The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. Approved by the European Parliament in March 2024 and formally adopted by the Council in May 2024, it entered into force on 1 August 2024 and applies progressively. It applies to any organisation whose AI systems affect people in the EU, regardless of where the organisation is based.
Key fact: The Act has extraterritorial reach. A US, UK, Australian, or Asian organisation whose AI system is used by EU residents is in scope. There is no exemption for organisations headquartered outside the EU.
EU AI Act, Regulation (EU) 2024/1689, the European Union's comprehensive AI law that classifies AI systems by risk level and imposes obligations proportionate to that risk on providers and deployers.
The EU AI Act is the world's first horizontal AI regulation. It applies extraterritorially: any organisation placing AI on the EU market, or whose AI outputs affect people in the EU, is in scope. The Act sets four risk tiers (prohibited, high-risk, limited-risk, minimal-risk), with the heaviest obligations on high-risk AI listed in Annex III. Key deadlines were amended by the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026.
Source: Regulation (EU) 2024/1689
Regulation entered into force (published in the Official Journal 12 July 2024).
Banned AI practices take effect: social scoring, subliminal manipulation, real-time biometric ID (with narrow exceptions), emotional recognition at work, biometric categorisation by sensitive characteristics. The Article 4 AI-literacy duty also applies from this date.
General-purpose AI model obligations: transparency, copyright compliance, technical documentation. Systemic risk rules for large frontier models. Models already on the market before this date have until 2 August 2027 to comply (Article 111).
General application date. Article 50 transparency duties take effect: chatbots must disclose they are AI, and AI-generated or deepfake content must be labelled. NOT postponed by the Digital Omnibus. Pre-existing generative-AI systems have a shortened grandfather window for the Article 50(2) marking duties, to 2 December 2026.
Main Annex III high-risk AI system rules: conformity assessment, technical documentation, human oversight, EU AI database registration, post-market monitoring. Postponed from 2 Aug 2026 by the Digital Omnibus on AI, published in the Official Journal 24 July 2026 and in force from 27 July 2026. A new prohibition on AI "nudifier" apps and AI-generated CSAM, added by the same Omnibus, applies now that the Omnibus is in force; providers have until 2 December 2026 to implement the required technical safeguards (refusal training, output controls, content filtering).
High-risk AI embedded in products covered by existing EU sector legislation (medical devices, civil aviation, motor vehicles, toys, etc.), postponed from Aug 2027 by the Digital Omnibus on AI, published in the Official Journal 24 July 2026 and in force from 27 July 2026.
Beyond the headline deadline deferrals, the Digital Omnibus on AI made several other changes to the Act that did not survive as originally proposed, or that expand rather than delay obligations.
AI Office supervisory powers expanded
The AI Office's oversight now reaches beyond the original case of a single provider's own general-purpose AI model plus its own downstream system: it extends to any AI system built on a GPAI model within the same undertaking, and to providers of very large online platforms or search engines (VLOPs/VLOSEs) under the Digital Services Act, with an explicit legal basis for the AI Office to cooperate with national market surveillance authorities.
Machinery Regulation carve-out
AI embedded in products governed by the EU Machinery Regulation is excluded from the AI Act's direct high-risk regime; the Commission can instead adopt delegated acts under the Machinery Regulation itself to add AI-specific requirements. Other Annex I sectoral products, medical devices and toys among them, remain fully in scope of the AI Act on the normal Annex I timeline.
Regulatory sandbox deadline postponed
The deadline for member states to establish national AI regulatory sandboxes has been postponed to 2 August 2027, giving national authorities more time to stand up testing environments for providers to trial AI systems under supervision before market entry.
Registration exclusions stayed narrow
The Commission had proposed letting more providers who self-assess their system as not high-risk skip EU database registration. That narrowing did not survive negotiation: the registration duty remains as broad as under the original Act.
AI literacy duty kept, made more flexible
The Article 4 AI-literacy obligation on organisations deploying AI systems is retained, but in a less prescriptive form than originally drafted, giving organisations more latitude in how they demonstrate compliance.
Bias-detection data use widened, but with a stricter test
The permission to process special-category personal data (health, biometric, racial or sexual-orientation data) to detect and correct bias, previously available only to high-risk AI, now extends to providers and deployers of any AI system. In exchange, the Omnibus reinstates a strict-necessity standard for that processing, tighter than the lower simple-necessity threshold the Commission had originally proposed.
Every AI system falls into one category. Classification drives your compliance obligations.
Prohibited
Banned outright. Includes AI used for social scoring by public authorities, real-time biometric surveillance in public spaces, subliminal manipulation causing harm, exploitation of vulnerable groups, and untargeted scraping of facial images for recognition databases.
High-risk
Listed in Annex III. Covers AI in: biometric identification, critical infrastructure, education and training, employment decisions, essential services access (credit, benefits), law enforcement, migration and border control, and judicial administration. Requires conformity assessment, technical documentation, human oversight, and EU database registration before deployment.
Limited-risk
Transparency obligations only. Chatbots must disclose they are AI. Deepfake and synthetic content must be labelled. Emotion recognition systems must notify users. No conformity assessment required.
Minimal-risk
The vast majority of AI systems. Spam filters, product recommendation engines, AI writing assistants, video game AI. No mandatory requirements under the Act. Voluntary codes of conduct apply.
Provider
Companies that develop, build, or place AI systems on the EU market.
Deployer
Companies that use AI systems built by others in the course of professional activities.
What is the EU AI Act?
The EU AI Act (Regulation EU 2024/1689) is the world's first comprehensive AI law. It classifies AI systems into four risk tiers, prohibited, high-risk, limited-risk, and minimal-risk, with obligations matched to risk level.
Has the EU AI Act been passed?
Yes. It was adopted by the European Parliament and Council, published in the Official Journal on 12 July 2024 as Regulation (EU) 2024/1689, and entered into force on 1 August 2024. Its obligations then apply on a phased timeline rather than all at once.
When does the EU AI Act apply?
Prohibited AI practices: 2 February 2025. GPAI model rules: 2 August 2025. Transparency obligations: 2 August 2026. High-risk AI (Annex III stand-alone): 2 December 2027. High-risk AI embedded in regulated products (Annex I): 2 August 2028. (High-risk deadlines postponed by the Digital Omnibus on AI, published in the Official Journal 24 July 2026 and in force from 27 July 2026, so these dates are now confirmed law rather than a pending agreement.)
Is the EU AI Act enforceable?
Yes. It is a Regulation, directly applicable in all EU member states without national implementing legislation, and it carries real penalties (up to 7% of global turnover for the most serious violations). National market surveillance authorities and, for GPAI models, the EU AI Office enforce it, and it already applies extraterritorially to non-EU providers whose AI affects people in the EU.
Does the EU AI Act apply outside the EU?
Yes. The Act applies to any organisation that places AI systems on the EU market or whose AI outputs affect people in the EU, regardless of where the organisation is based.
What is prohibited under the EU AI Act?
Since 2 February 2025: social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), subliminal or manipulative techniques that cause harm, exploitation of vulnerabilities (age, disability, socioeconomic situation), emotion recognition in the workplace and education, biometric categorisation inferring sensitive characteristics, and untargeted scraping of facial images to build recognition databases.
What are the penalties under the EU AI Act?
Up to €35 million or 7% of global turnover for prohibited AI; up to €15 million or 3% for other high-risk violations; up to €7.5 million or 1% for providing incorrect information.
What is high-risk AI under the EU AI Act?
High-risk AI is listed in Annex III. It includes AI in: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration control, and judicial administration.
Primary source: Regulation (EU) 2024/1689
View the readiness checklistThis page is general information about the EU AI Act, not legal advice, and does not capture every nuance, exception, or recent amendment. Always verify against the text of Regulation (EU) 2024/1689 and your own qualified legal counsel before relying on it.
Explainers on the EU AI Act risk tiers, timeline and extraterritorial reach, plus ISO 42001 and the NIST AI RMF.