European Union

The EU AI Act

The first comprehensive, horizontal AI statute from a major regulator — risk-tiered, phased in over several years, and already shaping how other jurisdictions draft their own AI laws.

Phasing inEffective August 1, 2024
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash
Governome Editorial Team4 min readHow we source and review this content.

The EU AI Act entered into force on August 1, 2024, but "in force" and "fully applicable" are different things for this law — its obligations phase in over roughly three years, and a system that's out of scope today can come into scope as later provisions activate. Treat this page as the status summary, not a substitute for the classification work your specific system needs.

The risk-tier structure

The Act sorts AI systems into four tiers, and the obligations attach to the tier, not to the technology:

  • Unacceptable risk — practices banned outright: social scoring by public authorities, certain forms of manipulative AI, untargeted scraping of facial images for recognition databases, among others. These prohibitions were among the first provisions to take effect — see our full breakdown of every Article 5 prohibited practice.
  • High-risk — systems subject to the Act's most substantial obligations: a maintained risk management system, data governance, technical documentation, logging, transparency, human oversight, and defined accuracy/robustness/cybersecurity standards, including the instructions for use a provider must give deployers. Classification runs through Article 6 — see our full breakdown of how that test actually works.
  • Limited risk — systems (like most chatbots) that face specific transparency obligations, such as disclosing that a user is interacting with AI, without the full high-risk compliance burden.
  • Minimal risk — the majority of AI applications, largely unregulated by the Act itself beyond voluntary codes of conduct.

What's actually in force right now

  • Prohibited practices and AI-literacy obligations — applicable since February 2025.
  • General-purpose AI (GPAI) model obligations — the Article 51-56 transparency and systemic-risk track — applicable since August 2025, and directly enforced at EU level by the EU AI Office rather than by national regulators. Most major providers demonstrate compliance with this track by signing the GPAI Code of Practice, which trades a presumption of conformity for a specific set of documentation, copyright, and safety-reporting commitments.
  • High-risk system obligations — phasing in on the longest timeline, and pushed later than originally planned: the July 2026 Digital Omnibus on AI moved the Annex III high-risk deadline from August 2026 to December 2, 2027, and the Annex I product-embedded deadline from August 2027 to August 2, 2028. Once a high-risk system clears conformity assessment, providers signal that outcome with CE marking, the same visible-compliance mechanism used across EU product law.

For the full corrected schedule — what's live, what moved, and why — see our complete EU AI Act implementation timeline. Check the effective-date field on this page rather than assuming — we update it when the underlying schedule or guidance changes, and enforcement bodies have signaled some willingness to phase in practical enforcement gradually even after formal applicability dates pass.

Who the Act actually applies to

The Act applies extraterritorially, similarly to the GDPR: providers and deployers outside the EU are in scope if the AI system's output is used within the EU. A U.S. or UK company with no EU office can still fall within scope if it sells or deploys a system that affects people in the EU — this is the single most commonly missed scope question in early compliance planning, and our full breakdown of the Article 2 extraterritorial-scope triggers walks through exactly when a non-EU company is, and isn't, actually covered. The two regulations aren't the same obligation twice, either — see where the AI Act and GDPR actually overlap and where they diverge for what a GDPR-compliant company still has to build separately.

Penalties

Penalties are tiered by violation type, with the most severe reserved for violations of the prohibited-practices provisions — up to the higher of a fixed amount in the tens of millions of euros or a percentage of global annual turnover, a structure that mirrors GDPR's own penalty tiers. For the full breakdown of all three Article 99 tiers, the separate fine track for general-purpose AI model providers, and how the calculation changes for SMEs, see our complete guide to the EU AI Act's tiered penalty structure.

Where to go next

If you're trying to determine whether a specific system is high-risk, our Article 6 classification breakdown walks through the actual two-track test. For how EU AI Act obligations compare with what's expected under ISO/IEC 42001, see our ISO 42001 coverage — the standard is increasingly used as a practical route to demonstrating EU AI Act conformity.

Sources & references

  1. Official source
  2. Regulation (EU) 2024/1689 (full text, EUR-Lex)
  3. European Commission — AI Act overview
Legal and compliance professionals reviewing which AI practices are prohibited under the EU AI Act
Photo: Leon Seibert via Unsplash
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Governome Editorial Team · 8 min read
Compliance team running a risk management review meeting around a whiteboard
Photo: Fiqih Alfarish via Unsplash
Article 9 requires high-risk AI providers to run a continuous risk management process across the system's entire lifecycle, not produce a one-time document. Here's what the process actually has to include, and the gap auditors flag most.
Governome Editorial Team · 7 min read
Data science team reviewing training data governance documentation
Photo: Jakub Żerdzicki via Unsplash
Article 10 requires documented data governance practices for training, validation, and testing data — provenance, bias examination, gap identification, and relevance to intended purpose — a materially different and broader standard than generic data cleaning. Here's what it actually covers.
Governome Editorial Team · 4 min read
Compliance team assembling technical documentation for a high-risk AI system
Photo: Vitaly Gariev via Unsplash
Article 11 requires a technical documentation file, built before market placement and kept current, that lets regulators verify a high-risk system's compliance. Annex IV's scope is real, but the more expensive mistake is assembling it retroactively instead of incrementally — here's what's actually required.
Governome Editorial Team · 5 min read
Engineers reviewing automated system logs on server monitoring screens
Photo: Tyler via Unsplash
Article 12 requires high-risk AI systems to automatically log events built for three specific purposes — risk identification, post-market monitoring, and deployer oversight — plus an extra minimum spec for remote biometric identification systems. Generic application logs rarely satisfy all three by accident.
Governome Editorial Team · 5 min read
Compliance reviewer checking a technical documentation package against requirements
Photo: Vitaly Gariev via Unsplash
Article 13 requires high-risk AI providers to produce instructions for use that let deployers interpret and correctly apply the system's output. It's routinely confused with end-user AI disclosure rules elsewhere in the Act — here's what it actually requires and why the distinction matters.
Governome Editorial Team · 6 min read
Compliance team reviewing human oversight design for a high-risk AI system
Photo: Benjamin Child via Unsplash
Article 14 requires human oversight measures that give a person real capability to understand, monitor, interpret, and override a high-risk AI system — not a procedural approval step. Here's the five specific capabilities the Act requires, including the automation-bias problem most teams never design for.
Governome Editorial Team · 5 min read
Security analysts reviewing AI-specific threat monitoring for a high-risk system
Photo: Rob Simmons via Unsplash
Article 15 requires high-risk AI systems to meet defined, maintained levels of accuracy, robustness, and cybersecurity — including AI-specific threats like data and model poisoning that a standard application security review typically doesn't test for. Here's what's actually required, and who tends to miss it.
Governome Editorial Team · 5 min read
Engineers and compliance staff reviewing technical documentation for a general-purpose AI model
Photo: selcuk sarikoz via Unsplash
Articles 51 through 56 of the EU AI Act put a separate, model-level obligations track on any provider of a general-purpose AI model — documentation, copyright, and training-data transparency for everyone, with a further layer of testing and incident-reporting duties for the models classified as posing systemic risk. Here's exactly what applies to whom, and what open source does and doesn't exempt.
Governome Editorial Team · 9 min read
Compliance and legal professionals comparing two separate regulatory frameworks in a meeting
Photo: Vitaly Gariev via Unsplash
Article 2(7) of the EU AI Act states plainly that the Act applies without prejudice to the GDPR. The two regimes overlap on automated decision-making and impact assessments, but diverge on scope triggers, risk classification, and enforcement — and meeting one doesn't discharge the other.
Governome Editorial Team · 7 min read
Compliance and legal professionals reviewing AI system documentation together
Photo: Sherwin Ker via Unsplash
Article 6 of the EU AI Act classifies a system as high-risk through a combination of Annex I product-safety overlap and Annex III use-case categories. Here's how the two-step test actually applies, with the exemption most teams get wrong.
Governome Editorial Team · 3 min read
Auditor reviewing AI management system documentation for certification
Photo: Zulfugar Karimov via Unsplash

frameworks

ISO/IEC 42001

ISO/IEC 42001 is a certifiable AI management system standard. Unlike the NIST AI RMF, an accredited body can actually audit you against it and issue a certificate.
Governome Editorial Team · 2 min read
An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.
Governome Editorial Team · 2 min read
The formal process a high-risk AI system goes through to demonstrate it meets the EU AI Act's requirements — internal self-assessment for most Annex III systems, or third-party assessment where a notified body is involved — before the system can be placed on the market or put into service.
Governome Editorial Team · 2 min read
Compliance team reviewing conformity assessment documentation for a high-risk AI system
Photo: Zulfugar Karimov via Unsplash
Article 43 conformity assessment has two routes: internal control, which covers most high-risk systems and involves no external reviewer at all, and notified-body assessment, reserved for a narrow slice of biometric systems. Here's how each one actually works, what gets produced, and what forces a redo.
Governome Editorial Team · 7 min read
Compliance team reviewing CE marking documentation for a high-risk AI system before EU market placement
Photo: Vitaly Gariev via Unsplash
CE marking under Article 48 of the EU AI Act is the provider's own compliance signal, applied after conformity assessment — for most high-risk systems, with no external body involved at all. Here's what has to be visible, legible, and indelible, how digital marking works for software-delivered AI, and what importers have to verify before a marked system reaches the EU market.
Governome Editorial Team · 8 min read
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
Governome Editorial Team · 7 min read
Compliance team calculating potential EU AI Act fine exposure across the tiered penalty structure
Photo: Vitaly Gariev via Unsplash
EU AI Act fines aren't a single €35 million number. Article 99 defines three separate tiers by violation type, Article 101 sets a fourth track for general-purpose AI model providers enforced directly by the Commission, and Article 100 even reaches EU institutions themselves. Here's the full structure, including the SME inversion rule that changes real exposure by orders of magnitude.
Governome Editorial Team · 7 min read
European Union policy officials reviewing a phased regulatory implementation schedule
Photo: Zoshua Colah via Unsplash
The EU AI Act's original phased schedule got rewritten mid-2026: the Digital Omnibus on AI pushed the high-risk-system deadline from August 2026 to December 2027, and the product-embedded high-risk deadline from August 2027 to August 2028. Article 5 prohibited practices, GPAI obligations, and the governance framework weren't touched. Here's what's actually in force right now, what moved, what didn't, and why.
Governome Editorial Team · 8 min read
Legal and compliance team at a non-EU company reviewing whether the EU AI Act applies to their AI system
Photo: Zulfugar Karimov via Unsplash
The EU AI Act doesn't ask where your company is incorporated. Article 2 sets two independent triggers — placing an AI system on the EU market, and having its output used in the Union — and the second one catches non-EU companies with no EU office, no EU sale, and no EU contract at all. Here's how both triggers actually work, what genuinely takes a company out of scope, and what happens next once you're in it.
Governome Editorial Team · 8 min read
Legal and compliance staff reviewing the commitments in the EU's GPAI Code of Practice
Photo: Anastassia Anufrieva via Unsplash
The EU AI Act's General-Purpose AI Code of Practice gets covered as a headline — 'OpenAI and Anthropic signed a pledge' — when it's actually three chapters of specific, auditable commitments tied to Article 53 and 55 obligations. Here's what a signatory agrees to do, chapter by chapter, and what happens to a provider that skips it or signs only part.
Governome Editorial Team · 7 min read