What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689, the European Union's binding law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages through to 2030. It regulates AI by risk rather than by technology: a short list of practices is banned outright, a defined set of high-risk uses carries a full compliance regime, some systems owe transparency duties only, and the large majority of AI faces no specific obligation beyond AI literacy.
It is the first comprehensive AI statute anywhere, and it reaches beyond the EU's borders: a provider established in the United States, India or the United Kingdom falls within scope if it places an AI system on the EU market, or if the system's output is used in the Union. The text was amended in 2026 by Regulation (EU) 2026/1744 , the Digital Omnibus on AI, which deferred the high-risk deadlines, softened the AI literacy duty and added two further prohibitions. See every change the Digital Omnibus made.
- Instrument
- Regulation (EU) 2024/1689
- In force since
- 1 August 2024
- Amended by
- Regulation (EU) 2026/1744, in force 27 July 2026
- Territorial scope
- EU market placement or EU use of output (Article 2)
- Enforced by
- National market surveillance authorities and the AI Office
- Maximum penalty
- €35 million or 7% of worldwide annual turnover
How the EU AI Act classifies AI systems
The Act sorts AI into four tiers. Which tier a system falls into decides everything that follows: the obligations, the paperwork and the maximum fine.
Most organisations discover they hold a mix: a handful of high-risk systems, a larger number with transparency duties, and a long tail of minimal-risk tools. Classify a specific system, work through the compliance checklist or read the high-risk classification guide.
When does the EU AI Act apply?
The Act does not switch on at a single moment. Obligations arrive in stages between February 2025 and August 2030, and the Digital Omnibus moved several of them. These are the dates as they now stand.
See the full implementation timeline for what each date switches on, who it binds and the governing provisions.
Who the EU AI Act applies to
The Act assigns duties by role, not by company type. One organisation is frequently several roles at once: a bank that buys a credit scoring model is a deployer, but becomes a provider the moment it substantially modifies that model or puts its own name on it.
Provider
Develops an AI system or a general-purpose AI model, or has one developed, and places it on the EU market or puts it into service under its own name or trademark.
Principal duties: Risk management, data governance, technical documentation, logging, human oversight design, accuracy and cybersecurity, conformity assessment, CE marking and registration for high-risk systems.
Deployer
Uses an AI system under its own authority in a professional capacity. Most organisations are deployers of far more systems than they provide.
Principal duties: Use the system per its instructions, assign competent human oversight, monitor operation, keep logs, inform affected workers, and, for some public-interest uses, complete a fundamental rights impact assessment.
GPAI model provider
Places a general-purpose AI model on the EU market, including large language and multimodal models, whether or not it also ships an application.
Principal duties: Technical documentation, information for downstream providers, a copyright policy, a public training-content summary, and, where the model presents systemic risk, model evaluation, adversarial testing, incident reporting and cybersecurity.
Importer and distributor
Places on the EU market, or makes available, an AI system carrying the name of an operator established outside the Union.
Principal duties: Verify the provider completed conformity assessment and documentation, keep records, cooperate with authorities, and stop making the system available if it is found non-conforming.
What are the penalties under the EU AI Act?
Fines run in three tiers, each expressed as a fixed sum or a percentage of worldwide annual turnover: whichever is higher for most operators, and whichever is lower for SMEs and start-ups.
Since the Digital Omnibus, the AI Office can also levy periodic penalty payments of up to 5% of average daily turnover for each day a breach continues: a charge that can outrun the headline maximum on a long-running infringement. How enforcement works in practice.
Frequently asked questions
What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689, the European Union's binding law on artificial intelligence. It entered into force on 1 August 2024 and regulates AI by risk: some practices are banned, high-risk uses carry a full compliance regime, some systems owe only transparency duties, and the rest are largely unregulated.
When did the EU AI Act come into force?
It entered into force on 1 August 2024, but obligations apply in stages. Prohibited practices and the AI literacy duty applied from 2 February 2025, general-purpose AI model obligations from 2 August 2025, and the general application date was 2 August 2026. High-risk obligations now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products.
Does the EU AI Act apply to companies outside the EU?
Yes. Under Article 2 the Regulation applies to providers that place an AI system on the EU market regardless of where they are established, and to providers and deployers outside the Union where the output of the system is used in the EU. A company with no EU entity can still be in scope.
What is a high-risk AI system under the EU AI Act?
There are two independent routes. A system is high-risk if it is a safety component of a product covered by the Union harmonisation legislation in Annex I, or if it is used in one of the eight areas listed in Annex III, including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice. The two routes carry different deadlines.
What AI practices does the EU AI Act ban?
Article 5 now prohibits ten practices. Eight have been unlawful since 2 February 2025: subliminal manipulation, exploitation of vulnerability, social scoring, predictive policing based on profiling alone, untargeted facial scraping, emotion inference at work and in education, biometric categorisation for sensitive traits, and real-time remote biometric identification in public for law enforcement subject to narrow carve-outs. Two further bans, covering non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026.
What are the fines under the EU AI Act?
Three tiers. Breaching the Article 5 prohibitions carries up to €35 million or 7% of worldwide annual turnover. Breaching most other operator obligations carries up to €15 million or 3%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%. For SMEs and start-ups the lower of the two figures applies. The AI Office can additionally impose periodic penalty payments of up to 5% of average daily turnover per day a breach continues.
Does the EU AI Act apply to ChatGPT and other general-purpose AI?
Yes. General-purpose AI models are regulated in their own right under Chapter V, with obligations that applied from 2 August 2025: technical documentation, information for downstream providers, a copyright policy and a public summary of training content. Models presenting systemic risk carry further duties including evaluation, adversarial testing and incident reporting. Separately, an application built on such a model may itself be high-risk or carry Article 50 transparency duties.
What is the AI literacy obligation in Article 4?
Article 4 requires providers and deployers to take measures to support a sufficient level of AI literacy among staff and others operating AI on their behalf, accounting for their technical knowledge, experience and the context of use. The Digital Omnibus softened this from a duty to ensure literacy to a duty to support it, but it still applies to every operator regardless of risk tier and has done since 2 February 2025.