European Union Artificial Intelligence Act
Start with the intended purpose of each AI system, your role and its EU connection. Check prohibited uses, high-risk classification, transparency duties and any GPAI model-provider obligations separately. Providers and deployers have different duties; record the applicable rules, evidence gaps and current application dates before deciding what to implement.
Updated 2026-09-06 · 79 tracked updates
The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It establishes a risk-based classification system for AI systems and imposes obligations on providers and deployers proportionate to the level of risk their AI systems pose.
Who Needs to Comply?
Applicability depends on the AI system, your role and its EU connection. The Act covers providers, deployers, importers and distributors in specified circumstances, including some organizations outside the EU whose systems' outputs are used in the EU. Check the scope exclusions and the duties attached to each role.
Key Dates & Timeline
Entered into force August 2024. The original prohibited practices apply from February 2025 and GPAI provider duties from August 2025, subject to transitional rules. Article 50 transparency duties apply from 2 August 2026, with a transition for certain existing generative AI systems. The Digital Omnibus, in force since July 2026, sets 2 December 2026 for its new Article 5 prohibitions and defers high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Verify the provisions and transitions relevant to your system.
Upcoming Milestones
ECB-requested comprehensive action plan for significant institutions
ESRB Warning on systemic cyber risks from frontier AI modelsArticle 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply
Digital Omnibus on AI amends the EU AI ActProviders of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026
Digital Omnibus on AI amends the EU AI ActEstimated deadline for adoption of Conference of the Parties rules of procedure after entry into force
Council of Europe AI Framework Convention publishedCommission deadline to publish AI Act guidance on complementarity and proportionality for Annex I-sector AI systems
Digital Omnibus on AI amends the EU AI ActLatest EU AI Act Updates
AI Act consultations and implementation guidance for GPAI, sandboxes, and transparency
The Commission has opened or advanced multiple AI Act implementation workstreams for GPAI, high-risk classification, transparency, and regulatory sandboxes, meaning providers and deployers must now align their implementation plans to the emerging guidance rather than wait for finalised national practice.
EU AI Act implementation consultations advance on GPAI, transparency, high-risk classification and sandboxes
The Commission’s AI Act consultations on GPAI, transparency obligations, high-risk classification, sandboxes, and the scientific panel show that the operational rulebook is still being finalized, so affected providers should engage now to shape interpretation.
EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services
On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.
EU AI Office and supervisors call for enhanced governance for frontier AI in financial services
EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.
EU AI Office and Commission implementation guidance for AI Act and GPAI code
The Commission and AI Office have moved from policy design into active AI Act implementation by issuing operational guidance on transparency, GPAI obligations, and governance, making immediate compliance mapping necessary for providers facing Article 50 and GPAI code expectations.
CJEU preliminary reference on whether AI software can be a high-risk AI system
A 2026 CJEU preliminary reference asks whether software using AI elements qualifies as a high-risk AI system, which could materially affect classification, oversight, and traceability expectations under the AI Act.
EU AI Office promotes Code of Practice on transparency of AI-generated content
The AI Office’s transparency code for AI-generated content is designed to support Article 50 compliance and applies from 2026-08-02, so content provenance and labeling controls now need to be operationalized.
EU AI Office publishes GPAI compliance guidance and transparency obligations
The European Commission’s AI Office issued GPAI and transparency guidance in 2026 and confirmed that full enforcement of GPAI and transparency obligations begins on 2026-08-02, creating an immediate deadline for providers and deployers.
Commission publishes transparency guidance under the AI Act
The Commission published guidance on Article 50 transparency obligations ahead of the 2 August 2026 applicability date, so providers and deployers now need to operationalize labeling and disclosure workflows rather than wait for enforcement to start.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
How do I comply with the EU AI Act?
Start with the intended purpose of each AI system, your role and its EU connection. Check prohibited uses, high-risk classification, transparency duties and any GPAI model-provider obligations separately. Providers and deployers have different duties; record the applicable rules, evidence gaps and current application dates before deciding what to implement.
What is the EU AI Act?
The EU AI Act is the European Union's comprehensive regulation governing artificial intelligence. It creates a risk-based classification system — from minimal risk to unacceptable risk — and sets requirements for AI system transparency, human oversight, data quality, and accountability.
Who needs to comply with the EU AI Act?
Providers, deployers, importers and distributors can have different duties, depending on the system and its EU connection. Certain providers and deployers outside the EU are also covered when system outputs are used in the EU. Article 2 contains scope rules and exclusions; using an AI tool does not by itself make an organization a GPAI model provider.
What are the penalties for non-compliance with the EU AI Act?
Article 99 sets maximum fines of 35 million euros or 7% of worldwide annual turnover for prohibited practices, 15 million euros or 3% for specified other violations, and 7.5 million euros or 1% for incorrect, incomplete or misleading information supplied in response to specified requests. Which ceiling applies depends on the infringement and enterprise category; special rules apply to SMEs and small mid-caps.
What AI systems are prohibited under the EU AI Act?
Article 5 prohibits specified harmful manipulation, exploitation of vulnerabilities, certain social scoring, untargeted facial-image scraping and specified biometric or emotion-recognition uses, among other practices. Each prohibition has defined conditions and possible exceptions. The social-scoring restriction is not limited to governments; check the current article and application date for the intended use.
How does the EU AI Act classify AI risk levels?
The Commission describes unacceptable, high, limited and minimal risk. For an actual review, check prohibited practices under Article 5, high-risk criteria under Article 6 and the relevant annexes, and transparency duties under Article 50 separately. GPAI model obligations and your provider or deployer role also matter; a risk label alone does not determine every duty.
Keep exploring
This hub tracks published regulatory actions; it is not legal advice and cannot replace counsel review for high-risk classifications.