AI Policy Wiki
Dashboard

EU AI Act (Regulation 2024/1689)

medium confidence · updated 2026-07-27

The European Union's comprehensive AI regulation — risk-based framework with four risk tiers, prohibited practices, high-risk requirements, transparency duties, and general-purpose AI rules including systemic risk provisions, plus the scope exclusions and open-source carve-outs that bound all of them.

The EU AI Act is the European Union's comprehensive AI law, enacted by the European Parliament and Council and published in the Official Journal as L 2024/1689 on June 13, 2024. It is described as the world's first comprehensive AI law and creates a risk-based regulatory framework covering AI systems placed on the EU market or affecting EU residents. The Act establishes four risk tiers (prohibited, high-risk, general-purpose AI, and limited/minimal risk), mandatory compliance obligations for the higher-risk categories, and a governance architecture at both EU and member-state levels.

The Act took effect August 1, 2024, with phased implementation: prohibited practices operative in February 2025, GPAI rules from August 2025, and high-risk obligations from August 2026.

Definition of an AI system

Article 3(1) defines an AI system as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments." Article 3(2) defines risk as "the combination of the probability of an occurrence of harm and the severity of that harm."

Scope and addressees

Article 2(1) lists seven categories of addressee: providers placing AI systems on the Union market or placing general-purpose AI models on it, "irrespective of whether those providers are established or located within the Union or in a third country"; deployers established or located in the Union; providers and deployers established in a third country "where the output produced by the AI system is used in the Union"; importers and distributors; product manufacturers placing an AI system on the market together with their product under their own name or trademark; authorised representatives of non-Union providers; and affected persons located in the Union.

The third of these is the Act's principal extraterritorial hook: a system built and operated outside the Union falls in scope where its output is used inside it.

Exclusions

A set of exclusions in Article 2 bounds the Regulation before any risk tier is reached:

ProvisionExcluded
Art. 2(3)Areas outside the scope of Union law; Member State competences over national security; AI systems placed on the market, put into service, or used "exclusively for military, defence or national security purposes, regardless of the type of entity"; and systems outside the Union whose output is used in the Union exclusively for those purposes
Art. 2(4)Third-country public authorities and international organisations using AI under law-enforcement and judicial-cooperation agreements with the Union, subject to adequate fundamental-rights safeguards
Art. 2(6)AI systems and models "specifically developed and put into service for the sole purpose of scientific research and development"
Art. 2(8)Any research, testing or development activity prior to placing on the market or putting into service — but "testing in real world conditions shall not be covered by that exclusion"
Art. 2(10)Deployers who are natural persons using AI in a "purely personal non-professional activity"
Art. 2(12)AI systems released under free and open-source licences, "unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50"

Article 2(11) preserves Member State freedom to maintain or introduce provisions more favourable to workers, and to encourage collective agreements to that effect. Article 2(5) leaves untouched the intermediary-liability regime of the Digital Services Act (Regulation (EU) 2022/2065). Article 2(7) preserves the application of EU data-protection law, without prejudice to Articles 10(5) and 59 of the AI Act itself.

The open-source carve-out at Article 2(12) and its general-purpose counterpart at Article 53(2) are the Act's principal accommodation of open-weight release, and are narrower than they first appear: neither reaches prohibited practices, high-risk systems, the Article 50 transparency duties, or GPAI models with systemic risk. See Open-Weight Frontier Models.

Risk-tier architecture

The Act sorts AI systems into four tiers, each carrying different obligations.

TierExamplesObligations
Prohibited (Art. 5)Social scoring, real-time biometric surveillance, subliminal manipulationComplete ban
High-risk (Annex III)AI in critical infrastructure, employment, education, law enforcementConformity assessment, registration, CE marking
GPAI with systemic risk (Arts. 51-56)Models trained with >10^25 FLOPEnhanced evaluation, adversarial testing, incident reporting
GPAI (Arts. 53-56)General-purpose modelsTechnical documentation, copyright compliance
Limited/minimal riskMost AI applicationsTransparency obligations only

Prohibited practices (Article 5)

The Act bans eight practices outright:

  1. Subliminal manipulation techniques causing harm
  2. Exploitation of vulnerability groups (age, disability, social situation)
  3. Government social scoring of natural persons
  4. Real-time remote biometric surveillance in public spaces (with exceptions)
  5. Retrospective remote biometric identification systems (with law enforcement exceptions)
  6. Emotion inference in workplaces or educational settings
  7. Biometric categorization to infer sensitive characteristics (race, political opinion, etc.)
  8. Predictive policing based purely on profiling

AI literacy (Article 4)

Providers and deployers must "take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf," calibrated to those persons' technical knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used. The obligation is horizontal — it attaches regardless of risk tier — and carries no conformity-assessment or registration machinery.

Classification as high-risk (Article 6)

Two independent routes lead to the high-risk tier.

The product-safety route (Art. 6(1)) applies where both conditions are met: the AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I; and that product is required to undergo a third-party conformity assessment under that legislation. This route attaches to the existing CE-marking regime rather than creating a parallel one. For Annex I Section B products, Article 2(2) narrows the Act's application to Article 6(1), Articles 102 to 109, and Article 112.

The listed-use-case route (Art. 6(2)) designates the systems enumerated in Annex III — critical infrastructure, employment, education, access to essential services, law enforcement, migration, justice, and democratic processes.

The derogation (Art. 6(3)) removes an Annex III system from the high-risk tier where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making," and where any of four conditions holds: the system performs a narrow procedural task; improves the result of a previously completed human activity; detects decision-making patterns or deviations from them without being meant to replace or influence the prior human assessment absent proper human review; or performs a preparatory task to an Annex III assessment. An override follows immediately: "an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."

A provider invoking the derogation must document the assessment before placing the system on the market, remains subject to the registration obligation in Article 49(2), and must produce the documentation on request (Art. 6(4)). Article 6(5) required the Commission, after consulting the AI Board, to issue practical-implementation guidelines with "a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk" no later than 2 February 2026. Articles 6(6) and 6(7) empower the Commission to add, modify, or delete the derogation conditions by delegated act; Article 6(8) provides that no such amendment may decrease the overall level of protection.

High-risk system obligations (Arts. 9-15)

High-risk categories are listed in Annex III: critical infrastructure, employment, education, access to essential services, law enforcement, justice, and democracy. AI systems in these categories must meet requirements for a risk management system throughout the lifecycle; training, validation, and testing data governance; technical documentation; record-keeping and logging; human oversight measures; and accuracy, robustness, and cybersecurity. Before market placement they require conformity assessment and registration in an EU database.

Providers who consider a system they have placed on the market to be non-conforming must "immediately take the necessary corrective actions" to bring it into conformity, withdraw, disable, or recall it, and inform distributors, deployers, authorised representatives and importers (Art. 20(1)). Where the system presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes in collaboration with the reporting deployer and inform the competent market surveillance authorities and any notified body (Art. 20(2)). Article 21 requires providers to supply competent authorities, on reasoned request, with the information and documentation necessary to demonstrate conformity, in an official Union language indicated by the Member State.

Fundamental rights impact assessment (Article 27)

Before deploying an Article 6(2) high-risk system, deployers that are bodies governed by public law or private entities providing public services — and deployers of the systems at Annex III points 5(b) and (c) — must assess the system's impact on fundamental rights. Systems in the Annex III point 2 area are excepted. The assessment must describe the deployer's processes in which the system will be used in line with its intended purpose, the period and frequency of intended use, and the categories of natural persons and groups likely to be affected in the specific context.

Serious incident reporting (Article 73)

Providers of high-risk systems placed on the Union market must report any serious incident to the market surveillance authorities of the Member State where it occurred, "immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link," and in any event no later than 15 days after becoming aware of it. The reporting period is to take account of the incident's severity.

Real-world testing (Article 60)

Providers and prospective providers of Annex III high-risk systems may test them in real-world conditions outside regulatory sandboxes, at any time before placing on the market, alone or in partnership with deployers, subject to a real-world testing plan whose elements the Commission specifies by implementing act. The Article operates "without prejudice to the prohibitions under Article 5" and to any ethical review required by Union or national law.

Transparency obligations (Article 50)

Article 50 attaches to certain systems irrespective of risk tier:

  • Human-interaction disclosure (50(1)). Providers must design systems intended to interact directly with natural persons so that those persons are informed they are interacting with an AI system, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect." Systems authorised by law to detect, prevent, investigate or prosecute criminal offences are exempt unless publicly available for reporting offences.
  • Synthetic-content marking (50(2)). Providers of AI systems generating synthetic audio, image, video or text — "including general-purpose AI systems" — must ensure outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated," with solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible." The obligation does not reach systems performing an assistive function for standard editing or not substantially altering the deployer's input data or its semantics.
  • Emotion recognition and biometric categorisation (50(3)). Deployers must inform exposed persons of the system's operation and process personal data in accordance with EU data-protection law.
  • Deepfake disclosure (50(4)). Deployers generating or manipulating image, audio or video content constituting a deep fake must disclose that it is artificially generated or manipulated. Where the content forms part of "an evidently artistic, creative, satirical, fictional or analogous work or programme," the duty narrows to disclosing the existence of such content "in an appropriate manner that does not hamper the display or enjoyment of the work." Deployers of systems generating or manipulating text "published with the purpose of informing the public on matters of public interest" must likewise disclose, except where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

Information must be provided clearly and distinguishably "at the latest at the time of the first interaction or exposure" and must meet applicable accessibility requirements (50(5)). Article 50(7) directs the AI Office to encourage codes of practice on detection and labelling of generated content, with a fallback under which the Commission may specify common rules by implementing act if it deems a code inadequate.

General-purpose AI (GPAI) model rules

Models trained with cumulative compute exceeding 10^25 FLOP are classified as GPAI models with systemic risk. As of 2024, this threshold captured the GPT-4 class of models.

Article 51(1) supplies two independent classification triggers: the model "has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks"; or the Commission decides, ex officio or "following a qualified alert from the scientific panel," that it has capabilities or impact equivalent to that, judged against the criteria in Annex XIII. The compute figure enters as a presumption rather than a definition: a model "shall be presumed to have high impact capabilities" when cumulative training compute exceeds 10^25 floating-point operations (Art. 51(2)). Article 51(3) empowers the Commission to amend the thresholds and supplement the benchmarks and indicators by delegated act "in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency."

Article 52 sets the procedure: a provider meeting the high-impact-capability condition must notify the Commission "without delay and in any event within two weeks," and the Commission may designate an unnotified model itself. The presumption is rebuttable — a provider may present with its notification "sufficiently substantiated arguments to demonstrate that, exceptionally," the model does not present systemic risks "due to its specific characteristics."

GPAI models with systemic risk carry obligations under Articles 51-56: adversarial testing and red-teaming, serious incident reporting to the EU AI Office, cybersecurity measures, energy efficiency disclosures, and notification when the systemic risk threshold is crossed. Article 55(1) states these as four duties additional to Articles 53 and 54: model evaluation "in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing"; assessment and mitigation of "possible systemic risks at Union level, including their sources"; tracking, documenting and reporting serious incidents and corrective measures to the AI Office without undue delay; and "an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model."

Standard GPAI obligations comprise technical documentation, a copyright policy and compliance with EU Directive 2019/790, a publicly available summary of training data, and a model card. Article 53(1) states them as four: keeping up-to-date technical documentation including the training and testing process and evaluation results, meeting at minimum the Annex XI content, for provision on request to the AI Office and national authorities; making documentation available to downstream providers integrating the model, sufficient for them "to have a good understanding of the capabilities and limitations" and to meet their own obligations, containing at minimum the Annex XII elements, without prejudice to intellectual property and trade secrets; putting in place a policy to comply with Union copyright law, "in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790"; and drawing up and making public "a sufficiently detailed summary about the content used for training," to an AI Office template.

The open-source GPAI exemption (Art. 53(2)) disapplies the first two of those duties — technical documentation and downstream documentation — for "providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available." The copyright-policy and training-data-summary duties are unaffected. The final sentence removes the exemption entirely at the systemic-risk tier: "This exception shall not apply to general-purpose AI models with systemic risks."

Article 53(4) routes compliance through soft law until standards exist: providers "may rely on codes of practice within the meaning of Article 56 to demonstrate compliance … until a harmonised standard is published," and compliance with European harmonised standards "grants providers the presumption of conformity." A provider adhering to neither "shall demonstrate alternative adequate means of compliance for assessment by the Commission." See EU General-Purpose AI Code of Practice (2025). Article 53(7) subjects information obtained under the Article, including trade secrets, to the confidentiality regime in Article 78.

Penalties

ViolationMaximum fine
Prohibited practices€35M or 7% of global annual turnover
High-risk violations€15M or 3% of global turnover
Incorrect information€7.5M or 1.5% of global turnover

The ceilings are set by Article 99(3) and (4) as "up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher," and the corresponding €15M / 3% figure for the operator and notified-body obligations in Articles 16, 22, 23 and related provisions. The rules themselves are laid down by Member States rather than by the Regulation: Article 99(1) requires penalties and other enforcement measures — which "may also include warnings and non-monetary measures" — to be "effective, proportionate and dissuasive," and to "take into account the interests of SMEs, including start-ups, and their economic viability." Member States were required to notify the Commission of those rules by the date of entry into application (Art. 99(2)).

Governance architecture

The Act creates a multi-level governance structure:

  • EU AI Office (within the European Commission) — oversight of GPAI models with systemic risk and enforcement against GPAI providers.
  • National competent authorities — oversight of high-risk AI systems in their jurisdiction.
  • AI Board — coordination among member states.
  • Scientific panel — independent experts advising on systemic risk. Article 51(1)(b) gives the panel a concrete lever: a qualified alert can prompt a Commission decision to classify a model as carrying systemic risk.

Application dates (Article 113)

The Regulation entered into force on the twentieth day following publication and "shall apply from 2 August 2026," subject to three staggered exceptions:

ProvisionsApply from
Chapters I and II (general provisions; prohibited practices)2 February 2025
Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 — notifying authorities and notified bodies, general-purpose AI models, governance, and confidentiality — with the exception of Article 1012 August 2025
Article 6(1) and its corresponding obligations — the Annex I product-safety route to high-risk classification2 August 2027

The general 2 August 2026 date therefore brings in the Annex III route to high-risk classification and its obligations, while the product-embedded route follows a year later.

Implementation (2026)

The Act's text is in force, but its rollout differs between the Commission layer and the member-state layer, with the member-state layer behind schedule, according to EU AI Office — GPAI Provider Guidelines and Enforcement Framework.

At the Commission and AI Office level, the office is operational with 125+ staff across six units. GPAI obligations have applied since 2 August 2025, and enforcement powers including fines activate 2 August 2026. The interpretive Guidelines on GPAI providers were last updated 26 March 2026, and documentation intake runs through the EU SEND platform.

At the member-state level, the deadline for designating national competent authorities and single points of contact was 2 August 2025. As of March 2026, only 8 of 27 Member States had designated a single point of contact, a gap affecting high-risk system oversight (not GPAI, which the Commission handles directly). The Digital Simplification Package (November 2025) proposes further centralisation of GPAI oversight at the Commission, partly in response to the fragmented member-state picture. The result is that GPAI supervision is operational and approaching full enforcement power, while high-risk system enforcement is formally in force but operationally patchy.

Subsequent amendment activity, including the Digital Omnibus on AI, is recorded on EU AI Act (Regulation 2024/1689); this page documents the Regulation as published.

Tensions and debates

The 10^25 FLOP systemic risk threshold has been described as an industry-lobbied compromise. At the Act's passage, only GPT-4 class models exceeded it, and models trained with 10^24 FLOP may still pose systemic risks. The Regulation's own text anticipates the threshold aging: Article 51(3) provides for amendment by delegated act to reflect algorithmic improvements and hardware efficiency, and Article 51(1)(b) supplies a capability-and-impact route that does not depend on the compute figure at all.

The EU Act is the only framework that directly regulates model developers based on the model itself (the compute threshold) rather than its downstream application. All eight US regulatory approaches regulate AI by application or deployment context.

High-risk obligations fall primarily on deployers in the EU rather than developers outside the EU, which creates enforcement challenges for models developed in the US or China.

Training data summary requirements are contested by AI developers, who argue that transparency on proprietary training data creates competitive disadvantage. The duty survives the open-source exemption in Article 53(2), which reaches only the technical- and downstream-documentation obligations.

Relationships