European Union
The EU AI Act
The first comprehensive, horizontal AI statute from a major regulator — risk-tiered, phased in over several years, and already shaping how other jurisdictions draft their own AI laws.
The EU AI Act entered into force on August 1, 2024, but "in force" and "fully applicable" are different things for this law — its obligations phase in over roughly three years, and a system that's out of scope today can come into scope as later provisions activate. Treat this page as the status summary, not a substitute for the classification work your specific system needs.
The risk-tier structure
The Act sorts AI systems into four tiers, and the obligations attach to the tier, not to the technology:
- Unacceptable risk — practices banned outright: social scoring by public authorities, certain forms of manipulative AI, untargeted scraping of facial images for recognition databases, among others. These prohibitions were among the first provisions to take effect — see our full breakdown of every Article 5 prohibited practice.
- High-risk — systems subject to the Act's most substantial obligations: a maintained risk management system, data governance, technical documentation, logging, transparency, human oversight, and defined accuracy/robustness/cybersecurity standards, including the instructions for use a provider must give deployers. Classification runs through Article 6 — see our full breakdown of how that test actually works.
- Limited risk — systems (like most chatbots) that face specific transparency obligations, such as disclosing that a user is interacting with AI, without the full high-risk compliance burden.
- Minimal risk — the majority of AI applications, largely unregulated by the Act itself beyond voluntary codes of conduct.
What's actually in force right now
- Prohibited practices and AI-literacy obligations — applicable since February 2025.
- General-purpose AI (GPAI) model obligations — the Article 51-56 transparency and systemic-risk track — applicable since August 2025, and directly enforced at EU level by the EU AI Office rather than by national regulators. Most major providers demonstrate compliance with this track by signing the GPAI Code of Practice, which trades a presumption of conformity for a specific set of documentation, copyright, and safety-reporting commitments.
- High-risk system obligations — phasing in on the longest timeline, and pushed later than originally planned: the July 2026 Digital Omnibus on AI moved the Annex III high-risk deadline from August 2026 to December 2, 2027, and the Annex I product-embedded deadline from August 2027 to August 2, 2028. Once a high-risk system clears conformity assessment, providers signal that outcome with CE marking, the same visible-compliance mechanism used across EU product law.
For the full corrected schedule — what's live, what moved, and why — see our complete EU AI Act implementation timeline. Check the effective-date field on this page rather than assuming — we update it when the underlying schedule or guidance changes, and enforcement bodies have signaled some willingness to phase in practical enforcement gradually even after formal applicability dates pass.
Who the Act actually applies to
The Act applies extraterritorially, similarly to the GDPR: providers and deployers outside the EU are in scope if the AI system's output is used within the EU. A U.S. or UK company with no EU office can still fall within scope if it sells or deploys a system that affects people in the EU — this is the single most commonly missed scope question in early compliance planning, and our full breakdown of the Article 2 extraterritorial-scope triggers walks through exactly when a non-EU company is, and isn't, actually covered. The two regulations aren't the same obligation twice, either — see where the AI Act and GDPR actually overlap and where they diverge for what a GDPR-compliant company still has to build separately.
Penalties
Penalties are tiered by violation type, with the most severe reserved for violations of the prohibited-practices provisions — up to the higher of a fixed amount in the tens of millions of euros or a percentage of global annual turnover, a structure that mirrors GDPR's own penalty tiers. For the full breakdown of all three Article 99 tiers, the separate fine track for general-purpose AI model providers, and how the calculation changes for SMEs, see our complete guide to the EU AI Act's tiered penalty structure.
Where to go next
If you're trying to determine whether a specific system is high-risk, our Article 6 classification breakdown walks through the actual two-track test. For how EU AI Act obligations compare with what's expected under ISO/IEC 42001, see our ISO 42001 coverage — the standard is increasingly used as a practical route to demonstrating EU AI Act conformity.
Sources & references
Suggested next reading
frameworks
ISO/IEC 42001
regulations
GPAI (General-Purpose AI Model)
regulations
Conformity Assessment
regulations eu
The EU AI Office: What It Does and Why It Matters to You
regulations eu