Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by the 2026 Digital Omnibus on AI.
Overview
The EU AI Act (Regulation 2024/1689) entered force on August 1, 2024 (the regulation was signed on July 12, 2024 and published in the Official Journal on July 12, 2024; it applies from 20 days after publication). It covers every organization — EU-based or not — that places AI systems on the EU market, uses AI professionally in the EU, or imports and distributes AI systems sold into EU member states.
Four risk tiers determine compliance obligations. Unacceptable-risk systems are banned outright (enforceable since February 2, 2025). High-risk systems listed in Annex I or Annex III must clear a conformity assessment, register in the EU AI database, and carry CE marking before going to market — most Annex III providers self-assess under Article 43, while biometric identification and certain critical infrastructure AI require third-party assessment under Annex VII procedures. Limited-risk systems — chatbots, emotion recognition tools, deepfake generators — must disclose their AI nature to users. Minimal-risk applications (spam filters, AI in video games, inventory tools) face no mandatory requirements.
Penalties follow the same four-tier logic: up to €35 million or 7% of global annual turnover for deploying prohibited AI (Article 99); €15 million or 3% for high-risk violations; €7.5 million or 1.5% for providing false or misleading information to authorities. SME penalties are capped at the lower applicable ceiling. National AI authorities handle enforcement; the European AI Office handles GPAI model oversight.
Important — read the 2026 Digital Omnibus Update before planning to any deadline. In May 2026 the EU institutions agreed targeted amendments that postpone the high-risk obligations, add a new prohibition on non-consensual intimate imagery and CSAM, and widen SME relief to mid-caps. The European Parliament approved the text on June 16, 2026; it awaits formal Council adoption and Official Journal publication.
2026 Digital Omnibus Update
The most significant 2026 development is the Digital Omnibus on AI, a Commission simplification package proposed on November 19, 2025. The co-legislators reached a provisional political agreement on May 7, 2026; Member State ambassadors (Coreper) approved it on May 13, 2026; and the European Parliament approved the text in plenary on June 16, 2026 (423 votes in favour, 57 against, 174 abstentions). The package still needs formal adoption by the Council and publication in the EU Official Journal before it becomes law. Publication is expected in July 2026, and the regulation enters into force three days after publication.
Until Official Journal publication, the new dates are not legally binding and the original August 2, 2026 high-risk deadline formally remains in effect. Both steps are expected to be completed before that date. The key changes are:
| Change | Detail |
|---|---|
| High-risk Annex III (stand-alone) deferred | Application date moves from 2 August 2026 to 2 December 2027 |
| High-risk Annex I (product-embedded) deferred | Application date moves from 2 August 2027 to 2 August 2028 |
| New Article 5 prohibition (NCII/CSAM) | Bans AI systems that generate or manipulate non-consensual intimate imagery ("nudifiers") and child sexual abuse material; transitional period to 2 December 2026 |
| AI-marking (Article 50(2)) grace period | Watermarking/machine-readable marking of AI-generated content is deferred to 2 December 2026 for systems placed on the market before 2 August 2026 |
| SME relief extended to mid-caps | Simplified documentation, proportionate penalties and sandbox access now reach small mid-cap companies (SMCs) — broadly up to 750 employees and €150M turnover |
| High-risk registration retained | Providers must still register high-risk systems in the EU database; those claiming the Article 6(3) exemption register with reduced information |
What the Omnibus did not change: the penalty tiers (€35M/7%, €15M/3%, €7.5M/1.5%), the GPAI model obligations (applicable since 2 August 2025), the 10^25 FLOP systemic-risk threshold, and the original list of prohibited practices (enforceable since 2 February 2025) all remain in force as written.
Risk Classification
Article 6 and Annex I–III define the classification. The EU does not self-certify risk tiers — providers use the criteria in the Act to determine their category, then proceed to the conformity assessment pathway that tier requires.
Tier 1 — Unacceptable Risk (Prohibited)
AI applications that pose an unacceptable risk to fundamental rights are banned outright. See the Prohibited AI Practices section below.
Tier 2 — High Risk
High-risk AI systems must meet extensive requirements before they can be placed on the EU market. There are two sub-categories:
Annex I — AI used as a safety component in products already governed by EU product safety legislation (medical devices, machinery, lifts, toys, aviation, automotive, etc.)
Annex III — Standalone high-risk AI systems in eight sensitive areas:
- Biometric identification and categorization
- Critical infrastructure management (energy, water, transport)
- Education — access to educational institutions, assessment of learners
- Employment — recruitment, selection, promotion, termination, task allocation
- Essential private and public services — creditworthiness, insurance risk assessment, social benefits
- Law enforcement — risk assessments, polygraphs, evidence reliability evaluation
- Migration, asylum, and border control — risk assessment, visa applications
- Administration of justice — AI assisting courts
Tier 3 — Limited Risk
AI systems that interact directly with humans (e.g., chatbots, deepfake generators) must disclose their AI nature. Emotion recognition and biometric categorization systems have additional transparency requirements.
Tier 4 — Minimal Risk
The vast majority of AI applications — spam filters, AI-powered video games, inventory management tools — fall here. There are no mandatory requirements, though providers are encouraged to adopt voluntary codes of conduct.
Prohibited AI Practices
The following eight AI applications are banned across all EU member states. Enforcement began February 2, 2025. National authorities can impose penalties of up to €35 million or 7% of global annual turnover per violation under Article 99(2).
-
Social scoring by public authorities — government systems that classify individuals based on behavior, social characteristics, or personality to assign scores affecting their access to services or benefits.
-
Real-time remote biometric identification (RBI) in public spaces — using live facial recognition or similar AI in publicly accessible areas for law enforcement purposes (with narrow exceptions for specific crimes and with judicial authorization).
-
Biometric categorization by protected characteristics — inferring race, political opinions, trade union membership, religious beliefs, or sexual orientation from biometrics.
-
Subliminal manipulation — AI that exploits unconscious vulnerabilities to manipulate behavior in ways that harm the person.
-
Exploitation of vulnerabilities — targeting AI specifically at vulnerable groups (children, people with disabilities) to distort behavior harmfully.
-
Untargeted facial scraping — mass harvesting of facial images from the internet or CCTV to build facial recognition databases.
-
Emotion recognition in workplaces and educational institutions — inferring employees' or students' emotional states through AI.
-
Predictive policing based solely on profiling — risk assessments for criminal behavior based purely on profiling without objective evidence of prior activity.
New prohibition added by the 2026 Digital Omnibus
The Digital Omnibus adds a ninth prohibition to Article 5 (not yet in force pending Official Journal publication):
- Non-consensual intimate imagery (NCII) and CSAM generation — AI systems that generate or manipulate non-consensual intimate images, video, or audio (so-called "nudifier" tools), or child sexual abuse material. The ban also reaches systems where such output is "a reasonably foreseeable and reproducible outcome." A transitional period applies until December 2, 2026.
High-Risk AI Requirements
Providers of high-risk AI systems listed in Annex III must meet all nine requirements below before placing the system on the EU market. This is a pre-market gate, not a post-deployment obligation — CE marking and EU AI database registration must be complete before first commercial sale.
Deadline note: Under the 2026 Digital Omnibus, these Annex III obligations now apply from December 2, 2027 (previously August 2, 2026), and Annex I product-embedded obligations from August 2, 2028 (previously August 2, 2027). See the 2026 Digital Omnibus Update.
1. Risk Management System
Implement and maintain a documented risk management system throughout the AI system's lifecycle, identifying and mitigating foreseeable risks.
2. Data Governance
Training, validation, and testing datasets must be subject to appropriate data governance practices, including examination for biases and relevance to the intended purpose.
3. Technical Documentation
Prepare comprehensive technical documentation before market placement, covering system design, development methodology, performance metrics, and known limitations.
4. Record-Keeping / Logging
High-risk AI systems must automatically log events ("traceability") sufficient to enable post-hoc auditing, including the period of operation and reference data inputs where relevant.
5. Transparency & Instructions for Use
Provide clear instructions for use to deployers, including the system's purpose, performance characteristics, circumstances that may lead to risks, and human oversight requirements.
6. Human Oversight
Design systems to allow natural persons to effectively oversee them, detect and address failures, and override, stop, or intervene in their operation.
7. Accuracy, Robustness & Cybersecurity
Meet appropriate levels of accuracy for the intended purpose, demonstrate robustness against errors and adversarial attacks, and implement cybersecurity measures.
8. Conformity Assessment
Before market placement, conduct a conformity assessment (self-assessment for most Annex III systems; third-party assessment for biometric identification and certain critical infrastructure AI) and draw up an EU Declaration of Conformity.
9. CE Marking & Registration
Affix CE marking and register the AI system in the EU-wide AI database operated by the European Commission. The 2026 Omnibus retains this registration duty; providers claiming the Article 6(3) exemption from high-risk classification must still register, with reduced information requirements.
Obligations for Deployers
Organizations using high-risk AI (deployers) must:
- Use the system in accordance with the provider's instructions for use
- Assign human oversight to competent individuals
- Monitor operation for unexpected risks
- Keep logs for at least 6 months (or longer per sectoral law)
- Conduct a Fundamental Rights Impact Assessment (FRIA) for public bodies and private entities providing regulated services
General Purpose AI Models
The EU AI Act adds a separate compliance track for General Purpose AI (GPAI) models — large foundation models capable of powering multiple downstream applications. The GPAI provisions took effect August 2, 2025 and were not changed by the 2026 Digital Omnibus.
Every GPAI provider, regardless of model size, must:
- Maintain and update technical documentation describing the model's training approach, architecture, capabilities, and known limitations
- Share documentation with downstream providers who integrate the model into their own systems
- Comply with EU copyright law and publish summaries of training data used
- Comply with the EU AI Code of Practice (or demonstrate equivalent compliance directly)
GPAI Models with Systemic Risk
GPAI models trained using more than 10^25 FLOPs of compute are presumed to carry systemic risk under Article 51. This threshold currently captures models comparable in scale to GPT-4, Gemini Ultra, and Claude 3 Opus — training runs costing roughly $50–100 million or more.
Providers of systemic-risk GPAI models face five additional requirements under Article 55:
- Adversarial testing (red-teaming) before each major release, with documented findings
- Incident reporting to the European AI Office for serious incidents, within defined timeframes
- Cybersecurity protections appropriate to the model's capabilities and deployment context
- Energy consumption reporting covering training and inference
- Cooperation with the European AI Office during ongoing evaluations and investigations
Providers can rebut the 10^25 FLOPs presumption by demonstrating the model does not in fact pose systemic risks, but the burden of proof rests with the provider.
Compliance Timeline
The table below reflects the deadlines as amended by the 2026 Digital Omnibus. The new high-risk dates become legally binding on Official Journal publication (expected July 2026); the original dates are shown for reference.
| Date | Milestone |
|---|---|
| July 12, 2024 | EU AI Act published in the Official Journal |
| August 1, 2024 | Act enters into force (20 days after publication) |
| February 2, 2025 | Prohibited AI provisions enforceable |
| August 2, 2025 | GPAI model obligations and governance provisions apply |
| December 2, 2026 | NCII/CSAM prohibition transitional period ends; Article 50(2) AI-marking grace period ends for systems on market before Aug 2, 2026 (per Digital Omnibus) |
| December 2, 2027 | High-risk AI (Annex III, stand-alone) requirements enforceable — deferred from the original August 2, 2026 date |
| August 2, 2028 | High-risk AI (Annex I, product safety integrated) requirements enforceable — deferred from the original August 2, 2027 date |
Legacy systems: The original Act gave high-risk systems already on the market a transitional runway tied to the August 2026 application date. Because the high-risk application dates themselves have moved, these legacy and transitional reference points are being re-anchored in the amending regulation. Treat the precise legacy cut-offs as provisional until the Digital Omnibus is published in the Official Journal.
Penalties & Enforcement
The EU AI Act establishes a tiered penalty structure (unchanged by the 2026 Digital Omnibus):
| Violation | Maximum Fine |
|---|---|
| Prohibited AI practices (Tier 1) | €35 million or 7% of global annual turnover |
| High-risk AI obligations (Tier 2) | €15 million or 3% of global annual turnover |
| Providing incorrect/misleading information to authorities | €7.5 million or 1.5% of global annual turnover |
SME / mid-cap cap: For small and medium enterprises — and, under the Digital Omnibus, small mid-cap companies (SMCs) — fines are capped at the lower of the applicable amounts and applied proportionately.
Who Enforces?
- Member State authorities: Each EU country must designate a National Competent Authority (NCA) to supervise market operators.
- European AI Office: Supervises GPAI model providers directly and coordinates cross-border enforcement. The Digital Omnibus strengthens the Office's role, giving it exclusive competence over AI systems built on GPAI models where the model and the system come from the same provider, plus powers to investigate, conduct on-site inspections, accept binding commitments, and impose fines.
- Market Surveillance Authorities: Existing product safety authorities enforce compliance for AI integrated into regulated products.
Compliance Steps
Follow this roadmap to prepare for EU AI Act compliance:
-
Inventory your AI systems. Catalog all AI systems your organization develops, deploys, or uses in a professional context affecting EU residents.
-
Classify each system by risk tier. Determine if each system falls under prohibited, high-risk, limited-risk, or minimal-risk categories using Annexes I and III.
-
Check if any systems are prohibited. If you run social scoring, mass facial scraping, or real-time RBI systems, you must cease operation (these have been banned since February 2, 2025). If you operate "nudifier"/NCII or CSAM-generating systems, the new Article 5 prohibition gives a transitional window only until December 2, 2026.
-
For high-risk AI (Annex III):
- Build a risk management system with documented procedures
- Review training data governance practices
- Prepare technical documentation
- Implement logging and human oversight mechanisms
- Conduct conformity assessment
- Register in the EU AI database
- Plan to the new December 2, 2027 application date — but track the Official Journal publication, since the original August 2, 2026 date stands until the Omnibus is published.
-
For GPAI models:
- Evaluate whether your model exceeds the 10^25 FLOP threshold (systemic risk)
- Prepare technical documentation and training data summaries
- Engage with the EU AI Code of Practice process
-
For limited-risk AI:
- Implement required transparency notices (chatbots must disclose their AI nature; deepfakes must be labeled). Note the Article 50(2) machine-readable marking obligation carries a grace period to December 2, 2026 for systems already on the market before August 2, 2026.
-
Appoint an EU representative if your organization is established outside the EU and places high-risk AI on the EU market.
-
Engage with regulatory sandboxes if you are an SME or small mid-cap — member states are required to make these available, and the Digital Omnibus extends SME-style relief to SMCs (broadly, up to 750 employees and €150M turnover).
Frequently Asked Questions
Does the EU AI Act apply to non-EU companies? Yes. If your AI system is placed on the EU market, used in the EU, or its outputs affect EU residents, you must comply — regardless of where your company is headquartered.
What are the highest penalties? Up to €35 million or 7% of global annual turnover for prohibited AI violations. High-risk AI requirement violations: up to €15 million or 3% of global turnover. The 2026 Digital Omnibus left these tiers unchanged.
What is a GPAI model? A general-purpose AI model capable of serving many different downstream tasks, typically a large language model. Models exceeding 10^25 FLOPs of training compute face additional systemic-risk obligations.
When do high-risk AI requirements become enforceable? Under the 2026 Digital Omnibus, stand-alone Annex III systems apply from December 2, 2027 and product-embedded Annex I systems from August 2, 2028 — replacing the original August 2, 2026 and August 2, 2027 dates. The new dates bind once the amending regulation is published in the Official Journal (expected July 2026); until then the August 2, 2026 date formally stands. Prohibited AI has been enforceable since February 2025.
Do I need a third-party assessment for all high-risk AI? No — most Annex III systems can self-certify. Third-party notified body assessment is required only for real-time remote biometric identification and certain critical infrastructure AI.
What is the EU AI Office? The European AI Office is a body within the European Commission responsible for directly supervising GPAI model providers, coordinating national enforcement, and developing standardization. The Digital Omnibus expands its enforcement powers and gives it exclusive competence over AI systems built on a provider's own GPAI model.
Are open-source AI models exempt? GPAI models released under a free and open-source license are largely exempt from technical documentation and information-sharing requirements — unless they pose systemic risk (>10^25 FLOPs).
Official Sources
Get weekly regulation updates, enforcement news, and compliance deadlines — free.