Independent EU AI Act information resourceLegal text verified against EUR-Lex

European Union Artificial Intelligence Act

EU AI Act, Simplified.

Explore Regulation (EU) 2024/1689: the European Union's risk-based framework for artificial intelligence. Search every article, recital and annex, track compliance dates, and translate obligations for providers, deployers and GPAI models into practical next steps.

The regulation at a glance

What is the EU AI Act?

The EU AI Act is the European Union's risk-based law for artificial intelligence. It bans a small number of practices, sets detailed rules for high-risk systems, and introduces transparency and governance duties for other AI.

Read the complete overview →

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's binding law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages through to 2030. It regulates AI by risk rather than by technology: a short list of practices is banned outright, a defined set of high-risk uses carries a full compliance regime, some systems owe transparency duties only, and the large majority of AI faces no specific obligation beyond AI literacy.

It is the first comprehensive AI statute anywhere, and it reaches beyond the EU's borders: a provider established in the United States, India or the United Kingdom falls within scope if it places an AI system on the EU market, or if the system's output is used in the Union. The text was amended in 2026 by Regulation (EU) 2026/1744 , the Digital Omnibus on AI, which deferred the high-risk deadlines, softened the AI literacy duty and added two further prohibitions. See every change the Digital Omnibus made.

Instrument
Regulation (EU) 2024/1689
In force since
1 August 2024
Amended by
Regulation (EU) 2026/1744, in force 27 July 2026
Territorial scope
EU market placement or EU use of output (Article 2)
Enforced by
National market surveillance authorities and the AI Office
Maximum penalty
€35 million or 7% of worldwide annual turnover

How the EU AI Act classifies AI systems

The Act sorts AI into four tiers. Which tier a system falls into decides everything that follows: the obligations, the paperwork and the maximum fine.

The four risk tiers of the EU AI Act
TierWhat falls into itConsequence
ProhibitedTen practices banned outright: eight since February 2025, two more from December 2026€35m or 7% of turnover
High riskAnnex I product safety and eight Annex III use-case areasFull Chapter III regime and conformity assessment
Transparency riskArticle 50: interaction notice, synthetic marking, deep fakesDisclosure and marking duties
Minimal riskEverything else: the large majority of AI systemsAI literacy duty only

Most organisations discover they hold a mix: a handful of high-risk systems, a larger number with transparency duties, and a long tail of minimal-risk tools. Classify a specific system, work through the compliance checklist or read the high-risk classification guide.

When does the EU AI Act apply?

The Act does not switch on at a single moment. Obligations arrive in stages between February 2025 and August 2030, and the Digital Omnibus moved several of them. These are the dates as they now stand.

EU AI Act application dates, as amended by Regulation (EU) 2026/1744
DateWhat appliesStatus
1 Aug 2024The Regulation enters into forceIn force
2 Feb 2025Prohibited practices and AI literacy applyIn force
2 Aug 2025General-purpose AI model obligations applyIn force
2 Aug 2026Transparency obligations and the general application dateIn force
2 Dec 2026Two new prohibitions and the legacy marking deadline : date added by the Digital OmnibusUpcoming
2 Dec 2027Annex III high-risk obligations apply : deferred from 2 August 2026Upcoming
2 Aug 2028Annex I product-safety high-risk obligations apply : deferred from 2 August 2027Upcoming
2 Aug 2030Legacy large-scale IT systems must complyUpcoming

See the full implementation timeline for what each date switches on, who it binds and the governing provisions.

Who the EU AI Act applies to

The Act assigns duties by role, not by company type. One organisation is frequently several roles at once: a bank that buys a credit scoring model is a deployer, but becomes a provider the moment it substantially modifies that model or puts its own name on it.

Provider

Develops an AI system or a general-purpose AI model, or has one developed, and places it on the EU market or puts it into service under its own name or trademark.

Principal duties: Risk management, data governance, technical documentation, logging, human oversight design, accuracy and cybersecurity, conformity assessment, CE marking and registration for high-risk systems.

Deployer

Uses an AI system under its own authority in a professional capacity. Most organisations are deployers of far more systems than they provide.

Principal duties: Use the system per its instructions, assign competent human oversight, monitor operation, keep logs, inform affected workers, and, for some public-interest uses, complete a fundamental rights impact assessment.

GPAI model provider

Places a general-purpose AI model on the EU market, including large language and multimodal models, whether or not it also ships an application.

Principal duties: Technical documentation, information for downstream providers, a copyright policy, a public training-content summary, and, where the model presents systemic risk, model evaluation, adversarial testing, incident reporting and cybersecurity.

Importer and distributor

Places on the EU market, or makes available, an AI system carrying the name of an operator established outside the Union.

Principal duties: Verify the provider completed conformity assessment and documentation, keep records, cooperate with authorities, and stop making the system available if it is found non-conforming.

What are the penalties under the EU AI Act?

Fines run in three tiers, each expressed as a fixed sum or a percentage of worldwide annual turnover: whichever is higher for most operators, and whichever is lower for SMEs and start-ups.

EU AI Act penalty tiers under Article 99
BreachProvisionMaximum fine
Prohibited AI practicesArticle 5€35 million or 7%
Other operator obligationsArticles 16, 22–27, 48–51€15 million or 3%
Incorrect informationArticle 99(5)€7.5 million or 1%

Since the Digital Omnibus, the AI Office can also levy periodic penalty payments of up to 5% of average daily turnover for each day a breach continues: a charge that can outrun the headline maximum on a long-running infringement. How enforcement works in practice.

Frequently asked questions

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's binding law on artificial intelligence. It entered into force on 1 August 2024 and regulates AI by risk: some practices are banned, high-risk uses carry a full compliance regime, some systems owe only transparency duties, and the rest are largely unregulated.

When did the EU AI Act come into force?

It entered into force on 1 August 2024, but obligations apply in stages. Prohibited practices and the AI literacy duty applied from 2 February 2025, general-purpose AI model obligations from 2 August 2025, and the general application date was 2 August 2026. High-risk obligations now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products.

Does the EU AI Act apply to companies outside the EU?

Yes. Under Article 2 the Regulation applies to providers that place an AI system on the EU market regardless of where they are established, and to providers and deployers outside the Union where the output of the system is used in the EU. A company with no EU entity can still be in scope.

What is a high-risk AI system under the EU AI Act?

There are two independent routes. A system is high-risk if it is a safety component of a product covered by the Union harmonisation legislation in Annex I, or if it is used in one of the eight areas listed in Annex III, including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice. The two routes carry different deadlines.

What AI practices does the EU AI Act ban?

Article 5 now prohibits ten practices. Eight have been unlawful since 2 February 2025: subliminal manipulation, exploitation of vulnerability, social scoring, predictive policing based on profiling alone, untargeted facial scraping, emotion inference at work and in education, biometric categorisation for sensitive traits, and real-time remote biometric identification in public for law enforcement subject to narrow carve-outs. Two further bans, covering non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026.

What are the fines under the EU AI Act?

Three tiers. Breaching the Article 5 prohibitions carries up to €35 million or 7% of worldwide annual turnover. Breaching most other operator obligations carries up to €15 million or 3%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%. For SMEs and start-ups the lower of the two figures applies. The AI Office can additionally impose periodic penalty payments of up to 5% of average daily turnover per day a breach continues.

Does the EU AI Act apply to ChatGPT and other general-purpose AI?

Yes. General-purpose AI models are regulated in their own right under Chapter V, with obligations that applied from 2 August 2025: technical documentation, information for downstream providers, a copyright policy and a public summary of training content. Models presenting systemic risk carry further duties including evaluation, adversarial testing and incident reporting. Separately, an application built on such a model may itself be high-risk or carry Article 50 transparency duties.

What is the AI literacy obligation in Article 4?

Article 4 requires providers and deployers to take measures to support a sufficient level of AI literacy among staff and others operating AI on their behalf, accounting for their technical knowledge, experience and the context of use. The Digital Omnibus softened this from a duty to ensure literacy to a duty to support it, but it still applies to every operator regardless of risk tier and has done since 2 February 2025.

Role-based pathways

Start with what your organization does.

01

AI providers & developers

Risk classification, technical documentation, conformity assessment and post-market monitoring.

Explore requirements →
02

Deployers & procurement teams

Human oversight, transparency, impact assessments and workplace responsibilities.

Explore requirements →
03

Risk, legal & compliance

Governance structures, enforcement exposure, reporting and implementation deadlines.

Explore requirements →