EU AI Act FAQ: Answers to 30+ Common Questions
Practical answers to the most common EU AI Act questions — scope, timelines, fines, classification, GPAI, GDPR overlap, and what companies need to do to comply with Regulation 2024/1689.
The EU AI Act (Regulation 2024/1689) is the most comprehensive AI law in the world, and it raises a lot of practical questions for the companies that have to comply with it. This FAQ collects the most frequently asked questions about the regulation — from basic scope and timelines to specific obligations for providers, deployers, and general-purpose AI model developers — and gives concise, citation-backed answers.
If you need deeper material on a topic, every answer links to a dedicated article.
What Changed in July 2026
Regulation (EU) 2026/1744 of 8 July 2026 (the "Digital Omnibus on AI") was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is the first amendment to the AI Act, and it moves three dates:
- Standalone high-risk systems under Article 6(2) and Annex III: from 2 August 2026 to 2 December 2027
- High-risk systems that are safety components of products under Article 6(1) and Annex I: from 2 August 2027 to 2 August 2028
- National regulatory sandboxes under Article 57: from 2 August 2026 to 2 August 2027
The deferral is unconditional. The Commission's original proposal would have tied the new dates to a decision confirming that harmonised standards were available — a "stop-the-clock" trigger — but the co-legislators dropped it. There is no standards-readiness condition in the adopted text and no further automatic delay.
Just as important is what did not move. 2 August 2026 remained the general application date, and the AI Office and national authorities began enforcing the regulation on that date. The AI Act was not delayed; the deferral is confined to Chapter III, Sections 1 to 3, and to Article 57. The Article 50 transparency obligations are in force now — chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content are live and enforceable — and Article 49 registration and the Article 5 prohibitions are equally unaffected.
Two further changes matter below. Two new prohibitions were added to Article 5, covering non-consensual intimate imagery (Article 5(1)(ba)) and child sexual abuse material (Article 5(1)(bb)); both apply from 2 December 2026. The new Article 111(4) gives generative AI systems placed on the market before 2 August 2026 until that same date to meet the Article 50(2) marking duty.
Scope and Applicability
Does the EU AI Act apply to my company?
Almost certainly yes if any of the following is true:
- You place an AI system on the EU market, regardless of where you are established (Article 2(1)(a))
- You put an AI system into service in the EU (Article 2(1)(a))
- You are a deployer of an AI system established or located in the EU (Article 2(1)(b))
- You are a provider or deployer outside the EU whose AI system's output is used in the EU (Article 2(1)(c))
- You are an importer or distributor of AI systems that end up on the EU market (Article 2(1)(d))
- You are a product manufacturer placing an AI system on the market or putting it into service together with your product and under your own name or trademark (Article 2(1)(e))
The "output used in the EU" trigger is broad. A US company running an AI hiring tool that screens candidates in Germany falls within the regulation even if it has no EU office.
Are there any exemptions from the EU AI Act?
Article 2 lists several specific exemptions:
- National security and defence: AI systems used exclusively for military, defence, or national-security purposes are excluded (Article 2(3))
- Scientific research and development: AI systems and AI models specifically developed and put into service for the sole purpose of scientific research and development are excluded outright (Article 2(6))
- Pre-market research, testing and development: research, testing and development activity on AI systems or models before they are placed on the market or put into service is excluded, but the exclusion does not cover testing in real world conditions (Article 2(8))
- Personal non-professional activities: AI used by individuals for purely personal activities is excluded (Article 2(10))
- Free and open-source AI components: AI components released under free and open-source licences are partially exempt, except when they are placed on the market or put into service as high-risk systems, prohibited practices, or limited-risk systems with transparency obligations (Article 2(12))
There is no exemption for small companies. SMEs and startups are fully subject to the regulation, although Article 99(6) provides that the lower of two fine amounts (absolute or percentage) applies to them.
Does the EU AI Act apply to AI systems that were already on the market before it started to apply?
Mostly yes, but with transitional periods:
- GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to comply (Article 111(3))
- High-risk AI systems placed on the market before 2 August 2026 generally do not have to comply with the regulation, unless they undergo significant changes in their design after that date (Article 111(2))
- Operators of high-risk AI systems intended for use by public authorities must bring legacy systems into compliance by 2 August 2030 (Article 111(2))
- AI systems that are components of the large-scale EU IT systems listed in Annex X placed on the market or put into service before 2 August 2027 must be brought into compliance by 31 December 2030 (Article 111(1) — this provision was not realigned when the high-risk dates moved, so it still refers to 2 August 2027)
- Generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2), under the grace period added by Article 111(4)
In practice, organisations should not rely on grandfathering. Most legacy systems are updated frequently enough that they will trigger compliance obligations at some point.
Timelines and Deadlines
When does the EU AI Act take effect?
The regulation follows a phased timeline:
- 1 August 2024: Entry into force
- 2 February 2025: Prohibitions on unacceptable-risk practices apply
- 2 August 2025: GPAI obligations, governance provisions, and penalty provisions apply
- 2 August 2026: General application. Enforcement begins, and the transparency obligations in Article 50 and the Article 49 registration duty take effect
- 2 December 2026: The two new Article 5 prohibitions apply, and the Article 111(4) grace period for machine-readable marking of pre-existing generative AI systems ends
- 2 August 2027: National regulatory sandboxes must be operational under Article 57, and GPAI models placed on the market before 2 August 2025 must be compliant
- 2 December 2027: Standalone high-risk AI system requirements under Annex III apply
- 2 August 2028: High-risk systems that are safety components of products under Annex I apply
- 2 August 2030: Legacy high-risk systems used by public authorities must be compliant
Was the EU AI Act delayed?
Only in part, and the distinction matters. Regulation (EU) 2026/1744 deferred the core high-risk regime in Chapter III, Sections 1 to 3, and pushed the sandbox deadline back by a year. It did not touch the general application date of 2 August 2026, which held, and it did not touch Article 5, Article 49 or Article 50. Saying "the AI Act was delayed" is wrong: the regulation is being enforced now, and only the high-risk requirements and sandboxes moved.
How much time do I have left to prepare?
That depends on which obligation you mean. Some are already live. The Article 5 prohibitions have been enforceable since February 2025, GPAI obligations since August 2025, and Article 50 transparency, Article 49 registration and the rest of the general regime since 2 August 2026. For those, the deadline is behind you and you are exposed to enforcement rather than working towards a target.
For the high-risk regime the picture changed in July 2026. Standalone Annex III systems now have until 2 December 2027, roughly sixteen months away, and Annex I product systems until 2 August 2028. A minimum-viable compliance programme — risk management, technical documentation, data governance, human oversight design, conformity assessment — takes most organisations six to twelve months to set up, so the extra time is useful but not generous, particularly while no harmonised standard has yet been cited in the Official Journal to confer a presumption of conformity.
If you have not yet started, prioritise: (1) inventorying your AI systems, (2) classifying each one, (3) addressing any prohibited practices and any live Article 50 transparency gaps immediately, and (4) building a compliance roadmap towards December 2027. The compliance checklist for CTOs and CIOs provides a practical starting point.
Risk Classification
How do I know if my AI system is high-risk?
A system is high-risk if it meets either of two tests:
-
Annex I test: The system is a safety component of, or itself constitutes, a product covered by Union harmonisation legislation listed in Annex I (medical devices, machinery, toys, automotive, aviation, marine, etc.) and that product is required to undergo a third-party conformity assessment.
-
Annex III test: The system is a standalone AI system used in one of eight sensitive areas: biometrics; critical infrastructure; education and vocational training; employment, workers management, and access to self-employment; access to essential private and public services; law enforcement; migration, asylum, and border control; or administration of justice and democratic processes.
Article 6(3) introduced an important carve-out: even if a system would otherwise qualify under Annex III, it is not high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons and one of four conditions is met. Those conditions are that the system performs a narrow procedural task; improves the result of a previously completed human activity; detects decision-making patterns or deviations from prior decision-making patterns without replacing or influencing the previously completed human assessment; or performs a preparatory task to an assessment relevant to an Annex III use case.
Two limits on the carve-out matter in practice. It never applies where the system performs profiling of natural persons, which is always high-risk. And a provider relying on it must document its assessment before the system is placed on the market or put into service, and make that documentation available to national competent authorities on request.
The Commission published guidelines on high-risk classification under Article 6(5) on 19 May 2026, but they remain draft: the consultation closed on 23 July 2026 and no final text has been adopted. Treat any position taken from them as a draft interpretation rather than settled guidance. Note also that Annex III itself was not amended by the Digital Omnibus — only the date from which its obligations bite moved, to 2 December 2027.
Are recommendation systems high-risk?
In most cases, no. Standard product, music, or content recommendation systems are typically classified as minimal-risk or limited-risk. They become high-risk only in specific scenarios — for example, when used to allocate access to essential services, or when integrated into a high-risk use case like education or employment.
Note that very large online platforms (VLOPs) and very large online search engines (VLOSEs) face additional, separate obligations under the Digital Services Act for their recommender systems, including transparency and user-control requirements.
Are chatbots high-risk?
Chatbots are usually limited-risk, not high-risk. Article 50(1) requires that natural persons interacting with a chatbot be informed that they are dealing with an AI, unless this is obvious from context. That duty has applied since 2 August 2026 and was not deferred, so it is an immediate obligation rather than a future one. A chatbot becomes high-risk only when it is deployed in a high-risk use case — for instance, a chatbot that screens job applications would fall under Annex III, point 4 (employment) and be subject to the full high-risk regime from 2 December 2027.
Need auditable AI for compliance?
Ctrl AI provides full execution traces, expert verification, and trust-tagged outputs for every AI decision.
Learn About Ctrl AISpecific Obligations
What documentation do I need for a high-risk AI system?
Article 11 and Annex IV specify the technical documentation requirements. The documentation must include, among other elements:
- A general description of the AI system, its intended purpose, and previous versions
- A detailed description of the system's components, including the algorithms, datasets, training methodology, and model design choices
- Information about the data, including provenance, scope, and characteristics
- A risk management plan compliant with Article 9
- A description of the human oversight measures
- Performance metrics and accuracy specifications
- Cybersecurity measures
- A copy of the EU declaration of conformity
The documentation must be kept up to date for the lifetime of the system and must be made available to national competent authorities on request for at least ten years after placing on the market.
What is the conformity assessment procedure?
Conformity assessment is the procedure by which a provider verifies that a high-risk AI system meets the requirements in Articles 8–15. For most Annex III high-risk systems, the procedure is internal control (Annex VI) — the provider performs the assessment itself. For certain biometric systems and for high-risk AI systems that are part of products under Annex I, third-party assessment by a notified body is required.
After successful conformity assessment, the provider issues an EU declaration of conformity, affixes the CE marking, and (for Annex III systems) registers the system in the EU database before placing it on the market.
Two practical constraints are worth planning around. No harmonised standard has yet been cited in the Official Journal, so no CEN-CENELEC deliverable currently confers a presumption of conformity under Article 40; the standardisation request M/613 runs to 28 February 2027. And under the new Article 43(3) deadline, notified bodies already notified under the sectoral legislation in Annex I, Section A must apply for designation under Chapter III, Section 4 by 28 January 2028.
Do I need to appoint a person responsible for AI compliance?
The regulation does not explicitly require a "Chief AI Officer," but it imposes a number of obligations that typically require named accountability:
- Article 4 asks providers and deployers to take measures towards a sufficient level of AI literacy among their staff. It was rewritten and softened by Regulation (EU) 2026/1744, and is best read as a good-practice duty rather than a hard, audited requirement
- Article 22 requires providers established outside the EU to appoint an authorised representative in the Union before making a high-risk AI system available on the EU market, and Article 54 imposes an equivalent duty on non-EU providers of GPAI models
- Article 26 imposes deployer obligations that need a clear owner
- Article 17 requires providers to establish a quality management system
In practice, most organisations subject to the AI Act create a designated AI compliance function, often combined with the existing data protection officer (DPO) role under the GDPR.
General-Purpose AI (GPAI)
What is a general-purpose AI model?
Article 3(63) defines a GPAI model as one that displays significant generality, is capable of competently performing a wide range of distinct tasks regardless of how it is placed on the market, and that can be integrated into a variety of downstream systems. Large language models, multimodal models, and other foundation models all fall within this definition.
What is a GPAI model with systemic risk?
Article 51(1)(a) classifies a GPAI model as having systemic risk where it has high impact capabilities, evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks. Article 51(2) then supplies a presumption: a model is presumed to have high impact capabilities where the cumulative amount of computation used for its training exceeds 10^25 floating-point operations (FLOPs). The Commission can also designate a model as having systemic risk under Article 51(1)(b), by reference to the Annex XIII criteria such as capability benchmarks, number of users, and ecosystem impact.
Models with systemic risk face additional obligations under Article 55: model evaluation including adversarial testing, systemic-risk mitigation, serious-incident reporting to the AI Office, and cybersecurity measures.
Chapter V was not substantively amended by Regulation (EU) 2026/1744. Articles 51 to 55 and Annexes XI to XIII stand as enacted, the 10^25 FLOP threshold in Article 51(2) is unchanged, and no delegated act has altered it. GPAI models placed on the market before 2 August 2025 still have until 2 August 2027 to comply under Article 111(3).
Are open-source GPAI models exempt from the AI Act?
Partially. Article 53(2) disapplies the documentation duties in Article 53(1)(a) and (b) for providers of models released under a free and open-source licence that allows access, use, modification and distribution, and whose parameters — including the weights, the information on the model architecture, and the information on model usage — are all made publicly available. The copyright-policy duty in Article 53(1)(c) and the training-content summary in Article 53(1)(d) continue to apply. The exemption also does not extend to GPAI models with systemic risk, which remain fully regulated regardless of licensing terms.
The open-source AI exemption is narrower than many developers assume; fine-tuning, hosting for a fee, or bundling with commercial services can all defeat the exemption.
GDPR and Other Regulations
How does the EU AI Act interact with the GDPR?
The two regulations apply in parallel. The GDPR governs the lawful processing of personal data; the AI Act governs the design and deployment of AI systems. When an AI system processes personal data — and most do — both regimes apply simultaneously.
Many concepts overlap but are not identical. Both require risk management; both require documentation; both impose transparency obligations. But the AI Act's risk management is system-centric, while the GDPR's is data-centric. The AI Act also adds requirements (such as data governance under Article 10 and human oversight under Article 14) that go beyond GDPR.
Does the EU AI Act override the Medical Devices Regulation?
No. For AI systems that qualify as medical devices, both regimes apply. Article 43(3) of the AI Act allows the conformity assessment to be integrated with the MDR/IVDR assessment, but the substantive requirements of both regulations must still be met. The result in practice is a coordinated but not consolidated compliance programme.
What is the relationship between the EU AI Act and the Digital Services Act?
The DSA imposes systemic-risk and content-moderation obligations on intermediary services. Where an AI system is used by a very large online platform (VLOP) or very large online search engine (VLOSE) to power its recommendation systems, content moderation, or ad targeting, both the DSA and the AI Act may apply.
Enforcement and Penalties
Who enforces the EU AI Act?
Enforcement is split between EU and national authorities:
- The European Commission, through the AI Office, has exclusive jurisdiction over GPAI model providers
- National market surveillance authorities in each Member State enforce the regulation against providers and deployers of AI systems within their territory
- National notifying authorities designate and supervise notified bodies that conduct conformity assessments
- The European Artificial Intelligence Board coordinates implementation across Member States
How much have companies actually been fined so far?
As at 4 August 2026, no fines have been publicly announced under the AI Act, and no formal AI Act proceedings against a named company can be verified. That is largely a function of sequencing: the Article 5 prohibitions became enforceable in February 2025, GPAI obligations in August 2025, and general application and enforcement only began on 2 August 2026. The high-risk regime does not bite until 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, so the obligations that carry the largest documentation and conformity burden are not yet enforceable. No CJEU judgment interpreting the AI Act has been delivered either.
Note that enforcement action against AI providers under other instruments is sometimes reported as AI Act enforcement. The Commission's proceedings against X over Grok, opened on 26 January 2026, are a Digital Services Act matter, not an AI Act case.
Can I be fined under both the AI Act and the GDPR for the same conduct?
In principle, yes — if the conduct violates both regulations. The two regimes protect different interests (AI safety vs. data protection) and have different competent authorities. Member States and the Commission are expected to coordinate to avoid bis in idem (double-punishment) issues, but the regulation does not exclude parallel enforcement.
Practical Next Steps
What should I do first if my company has AI?
A practical five-step starting plan:
- Inventory every AI system your organisation develops, deploys, or uses. Include third-party tools, embedded AI features in SaaS products, and internal models.
- Classify each system against the risk framework. Pay special attention to any system touching biometrics, employment, education, essential services, law enforcement, or critical infrastructure.
- Address prohibited practices immediately. They have been enforceable since February 2025; any in-scope system should be stopped, modified, or replaced. Check the two new prohibitions on non-consensual intimate imagery and child sexual abuse material as well — they apply from 2 December 2026.
- Close your Article 50 transparency gaps now. Chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content have applied since 2 August 2026 and were not deferred. Generative systems already on the market before that date have until 2 December 2026 to meet the marking duty.
- Build a compliance roadmap for high-risk and GPAI systems, working back from 2 December 2027 for standalone Annex III systems and 2 August 2028 for high-risk AI in products covered by Annex I.
Who can help me comply with the EU AI Act?
You will likely need a combination of legal counsel (for regulatory interpretation), in-house engineering and product teams (for technical implementation), and possibly a third-party platform that supports AI governance — for example by providing audit-ready documentation, execution traces, and trust-tagged outputs. The EU also encourages regulatory sandboxes (Article 57) that Member States must have operational by 2 August 2027 — a year later than originally required, following Regulation (EU) 2026/1744 — to support innovation under supervision.
Conclusion
The EU AI Act is broad, technical, and consequential — but it is also navigable. Most organisations subject to it can build a workable compliance programme by understanding the risk framework, mapping their AI systems against it, prioritising prohibited and high-risk obligations, and putting durable governance in place. The questions in this FAQ are the ones companies ask most often; the linked deep-dive articles answer them in much more depth.
If a specific question is not covered here, our complete EU AI Act overview is the best starting point for the full regulatory picture.
Frequently Asked Questions
What is the EU AI Act?
When did the EU AI Act enter into force?
Does the EU AI Act apply to companies outside the European Union?
What is the maximum fine under the EU AI Act?
What are the four risk levels under the EU AI Act?
When do high-risk AI system obligations apply?
Does the EU AI Act apply to ChatGPT, Claude, and other large language models?
What is the difference between a provider and a deployer?
Is the EU AI Act the same as the GDPR?
Do I need to register my AI system with the EU?
Make Your AI Auditable and Compliant
Ctrl AI provides expert-verified reasoning units with full execution traces — the infrastructure you need for EU AI Act compliance.
Explore Ctrl AIRelated Articles
EU AI Act: Complete Overview of Europe's AI Regulation
Everything you need to know about the EU AI Act (Regulation 2024/1689) — the world's first comprehensive AI law covering risk classification, compliance requirements, and enforcement timeline.
EU AI Act Glossary: 50+ Key Terms Defined
Plain-language definitions of the most important EU AI Act terms — AI system, provider, deployer, GPAI, high-risk, conformity assessment, and more, with article references.
EU AI Act Penalties: Fines Up to €35 Million Explained
Complete breakdown of EU AI Act penalties and fines — from €35 million for prohibited practices to €7.5 million for incorrect information. Understand the enforcement regime and how to avoid penalties.