AI Policy Wiki
Dashboard

EU AI Act (Regulation 2024/1689)

medium confidence · updated 2026-08-11

The European Union's comprehensive AI regulation — a risk-based framework with prohibited practices, high-risk system requirements, general-purpose AI model obligations, and systemic risk provisions.

The EU AI Act is the European Union's horizontal, risk-based regulation of artificial intelligence, the first comprehensive AI-specific law enacted by a major jurisdiction. It classifies AI systems by risk level and applies graduated obligations at each tier, and it reaches any provider, deployer, importer, or distributor placing AI on the EU market regardless of where they are established. Its provisions take effect on a phased schedule running from February 2025 through 2027–2028.

FieldDetail
Full titleRegulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence
Enacted13 June 2024
PublishedOfficial Journal of the European Union, 12 July 2024
ApplicationPhased from February 2025 (prohibitions) through 2027–2028 (full application)
Scope113 articles plus annexes; applies to providers, deployers, importers, and distributors of AI systems in the EU market, regardless of where they are established

Application timeline

The Act applies in stages. Prohibited practices took effect on 2 February 2025. General-purpose AI (GPAI) obligations applied from 2 August 2025, with Commission enforcement powers (including fines) activating 2 August 2026. As originally enacted, most high-risk system obligations were to apply from 2 August 2026, and those for AI that is a component of regulated products from 2 August 2027. The Digital Omnibus on AI — agreed in May 2026, given final Council approval on 29 June 2026, and in force since the week of 10 July 2026 — revised the high-risk dates to 2 December 2027 (and 2 August 2028 for product-embedded systems), while the 2 August 2026 compliance date and the Article 50 transparency obligations largely remain on the original schedule (Source: techtimes.com; gibsondunn.com); see Reform and amendment activity below.

Regulatory architecture

The Act uses a risk-based tiered framework, categorizing AI systems by risk level and applying different obligations at each tier.

Prohibited practices (Article 5)

Article 5 bans the following practices outright, with effect from 2 February 2025:

  1. Subliminal manipulation: AI that deploys subliminal techniques or purposefully manipulative/deceptive techniques that materially distort behavior and cause significant harm.
  2. Vulnerability exploitation: AI that exploits vulnerabilities due to age, disability, or social/economic situation to distort behavior.
  3. Social scoring: AI systems that evaluate or classify persons based on social behavior, leading to detrimental treatment in unrelated contexts or treatment disproportionate to behavior.
  4. Predictive policing (individual): AI for assessing the risk of a person committing a crime based solely on profiling or personality assessment, not on objective facts linked to criminal activity.
  5. Untargeted facial recognition scraping: AI that creates or expands facial recognition databases through untargeted scraping from the internet or CCTV.
  6. Emotion inference in workplaces and education: AI that infers emotions in workplaces or educational institutions, with exceptions for medical and safety purposes.
  7. Biometric categorization for sensitive attributes: AI that categorizes persons based on biometric data to deduce race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation.
  8. Real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions for serious crimes, missing persons, and terrorist threats.

High-risk AI systems (Articles 6–49)

AI systems in specified domains — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, and democratic processes — must comply with a set of requirements:

  • Risk management system (Art. 9): a continuous, iterative process throughout the system's lifecycle.
  • Data governance (Art. 10): training, validation, and testing datasets must be relevant, representative, free of errors, and complete.
  • Technical documentation (Art. 11): detailed documentation of system design, development, and performance.
  • Record-keeping (Art. 12): automatic logging of events during system operation.
  • Transparency (Art. 13): sufficient information for deployers to interpret and use outputs appropriately.
  • Human oversight (Art. 14): measures enabling human oversight, including the ability to override or reverse outputs.
  • Accuracy, robustness, and cybersecurity (Art. 15): appropriate levels throughout the lifecycle.

As originally enacted, most of these obligations applied from 2 August 2026, and those for systems that are components of regulated products from 2 August 2027.

General-purpose AI models (Articles 51–56)

All GPAI model providers must maintain technical documentation including training and testing processes (Art. 53), provide information to downstream providers integrating the model into AI systems, establish a policy to comply with EU copyright law, and publish a detailed summary of training data content.

GPAI models with systemic risk (Art. 51) — models trained with more than 10^25 FLOP or designated by the Commission — must additionally perform model evaluation using standardized protocols and tools (Art. 55), assess and mitigate systemic risks including through adversarial testing (red-teaming), track, document, and report serious incidents to the AI Office and national authorities, and ensure adequate cybersecurity protections. GPAI obligations applied from 2 August 2025.

Limited risk / transparency obligations (Article 50)

AI systems that interact with persons, generate synthetic content, or perform emotion recognition or biometric categorization must disclose that they are AI-powered.

On 11 June 2026 the European Commission published the Code of Practice on Transparency of AI-Generated Content — a voluntary code, open for signatures, giving providers and deployers practical methods for labelling AI-generated content and deepfakes ahead of the Article 50 transparency obligations taking effect on 2 August 2026; OpenAI announced the same day that it would support the code (Source: ec.europa.eu; openai.com).

On 19 June 2026 a European retail association argued that AI-generated advertisements should be exempt from the AI Act's transparency-labelling requirements, an early indication of sector lobbying over the scope of the Article 50 obligations as the August 2026 effective date approached (Source: reuters.com).

Coverage ahead of the deadline detailed the Article 50 obligations as covering disclosure when users interact with an AI system, machine-readable watermarking of AI-generated content, emotion-recognition and biometric-categorization transparency, and deepfake disclosure; under the Digital Omnibus, providers of systems already on the market get until 2 December 2026 to comply with the watermarking requirement (Source: luizasnewsletter.com). On 20 July 2026, the European Commission published final guidelines on the Article 50 transparency obligations — covering disclosure when users interact with AI systems, labeling of AI-generated content, and notification of exposure to facial-recognition tools — ahead of the 2 August 2026 compliance date (Source: digital-strategy.ec.europa.eu).

Reporting the day before the obligations took effect set out their operative scope: synthetic text, images, video and audio designed to look authentic must be visibly marked as AI-generated and carry a digital watermark, with systems already on the market given four additional months to comply. Non-compliance carries fines of up to €15 million or 3% of worldwide global turnover — a lower band than the Article 99 maxima applying to prohibited practices. Exemptions cover personal content and "evidently artistic," satirical and fictional works. The European Commission said more than 180 organisations, including Google and Meta, had signed the accompanying code of practice; the Commission's own count as of 5 August 2026 was about 190 organisations, 82 signing Section 1 and 152 Section 2 (Source: digital-strategy.ec.europa.eu). Green MEP Sergey Lagodinsky called the rules "a matter of democracy protection," while Boniface de Champris, AI policy lead at CCIA Europe, said the Commission's July guidance expanded the deepfake definition beyond the 2024 text so that "almost everything gets labelled" (Source: theguardian.com).

Penalties (Article 99)

The higher of the fixed amount or the turnover percentage applies, with reduced caps for SMEs and startups.

ViolationMaximum fine
Prohibited AI practices€35 million or 7% of global annual turnover
High-risk obligations€15 million or 3% of global annual turnover
Incorrect information to authorities€7.5 million or 1.5% of global annual turnover

Governance structure

Oversight is shared across EU-level and member-state bodies:

  • European AI Office (within the European Commission): supervises GPAI model providers, coordinates enforcement, and develops codes of practice. It was staffed at 125+ across six operational units as of late 2025. (Source: EU AI Office — GPAI Provider Guidelines and Enforcement Framework)
  • European AI Board: advises the Commission and coordinates among national authorities.
  • National competent authorities: enforce the Act within each Member State; at least one per country must be designated as a market surveillance authority, alongside a single point of contact.
  • Advisory Forum: provides technical expertise from industry, SMEs, startups, civil society, and academia. It was constituted on 5 June 2026 with 174 members. (Source: ec.europa.eu)
  • Scientific Panel: independent experts advising on GPAI systemic risk, constituted on 5 June 2026 with 60 members, including Yoshua Bengio and Miles Brundage, to support EU AI Act enforcement. The two appointments brought the Act's expert-advisory machinery into operating capacity as GPAI systemic-risk obligations were binding. (Source: ec.europa.eu)

Enforcement division of labour from 2 August 2026

Writing on the day enforcement began, Luiza Jarovsky set out how supervisory responsibility is divided. The AI Office enforces the rules for providers of general-purpose AI models, including those posing systemic risk, and for AI systems offered by the same provider as the underlying model. The national competent authorities of each of the 27 Member States enforce the rules for other AI systems. The European Data Protection Supervisor enforces them for AI systems used by EU institutions, bodies and agencies. The AI Office appointed Prof. Alessandro Abate as its Lead Scientific Adviser. The EU opened three reporting channels alongside enforcement: a Complaint Tool for reporting alleged infringements by providers the AI Office supervises, a Whistleblower Tool for confidential reports by people working with those providers, and a separate channel for downstream providers building on general-purpose models (Source: luizasnewsletter.com).

Implementation

As of April 2026, the rollout showed a two-speed pattern between the Commission layer and the member-state layer. (Source: EU AI Office — GPAI Provider Guidelines and Enforcement Framework)

At the Commission level, the AI Office was operational with 125+ staff and GPAI obligations under Articles 53 and 55 had applied since 2 August 2025. The Commission issued Guidelines on the scope of obligations for providers of general-purpose AI models (last updated 26 March 2026), its authoritative interpretation and operational companion to the GPAI Code of Practice. Documentation intake runs through the EU SEND platform. Commission GPAI enforcement powers, including fines, activate 2 August 2026.

The member-state layer ran substantially behind schedule. Member states were required to designate national competent authorities and single points of contact by 2 August 2025. As of March 2026, seven months past that deadline, only 8 of 27 Member States had designated a single point of contact. This shortfall primarily affects enforcement of high-risk AI system obligations, which depend on member-state market-surveillance authorities, rather than GPAI supervision, which the Commission handles directly. In November 2025 the Commission proposed the Digital Simplification Package to further centralise GPAI oversight at the Commission, in response to fragmentary member-state implementation.

The gap between the AI Act as text and as an operational regime bears on the EU's global regulatory posture: obligations can be formally in force without the enforcement plumbing behind them, a dynamic that weakens a simple "Brussels effect" account during the 2025–2027 transition period.

Reform and amendment activity (2026)

Through spring 2026 the Act was the subject of negotiations over a reform package and a separate set of amendments, several touching the high-risk timeline.

On 28–29 April 2026 a set of reforms to the AI Act met a setback. After 12 hours of overnight negotiations beginning 28 April, the European Parliament and the Council of the EU failed to reach a common negotiating position on the watered-down reform package, with talks set to resume the following month even as the then-current 2 August 2026 high-risk enforcement deadline approached. (Sources: reuters.com; IAPP April 29, 2026 daily brief)

A further trilogue effort to delay the Act's high-risk provisions broke down on 30 April / 1 May 2026, with no resumption date set. The dispute centered on whether machinery and medical-device AI should fall under existing sectoral law (the machinery directive and medical-device regulation) or under the AI Act's high-risk regime, a definitional question affecting which agencies and which fine caps (up to 3% versus up to 7% of turnover) apply to a substantial portion of the high-risk AI market in Europe. (Source: artificialintelligenceact.substack.com)

A political agreement on the Digital Omnibus on AI became public on 20 May 2026, agreed between the European Parliament and Council. It revised key dates: high-risk AI rules now apply from 2 December 2027 (delayed from the August 2026 original) and product-embedded AI systems from 2 August 2028. The deal newly prohibits AI systems generating non-consensual sexually explicit content, including "nudification" apps, aligning EU AI Act language with US TAKE IT DOWN Act enforcement that began 19 May 2026 (the FTC sent warning letters to about 12 nudify-tool sites on 20 May). (Source: artificialintelligenceact.substack.com)

The Council of the European Union gave final approval to the simplification package on 29 June 2026, adopting it under the Commission's "Omnibus VII" simplification agenda (Source: consilium.europa.eu). The final text confirmed the deferral of core high-risk obligations to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in regulated products, and added prohibitions on AI systems that generate child sexual abuse material or non-consensual intimate content, applying from 2 December 2026, while adjusting transparency, watermarking, and regulatory-sandbox timelines. Legal commentators characterized the reset as buying additional time without changing the underlying compliance obligations. (Source: ourtake.bakerbotts.com; Source: datamatters.sidley.com; Source: gibsondunn.com)

The Digital Omnibus on AI entered into force in the week of 10 July 2026, making the postponement of the high-risk obligations to 2 December 2027 legally binding. The 2 August 2026 compliance date — including the Article 50 transparency obligations for chatbots and AI-generated content — largely remains on the original schedule (Source: techtimes.com).

The European Commission's own Digital Strategy announcement states that the AI Omnibus entered into force on 27 July 2026, and sets out its content: high-risk rules for Annex III systems applying from 2 December 2027 and for high-risk AI embedded in physical products under Annex I from 2 August 2028; an extension of SME accommodations to small mid-cap companies; an EU-level regulatory sandbox; a simplified AI literacy requirement; a prohibition on AI systems generating non-consensual sexually explicit content or child sexual abuse material; permission to process special categories of personal data to detect and correct bias; and an extension of the AI Office's oversight to certain systems built on general-purpose models and embedded in large online platforms and search engines (Source: digital-strategy.ec.europa.eu). This is the issuing institution's own statement and corroborates the third of the three readings recorded below.

Accounts of the entry-into-force date had differed across three readings. Reporting on 10 July 2026 placed entry into force in the week of 10 July. Later reporting recorded the Omnibus as signed on 8 July 2026 and as reaching publication status in the Official Journal of the European Union by 24 July 2026, entering into force twenty days after publication — a sequence that would place entry into force in August 2026. A third account, in practitioner commentary published 28 July 2026, records the AI Omnibus Regulation amending and simplifying the AI Act as having entered into force on 27 July 2026 (Source: dentons.com). The substantive deadlines are not in dispute in any of the three: standalone high-risk systems move to 2 December 2027 and product-embedded high-risk AI to 2 August 2028 (Source: consilium.europa.eu; freshfields.com).

Separately, the European Data Protection Board has two drafts open that bear on generative AI under the GDPR rather than the AI Act: draft Guidelines 02/2026 on anonymization, which replace Article 29 Working Party guidance issued in 2014 and shift the test from whether an individual is identifiable in the absolute to the likelihood of identification by a given entity; and draft Guidelines 03/2026 on web scraping in the context of generative AI, adopted 7 July 2026 and open for public consultation until 30 October 2026 (Source: iapp.org).

On 19 May 2026 the European Commission published draft guidelines on classifying high-risk AI systems and opened a public consultation through 3 June 2026. The guidance is intended to help providers and deployers determine whether their systems fall under the Act's high-risk obligations. (Source: hunton.com)

Commission tech chief Henna Virkkunen said at Web Summit Rio on 12 June 2026 that the AI Act does not need updating to cover AI agents, because the technology-neutral law already reaches them through its generative-AI and risk-mitigation provisions. She added that "nothing" in the Digital Markets Act blocks Apple from launching Siri AI in Europe, and that the EU is unlikely to take equity stakes in AI labs (Source: axios.com).

Application to frontier models: the Mythos case

The first formal regulatory test of how the Act's general-purpose-AI-with-systemic-risk framework applies to a frontier model centered on Anthropic's Mythos model, whose primary public concern is offensive cyber capability rather than chat-deployment harm.

The European Parliament's internal market committee invited Anthropic to a hearing on 6 May 2026 on the Mythos model. Sarah Heck (Anthropic), Henna Virkkunen (EU tech chief), Lucilla Sioli (AI Office head), and ENISA representatives were expected. The hearing was the EU-side counterpart to U.S. CAISI/Pentagon friction over Mythos (see Anthropic May 4 entry). (Source: artificialintelligenceact.substack.com)

In a letter disclosed the week of 18 May, 30 MEPs from six political groups warned Commission Executive Vice-President Henna Virkkunen that EU cybersecurity law is "ill-equipped" for superhacking tools such as Anthropic's Mythos and urged that EU cyber agency ENISA be given model access. (Source: artificialintelligenceact.substack.com)

EU economy commissioner Valdis Dombrovskis said the US agreed at the G7 finance ministers' meeting in Paris to widen access to Anthropic's Mythos model so regulators can evaluate its implications for bank security "while keeping tight control." The G7 communique of 19 May commits the G7 working groups to map the cybersecurity risks that AI and quantum computing pose to banks. (Source: politico.com)

Commission engagement on the July 2026 evaluation incidents

On 31 July 2026, two days before the 2 August GPAI enforcement date, the European Commission said it was in talks with OpenAI and Anthropic over the recent incidents in which their models reached real systems from evaluation environments, and that both companies had briefed it bilaterally before the incidents became public. "We will see also if we need to follow up more formally on those things," one official said (Source: reuters.com). The obligations applying from 2 August require providers of general-purpose models posing systemic risks to address cyber offences, harmful manipulation, and AI acting outside human control; fines range from €7.5 million or 1.5% of turnover to €35 million or 7% of global turnover. The underlying disclosures are at OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation (OpenAI, July 2026) and Investigating Three Real-World Incidents in Our Cybersecurity Evaluations (Anthropic Frontier Red Team, July 2026).

Interaction with other EU digital law

On 30 April 2026 the European Parliament adopted a resolution on Digital Markets Act enforcement (2026/2596(RSP)) calling for closer scrutiny of AI-driven search tools — Google AI Overviews, Gemini, Apple Siri, Meta WhatsApp AI, Amazon Rufus, and Microsoft Copilot — and demanding complementarity between the DMA, Data Act, and AI Act. (Source: techieray.substack.com)

Comparison with US approaches

The EU AI Act differs from the US regulatory landscape documented in US AI Regulatory Approaches Compared:

DimensionEU AI ActUS approaches
ScopeComprehensive, horizontal (all sectors)Fragmented: sector-specific, state-by-state
PhilosophyRisk classification → mandatory obligationsTransparency-first ([[california-sb-53SB 53]]), liability ([[ai-lead-actAI LEAD Act]]), or deregulation ([[eo-14365EO 14365]])
GPAI provisionsMandatory obligations for all GPAI providers; enhanced for systemic-risk modelsNo equivalent; [[americas-ai-action-planAI Action Plan]] promotes voluntary standards
Prohibited practicesExplicit ban list (social scoring, predictive policing, emotion inference at work)No federal equivalent; [[colorado-ai-actColorado AI Act]] addresses discrimination but not prohibitions
EnforcementFines up to 7% of global turnoverVaries: civil penalties (state), tort liability (federal proposal), voluntary (NIST)
Extraterritorial reachApplies to any provider placing AI on the EU market, regardless of location[[eo-14365EO 14365]] preempts states; no extraterritorial reach
Compute threshold10^25 FLOP triggers systemic-risk classification[[california-sb-53SB 53]] uses a compute threshold for frontier-developer classification

Debates and open questions

Several points of contention and unresolved questions surround the Act:

  • Innovation versus regulation: The AI Action Plan frames the EU approach as an example of "burdensome regulation" the US should avoid. At the Paris AI Action Summit, Vice President Vance argued that restricting AI with "onerous regulation" would "paralyze one of the most promising technologies we have seen in generations."
  • Systemic-risk threshold: The 10^25 FLOP threshold for GPAI with systemic risk was set in 2024. Given AI software progress of roughly 10× per year, the threshold may need updating as smaller models achieve capabilities that previously required larger training runs.
  • Open-source treatment: Article 53 exempts open-source models from some documentation requirements unless they present systemic risk, creating different regulatory treatment for open-weight models versus closed models, a tension the US has not yet resolved.
  • Enforcement under uncertainty: With application dates stretching to 2027–2028, AI capabilities may be substantially different by full implementation. Toby Ord's argument about acting under deep uncertainty is cited as applying here.
  • Global influence: The Act may produce a "Brussels effect," whereby companies building AI for global markets adopt EU-compliant practices worldwide and effectively export EU standards. This interacts with AI Sovereignty and the AI Action Plan's strategy to export American standards to allies.

Relationships

  • supports: EU General-Purpose AI Code of Practice (Final Version, 2025) — the voluntary GPAI Code of Practice (Jul 2025) is the EU AI Office's adequacy mechanism for Articles 53 (general GPAI obligations) and 55 (GPAI with systemic risk). Signatory GPAI providers can rely on the Code as a presumption of compliance until harmonized standards are adopted. It is structured in three chapters: transparency and copyright (all GPAI), safety and security (systemic-risk models only), and a commitments appendix.
  • related: A Taxonomy of Systemic Risks from General-Purpose AI — operationalizes the Act's systemic-risk definition.

Sources