Regulationfaqeu-ai-actcompliance

EU AI Act FAQ: Answers to 30+ Common Questions

Practical answers to the most common EU AI Act questions — scope, timelines, fines, classification, GPAI, GDPR overlap, and what companies need to do to comply with Regulation 2024/1689.

May 12, 2026Updated August 4, 202619 min read

The EU AI Act (Regulation 2024/1689) is the most comprehensive AI law in the world, and it raises a lot of practical questions for the companies that have to comply with it. This FAQ collects the most frequently asked questions about the regulation — from basic scope and timelines to specific obligations for providers, deployers, and general-purpose AI model developers — and gives concise, citation-backed answers.

If you need deeper material on a topic, every answer links to a dedicated article.

What Changed in July 2026

Regulation (EU) 2026/1744 of 8 July 2026 (the "Digital Omnibus on AI") was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is the first amendment to the AI Act, and it moves three dates:

  • Standalone high-risk systems under Article 6(2) and Annex III: from 2 August 2026 to 2 December 2027
  • High-risk systems that are safety components of products under Article 6(1) and Annex I: from 2 August 2027 to 2 August 2028
  • National regulatory sandboxes under Article 57: from 2 August 2026 to 2 August 2027

The deferral is unconditional. The Commission's original proposal would have tied the new dates to a decision confirming that harmonised standards were available — a "stop-the-clock" trigger — but the co-legislators dropped it. There is no standards-readiness condition in the adopted text and no further automatic delay.

Just as important is what did not move. 2 August 2026 remained the general application date, and the AI Office and national authorities began enforcing the regulation on that date. The AI Act was not delayed; the deferral is confined to Chapter III, Sections 1 to 3, and to Article 57. The Article 50 transparency obligations are in force now — chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content are live and enforceable — and Article 49 registration and the Article 5 prohibitions are equally unaffected.

Two further changes matter below. Two new prohibitions were added to Article 5, covering non-consensual intimate imagery (Article 5(1)(ba)) and child sexual abuse material (Article 5(1)(bb)); both apply from 2 December 2026. The new Article 111(4) gives generative AI systems placed on the market before 2 August 2026 until that same date to meet the Article 50(2) marking duty.

Scope and Applicability

Does the EU AI Act apply to my company?

Almost certainly yes if any of the following is true:

  • You place an AI system on the EU market, regardless of where you are established (Article 2(1)(a))
  • You put an AI system into service in the EU (Article 2(1)(a))
  • You are a deployer of an AI system established or located in the EU (Article 2(1)(b))
  • You are a provider or deployer outside the EU whose AI system's output is used in the EU (Article 2(1)(c))
  • You are an importer or distributor of AI systems that end up on the EU market (Article 2(1)(d))
  • You are a product manufacturer placing an AI system on the market or putting it into service together with your product and under your own name or trademark (Article 2(1)(e))

The "output used in the EU" trigger is broad. A US company running an AI hiring tool that screens candidates in Germany falls within the regulation even if it has no EU office.

Are there any exemptions from the EU AI Act?

Article 2 lists several specific exemptions:

  • National security and defence: AI systems used exclusively for military, defence, or national-security purposes are excluded (Article 2(3))
  • Scientific research and development: AI systems and AI models specifically developed and put into service for the sole purpose of scientific research and development are excluded outright (Article 2(6))
  • Pre-market research, testing and development: research, testing and development activity on AI systems or models before they are placed on the market or put into service is excluded, but the exclusion does not cover testing in real world conditions (Article 2(8))
  • Personal non-professional activities: AI used by individuals for purely personal activities is excluded (Article 2(10))
  • Free and open-source AI components: AI components released under free and open-source licences are partially exempt, except when they are placed on the market or put into service as high-risk systems, prohibited practices, or limited-risk systems with transparency obligations (Article 2(12))

There is no exemption for small companies. SMEs and startups are fully subject to the regulation, although Article 99(6) provides that the lower of two fine amounts (absolute or percentage) applies to them.

Does the EU AI Act apply to AI systems that were already on the market before it started to apply?

Mostly yes, but with transitional periods:

  • GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to comply (Article 111(3))
  • High-risk AI systems placed on the market before 2 August 2026 generally do not have to comply with the regulation, unless they undergo significant changes in their design after that date (Article 111(2))
  • Operators of high-risk AI systems intended for use by public authorities must bring legacy systems into compliance by 2 August 2030 (Article 111(2))
  • AI systems that are components of the large-scale EU IT systems listed in Annex X placed on the market or put into service before 2 August 2027 must be brought into compliance by 31 December 2030 (Article 111(1) — this provision was not realigned when the high-risk dates moved, so it still refers to 2 August 2027)
  • Generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2), under the grace period added by Article 111(4)

In practice, organisations should not rely on grandfathering. Most legacy systems are updated frequently enough that they will trigger compliance obligations at some point.

Timelines and Deadlines

When does the EU AI Act take effect?

The regulation follows a phased timeline:

  • 1 August 2024: Entry into force
  • 2 February 2025: Prohibitions on unacceptable-risk practices apply
  • 2 August 2025: GPAI obligations, governance provisions, and penalty provisions apply
  • 2 August 2026: General application. Enforcement begins, and the transparency obligations in Article 50 and the Article 49 registration duty take effect
  • 2 December 2026: The two new Article 5 prohibitions apply, and the Article 111(4) grace period for machine-readable marking of pre-existing generative AI systems ends
  • 2 August 2027: National regulatory sandboxes must be operational under Article 57, and GPAI models placed on the market before 2 August 2025 must be compliant
  • 2 December 2027: Standalone high-risk AI system requirements under Annex III apply
  • 2 August 2028: High-risk systems that are safety components of products under Annex I apply
  • 2 August 2030: Legacy high-risk systems used by public authorities must be compliant

Was the EU AI Act delayed?

Only in part, and the distinction matters. Regulation (EU) 2026/1744 deferred the core high-risk regime in Chapter III, Sections 1 to 3, and pushed the sandbox deadline back by a year. It did not touch the general application date of 2 August 2026, which held, and it did not touch Article 5, Article 49 or Article 50. Saying "the AI Act was delayed" is wrong: the regulation is being enforced now, and only the high-risk requirements and sandboxes moved.

How much time do I have left to prepare?

That depends on which obligation you mean. Some are already live. The Article 5 prohibitions have been enforceable since February 2025, GPAI obligations since August 2025, and Article 50 transparency, Article 49 registration and the rest of the general regime since 2 August 2026. For those, the deadline is behind you and you are exposed to enforcement rather than working towards a target.

For the high-risk regime the picture changed in July 2026. Standalone Annex III systems now have until 2 December 2027, roughly sixteen months away, and Annex I product systems until 2 August 2028. A minimum-viable compliance programme — risk management, technical documentation, data governance, human oversight design, conformity assessment — takes most organisations six to twelve months to set up, so the extra time is useful but not generous, particularly while no harmonised standard has yet been cited in the Official Journal to confer a presumption of conformity.

If you have not yet started, prioritise: (1) inventorying your AI systems, (2) classifying each one, (3) addressing any prohibited practices and any live Article 50 transparency gaps immediately, and (4) building a compliance roadmap towards December 2027. The compliance checklist for CTOs and CIOs provides a practical starting point.

Risk Classification

How do I know if my AI system is high-risk?

A system is high-risk if it meets either of two tests:

  1. Annex I test: The system is a safety component of, or itself constitutes, a product covered by Union harmonisation legislation listed in Annex I (medical devices, machinery, toys, automotive, aviation, marine, etc.) and that product is required to undergo a third-party conformity assessment.

  2. Annex III test: The system is a standalone AI system used in one of eight sensitive areas: biometrics; critical infrastructure; education and vocational training; employment, workers management, and access to self-employment; access to essential private and public services; law enforcement; migration, asylum, and border control; or administration of justice and democratic processes.

Article 6(3) introduced an important carve-out: even if a system would otherwise qualify under Annex III, it is not high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons and one of four conditions is met. Those conditions are that the system performs a narrow procedural task; improves the result of a previously completed human activity; detects decision-making patterns or deviations from prior decision-making patterns without replacing or influencing the previously completed human assessment; or performs a preparatory task to an assessment relevant to an Annex III use case.

Two limits on the carve-out matter in practice. It never applies where the system performs profiling of natural persons, which is always high-risk. And a provider relying on it must document its assessment before the system is placed on the market or put into service, and make that documentation available to national competent authorities on request.

The Commission published guidelines on high-risk classification under Article 6(5) on 19 May 2026, but they remain draft: the consultation closed on 23 July 2026 and no final text has been adopted. Treat any position taken from them as a draft interpretation rather than settled guidance. Note also that Annex III itself was not amended by the Digital Omnibus — only the date from which its obligations bite moved, to 2 December 2027.

Are recommendation systems high-risk?

In most cases, no. Standard product, music, or content recommendation systems are typically classified as minimal-risk or limited-risk. They become high-risk only in specific scenarios — for example, when used to allocate access to essential services, or when integrated into a high-risk use case like education or employment.

Note that very large online platforms (VLOPs) and very large online search engines (VLOSEs) face additional, separate obligations under the Digital Services Act for their recommender systems, including transparency and user-control requirements.

Are chatbots high-risk?

Chatbots are usually limited-risk, not high-risk. Article 50(1) requires that natural persons interacting with a chatbot be informed that they are dealing with an AI, unless this is obvious from context. That duty has applied since 2 August 2026 and was not deferred, so it is an immediate obligation rather than a future one. A chatbot becomes high-risk only when it is deployed in a high-risk use case — for instance, a chatbot that screens job applications would fall under Annex III, point 4 (employment) and be subject to the full high-risk regime from 2 December 2027.

Need auditable AI for compliance?

Ctrl AI provides full execution traces, expert verification, and trust-tagged outputs for every AI decision.

Learn About Ctrl AI

Specific Obligations

What documentation do I need for a high-risk AI system?

Article 11 and Annex IV specify the technical documentation requirements. The documentation must include, among other elements:

  • A general description of the AI system, its intended purpose, and previous versions
  • A detailed description of the system's components, including the algorithms, datasets, training methodology, and model design choices
  • Information about the data, including provenance, scope, and characteristics
  • A risk management plan compliant with Article 9
  • A description of the human oversight measures
  • Performance metrics and accuracy specifications
  • Cybersecurity measures
  • A copy of the EU declaration of conformity

The documentation must be kept up to date for the lifetime of the system and must be made available to national competent authorities on request for at least ten years after placing on the market.

What is the conformity assessment procedure?

Conformity assessment is the procedure by which a provider verifies that a high-risk AI system meets the requirements in Articles 8–15. For most Annex III high-risk systems, the procedure is internal control (Annex VI) — the provider performs the assessment itself. For certain biometric systems and for high-risk AI systems that are part of products under Annex I, third-party assessment by a notified body is required.

After successful conformity assessment, the provider issues an EU declaration of conformity, affixes the CE marking, and (for Annex III systems) registers the system in the EU database before placing it on the market.

Two practical constraints are worth planning around. No harmonised standard has yet been cited in the Official Journal, so no CEN-CENELEC deliverable currently confers a presumption of conformity under Article 40; the standardisation request M/613 runs to 28 February 2027. And under the new Article 43(3) deadline, notified bodies already notified under the sectoral legislation in Annex I, Section A must apply for designation under Chapter III, Section 4 by 28 January 2028.

Do I need to appoint a person responsible for AI compliance?

The regulation does not explicitly require a "Chief AI Officer," but it imposes a number of obligations that typically require named accountability:

  • Article 4 asks providers and deployers to take measures towards a sufficient level of AI literacy among their staff. It was rewritten and softened by Regulation (EU) 2026/1744, and is best read as a good-practice duty rather than a hard, audited requirement
  • Article 22 requires providers established outside the EU to appoint an authorised representative in the Union before making a high-risk AI system available on the EU market, and Article 54 imposes an equivalent duty on non-EU providers of GPAI models
  • Article 26 imposes deployer obligations that need a clear owner
  • Article 17 requires providers to establish a quality management system

In practice, most organisations subject to the AI Act create a designated AI compliance function, often combined with the existing data protection officer (DPO) role under the GDPR.

General-Purpose AI (GPAI)

What is a general-purpose AI model?

Article 3(63) defines a GPAI model as one that displays significant generality, is capable of competently performing a wide range of distinct tasks regardless of how it is placed on the market, and that can be integrated into a variety of downstream systems. Large language models, multimodal models, and other foundation models all fall within this definition.

What is a GPAI model with systemic risk?

Article 51(1)(a) classifies a GPAI model as having systemic risk where it has high impact capabilities, evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks. Article 51(2) then supplies a presumption: a model is presumed to have high impact capabilities where the cumulative amount of computation used for its training exceeds 10^25 floating-point operations (FLOPs). The Commission can also designate a model as having systemic risk under Article 51(1)(b), by reference to the Annex XIII criteria such as capability benchmarks, number of users, and ecosystem impact.

Models with systemic risk face additional obligations under Article 55: model evaluation including adversarial testing, systemic-risk mitigation, serious-incident reporting to the AI Office, and cybersecurity measures.

Chapter V was not substantively amended by Regulation (EU) 2026/1744. Articles 51 to 55 and Annexes XI to XIII stand as enacted, the 10^25 FLOP threshold in Article 51(2) is unchanged, and no delegated act has altered it. GPAI models placed on the market before 2 August 2025 still have until 2 August 2027 to comply under Article 111(3).

Are open-source GPAI models exempt from the AI Act?

Partially. Article 53(2) disapplies the documentation duties in Article 53(1)(a) and (b) for providers of models released under a free and open-source licence that allows access, use, modification and distribution, and whose parameters — including the weights, the information on the model architecture, and the information on model usage — are all made publicly available. The copyright-policy duty in Article 53(1)(c) and the training-content summary in Article 53(1)(d) continue to apply. The exemption also does not extend to GPAI models with systemic risk, which remain fully regulated regardless of licensing terms.

The open-source AI exemption is narrower than many developers assume; fine-tuning, hosting for a fee, or bundling with commercial services can all defeat the exemption.

GDPR and Other Regulations

How does the EU AI Act interact with the GDPR?

The two regulations apply in parallel. The GDPR governs the lawful processing of personal data; the AI Act governs the design and deployment of AI systems. When an AI system processes personal data — and most do — both regimes apply simultaneously.

Many concepts overlap but are not identical. Both require risk management; both require documentation; both impose transparency obligations. But the AI Act's risk management is system-centric, while the GDPR's is data-centric. The AI Act also adds requirements (such as data governance under Article 10 and human oversight under Article 14) that go beyond GDPR.

Does the EU AI Act override the Medical Devices Regulation?

No. For AI systems that qualify as medical devices, both regimes apply. Article 43(3) of the AI Act allows the conformity assessment to be integrated with the MDR/IVDR assessment, but the substantive requirements of both regulations must still be met. The result in practice is a coordinated but not consolidated compliance programme.

What is the relationship between the EU AI Act and the Digital Services Act?

The DSA imposes systemic-risk and content-moderation obligations on intermediary services. Where an AI system is used by a very large online platform (VLOP) or very large online search engine (VLOSE) to power its recommendation systems, content moderation, or ad targeting, both the DSA and the AI Act may apply.

Enforcement and Penalties

Who enforces the EU AI Act?

Enforcement is split between EU and national authorities:

  • The European Commission, through the AI Office, has exclusive jurisdiction over GPAI model providers
  • National market surveillance authorities in each Member State enforce the regulation against providers and deployers of AI systems within their territory
  • National notifying authorities designate and supervise notified bodies that conduct conformity assessments
  • The European Artificial Intelligence Board coordinates implementation across Member States

How much have companies actually been fined so far?

As at 4 August 2026, no fines have been publicly announced under the AI Act, and no formal AI Act proceedings against a named company can be verified. That is largely a function of sequencing: the Article 5 prohibitions became enforceable in February 2025, GPAI obligations in August 2025, and general application and enforcement only began on 2 August 2026. The high-risk regime does not bite until 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, so the obligations that carry the largest documentation and conformity burden are not yet enforceable. No CJEU judgment interpreting the AI Act has been delivered either.

Note that enforcement action against AI providers under other instruments is sometimes reported as AI Act enforcement. The Commission's proceedings against X over Grok, opened on 26 January 2026, are a Digital Services Act matter, not an AI Act case.

Can I be fined under both the AI Act and the GDPR for the same conduct?

In principle, yes — if the conduct violates both regulations. The two regimes protect different interests (AI safety vs. data protection) and have different competent authorities. Member States and the Commission are expected to coordinate to avoid bis in idem (double-punishment) issues, but the regulation does not exclude parallel enforcement.

Practical Next Steps

What should I do first if my company has AI?

A practical five-step starting plan:

  1. Inventory every AI system your organisation develops, deploys, or uses. Include third-party tools, embedded AI features in SaaS products, and internal models.
  2. Classify each system against the risk framework. Pay special attention to any system touching biometrics, employment, education, essential services, law enforcement, or critical infrastructure.
  3. Address prohibited practices immediately. They have been enforceable since February 2025; any in-scope system should be stopped, modified, or replaced. Check the two new prohibitions on non-consensual intimate imagery and child sexual abuse material as well — they apply from 2 December 2026.
  4. Close your Article 50 transparency gaps now. Chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content have applied since 2 August 2026 and were not deferred. Generative systems already on the market before that date have until 2 December 2026 to meet the marking duty.
  5. Build a compliance roadmap for high-risk and GPAI systems, working back from 2 December 2027 for standalone Annex III systems and 2 August 2028 for high-risk AI in products covered by Annex I.

Who can help me comply with the EU AI Act?

You will likely need a combination of legal counsel (for regulatory interpretation), in-house engineering and product teams (for technical implementation), and possibly a third-party platform that supports AI governance — for example by providing audit-ready documentation, execution traces, and trust-tagged outputs. The EU also encourages regulatory sandboxes (Article 57) that Member States must have operational by 2 August 2027 — a year later than originally required, following Regulation (EU) 2026/1744 — to support innovation under supervision.

Conclusion

The EU AI Act is broad, technical, and consequential — but it is also navigable. Most organisations subject to it can build a workable compliance programme by understanding the risk framework, mapping their AI systems against it, prioritising prohibited and high-risk obligations, and putting durable governance in place. The questions in this FAQ are the ones companies ask most often; the linked deep-dive articles answer them in much more depth.

If a specific question is not covered here, our complete EU AI Act overview is the best starting point for the full regulatory picture.

Frequently Asked Questions

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It establishes harmonised rules for the development, market placement, deployment, and use of AI systems across the European Union, using a risk-based approach with four tiers: unacceptable, high, limited, and minimal risk.

When did the EU AI Act enter into force?

The EU AI Act entered into force on 1 August 2024, twenty days after its publication in the Official Journal on 12 July 2024. Different provisions apply at different dates between February 2025 and August 2028, following the amendments made by Regulation (EU) 2026/1744 (the 'Digital Omnibus on AI'), which entered into force on 27 July 2026.

Does the EU AI Act apply to companies outside the European Union?

Yes. Article 2 establishes a broad territorial scope: the regulation applies to providers placing AI systems on the EU market regardless of where they are established, to deployers in the EU, and to providers and deployers outside the EU whenever the output produced by their AI system is used inside the Union.

What is the maximum fine under the EU AI Act?

Article 99 sets the maximum administrative fine at €35 million or 7% of total worldwide annual turnover, whichever is higher, for violations of the prohibited AI practices listed in Article 5. Lower tiers apply to other violations: €15 million / 3% for breaches of other operator obligations, including the high-risk requirements and the Article 50 transparency duties, and €7.5 million / 1% for supplying incorrect or misleading information to authorities.

What are the four risk levels under the EU AI Act?

Unacceptable risk (prohibited under Article 5), high risk (Articles 6–7 and Annexes I and III), limited risk (transparency obligations under Article 50), and minimal risk (no specific obligations beyond existing law).

When do high-risk AI system obligations apply?

Regulation (EU) 2026/1744 (the 'Digital Omnibus on AI'), in force since 27 July 2026, deferred the core high-risk regime in Chapter III, Sections 1 to 3. Standalone high-risk systems listed in Annex III now have to comply from 2 December 2027, and high-risk systems that are safety components of products covered by the EU harmonisation legislation in Annex I from 2 August 2028. The deferral is unconditional. Article 6(5) is carved out of it, and the Article 49 registration duty in Chapter III, Section 5 was not deferred.

Does the EU AI Act apply to ChatGPT, Claude, and other large language models?

Yes. Large language models fall under the General-Purpose AI Model regime in Chapter V. All GPAI providers must maintain technical documentation, publish a summary of training content, and respect copyright law. Models whose cumulative training compute exceeds 10^25 FLOPs are presumed under Article 51(2) to have high impact capabilities, and so fall into the systemic-risk tier, which carries additional obligations including model evaluations, adversarial testing, and incident reporting.

What is the difference between a provider and a deployer?

A provider (Article 3(3)) develops an AI system or GPAI model and places it on the market or puts it into service under its own name or trademark. A deployer (Article 3(4)) uses an AI system under its authority in the course of a professional activity. Providers bear most of the substantive obligations for high-risk systems; deployers have a narrower set focused on operating the system correctly, monitoring it, and (for public-sector deployers) conducting a fundamental rights impact assessment.

Is the EU AI Act the same as the GDPR?

No. The GDPR (Regulation 2016/679) governs the processing of personal data. The EU AI Act governs the design, market placement, and use of AI systems regardless of whether they process personal data. Many AI systems are subject to both regimes simultaneously: the AI Act governs the system's classification and safety, while the GDPR governs any personal-data processing.

Do I need to register my AI system with the EU?

Providers and deployers of high-risk AI systems listed in Annex III (with limited exceptions) must register the system in the EU database before placing it on the market or putting it into service, under Article 49. Deployers that are public authorities or Union institutions also have registration obligations. Lower-risk systems do not require registration. Article 49 sits in Chapter III, Section 5 and was not deferred by Regulation (EU) 2026/1744, so it has applied since 2 August 2026.

Make Your AI Auditable and Compliant

Ctrl AI provides expert-verified reasoning units with full execution traces — the infrastructure you need for EU AI Act compliance.

Explore Ctrl AI

Related Articles