The European Union’s Artificial Intelligence Act (Regulation (EU) 2024/1689), the world’s first comprehensive horizontal legal framework for artificial intelligence, which classifies AI systems into risk tiers — unacceptable, high, limited and minimal — and imposes proportionate obligations on providers and deployers, including conformity assessment, data governance, transparency, human oversight, robustness and post-market monitoring, with extraterritorial reach over any system placed on the EU market and penalties of up to 7% of global annual turnover.

Semantic Classification

Content

Definition

The EU AI Act entered into force on 1 August 2024 as Regulation (EU) 2024/1689, establishing the first binding, economy-wide legal regime for artificial intelligence anywhere in the world. Its central mechanism is a risk-based pyramid: practices deemed an unacceptable risk (social scoring by public authorities, manipulative subliminal techniques, untargeted scraping of facial images, most real-time remote biometric identification in public spaces) are prohibited outright; high-risk systems (in areas such as employment, credit scoring, education, critical infrastructure, law enforcement and medical devices) must satisfy strict requirements before and after market placement; limited-risk systems carry transparency duties such as disclosing that a user is interacting with an AI; and minimal-risk systems remain unregulated.

For high-risk systems the Act mandates a quality-management system, risk management across the lifecycle, training-data governance to limit Algorithmic Bias, technical documentation, record-keeping and logging, human oversight, and demonstrated accuracy, robustness and cybersecurity — obligations verified through conformity assessment and CE marking. A separate chapter added late in negotiation governs general-purpose AI (GPAI) models, imposing documentation and copyright-policy duties on all providers and additional systemic-risk obligations (model evaluation, adversarial testing, incident reporting) on models trained above a compute threshold of 10²⁵ FLOPs.

The Act applies extraterritorially: any provider placing a system on the EU market, or whose system’s output is used in the Union, falls within scope regardless of establishment. Enforcement is shared between national market-surveillance authorities and the European AI Office for GPAI, with fines tiered up to €35 million or 7% of worldwide annual turnover for prohibited practices.

Current Landscape

Application is phased, and the timeline was substantially revised in 2026. Prohibitions and AI-literacy duties applied from 2 February 2025 and GPAI obligations from 2 August 2025. The “Digital Omnibus on AI” (Regulation (EU) 1744/2026, applicable from 27 July 2026) then deferred the bulk of the high-risk regime: obligations for stand-alone Annex III high-risk systems (employment, education, biometrics, law enforcement, critical infrastructure) now apply from 2 December 2027, and those for AI embedded in regulated products under Annex I from 2 August 2028, largely because CEN-CENELEC JTC 21 harmonised standards — whose adoption gives providers a presumption of conformity — were not ready in time.

What the Omnibus did not move: Article 50 transparency duties (disclosing interaction with AI, deepfake labelling) applied on schedule on 2 August 2026 for newly placed systems, with the Article 50(2) machine-readable marking of synthetic content deferred only to 2 December 2026; and the AI Office’s GPAI enforcement powers, including fines, activated on 2 August 2026. The Act continues to function as a de facto global standard through the “Brussels effect”, shaping vendor compliance programmes far beyond Europe.

Sources: