AI governance

EU Artificial Intelligence Act

Regulation (EU) 2024/1689 European Union Entered into force 1 August 2024; phased application

Published Reviewed

What is EU AI Act?

The EU AI Act assigns obligations by an organisation’s role and an AI system’s risk class, with phased rules for providers, deployers, importers and distributors.

At a glance
JurisdictionEuropean Union
AuthorityRegulation (EU) 2024/1689
Current statusEntered into force 1 August 2024; phased application
Reviewed

Why it matters operationally

The AI Act applies by role — provider, deployer, importer or distributor — and reaches organisations outside the EU whenever a system’s output is used inside it. Its obligations arrive in waves: prohibited practices apply from 2 February 2025, general-purpose AI duties from 2 August 2025, and transparency duties from 2 August 2026. The July 2026 AI Omnibus removed the former binding AI-literacy duty and extended the high-risk dates. For most organisations the practical work starts with an inventory question: which of your systems count as AI, in which role, at which risk class — few organisations can answer at first ask.

Are you aware?

The dates that bind

2 Feb 2025

Prohibited practices bind first

Practices such as social scoring and untargeted facial-image scraping are banned. The July 2026 AI Omnibus replaced the former binding AI-literacy duty with non-binding encouragement.

2 Aug 2025

General-purpose AI obligations follow

Providers of general-purpose models face transparency, copyright-policy and documentation duties, and the EU governance and penalty regime applies from the same date.

2 Aug 2026

Transparency and GPAI enforcement

Article 50 transparency duties apply, and the Commission begins full enforcement of the general-purpose AI obligations that started applying in 2025.

2 Dec 2027

Annex III high-risk rules apply

The high-risk rules begin for specified sensitive uses such as employment, education, biometrics, critical infrastructure, migration and justice.

2 Aug 2028

Embedded high-risk systems follow

The extended transition ends for high-risk AI embedded in products governed by the EU product-safety legislation listed in Annex I.

Where to start

  1. 1

    Inventory every AI system in use or development, recording the organisation’s role for each: provider, deployer, importer or distributor.

  2. 2

    Screen the inventory against the prohibited-practice list and the Annex III high-risk categories — those two lists drive everything else.

  3. 3

    For anything user-facing, plan the transparency duties now: people must know when they are interacting with AI or AI-generated content.

Authority links

Read the official sources

The official text is the authority. This guide is only a short orientation for operational planning.

Common questions

Frequently asked questions

Does the AI Act apply to companies outside the EU?

Yes — when they place AI systems on the EU market, or when the output of their system is used in the EU (Article 2). A provider anywhere in the world whose model serves EU users is in scope.

What are the penalty tiers?

Up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for most other violations; up to €7.5 million or 1% for supplying incorrect or misleading information to authorities.

We only use third-party AI tools — are we still in scope?

Deployers have their own duties: operating systems according to instructions, ensuring human oversight, checking input-data relevance, monitoring, and in some cases running a fundamental-rights impact assessment. Buying rather than building is a role, not an exemption.

Which systems count as high-risk?

Two routes: AI that is a safety component of products already regulated in Annex I, and the standalone Annex III use cases — employment and worker management, credit scoring, education, essential services and more. Classification depends on the actual use, not the marketing label.

Side by side

Operational deep dives

Work through the decision, not just the definition.

Key terms in this guide

A quick self-check

Are you ready?

  • Do you have a complete, dated inventory of the AI systems your organisation provides or deploys?
  • Has each system been screened against the prohibited-practice list — a duty that became binding in February 2025?
  • Can you name the risk class and your organisation’s role for every system on the list?
  • Do staff have the competence, instructions and authority needed to operate and oversee the tools they use?

Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.

This guide is general information about public law, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official source and seek qualified advice where needed.