EU AI Act

The EU AI Act

A risk-based product-safety regime for AI systems and general-purpose AI models placed on the EU market or used in the EU: banned practices, high-risk obligations, transparency duties and GPAI rules.

Who it applies to

Any organisation, wherever it is based, that places AI on the EU market or puts it into service there, and non-EU providers and deployers whose AI output is used in the EU. Brexit does not take a UK firm out of scope.

Latest check 27 Sep 2026 15 rules · See changes in the Ledger


The rules

The Article 4 AI literacy duty, as amended by the Omnibus

Providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". The amended text adds: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual." The original wording required measures "to ensure" a sufficient level.

Verified 27 Sep 2026 · Read the source

When a deployer becomes a provider (Article 25)

When it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or modifies the intended purpose of an AI system (including a general-purpose one) so that it becomes high-risk. The original provider is then no longer treated as the provider of that system.

Verified 27 Sep 2026 · Read the source

What a deployer of a high-risk system must do (Article 26)

Use it in line with the provider's instructions; assign human oversight to people with the necessary competence, training and authority; make sure input data it controls is relevant and sufficiently representative; monitor operation and report serious incidents; keep automatically generated logs for at least six months; inform workers' representatives and affected workers before workplace use; and tell people when they are subject to decisions it helps make.

Verified 27 Sep 2026 · Read the source

The Digital Omnibus on AI

Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It amends the AI Act to delay the high-risk obligations, rewrite the AI literacy duty, extend SME relief to small mid-caps and add a new prohibition.

Verified 27 Sep 2026 · Read the source

When the AI Act entered into force

1 August 2024. The AI Act is Regulation (EU) 2024/1689; its obligations then apply in stages.

Verified 27 Sep 2026 · Read the source

Who is caught outside the EU

Article 2(1) covers providers placing AI systems or GPAI models on the EU market "irrespective of whether those providers are established or located within the Union or in a third country", and providers and deployers in a third country "where the output produced by the AI system is used in the Union".

Verified 27 Sep 2026 · Read the source

The general date of application

2 August 2026. The Act became generally applicable on that date, including the Article 50 transparency rules, and the AI Office and national authorities became responsible for supervision and enforcement. The high-risk obligations are the main exception.

Verified 27 Sep 2026 · Read the source

When the general-purpose AI model obligations applied

2 August 2025 for GPAI models placed on the market from that date. Models already on the market before 2 August 2025 have until 2 August 2027 (Article 111(3)). The Commission's enforcement powers over GPAI providers apply from 2 August 2026.

Verified 27 Sep 2026 · Read the source

What every GPAI model provider must do (Article 53)

Keep up-to-date technical documentation; give downstream providers the information they need to understand the model's capabilities and limitations; put in place a policy to comply with EU copyright law; and publish a sufficiently detailed summary of the content used for training. The voluntary General-Purpose AI Code of Practice, published 10 July 2025, is one recognised way to show compliance.

Verified 27 Sep 2026 · Read the source

The compute threshold for systemic-risk GPAI models

A GPAI model is presumed to have high-impact capabilities, and so systemic risk, when the cumulative compute used to train it exceeds 10^25 floating point operations (Article 51(2)). Those providers carry extra duties, including assessing and mitigating systemic risks.

Verified 27 Sep 2026 · Read the source

When the high-risk obligations apply, after the Omnibus

2 December 2027 for stand-alone high-risk systems listed in Annex III (such as employment, credit scoring, education and biometrics). 2 August 2028 for high-risk AI in products covered by Annex I legislation (such as machinery and medical devices). The original dates were 2 August 2026 and 2 August 2027.

Verified 27 Sep 2026 · Read the source

Transition for the AI-generated content marking duty

The Omnibus gives providers of generative AI systems already placed on the market before 2 August 2026 a four-month transitional period to meet the Article 50(2) duty to mark AI-generated output.

Verified 27 Sep 2026 · Read the source

Maximum fines

Up to €35m or 7% of total worldwide annual turnover (whichever is higher) for prohibited practices; up to €15m or 3% for most other obligations, and for GPAI model providers; up to €7.5m or 1% for supplying incorrect, incomplete or misleading information to authorities.

Verified 27 Sep 2026 · Read the source

The prohibition added by the Omnibus

AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material (for example "nudification" apps) join the list of prohibited practices, taking the Commission's count to nine. The Commission states it comes into effect in December 2026.

Verified 27 Sep 2026 · Read the source

When the prohibitions and AI literacy duty applied

2 February 2025. The prohibited practices in Article 5 and the AI literacy obligation in Article 4 have applied since that date.

Verified 27 Sep 2026 · Read the source


What people get wrong

The five misreadings we see most often, and what follows from them.

Assuming the AI Act stopped at the Channel because the UK left the EU.

Article 2 reaches UK providers placing AI on the EU market and UK providers and deployers whose AI output is used in the EU. Fines for the most serious breaches run to €35m or 7% of worldwide turnover.

Reading the Omnibus as "the AI Act has been delayed".

Only the high-risk obligations moved. Prohibitions (since February 2025), GPAI rules (since August 2025), transparency duties and general application (August 2026) are all live, and a new prohibition arrives in December 2026.

Treating the softened AI literacy wording as the end of the duty.

Article 4 still requires providers and deployers to take measures. What changed is that no specific level of literacy has to be guaranteed. An organisation with no measures at all is still out of line.

Assuming a business that only buys AI has no obligations because it is "just a deployer".

Deployers of high-risk systems carry their own Article 26 duties, and a deployer that rebrands, substantially modifies or repurposes a system into a high-risk use becomes its provider, with the full provider burden.

Pausing high-risk compliance work until late 2027.

Conformity assessment, quality management, technical documentation and human-oversight design take many months. Starting in 2027 leaves no room to find that a key supplier cannot supply the documentation you need.


The other four

The UK's approach to AI regulationThe Information Commission and UK GDPRAI management standardsSector regulators and AI
Next step

Knowing the rule is not the same as having a process

Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.

This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.