The EU AI Act
A risk-based product-safety regime for AI systems and general-purpose AI models placed on the EU market or used in the EU: banned practices, high-risk obligations, transparency duties and GPAI rules.
Any organisation, wherever it is based, that places AI on the EU market or puts it into service there, and non-EU providers and deployers whose AI output is used in the EU. Brexit does not take a UK firm out of scope.
Latest check 27 Sep 2026 15 rules · See changes in the Ledger
The rules
The Article 4 AI literacy duty, as amended by the Omnibus
Providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". The amended text adds: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual." The original wording required measures "to ensure" a sufficient level.
Verified 27 Sep 2026 · Read the source
When a deployer becomes a provider (Article 25)
When it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or modifies the intended purpose of an AI system (including a general-purpose one) so that it becomes high-risk. The original provider is then no longer treated as the provider of that system.
Verified 27 Sep 2026 · Read the source
What a deployer of a high-risk system must do (Article 26)
Use it in line with the provider's instructions; assign human oversight to people with the necessary competence, training and authority; make sure input data it controls is relevant and sufficiently representative; monitor operation and report serious incidents; keep automatically generated logs for at least six months; inform workers' representatives and affected workers before workplace use; and tell people when they are subject to decisions it helps make.
Verified 27 Sep 2026 · Read the source
The Digital Omnibus on AI
Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It amends the AI Act to delay the high-risk obligations, rewrite the AI literacy duty, extend SME relief to small mid-caps and add a new prohibition.
Verified 27 Sep 2026 · Read the source
When the AI Act entered into force
1 August 2024. The AI Act is Regulation (EU) 2024/1689; its obligations then apply in stages.
Verified 27 Sep 2026 · Read the source
Who is caught outside the EU
Article 2(1) covers providers placing AI systems or GPAI models on the EU market "irrespective of whether those providers are established or located within the Union or in a third country", and providers and deployers in a third country "where the output produced by the AI system is used in the Union".
Verified 27 Sep 2026 · Read the source
The general date of application
2 August 2026. The Act became generally applicable on that date, including the Article 50 transparency rules, and the AI Office and national authorities became responsible for supervision and enforcement. The high-risk obligations are the main exception.
Verified 27 Sep 2026 · Read the source
When the general-purpose AI model obligations applied
2 August 2025 for GPAI models placed on the market from that date. Models already on the market before 2 August 2025 have until 2 August 2027 (Article 111(3)). The Commission's enforcement powers over GPAI providers apply from 2 August 2026.
Verified 27 Sep 2026 · Read the source
What every GPAI model provider must do (Article 53)
Keep up-to-date technical documentation; give downstream providers the information they need to understand the model's capabilities and limitations; put in place a policy to comply with EU copyright law; and publish a sufficiently detailed summary of the content used for training. The voluntary General-Purpose AI Code of Practice, published 10 July 2025, is one recognised way to show compliance.
Verified 27 Sep 2026 · Read the source
The compute threshold for systemic-risk GPAI models
A GPAI model is presumed to have high-impact capabilities, and so systemic risk, when the cumulative compute used to train it exceeds 10^25 floating point operations (Article 51(2)). Those providers carry extra duties, including assessing and mitigating systemic risks.
Verified 27 Sep 2026 · Read the source
When the high-risk obligations apply, after the Omnibus
2 December 2027 for stand-alone high-risk systems listed in Annex III (such as employment, credit scoring, education and biometrics). 2 August 2028 for high-risk AI in products covered by Annex I legislation (such as machinery and medical devices). The original dates were 2 August 2026 and 2 August 2027.
Verified 27 Sep 2026 · Read the source
Transition for the AI-generated content marking duty
The Omnibus gives providers of generative AI systems already placed on the market before 2 August 2026 a four-month transitional period to meet the Article 50(2) duty to mark AI-generated output.
Verified 27 Sep 2026 · Read the source
Maximum fines
Up to €35m or 7% of total worldwide annual turnover (whichever is higher) for prohibited practices; up to €15m or 3% for most other obligations, and for GPAI model providers; up to €7.5m or 1% for supplying incorrect, incomplete or misleading information to authorities.
Verified 27 Sep 2026 · Read the source
The prohibition added by the Omnibus
AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material (for example "nudification" apps) join the list of prohibited practices, taking the Commission's count to nine. The Commission states it comes into effect in December 2026.
Verified 27 Sep 2026 · Read the source
When the prohibitions and AI literacy duty applied
2 February 2025. The prohibited practices in Article 5 and the AI literacy obligation in Article 4 have applied since that date.
Verified 27 Sep 2026 · Read the source
What people get wrong
The five misreadings we see most often, and what follows from them.
Article 2 reaches UK providers placing AI on the EU market and UK providers and deployers whose AI output is used in the EU. Fines for the most serious breaches run to €35m or 7% of worldwide turnover.
Only the high-risk obligations moved. Prohibitions (since February 2025), GPAI rules (since August 2025), transparency duties and general application (August 2026) are all live, and a new prohibition arrives in December 2026.
Article 4 still requires providers and deployers to take measures. What changed is that no specific level of literacy has to be guaranteed. An organisation with no measures at all is still out of line.
Deployers of high-risk systems carry their own Article 26 duties, and a deployer that rebrands, substantially modifies or repurposes a system into a high-risk use becomes its provider, with the full provider burden.
Conformity assessment, quality management, technical documentation and human-oversight design take many months. Starting in 2027 leaves no room to find that a key supplier cannot supply the documentation you need.
The other four
Knowing the rule is not the same as having a process
Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.
This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.
