EU AI Act

Jurisdiction:
European Union
phased enforcement
Effective:
Aug 1, 2024
Full enforcement:
Aug 1, 2027
Authority:
European Commission
Official text Verified Mar 25, 2026

Obligations Covered

AI Literacy & Training Human Oversight Transparency & Disclosure Risk Assessment Conformity Assessment Record-Keeping & Documentation

AI Literacy (Article 4) #

Obligation:
Ai Literacy
enforcing
Effective:
Feb 2, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Staff AI literacyProviders AND deployers must ensure sufficient AI literacy
Context-specificTailored to role, industry, use case
No method prescribedCompliance method is flexible

Penalties

ViolationFine
Non-complianceUp to EUR 15M or 3% global turnover (aggravating factor)

Human Oversight (Article 14) #

Obligation:
Human Oversight
enacted
Effective:
Aug 2, 2026
Risk tier:
high-risk
Scope:
providers, deployers

Requirements

RequirementDetails
Effective oversightHigh-risk AI must enable oversight by natural persons
Understand capabilitiesOverseers must understand system capabilities and limitations
Interpret outputMust be able to correctly interpret output
Override/reverseMust be able to override or reverse AI output
Address automation biasMust address risk of automation bias
Competent personnelDeployers must assign persons with necessary competence, training, authority

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Transparency Requirements #

Obligation:
Transparency
phased enforcement
Effective:
Aug 2, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Usage disclosureDeployers must inform users they're interacting with AI
Deepfake labelingProviders must mark AI-generated content
Technical docsProviders must document system capabilities and limits

Penalties

ViolationFine
Prohibited practicesUp to EUR 35M or 7% global turnover
High-risk non-complianceUp to EUR 15M or 3% global turnover
Incorrect informationUp to EUR 7.5M or 1% global turnover

Risk Management (Article 9) #

Obligation:
Risk Assessment
enacted
Effective:
Aug 2, 2026
Risk tier:
high-risk
Scope:
providers

Requirements

RequirementDetails
Risk management systemEstablish and maintain throughout AI lifecycle
Identify risksIdentify and analyze known and foreseeable risks
TestingTest against risk management measures
Residual riskEnsure residual risks are acceptable

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Conformity Assessment #

Obligation:
Conformity Assessment
enacted
Effective:
Aug 2, 2026
Risk tier:
high-risk
Scope:
providers

Requirements

RequirementDetails
Conformity assessmentMust undergo before placing on market
CE markingRequired for high-risk AI
Quality managementMust establish quality management system
DocumentationMaintain technical documentation

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover

Record-Keeping & Automatic Logging (Article 12) #

Obligation:
Record Keeping
enacted
Effective:
Aug 2, 2026
Risk tier:
high-risk
Scope:
providers, deployers
high-impactupcoming

Requirements

RequirementDetails
Automatic loggingHigh-risk AI systems must log events automatically throughout lifecycle
TraceabilityLogs must enable risk identification and post-market monitoring
Deployer monitoringLogs must support operational monitoring by deployers (Article 26(5))
Immutable storageLogs must be stored tamper-evident and immutable
Biometric ID specificsRemote biometric systems must log period of use, reference database, input data, and verifying personnel

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover