GovernanceCore
Partially in forceEuropean UnionExtraterritorial reach

EU Artificial Intelligence Act

The world's first comprehensive, risk-based AI law. Classifies AI by risk tier (prohibited, high-risk, limited, minimal) and imposes graduated obligations, with most high-risk rules and enforcement starting 2 August 2026.

Next deadline450 daysHigh-risk (Annex III) rules apply · Dec 2, 2027
Status
Partially in force
Jurisdiction
European Union · Supranational
Adopted
Jul 12, 2024
In force
Aug 1, 2024
Enforcement date
Aug 2, 2026
Regulator / body
European AI Office & national market-surveillance authorities
Sectors
Cross-sector
Extraterritorial
Yes

Overview

Duties attach to a role rather than to a technology, so the same system carries different obligations depending on whether you are its provider, deployer, importer or distributor, and non-EU firms are caught where the output produced by the system is used in the Union (Art. 2(1)). Annex III listing is not automatically decisive: a provider may document that a listed system performs only a narrow procedural, preparatory or human-improving task, although any system that profiles natural persons is always high-risk (Art. 6(3), (4)). General-purpose AI models sit in a parallel regime with documentation, downstream information and copyright-policy duties, plus a presumption of systemic risk once cumulative training compute exceeds 10^25 floating-point operations (Art. 51(2), Art. 53, Art. 55). Enforcement is split between national market-surveillance authorities for AI systems and the Commission's AI Office for GPAI models, with fine ceilings running from 1 percent of worldwide turnover for misleading information up to 7 percent for prohibited practices (Art. 99(3) to (5)). Regulation (EU) 2026/1744, in force from 27 July 2026, moved the Annex III high-risk regime to 2 December 2027 and product-embedded high-risk AI to 2 August 2028, while leaving AI literacy, the prohibitions and the Art. 50 transparency duties on their original dates (Art. 113, as amended).

Key dates

  • Aug 1, 2024
    Entered into force
  • Feb 2, 2025
    Prohibited practices & AI literacy duties apply
  • Aug 2, 2025
    General-purpose AI (GPAI) model obligations & governance apply
  • Aug 2, 2026
    Transparency duties (Art. 50) and enforcement apply
  • Dec 2, 2027
    High-risk (Annex III) rules apply
  • Aug 2, 2028
    High-risk AI embedded in Annex I regulated products applies

Risk areas addressed

Bias & discriminationTransparencySafety & robustnessHuman oversightFundamental rightsGovernance & accountability

Who it applies to

In scope are providers placing AI systems or GPAI models on the EU market, deployers established or located in the Union, and providers or deployers in third countries whose system output is used in the Union, together with importers, distributors, authorised representatives and product manufacturers that ship an AI system under their own brand (Art. 2(1)). No headcount or turnover threshold applies: SMEs, start-ups and small mid-cap enterprises get simplified Annex IV documentation, proportionate quality-management implementation and a lower-of-the-two fine cap, not an exemption (Art. 11(1), Art. 17(2), Art. 99(6), (6a)). Outside scope are systems used exclusively for military, defence or national security purposes, systems developed solely for scientific research and development, pre-market research and testing other than real-world testing, purely personal non-professional use by individuals, and free and open-source releases unless placed on the market as high-risk or caught by Art. 5 or Art. 50 (Art. 2(3), (6), (8), (10), (12)).

Key obligations

  • Provide AI literacy measures for staff and anyone operating AI systems on your behalf, calibrated to their technical knowledge, training and the context of use, and to the people the systems will be used on (Art. 4).
  • Run a documented, iterative risk-management process across each high-risk system's whole lifecycle, covering reasonably foreseeable misuse and post-market monitoring data, and test against predefined metrics and probabilistic thresholds before market placement (Art. 9).
  • Apply data-governance practices to training, validation and testing sets, including examination for biases likely to harm health, safety or fundamental rights, measures to mitigate any bias found, and identification of data gaps (Art. 10(2)).
  • Draw up Annex IV technical documentation before placing a high-risk system on the market, keep it current, build in automatic event logging over the system's lifetime, and supply instructions for use that let deployers interpret and act on outputs (Art. 11, Art. 12, Art. 13).
  • Design in human-machine interface tools so identified natural persons can effectively oversee and override the system in use, and achieve an appropriate and consistent level of accuracy, robustness and cybersecurity across the lifecycle (Art. 14, Art. 15).
  • Operate a documented quality management system, complete the applicable conformity assessment, draw up the EU declaration of conformity, affix CE marking, and register yourself and the system in the EU database before placing it on the market (Art. 16, Art. 17, Art. 43, Art. 47, Art. 49).
  • As a deployer, assign human oversight to competent, trained and empowered staff, keep the automatically generated logs for at least six months, inform workers and their representatives before workplace use, tell individuals subject to Annex III decisions, and suspend use and alert the provider and market-surveillance authority on identifying a risk or serious incident (Art. 26).
  • Mark synthetic audio, image, video and text as machine-readable AI output, disclose deep fakes and AI-generated public-interest text, and inform people when they are interacting with an AI system or exposed to emotion recognition or biometric categorisation (Art. 50(1) to (4)).

How to prepare

  1. Build an inventory of every AI system and GPAI model your organisation provides or deploys, recording your legal role for each one and whether its output reaches the Union.
  2. Classify each entry against Art. 5, Annex I and Annex III, and where you conclude a listed system is not high-risk under Art. 6(3), write up that assessment before deployment and register the system under Art. 49(2).
  3. Close the live gaps first, namely GPAI model documentation and copyright policy under Art. 53 and the Art. 50 transparency and labelling duties, then plan backwards from 2 December 2027 for Annex III systems and 2 August 2028 for product-embedded ones.
  4. Stand up the Chapter III evidence base per high-risk system: risk-management file, data-governance records and bias testing, Annex IV documentation, logging design, instructions for use and a named human overseer.
  5. Rewrite provider and deployer contracts and information flows so deployers actually receive what Art. 13 requires and providers receive the monitoring and incident data that Art. 26(5) and Art. 72 depend on.
  6. Run the conformity assessment, sign the declaration of conformity, affix CE marking, register in the EU database, and build serious-incident reporting that meets the 15-day, 10-day and 2-day deadlines in Art. 73.

Penalties & enforcement

Up to €35M or 7% of global annual turnover (prohibited practices); lower tiers for other breaches.

Enforced by: European AI Office & national market-surveillance authorities

Enforcement under EU AI Act

EU · AI systemsDecision

The EU AI Act prohibits certain AI practices, with violations carrying fines of up to €35 million or 7% of global annual turnover.

€30MEU AI Office · DeepGen Ltd.Fine issued

The EU AI Office fined DeepGen €30 million for providing a generative model used to create non‑consensual deepfake pornography, a breach of the prohibited AI practices under the AI Act.

€138AI Act Enforcement Tracker · 27 member statesDecision

The AI Act Enforcement Tracker reports 88 enforcement actions and €138M in fines.

EU AI Office · General-purpose AI model providersInvestigation open

The EU AI Office began enforcing transparency rules for general-purpose AI models.

EU AI Office · General-purpose AI modelsFine issued

The EU AI Office's enforcement powers over general-purpose AI models enter into application, including the ability to request technical documentation, evaluate models, require corrective measures, and issue fines for non-compliance.

All enforcement actions →
Getting ready

EU AI Act is enforced by European AI Office & national market-surveillance authorities. The next dated milestone falls on Dec 2, 2027, 450 days away: High-risk (Annex III) rules apply. In practice that means knowing which of your AI systems fall in scope across every sector you operate in, holding assessments that speak to bias & discrimination, transparency and safety & robustness, and being able to produce that evidence on request, including for systems built outside the jurisdiction.

Official source

Regulation (EU) 2024/1689, EUR-Lex

Related regulations

← All regulations