AI regulation

    What Is the EU AI Act?

    A current guide to the Act's scope, risk-based rules, Article 50 transparency duties, penalties, and revised 2026–2028 timeline.

    Reviewed August 2026
    10 min read
    Quick answer

    Quick answer

    The EU AI Act is a risk-based legal framework for AI. It regulates actors according to their role—such as provider, deployer, importer, distributor, or GPAI-model provider—and imposes different rules for prohibited practices, high-risk systems, transparency-specific uses, and general-purpose AI. It can also apply to organizations outside the EU in defined circumstances.

    Entered into force
    1 August 2024
    Article 50
    Applies from 2 August 2026
    Maximum fine tier
    €35M or 7% of turnover

    EU AI Act definition

    The European Union Artificial Intelligence Act is the EU's comprehensive, risk-based framework for artificial intelligence. The regulation entered into force on August 1, 2024, then began applying in stages rather than all at once.

    The Act does not assign one universal checklist to every AI product. Duties depend on what the system does, the role an organization plays, where the system or model is placed or used, and whether a prohibition, high-risk classification, transparency rule, or GPAI obligation applies.

    Who can fall within its scope?

    The Act distinguishes among several actors. A business should identify its role for each system or model before deciding which obligations apply.

    Providers

    Develop an AI system or GPAI model, or have one developed, and place it on the market or put it into service under their name.

    Deployers

    Use an AI system under their authority in a professional context, subject to the Act's exclusions and definitions.

    Importers and distributors

    Bring covered systems into the EU market or make them available through the supply chain.

    Some non-EU actors

    Can be covered when placing systems or models on the EU market, putting systems into service in the EU, or where covered output is used in the EU.

    Simply having a website accessible in Europe does not, by itself, answer the scope question. The product, role, market activity, place of use, and contractual chain all matter.

    How the risk-based framework works

    The familiar “four risk levels” shorthand is useful for orientation, but the legal analysis is more precise: first test for prohibited practices, then high-risk classifications and any role-specific obligations, and separately check transparency and GPAI rules.

    Prohibited practices

    Uses the Act bans outright, subject to its definitions and limited exceptions.

    • Certain manipulative or exploitative techniques
    • Certain social-scoring practices
    • Certain real-time remote biometric identification uses

    High-risk AI systems

    Systems covered by Annex I or Annex III can face requirements across risk management, data, documentation, oversight, accuracy, and monitoring.

    • Some employment and worker-management uses
    • Some education, credit, essential-service, and law-enforcement uses
    • Safety components in certain regulated products

    Transparency-specific uses

    Article 50 creates targeted notice, labeling, and machine-readable-marking duties for defined AI interactions and synthetic content.

    • Some direct human interaction with AI
    • Deepfakes and certain public-interest text
    • Emotion recognition and biometric categorization

    Other AI systems

    Many AI uses do not fall into the Act's prohibited or high-risk categories, but other duties and laws can still apply.

    • Risk classification still needs to be documented
    • AI-literacy duties can still be relevant
    • Privacy, consumer, copyright, and sector rules remain separate

    What high-risk systems may need

    When a system is high-risk under the Act, the provider's obligations can include a documented risk-management system, data-governance measures, technical documentation, logging, instructions for deployers, human-oversight design, and standards for accuracy, robustness, and cybersecurity.

    Risk management throughout the lifecycle
    Data and data-governance controls
    Technical documentation and record keeping
    Human oversight and deployer instructions
    Accuracy, robustness, and cybersecurity
    Quality management and post-market monitoring

    Deployers, importers, distributors, and product manufacturers can have their own duties. A provider checklist should not be copied onto every actor without checking the relevant role.

    Article 50 transparency obligations

    Article 50 has applied since August 2, 2026. It contains targeted rules, not a blanket instruction to place the same “AI-generated” label on every use of AI.

    Direct AI interaction

    Providers of certain systems intended to interact directly with people must ensure people are informed that they are interacting with AI, unless that is obvious in context.

    Synthetic outputs

    Providers of systems that generate synthetic audio, image, video, or text must support machine-readable marking and detection, subject to the Act's scope and exceptions.

    Deepfakes and public-interest text

    Deployers can have disclosure duties for deepfakes and certain AI-generated or manipulated text published to inform the public, with defined exceptions.

    Emotion and biometric systems

    Deployers of emotion-recognition or biometric-categorization systems must inform exposed people, subject to applicable law and exceptions.

    The disclosure should be clear, distinguishable, and timely. A website disclaimer may be useful context, but it may not replace a required in-interface notice, post label, or machine-readable marking.

    Document your AI use

    Create a clear AI-use disclaimer

    Describe how your organization uses AI and generate an editable starting point for reader-facing disclosures. The result is a template to review—not a substitute for classifying your duties under the Act.

    • Tailored to your answers
    • Editable before publishing
    • Free account available

    General-purpose AI obligations

    Providers of general-purpose AI models have a separate obligation set. It includes technical documentation, information for downstream providers, a copyright-law compliance policy, and a sufficiently detailed public summary of training content. Providers of GPAI models with systemic risk have additional evaluation, systemic-risk mitigation, serious-incident reporting, and cybersecurity duties.

    Current implementation timeline

    The EU changed important dates through the AI Omnibus adopted in June 2026. The high-risk timeline below replaces the earlier assumption that those rules were fully applicable in August 2026.

    1. 2 February 2025

      Applies now

      Prohibitions and AI literacy

      Rules on prohibited AI practices and the Article 4 AI-literacy duty began applying.

    2. 2 August 2025

      Applies now

      General-purpose AI

      GPAI obligations and several governance provisions began applying, with transition rules for models already on the market.

    3. 2 August 2026

      Applies now

      Article 50 transparency

      Transparency duties for defined AI interactions and synthetic content began applying. Some pre-existing systems have a transition period for marking and detection duties.

    4. 2 December 2027

      Upcoming

      Many high-risk-system rules

      Following the 2026 AI Omnibus, the main high-risk-system obligations apply on this later date.

    5. 2 August 2028

      Upcoming

      High-risk AI in regulated products

      The later date applies to high-risk AI systems that are safety components of, or themselves are, certain regulated products.

    Penalties

    Maximum administrative fines depend on the violation. These are ceilings, not automatic penalties, and authorities consider the facts of the case.

    €35M or 7%

    Certain prohibited-practice or data-related violations

    €15M or 3%

    Other obligations under the Act

    €7.5M or 1%

    Incorrect, incomplete, or misleading information

    The percentage refers to worldwide annual turnover in the preceding financial year. For undertakings, the higher of the fixed or percentage amount can apply; for SMEs, including startups, each fine must not exceed the lower percentage or fixed amount for the relevant tier.

    A practical first-pass checklist

    1. Inventory AI systems and models, including third-party tools embedded in workflows.
    2. Map your role for each one: provider, deployer, importer, distributor, product manufacturer, or GPAI provider.
    3. Test territorial scope and document why the Act does or does not apply.
    4. Screen for prohibited practices before moving to risk classification.
    5. Assess high-risk and transparency categories using the actual use case, not the product's marketing label.
    6. Identify separate legal duties under privacy, consumer, employment, copyright, and sector-specific law.
    7. Assign owners and evidence for notices, documentation, monitoring, and staff AI literacy.

    Frequently asked questions

    What is the EU AI Act?

    The EU AI Act is the European Union's risk-based legal framework for artificial intelligence. It regulates different AI uses according to their role and risk, from prohibited practices to transparency, general-purpose AI, and high-risk-system obligations.

    Does the EU AI Act apply to companies outside the EU?

    It can. The Act covers public and private actors inside and outside the EU when they place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, or use an AI system in the EU. Applicability depends on the actor's role and the specific facts.

    When do the EU AI Act rules apply?

    The rules phase in. Prohibited practices and AI-literacy duties have applied since February 2, 2025; general-purpose AI obligations since August 2, 2025; and Article 50 transparency duties since August 2, 2026. Following the 2026 AI Omnibus, key high-risk-system rules apply from December 2, 2027, or August 2, 2028 for high-risk AI embedded in regulated products.

    Does every piece of AI-generated content need an EU AI Act label?

    No. Article 50 contains specific duties for providers and deployers, including notices when people interact directly with certain AI systems, machine-readable marking of synthetic content, and disclosures for deepfakes and certain public-interest text. The exact duty, format, timing, and exceptions depend on the use case.

    What are the maximum EU AI Act fines?

    The highest tier is up to €35 million or 7% of worldwide annual turnover for certain prohibited-practice or data-related violations. Other tiers include up to €15 million or 3%, and up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information. The calculation differs for smaller businesses.

    Official sources

    This guide was reviewed against European Commission materials on August 11, 2026. Check the official text and current guidance for your specific role and use case.