What Is the EU AI Act?
A current guide to the Act's scope, risk-based rules, Article 50 transparency duties, penalties, and revised 2026–2028 timeline.
Quick answer
The EU AI Act is a risk-based legal framework for AI. It regulates actors according to their role—such as provider, deployer, importer, distributor, or GPAI-model provider—and imposes different rules for prohibited practices, high-risk systems, transparency-specific uses, and general-purpose AI. It can also apply to organizations outside the EU in defined circumstances.
- Entered into force
- 1 August 2024
- Article 50
- Applies from 2 August 2026
- Maximum fine tier
- €35M or 7% of turnover
Reviewed against official sources on August 11, 2026. This guide is general information, not legal advice.
EU AI Act definition
The European Union Artificial Intelligence Act is the EU's comprehensive, risk-based framework for artificial intelligence. The regulation entered into force on August 1, 2024, then began applying in stages rather than all at once.
The Act does not assign one universal checklist to every AI product. Duties depend on what the system does, the role an organization plays, where the system or model is placed or used, and whether a prohibition, high-risk classification, transparency rule, or GPAI obligation applies.
Who can fall within its scope?
The Act distinguishes among several actors. A business should identify its role for each system or model before deciding which obligations apply.
Providers
Develop an AI system or GPAI model, or have one developed, and place it on the market or put it into service under their name.
Deployers
Use an AI system under their authority in a professional context, subject to the Act's exclusions and definitions.
Importers and distributors
Bring covered systems into the EU market or make them available through the supply chain.
Some non-EU actors
Can be covered when placing systems or models on the EU market, putting systems into service in the EU, or where covered output is used in the EU.
Simply having a website accessible in Europe does not, by itself, answer the scope question. The product, role, market activity, place of use, and contractual chain all matter.
How the risk-based framework works
The familiar “four risk levels” shorthand is useful for orientation, but the legal analysis is more precise: first test for prohibited practices, then high-risk classifications and any role-specific obligations, and separately check transparency and GPAI rules.
Prohibited practices
Uses the Act bans outright, subject to its definitions and limited exceptions.
- • Certain manipulative or exploitative techniques
- • Certain social-scoring practices
- • Certain real-time remote biometric identification uses
High-risk AI systems
Systems covered by Annex I or Annex III can face requirements across risk management, data, documentation, oversight, accuracy, and monitoring.
- • Some employment and worker-management uses
- • Some education, credit, essential-service, and law-enforcement uses
- • Safety components in certain regulated products
Transparency-specific uses
Article 50 creates targeted notice, labeling, and machine-readable-marking duties for defined AI interactions and synthetic content.
- • Some direct human interaction with AI
- • Deepfakes and certain public-interest text
- • Emotion recognition and biometric categorization
Other AI systems
Many AI uses do not fall into the Act's prohibited or high-risk categories, but other duties and laws can still apply.
- • Risk classification still needs to be documented
- • AI-literacy duties can still be relevant
- • Privacy, consumer, copyright, and sector rules remain separate
What high-risk systems may need
When a system is high-risk under the Act, the provider's obligations can include a documented risk-management system, data-governance measures, technical documentation, logging, instructions for deployers, human-oversight design, and standards for accuracy, robustness, and cybersecurity.
Deployers, importers, distributors, and product manufacturers can have their own duties. A provider checklist should not be copied onto every actor without checking the relevant role.
Article 50 transparency obligations
Article 50 has applied since August 2, 2026. It contains targeted rules, not a blanket instruction to place the same “AI-generated” label on every use of AI.
Direct AI interaction
Providers of certain systems intended to interact directly with people must ensure people are informed that they are interacting with AI, unless that is obvious in context.
Synthetic outputs
Providers of systems that generate synthetic audio, image, video, or text must support machine-readable marking and detection, subject to the Act's scope and exceptions.
Deepfakes and public-interest text
Deployers can have disclosure duties for deepfakes and certain AI-generated or manipulated text published to inform the public, with defined exceptions.
Emotion and biometric systems
Deployers of emotion-recognition or biometric-categorization systems must inform exposed people, subject to applicable law and exceptions.
The disclosure should be clear, distinguishable, and timely. A website disclaimer may be useful context, but it may not replace a required in-interface notice, post label, or machine-readable marking.
Document your AI use
Create a clear AI-use disclaimer
Describe how your organization uses AI and generate an editable starting point for reader-facing disclosures. The result is a template to review—not a substitute for classifying your duties under the Act.
- Tailored to your answers
- Editable before publishing
- Free account available
General-purpose AI obligations
Providers of general-purpose AI models have a separate obligation set. It includes technical documentation, information for downstream providers, a copyright-law compliance policy, and a sufficiently detailed public summary of training content. Providers of GPAI models with systemic risk have additional evaluation, systemic-risk mitigation, serious-incident reporting, and cybersecurity duties.
Current implementation timeline
The EU changed important dates through the AI Omnibus adopted in June 2026. The high-risk timeline below replaces the earlier assumption that those rules were fully applicable in August 2026.
2 February 2025
Applies nowProhibitions and AI literacy
Rules on prohibited AI practices and the Article 4 AI-literacy duty began applying.
2 August 2025
Applies nowGeneral-purpose AI
GPAI obligations and several governance provisions began applying, with transition rules for models already on the market.
2 August 2026
Applies nowArticle 50 transparency
Transparency duties for defined AI interactions and synthetic content began applying. Some pre-existing systems have a transition period for marking and detection duties.
2 December 2027
UpcomingMany high-risk-system rules
Following the 2026 AI Omnibus, the main high-risk-system obligations apply on this later date.
2 August 2028
UpcomingHigh-risk AI in regulated products
The later date applies to high-risk AI systems that are safety components of, or themselves are, certain regulated products.
Penalties
Maximum administrative fines depend on the violation. These are ceilings, not automatic penalties, and authorities consider the facts of the case.
€35M or 7%
Certain prohibited-practice or data-related violations
€15M or 3%
Other obligations under the Act
€7.5M or 1%
Incorrect, incomplete, or misleading information
The percentage refers to worldwide annual turnover in the preceding financial year. For undertakings, the higher of the fixed or percentage amount can apply; for SMEs, including startups, each fine must not exceed the lower percentage or fixed amount for the relevant tier.
A practical first-pass checklist
- Inventory AI systems and models, including third-party tools embedded in workflows.
- Map your role for each one: provider, deployer, importer, distributor, product manufacturer, or GPAI provider.
- Test territorial scope and document why the Act does or does not apply.
- Screen for prohibited practices before moving to risk classification.
- Assess high-risk and transparency categories using the actual use case, not the product's marketing label.
- Identify separate legal duties under privacy, consumer, employment, copyright, and sector-specific law.
- Assign owners and evidence for notices, documentation, monitoring, and staff AI literacy.
Frequently asked questions
What is the EU AI Act?
The EU AI Act is the European Union's risk-based legal framework for artificial intelligence. It regulates different AI uses according to their role and risk, from prohibited practices to transparency, general-purpose AI, and high-risk-system obligations.
Does the EU AI Act apply to companies outside the EU?
It can. The Act covers public and private actors inside and outside the EU when they place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, or use an AI system in the EU. Applicability depends on the actor's role and the specific facts.
When do the EU AI Act rules apply?
The rules phase in. Prohibited practices and AI-literacy duties have applied since February 2, 2025; general-purpose AI obligations since August 2, 2025; and Article 50 transparency duties since August 2, 2026. Following the 2026 AI Omnibus, key high-risk-system rules apply from December 2, 2027, or August 2, 2028 for high-risk AI embedded in regulated products.
Does every piece of AI-generated content need an EU AI Act label?
No. Article 50 contains specific duties for providers and deployers, including notices when people interact directly with certain AI systems, machine-readable marking of synthetic content, and disclosures for deepfakes and certain public-interest text. The exact duty, format, timing, and exceptions depend on the use case.
What are the maximum EU AI Act fines?
The highest tier is up to €35 million or 7% of worldwide annual turnover for certain prohibited-practice or data-related violations. Other tiers include up to €15 million or 3%, and up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information. The calculation differs for smaller businesses.
Official sources
This guide was reviewed against European Commission materials on August 11, 2026. Check the official text and current guidance for your specific role and use case.