2026 | HIGH-RISK AI (Annex III) fully compliant · Article 50 transparency live · EU database open | All high-risk AI providers & deployers; all AI content producers | Primary Deadline |
| 2 Aug 2027 | High-risk AI in Annex I legacy products (medical devices, machinery, etc.) must comply | Manufacturers of regulated products with AI components | Upcoming |
10. EU AI Act Penalties and Enforcement
The EU AI Act’s penalty structure is explicitly designed to make compliance less costly than non-compliance for organisations of any size. The fines are calculated as the higher of a fixed cap or a percentage of global annual turnover — ensuring large multinationals face penalties proportionate to their scale.
| Violation Type | Maximum Fine | Global Turnover Cap | GDPR Comparison |
|---|---|---|---|
| Prohibited AI (Article 5) | €35,000,000 | 7% | 2× higher than GDPR max (4%) |
| High-Risk AI / GPAI Obligations | €15,000,000 | 3% | ≈ GDPR mid-tier |
| Misleading Authorities | €7,500,000 | 1.5% | Lower tier |
| SME / Startup Mitigation | Lower of fixed cap or percentage applies. Regulators must consider proportionality, company size, and cooperation with authorities when setting fines. | ||
Beyond financial penalties, national authorities can order market withdrawal of non-compliant AI systems, impose temporary or permanent bans on operation in the EU, and require public disclosure of violations. For non-EU providers, this can effectively mean total loss of EU market access.
Reference: IAPP EU AI Act Resource Centre · Our Full Penalties Guide
11. Quick Reference Tables
Use these tables to quickly locate key articles, understand obligations by actor, and identify your compliance priorities.
Table A: Key Articles at a Glance
| Article | Topic | Key Provision |
|---|---|---|
| Art. 3 | Definitions | 48 defined terms including AI system, provider, deployer, GPAI model |
| Art. 5 | Prohibited Practices | Eight banned AI use cases; effective 2 Feb 2025 |
| Art. 6 | High-Risk Classification | Rules for classifying AI systems as high-risk; references to Annex I and III |
| Art. 9 | Risk Management | Mandatory risk management system for high-risk AI; iterative lifecycle requirement |
| Art. 10 | Data Governance | Training data quality, bias testing, data management practices |
| Art. 11 | Technical Documentation | Documentation requirements; Annex IV specifies content |
| Art. 13 | Transparency | Clear instructions for use; information to deployers |
| Art. 14 | Human Oversight | Design requirements enabling human monitoring and override |
| Art. 17 | Quality Management | QMS requirements covering full development and deployment lifecycle |
| Art. 25 | Deployer Reclassification | Conditions under which a deployer becomes a provider (substantial modification) |
| Art. 43 | Conformity Assessment | Self-assessment vs third-party assessment rules |
| Art. 49 | EU Database Registration | Mandatory registration before market placement |
| Art. 50 | Transparency Obligations | Chatbot disclosure, deepfake labeling, AI-generated content rules |
| Art. 53 | GPAI Provider Obligations | Documentation, copyright compliance, downstream transparency |
| Art. 72 | Incident Reporting | Serious incident reporting; 15-day notification window |
Table B: Compliance Obligations by Actor Type
| Obligation | Provider | Deployer | Importer | Distributor | GPAI Provider |
|---|---|---|---|---|---|
| Risk Management System | ✅ | — | — | — | — |
| Technical Documentation | ✅ | — | ✅ (verify) | — | ✅ |
| Conformity Assessment | ✅ | — | ✅ (verify) | — | — |
| EU AI Database Registration | ✅ | ✅ (some) | — | — | ✅ |
| Human Oversight Design | ✅ | ✅ (operate) | — | — | — |
| AI Literacy Training for Staff | ✅ | ✅ | — | — | ✅ |
| Fundamental Rights Impact Assessment | — | ✅ | — | — | — |
| Maintain Use Logs (6 months) | — | ✅ | — | — | — |
| Incident Reporting | ✅ | ✅ | — | — | ✅ |
| Copyright & Training Data Disclosure | — | — | — | — | ✅ |
Table C: Annex III High-Risk Categories — Common Affected Products
| Category | Common Products / Systems | Who Is Typically Affected |
|---|---|---|
| Biometric ID | Face recognition, fingerprint systems, gait analysis | Security companies, access control vendors, law enforcement tech |
| Critical Infrastructure | Grid management AI, traffic control, flood prediction | Utilities, smart city platforms, transport operators |
| Education | Admissions AI, automated grading, proctoring tools | EdTech companies, universities, exam boards |
| Employment / HR | CV screening, interview analysis AI, performance monitoring | HR software vendors, enterprises using these tools |
| Essential Services | Credit scoring, insurance underwriting AI, benefits eligibility | Banks, insurers, fintech companies, public sector |
| Law Enforcement | Predictive policing tools, AI lie detectors, evidence analysis | Legal tech vendors, police technology suppliers |
| Migration & Border | Risk profiling tools, document verification, asylum processing AI | Border tech vendors, immigration authorities |
| Justice Administration | Legal research AI, sentencing recommendation tools | Legal tech companies, court administration bodies |
Source: Annex III, Regulation EU 2024/1689 · Our Full Annex III Guide
12. EU AI Act Summary — FAQ
Comprehensive answers to the most-searched questions about the EU AI Act, structured for fast reference by legal, compliance, and technical teams.
Martina Fowler is a senior AI regulatory counsel with over a decade of experience advising multinational organisations on technology law, data governance, and EU digital policy. She has closely tracked the EU AI Act since the Commission’s initial proposal in April 2021 and has guided dozens of enterprises through risk classification, conformity assessment design, and cross-border compliance strategy. Martina holds an LL.M. in European Law from KU Leuven and is a frequent speaker at EU policy forums on AI regulation and fundamental rights. Her work at EU AI Act Guide focuses on translating complex legislative text into actionable compliance frameworks for legal, technical, and business audiences.
martina.fowler@euaiactguide.com