AI governance
EU Artificial Intelligence Act
Published Reviewed
What is EU AI Act?
The EU AI Act assigns obligations by an organisation’s role and an AI system’s risk class, with phased rules for providers, deployers, importers and distributors.
| Jurisdiction | European Union |
|---|---|
| Authority | Regulation (EU) 2024/1689 |
| Current status | Entered into force 1 August 2024; phased application |
| Reviewed |
Why it matters operationally
The AI Act applies by role — provider, deployer, importer or distributor — and reaches organisations outside the EU whenever a system’s output is used inside it. Its obligations arrive in waves: prohibited practices apply from 2 February 2025, general-purpose AI duties from 2 August 2025, and transparency duties from 2 August 2026. The July 2026 AI Omnibus removed the former binding AI-literacy duty and extended the high-risk dates. For most organisations the practical work starts with an inventory question: which of your systems count as AI, in which role, at which risk class — few organisations can answer at first ask.
Are you aware?
The dates that bind
Prohibited practices bind first
Practices such as social scoring and untargeted facial-image scraping are banned. The July 2026 AI Omnibus replaced the former binding AI-literacy duty with non-binding encouragement.
General-purpose AI obligations follow
Providers of general-purpose models face transparency, copyright-policy and documentation duties, and the EU governance and penalty regime applies from the same date.
Transparency and GPAI enforcement
Article 50 transparency duties apply, and the Commission begins full enforcement of the general-purpose AI obligations that started applying in 2025.
Annex III high-risk rules apply
The high-risk rules begin for specified sensitive uses such as employment, education, biometrics, critical infrastructure, migration and justice.
Embedded high-risk systems follow
The extended transition ends for high-risk AI embedded in products governed by the EU product-safety legislation listed in Annex I.
Where to start
- 1
Inventory every AI system in use or development, recording the organisation’s role for each: provider, deployer, importer or distributor.
- 2
Screen the inventory against the prohibited-practice list and the Annex III high-risk categories — those two lists drive everything else.
- 3
For anything user-facing, plan the transparency duties now: people must know when they are interacting with AI or AI-generated content.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
Does the AI Act apply to companies outside the EU?
Yes — when they place AI systems on the EU market, or when the output of their system is used in the EU (Article 2). A provider anywhere in the world whose model serves EU users is in scope.
What are the penalty tiers?
Up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for most other violations; up to €7.5 million or 1% for supplying incorrect or misleading information to authorities.
We only use third-party AI tools — are we still in scope?
Deployers have their own duties: operating systems according to instructions, ensuring human oversight, checking input-data relevance, monitoring, and in some cases running a fundamental-rights impact assessment. Buying rather than building is a role, not an exemption.
Which systems count as high-risk?
Two routes: AI that is a safety component of products already regulated in Annex I, and the standalone Annex III use cases — employment and worker management, credit scoring, education, essential services and more. Classification depends on the actual use, not the marketing label.
Side by side
Compared against
Operational deep dives
Work through the decision, not just the definition.
Key terms in this guide
A quick self-check
Are you ready?
- Do you have a complete, dated inventory of the AI systems your organisation provides or deploys?
- Has each system been screened against the prohibited-practice list — a duty that became binding in February 2025?
- Can you name the risk class and your organisation’s role for every system on the list?
- Do staff have the competence, instructions and authority needed to operate and oversee the tools they use?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.