EU AI Act

Jurisdiction:
European Union
phased enforcement
Effective:
Aug 2, 2026
Full enforcement:
Aug 2, 2027
Authority:
European Parliament and Council of the European Union
Official text
Amendments:
  • — Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted.
  • — Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged.

Obligations Covered

AI Literacy & Training Human Oversight Transparency & Disclosure Risk Assessment Conformity Assessment Record-Keeping & Documentation Bias & Discrimination Prevention

Timeline

MilestoneDateNotes
AdoptedMar 13, 2024European Parliament
Signed into lawJun 13, 2024Signature by Parliament + Council presidents; ELI date of the act (enacted)
Entered into forceAug 1, 202420 days after publication
AI literacy + prohibited practicesFeb 2, 2025Articles 4 and 5
GPAI model rulesAug 2, 2025National authorities designated
High-risk classification guidelinesFeb 2, 2026Commission guidelines published
Digital Omnibus on AI in forceJul 27, 2026Regulation (EU) 2026/1744 (OJ 2026-07-24); Articles 102-110 apply from this date (Art. 113 third para. point (d))
General application + Article 50 transparencyAug 2, 2026Default application date under Article 113; limited-risk transparency obligations apply
New Art. 5 prohibitions (NCIM/CSAM)Dec 2, 2026Added by Digital Omnibus
Article 50(2) marking, pre-existing generative systemsDec 2, 2026Four-month transitional period under new Article 111(4)
Article 6(1) + pre-existing GPAIAug 2, 2027Unchanged by Omnibus
National regulatory sandboxes operationalAug 2, 2027Amended Article 57(1); deferred from 2026-08-02
Full high-risk obligations (Annex III)Dec 2, 2027Deferred from 2026-08-02 by Digital Omnibus — human oversight, risk management, conformity assessment, logging
Notified-body designation under Section A of Annex IJan 28, 2028Amended Article 43(3) second subparagraph
Annex I product-safety high-riskAug 2, 2028Deferred from 2027-08-02 by Digital Omnibus
Legacy high-risk systems used by public authoritiesAug 2, 2030Amended Article 111(2)

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

AI Literacy (Article 4) #

Obligation:
Ai Literacy
enforcing
Effective:
Feb 2, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Support AI literacyProviders and deployers must take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf (Article 4(1), as replaced by Regulation (EU) 2026/1744 from 2026-07-27)
Context-specificMeasures must take account of technical knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used (Article 4(1))
No guaranteed levelThe obligation expressly does not require providers or deployers to guarantee any specific level of AI literacy of any individual (Article 4(1), second sentence — added by the Digital Omnibus)
Commission supportThe Commission and Member States must support providers and deployers, in particular SMEs, and the Commission must publish practical compliance examples on the single information platform (Article 4(2), Article 62(3)(b))
Board recommendationsThe AI Board must adopt recommendations, taking account of European competence frameworks, including common objectives (Article 4(3))

Penalties

ViolationFine
Non-complianceUp to EUR 15M or 3% global turnover (aggravating factor)

Human Oversight (Article 14) #

Obligation:
Human Oversight
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
providers, deployers

Requirements

RequirementDetails
Effective oversightHigh-risk AI must enable oversight by natural persons (Article 14(1))
Understand capabilitiesOverseers must understand system capacities and limitations (Article 14(4)(a))
Monitor for anomaliesMust monitor operation and detect unexpected performance, anomalies, and dysfunctions (Article 14(4)(a))
Address automation biasMust remain aware of automation-bias risk in oversight (Article 14(4)(b))
Interpret outputMust be able to correctly interpret output using available tools (Article 14(4)(c))
Override/reverseMust be able to decide not to use, disregard, override, or reverse AI output (Article 14(4)(d))
Intervene or haltMust be able to intervene or interrupt system operation via stop button or equivalent halt procedure (Article 14(4)(e))
Competent personnelDeployers must assign persons with necessary competence, training, and authority (Article 26(2))
Dual verification (biometric)For Annex III point 1(a) systems (remote biometric ID), no action or decision may be taken unless separately verified and confirmed by at least two natural persons with competence, training, and authority — except where EU/national law deems disproportionate for law enforcement, migration, border, or asylum purposes (Article 14(5))

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Transparency Disclosure (Article 50) #

Obligation:
Transparency
phased enforcement
Effective:
Aug 2, 2026
Risk tier:
limited-risk
Scope:
Providers of systems intended to interact directly with natural persons and of systems generating synthetic audio, image, video or text (Article 50(1)-(2)); deployers of emotion recognition or biometric categorisation systems and of systems producing deepfakes (Article 50(3)-(4))
high-impactcross-domain
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02.

Requirements

RequirementDetails
Interaction disclosureProviders must design systems intended to interact directly with natural persons so those persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Article 50(1))
Synthetic content markingProviders of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated or manipulated (Article 50(2))
Emotion recognition and biometric categorisation noticeDeployers must inform natural persons exposed to emotion recognition or biometric categorisation systems of their operation (Article 50(3))
Deepfake disclosureDeployers generating or manipulating image, audio or video constituting a deepfake must disclose that the content is artificially generated or manipulated (Article 50(4))
Generative AI grace periodPre-existing generative AI systems on the market before 2026-08-02 have until 2026-12-02 to comply with Article 50(2) machine-readable marking (Article 111(4), inserted by Regulation (EU) 2026/1744)
Marking codes of practiceThe Commission facilitates Union-level codes of practice for detection, marking and labelling of AI-generated or manipulated content, assesses their adequacy for Article 50(2) and (4), and may impose common rules by implementing act if a code is inadequate (Article 50(7), as replaced by Regulation (EU) 2026/1744)

Penalties

ViolationFine
Transparency non-compliance (Article 50)Up to EUR 15M or 3% global turnover (Article 99(4))
Incorrect informationUp to EUR 7.5M or 1% global turnover (Article 99(5))
SMC ceilingFor small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)

High-Risk Transparency and Instructions for Use (Article 13) #

Obligation:
Transparency
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems. The duty runs to the instructions for use supplied to deployers, not to end users
upcominghigh-impact
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.

Requirements

RequirementDetails
Operational transparencyHigh-risk systems must be designed and developed so their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately (Article 13(1))
Instructions for useHigh-risk systems must be accompanied by instructions for use in an appropriate digital format, containing concise, complete, correct and clear information accessible and comprehensible to deployers (Article 13(2))
Provider identityInstructions must state the identity and contact details of the provider and, where applicable, its authorised representative (Article 13(3)(a))
Capabilities and limitationsInstructions must state intended purpose, the accuracy, robustness and cybersecurity metrics the system was validated against, foreseeable circumstances affecting those levels, and risks arising under intended use or reasonably foreseeable misuse (Article 13(3)(b))
Explainability informationWhere applicable, instructions must describe technical capabilities to provide information explaining the system's output (Article 13(3)(b)(iv))
Human oversight measuresInstructions must describe the human oversight measures built in under Article 14, including technical measures facilitating output interpretation by deployers (Article 13(3)(d))
Pre-determined changesWhere applicable, instructions must describe the changes to the system and its performance which the provider pre-determined at the moment of the initial conformity assessment (Article 13(3)(b)(vii))
Expected lifetime and maintenanceInstructions must state expected lifetime and any necessary maintenance and care measures, including software updates (Article 13(3)(e))

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover (Article 99(4))
Incorrect informationUp to EUR 7.5M or 1% global turnover (Article 99(5))
SMC ceilingFor small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)

Risk Management (Article 9) #

Obligation:
Risk Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
providers of high-risk AI systems

Requirements

RequirementDetails
Risk management systemEstablish and maintain throughout AI lifecycle (Article 9(1))
Identify and analyzeIdentify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a))
Estimate and evaluateEstimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b))
Post-market evaluationEvaluate risks based on data from post-market monitoring (Article 9(2)(c))
Risk mitigationTake appropriate and targeted mitigation measures addressing identified risks (Article 9(2)(d))
Design-based reductionEliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a))
Residual riskEnsure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5))
TestingTest to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8))
Continuous monitoringOngoing performance monitoring throughout the system lifecycle

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Conformity Assessment #

Obligation:
Conformity Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
providers

Requirements

RequirementDetails
Conformity assessmentMust undergo before placing on market or putting into service (Article 43)
CE markingRequired for high-risk AI systems once assessment complete (Article 48)
Quality managementMust establish quality management system (Article 17); implementation must be proportionate to the size of the provider's organisation, in particular for SMEs, start-ups, and small mid-cap enterprises, without lowering the rigour needed for compliance (Article 17(2), as replaced by Regulation (EU) 2026/1744)
DocumentationMaintain technical documentation throughout lifecycle (Article 18); SMEs, start-ups, and SMCs may supply the Annex IV elements in simplified form using a Commission-issued simplified form (Article 11(1), as amended)
No forced third-party assessmentWhere Annex I Section A legislation lets a manufacturer self-assess against harmonised standards, classification of the product as high-risk under Article 6(1) does not by itself force a third-party conformity assessment (Article 43(3), as replaced)
Annex III phasingAnnex III high-risk systems: 2027-12-02 (deferred from 2026-08-02 by Regulation (EU) 2026/1744). Annex I high-risk (safety components covered by other EU product laws, e.g., medical devices): 2028-08-02 (deferred from 2027-08-02). Notified bodies already notified under Annex I Section A legislation must apply for designation under the AI Act by 2028-01-28

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Record-Keeping & Automatic Logging (Article 12) #

Obligation:
Record Keeping
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
providers, deployers
high-impactupcoming

Requirements

RequirementDetails
Automatic loggingHigh-risk AI systems must log events automatically throughout lifecycle
TraceabilityLogs must enable risk identification and post-market monitoring
Deployer monitoringLogs must support operational monitoring by deployers (Article 26(5))
Log retentionProviders must keep Article 12(1) logs under their control for at least six months (Article 19(1)); deployers must keep logs under their control for at least six months (Article 26(6)); financial institutions keep logs per Union financial services law (Articles 19(2), 26(6))
Tamper-evident storageBest-practice/conformity expectation — Article 12 does not itself use "immutable" or "tamper-evident"; integrity of logs is derived from broader auditability and conformity-assessment requirements
Biometric ID specificsRemote biometric systems (Annex III point 1(a)) must log period of use, reference database, input data, and verifying personnel (Article 12(3))

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Fundamental Rights Impact Assessment (Article 27) #

Obligation:
Risk Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Deployers that are bodies governed by public law or private entities providing public services, and any deployer of Annex III point 5(b)-(c) systems (creditworthiness assessment, life and health insurance risk assessment and pricing); Annex III point 2 (critical infrastructure) systems are excluded
upcominghigh-impact
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: a completed GDPR data protection impact assessment can now be cross-referenced rather than duplicated, and the AI Office must ship a questionnaire template.

Requirements

RequirementDetails
Pre-deployment assessmentAssess the impact on fundamental rights before putting the high-risk system into use (Article 27(1))
Process descriptionDescribe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a))
Period and frequencyDescribe the period and frequency of intended use (Article 27(1)(b))
Affected personsIdentify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c))
Specific harmsIdentify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d))
Human oversightDescribe implementation of human oversight measures per the instructions for use (Article 27(1)(e))
Response measuresSet out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f))
First use and updatesApplies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2))
Notify authorityNotify the market surveillance authority of the results, submitting the filled-out template (Article 27(3))
DPIA cross-referenceWhere an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744)
AI Office templateThe AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced)

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Bias Detection Data Basis (Article 4a) #

Obligation:
Bias Prevention
enforcing
Effective:
Jul 27, 2026
Risk tier:
all
Scope:
Providers of high-risk AI systems (Article 4a(1)); providers and deployers of other AI systems and models, and deployers of high-risk AI systems (Article 4a(2))
cross-domain
A permission, not a mandate — Article 4a(2) states expressly that it creates no obligation to conduct bias detection. It matters because it is the only lawful route to processing special-category personal data for bias work, and the six cumulative safeguards are themselves an ongoing compliance burden for anyone who uses it. Replaces the former Article 10(5), which was limited to high-risk training data.

Requirements

RequirementDetails
Strict necessityProcessing is permitted only to the extent strictly necessary for bias detection and correction under Article 10(2)(f)-(g) (Article 4a(1))
No alternative dataBias detection and correction must be impossible to achieve effectively with other data, including synthetic or anonymised data (Article 4a(1)(a))
Technical limitsRe-use must be technically limited, with state-of-the-art security and privacy-preserving measures including pseudonymisation (Article 4a(1)(b))
Access controlStrict, documented access controls, confidentiality obligations, and authorised-person-only access (Article 4a(1)(c))
No onward transferThe special-category data must not be transmitted, transferred, or otherwise accessed by other parties (Article 4a(1)(d))
DeletionDelete once the bias is corrected or the retention period ends, whichever is first (Article 4a(1)(e))
Documented justificationGDPR/EUDPR/LED records of processing must state why the processing was strictly necessary and why other data would not achieve the objective (Article 4a(1)(f))
Extension beyond high-riskProviders and deployers of other AI systems and models, and deployers of high-risk systems, may rely on the same basis where strictly necessary to address biases affecting health, safety, fundamental rights, or prohibited discrimination — subject to all Article 4a(1) safeguards (Article 4a(2))
No duty createdArticle 4a(2) expressly creates no obligation to carry out bias detection and correction

Penalties

ViolationFine
Processing outside the conditionsNo AI Act fine attaches to Article 4a itself; processing that falls outside its conditions loses the Article 9(2)(g) GDPR basis and is exposed to data protection enforcement
Cite this regulation

Permalink: https://everyailaw.com/regulation/eu-ai-act/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “EU AI Act”, EveryAILaw.com, Aug 15, 2026. https://everyailaw.com/regulation/eu-ai-act/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.