EU Regulatory Domain
Regulation (EU) 2024/1689 (AI Act), as amended in 2026: a risk-based framework for AI systems and general-purpose AI models.
Key facts
Obligations fall on providers, deployers, importers and distributors, so organisations that simply use AI tools are also concerned.
The prohibited AI practices have applied since 2 February 2025.
Annex III high-risk systems apply from 2 December 2027, and systems embedded in Annex I products from 2 August 2028.
Prohibited practices carry fines of up to EUR 35 million or 7% of worldwide annual turnover.
The AI Act entered into force on 1 August 2024 and establishes a risk-based framework for AI systems placed on the market or used in the European Union. It was amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026 and postponed most high-risk obligations. Obligations fall on providers, deployers, importers and distributors, which means that organisations simply using AI tools are also concerned.
prohibited practices (Article 5): for example, social scoring, manipulative techniques that cause significant harm, untargeted scraping of facial images and emotion recognition in the workplace and in education, subject to narrow exceptions, to which the 2026 amendment adds, from 2 December 2026, the generation of child sexual abuse material and non-consensual intimate imagery;
high-risk systems: AI used as a safety component of regulated products (Annex I) or in sensitive areas such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and justice (Annex III), subject to requirements on risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity;
transparency obligations (Article 50): users must be told when they interact with an AI system, and synthetic or manipulated content must be disclosed or marked;
general-purpose AI models: documentation, copyright and transparency duties for providers, with additional duties for models with systemic risk.
Deployers of high-risk systems must use them according to the instructions, ensure human oversight, monitor operation and, in the case of public bodies and certain other deployers, carry out a fundamental-rights impact assessment.
2 February 2025: prohibitions and AI literacy;
2 August 2025: general-purpose AI models, governance and penalties;
2 August 2026: transparency obligations under Article 50;
2 December 2026: the new prohibitions added in 2026 and the end of the transitional period for marking AI-generated content of systems already on the market;
2 December 2027: high-risk systems listed in Annex III;
2 August 2028: high-risk systems embedded in products covered by Annex I.
Providers and deployers must take measures to support a sufficient level of AI literacy among the staff who operate and use AI systems (Article 4, as amended in 2026). In practice, this requires an inventory of the AI tools in use, an internal use policy and training proportionate to each role.
Fines reach EUR 35 million or 7% of worldwide annual turnover for prohibited practices, EUR 15 million or 3% for most other infringements, and EUR 7.5 million or 1% for supplying incorrect information. The European AI Office supervises general-purpose AI models, while national market surveillance authorities enforce the remaining rules.
Compliance Assessment: an inventory of AI systems and their risk classification;
Implementation Kits: an AI use policy, an AI register and impact-assessment templates;
Training & Capacity: AI literacy programmes by role;
Alerts & Repository: monitoring of guidelines, standards and codes of practice.
Related domains: Data Protection · Digital Services & Markets · Third-Party & Supply Chain · Corporate Governance
Official texts: Regulation (EU) 2024/1689 · Regulation (EU) 2026/1744
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free assessment to inventory your AI tools and classify their risk.