Regulationeu-ai-actoverviewregulation

EU AI Act: Complete Overview of Europe's AI Regulation

Everything you need to know about the EU AI Act (Regulation 2024/1689) — the world's first comprehensive AI law covering risk classification, compliance requirements, and enforcement timeline.

January 15, 2025Updated August 4, 202613 min read

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Adopted by the European Parliament on 13 March 2024 and published in the Official Journal of the European Union on 12 July 2024, it establishes harmonised rules for the development, deployment, and use of AI systems across the European Union.

This regulation marks a paradigm shift in how governments approach artificial intelligence. Rather than relying on voluntary guidelines or sector-specific rules, the EU has created a horizontal, risk-based framework that applies across all industries and use cases.

The EU AI Act entered into force on 1 August 2024, with a phased implementation schedule now running through 2 August 2028. Different provisions apply at different dates, and the regulation has been generally applicable and enforceable since 2 August 2026.

What Changed in July 2026

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and is the first amendment to the AI Act. It defers the Chapter III, Sections 1–3 obligations for high-risk AI systems: systems classified as high-risk under Article 6(2) and Annex III now apply from 2 December 2027 (previously 2 August 2026), and systems classified as high-risk under Article 6(1) and Annex I from 2 August 2028 (previously 2 August 2027). National regulatory sandboxes under Article 57 must now be operational by 2 August 2027.

The deferral is unconditional. The Commission's original proposal would have tied the new dates to a decision confirming that harmonised standards were available — a "stop-the-clock" trigger — but the co-legislators dropped it. There is no standards-readiness condition in the adopted text and no further automatic delay. A fuller account of what the amending regulation moved and what it left alone is set out in The Digital Omnibus on AI.

Just as importantly, the AI Act itself was not delayed. 2 August 2026 remained the general application date, that provision was not amended, and the Commission's AI Office and national authorities began enforcing the regulation on that date. The Article 50 transparency obligations — chatbot disclosure, deepfake labelling, and machine-readable marking of synthetic content — are in force now, because Article 50 sits in Chapter IV and outside the deferred sections. Article 49 registration, which sits in Chapter III Section 5, likewise applies from 2 August 2026, and Article 6(5) is expressly carved out of the deferral.

The amendment also adds two new prohibited practices under Article 5, applying from 2 December 2026: AI systems that generate or manipulate realistic intimate imagery of an identifiable person without their consent, and AI systems that generate or manipulate child sexual abuse material. A new Article 111(4) gives generative AI systems placed on the market before 2 August 2026 until the same date, 2 December 2026, to meet the Article 50(2) machine-readable marking duty.

Why the EU AI Act Matters

The EU AI Act matters far beyond Europe's borders. Much like the General Data Protection Regulation (GDPR) before it, the AI Act is expected to set a global standard for AI governance. There are several reasons this regulation demands attention from any organisation working with AI.

Global Reach Through Extraterritorial Application

Article 2 of the AI Act establishes a broad territorial scope. The regulation applies not only to providers and deployers established within the EU but also to providers and deployers in third countries when the output of their AI system is used within the Union. This means a company headquartered in the United States, Japan, or anywhere else must comply if its AI system produces results that affect people in the EU.

Setting the Global Standard

The EU has a well-documented track record of exporting its regulatory standards. The so-called "Brussels Effect" means that multinational companies often adopt EU standards globally rather than maintain separate compliance regimes. The AI Act is expected to follow this pattern, effectively becoming the baseline for AI governance worldwide.

Fundamental Rights Protection

Unlike approaches that focus primarily on innovation or economic considerations, the EU AI Act places fundamental rights at its core. Recital 1 explicitly states that the purpose of the regulation is to improve the functioning of the internal market while promoting the uptake of human-centric and trustworthy AI, and ensuring a high level of protection of health, safety, and fundamental rights.

Who Does the EU AI Act Apply To?

The AI Act defines several categories of actors within the AI value chain. Understanding which role your organisation plays is the first step toward compliance.

Providers

A provider is any natural or legal person that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark (Article 3(3)). Providers bear the heaviest compliance burden, particularly for high-risk AI systems.

Deployers

A deployer is any natural or legal person that uses an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity (Article 3(4)). Deployers have their own set of obligations, including conducting fundamental rights impact assessments for certain high-risk systems.

Importers and Distributors

Importers place AI systems from third countries on the EU market, while distributors make AI systems available on the market without modifying them. Both have verification and documentation obligations under Articles 26 and 27.

Authorised Representatives

Providers established outside the EU must appoint an authorised representative within the Union before making their high-risk AI systems available on the EU market (Article 22).

If your organisation modifies a high-risk AI system in a way that affects its compliance, or if you place your name or trademark on it, you may be reclassified as a provider under Article 25 — with all the corresponding obligations.

The Risk-Based Approach

The centrepiece of the EU AI Act is its risk-based classification system. Rather than imposing uniform requirements on all AI systems, the regulation establishes four tiers of risk, each with proportionate obligations.

Unacceptable Risk (Prohibited Practices)

Article 5 of the AI Act lists AI practices that are outright banned. These include AI systems that use subliminal, manipulative, or deceptive techniques to distort behaviour, systems that exploit vulnerabilities related to age, disability, or socioeconomic situation, social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces by law enforcement (with narrow exceptions), and emotion recognition in the workplace and educational institutions. These prohibitions have applied since 2 February 2025. The two prohibitions added by Regulation (EU) 2026/1744 — covering non-consensual intimate imagery and child sexual abuse material — apply from 2 December 2026.

High Risk

Articles 6 and 7, along with Annexes I and III, define high-risk AI systems. These fall into two categories: AI systems that are safety components of products already subject to EU harmonisation legislation (such as medical devices, machinery, and vehicles), and standalone AI systems used in sensitive areas listed in Annex III, including biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice.

High-risk AI systems face the most extensive compliance requirements, detailed in Articles 8 through 15. Those requirements now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. Registration under Article 49 is not affected by that deferral and applies from 2 August 2026.

Limited Risk

AI systems posing limited risk are subject to specific transparency obligations under Article 50. This includes chatbots (which must disclose that the user is interacting with an AI), deepfakes (which must be labelled), and AI-generated content (which must be marked as such). These obligations have applied since 2 August 2026 and are enforceable today, with one transitional exception: generative AI systems placed on the market before that date have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).

Minimal Risk

AI systems that pose minimal or no risk — the vast majority of AI applications — can be developed and used with no additional obligations beyond existing legislation. The regulation encourages, but does not require, the development of voluntary codes of conduct for these systems.

Key Provisions and Requirements

Beyond risk classification, the AI Act introduces several important mechanisms and requirements.

General-Purpose AI Models (GPAI)

Chapter V of the AI Act addresses general-purpose AI models, including large language models. All GPAI model providers must maintain technical documentation, provide information to downstream providers, comply with copyright law, and publish a sufficiently detailed summary of training content.

GPAI models with systemic risk — generally those trained with more than 10^25 FLOPs of compute — face additional obligations including model evaluations, adversarial testing, incident reporting, and cybersecurity measures.

Need auditable AI for compliance?

Ctrl AI provides full execution traces, expert verification, and trust-tagged outputs for every AI decision.

Learn About Ctrl AI

AI Governance Structure

The AI Act establishes a multi-layered governance structure:

  • AI Office (Article 64): A body within the European Commission responsible for overseeing GPAI models and supporting the uniform application of the regulation.
  • European Artificial Intelligence Board (Article 65): Composed of representatives from each Member State, the Board advises the Commission and facilitates consistent application across the EU.
  • National Competent Authorities (Article 70): Each Member State must designate at least one notifying authority and one market surveillance authority.
  • Advisory Forum (Article 67): A body of stakeholders providing technical expertise to the Board and the Commission.

Regulatory Sandboxes

Article 57 requires each Member State to establish at least one AI regulatory sandbox. Regulation (EU) 2026/1744 moved that deadline from 2 August 2026 to 2 August 2027. These controlled environments allow innovative AI systems to be developed and tested under regulatory supervision, with legal certainty and structured oversight.

Fundamental Rights Impact Assessment

Article 27 requires deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services, to conduct a fundamental rights impact assessment before putting a high-risk AI system into use. This assessment must identify risks to fundamental rights and describe the measures taken to mitigate them.

Penalties and Enforcement

The EU AI Act establishes a tiered penalty structure that reflects the severity of violations.

Fines

Under Article 99, the maximum administrative fines are:

  • Prohibited AI practices (Article 5): Up to 35 million EUR or 7% of total worldwide annual turnover, whichever is higher.
  • Non-compliance with high-risk requirements: Up to 15 million EUR or 3% of total worldwide annual turnover.
  • Supplying incorrect information to authorities: Up to 7.5 million EUR or 1% of total worldwide annual turnover.

For SMEs and startups, the lower of the two amounts applies, providing some proportionality for smaller organisations.

These fines are calculated on total worldwide annual turnover of the preceding financial year, not just EU revenue. For large multinationals, the percentage-based fines could result in penalties of hundreds of millions or even billions of euros.

Market Surveillance

National market surveillance authorities have the power to conduct inspections, require corrective actions, and withdraw non-compliant AI systems from the market. The regulation also empowers individuals to lodge complaints with market surveillance authorities.

Implementation Timeline

The AI Act follows a phased implementation schedule:

  • 1 August 2024: Entry into force.
  • 2 February 2025: Prohibitions on unacceptable-risk AI practices apply.
  • 2 August 2025: Obligations for GPAI models apply. Governance structure provisions take effect.
  • 2 August 2026: General application and start of enforcement, including the Article 50 transparency obligations and Article 49 registration.
  • 2 December 2026: The two new Article 5 prohibitions apply, and the Article 111(4) grace period for machine-readable marking of pre-existing generative AI systems expires.
  • 2 August 2027: National regulatory sandboxes must be operational under Article 57. GPAI models placed on the market before 2 August 2025 must be brought into compliance (Article 111(3)).
  • 2 December 2027: Chapter III, Sections 1–3 obligations apply to high-risk AI systems listed in Annex III.
  • 2 August 2028: Chapter III, Sections 1–3 obligations apply to high-risk AI systems that are safety components of products covered by existing EU harmonisation legislation (Annex I).

How to Prepare for Compliance

Preparing for the EU AI Act is not something that can be done overnight. With the regulation already applicable and enforceable, and the high-risk regime roughly sixteen months away, organisations need a structured approach that separates what is due now from what is due in 2027 and 2028.

Step 1: AI System Inventory

Start by cataloguing all AI systems your organisation develops, deploys, or uses. For each system, identify its purpose, the data it processes, who it affects, and which role your organisation plays (provider, deployer, importer, or distributor).

Step 2: Risk Classification

Map each AI system against the risk categories defined in Articles 5, 6, and Annex III. Determine whether any of your systems fall into the high-risk or prohibited categories.

Step 3: Gap Analysis

For high-risk systems, assess your current practices against the requirements in Articles 8 through 15. Identify gaps in risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and cybersecurity.

Step 4: Compliance Roadmap

Develop a prioritised roadmap to address identified gaps. The obligations that are already live come first: prohibited practices under Article 5, GPAI obligations, Article 50 transparency, and Article 49 registration. Next come the two new prohibitions and the marking grace period on 2 December 2026, and then the high-risk requirements on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.

Step 5: Ongoing Monitoring

Compliance with the AI Act is not a one-time exercise. Article 9 requires continuous risk management, and Article 72 mandates post-market monitoring for high-risk AI systems. Establish processes for ongoing compliance monitoring and documentation.

Organisations that begin compliance work early will have a significant advantage. Beyond avoiding penalties, demonstrating responsible AI practices builds trust with customers, partners, and regulators alike.

Conclusion

The EU AI Act represents a fundamental shift in how artificial intelligence is regulated. Its risk-based approach provides a proportionate framework that balances innovation with the protection of fundamental rights. Enforcement is now underway: the prohibitions, the GPAI regime, and the Article 50 transparency obligations are all live, while the extra time granted to the high-risk regime by Regulation (EU) 2026/1744 is best treated as room to do the work properly rather than a reason to postpone it.

Whether you are a provider developing AI systems, a deployer integrating them into your operations, or an organisation trying to understand your obligations, a systematic approach to compliance is essential. Understanding the regulation, classifying your AI systems, and building robust governance processes will position your organisation not just for compliance but for sustainable, trustworthy AI development. For a step-by-step starting point, see our EU AI Act compliance checklist for CTOs and CIOs.

Frequently Asked Questions

When does the EU AI Act apply?

The EU AI Act entered into force on 1 August 2024. Prohibitions on unacceptable-risk practices applied from 2 February 2025 and GPAI obligations from 2 August 2025. The regulation became generally applicable and enforceable on 2 August 2026, including the Article 50 transparency obligations. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force from 27 July 2026, deferred the Chapter III high-risk obligations to 2 December 2027 for systems classified as high-risk under Annex III and to 2 August 2028 for systems classified as high-risk under Annex I.

Does the EU AI Act apply to companies outside the EU?

Yes. Under Article 2, the regulation applies to providers and deployers established outside the EU whenever the output of their AI system is used within the Union, regardless of where the company is headquartered.

What is the maximum fine under the EU AI Act?

Article 99 sets the maximum administrative fine at €35 million or 7% of total worldwide annual turnover (whichever is higher) for the use of prohibited AI practices. Other violations carry lower ceilings of €15 million or 3% (high-risk non-compliance) and €7.5 million or 1% (incorrect information to authorities).

What is the difference between a provider and a deployer under the EU AI Act?

A provider (Article 3(3)) develops an AI system or general-purpose AI model and places it on the market under its own name or trademark. A deployer (Article 3(4)) uses an AI system under its authority in a professional capacity. Providers bear most of the high-risk system obligations; deployers have a narrower set focused on monitoring and oversight.

What are the four risk categories in the EU AI Act?

Unacceptable risk (prohibited under Article 5), high risk (Articles 6–7 plus Annexes I and III, with full Chapter III obligations), limited risk (Article 50 transparency obligations), and minimal risk (no obligations beyond existing law).

Does the EU AI Act apply to ChatGPT and other large language models?

Yes. Large language models fall under the General-Purpose AI Model regime in Chapter V. All GPAI providers must maintain technical documentation, publish training-data summaries, and respect copyright. Models trained with more than 10^25 FLOPs are presumed to pose systemic risk and face additional obligations including model evaluation, adversarial testing, and incident reporting.

Make Your AI Auditable and Compliant

Ctrl AI provides expert-verified reasoning units with full execution traces — the infrastructure you need for EU AI Act compliance.

Explore Ctrl AI

Related Articles