The European Union’s Artificial Intelligence Act, Regulation (EU) 2024/1689, is the first comprehensive law regulating AI across a major economy. It entered into force on 1 August 2024, and its obligations are being phased in over several years. If you build, sell or use AI systems that affect people in the EU, it may apply to you, even if your company is based elsewhere.
In July 2026 the EU amended the Act through the so-called AI Omnibus, Regulation (EU) 2026/1744, which pushed back the main high-risk deadlines. This guide reflects those changes. It is not legal advice, and guidance documents continue to be published, so check official EU sources or a qualified adviser before making decisions.
Updated September 2026: we added links to the legal text, rewrote the timeline to reflect the 2026 AI Omnibus amendments, and added the exact penalty levels.
The risk-based approach
The AI Act sorts AI systems into categories based on the risk they pose:
| Category | Examples | What it means |
|---|---|---|
| Unacceptable risk | Social scoring, certain manipulative systems and, from December 2026, systems that generate non-consensual intimate imagery or child sexual abuse material | Banned |
| High risk | AI used in hiring, credit scoring, education, critical infrastructure, some medical and law-enforcement uses | Strict requirements before and after deployment |
| Transparency risk | Chatbots, deepfakes, AI-generated content | Users must be told they are dealing with AI or AI content |
| Minimal risk | Spam filters, AI in video games | No new obligations |
The timeline, after the 2026 amendments
The original timetable is set out in Article 113 of the Regulation. The AI Omnibus, which the Council gave final approval to on 29 June 2026 and which entered into force on 27 July 2026, moved several later deadlines:
| Date | What applies |
|---|---|
| 2 February 2025 | Bans on unacceptable-risk practices, and the AI literacy provision |
| 2 August 2025 | Obligations for providers of general-purpose AI models |
| 2 August 2026 | Transparency duties such as telling people they are talking to a chatbot |
| 2 December 2026 | Machine-readable marking of AI-generated content (with a grace period for systems already on the market), and the new bans on nudifier and CSAM-generating systems |
| 2 December 2027 | Stand-alone high-risk systems listed in Annex III, such as AI in hiring, credit and education (originally August 2026) |
| 2 August 2028 | High-risk AI built into products covered by EU product-safety law, such as medical devices |
Key obligations by type
Banned practices. Prohibitions on unacceptable-risk AI have applied since February 2025, and the Omnibus added two new banned categories from December 2026.
General-purpose AI models. Providers of large foundation models must keep technical documentation, give information to downstream developers, have a copyright policy and publish a summary of training content. The most capable models face extra requirements on risk assessment and security. These rules began applying in August 2025.
High-risk systems. Providers must implement risk management, data governance, logging, human oversight, accuracy and cybersecurity measures, and complete conformity assessments. Organizations that deploy high-risk systems also have duties, such as monitoring and ensuring human oversight. After the Omnibus, these requirements apply from December 2027 for stand-alone systems and August 2028 for AI embedded in regulated products.
Transparency. People must be informed when they interact with a chatbot, and synthetic media such as deepfakes must be disclosed. Providers of generative systems must also mark AI-generated output in a machine-readable way.
AI literacy. The original text required organizations to ensure staff working with AI have sufficient AI literacy. The Omnibus softened this to taking measures to support AI literacy, according to White & Case‘s analysis. Training staff remains good practice either way.
Who is affected
- Providers: companies that develop an AI system or place it on the EU market
- Deployers: organizations that use AI systems in a professional context
- Importers and distributors of AI systems
Most businesses are deployers rather than providers. If you use a chatbot on your website or an AI tool in hiring, your obligations depend on how the system is used, not just who built it.
Penalties
Fines are set in Article 99 and scale with the severity of the violation:
| Violation | Maximum fine |
|---|---|
| Prohibited practices | EUR 35 million or 7% of worldwide annual turnover, whichever is higher |
| Most other obligations, including high-risk and transparency duties | EUR 15 million or 3% of turnover |
| Supplying incorrect or misleading information to authorities | EUR 7.5 million or 1% of turnover |
For small and medium-sized companies, including start-ups, the lower of the two amounts applies instead.
Practical first steps
- Inventory your AI use. List every AI tool and feature your organization builds or uses.
- Classify each use against the risk categories.
- Check vendor commitments. Ask suppliers how their products support compliance.
- Add transparency notices for chatbots and AI-generated content. These duties already apply.
- Train staff on approved tools and human oversight.
- Assign ownership. Someone should be responsible for tracking guidance as it is published.
Keep in mind The AI Act sits alongside existing laws such as the GDPR. If an AI system processes personal data, data protection rules still apply in full. The delay to high-risk rules is a delay, not a cancellation, so use the extra time to prepare.
Frequently asked questions
Does the AI Act apply to companies outside the EU?
Yes, in many cases. It covers providers that place AI systems or models on the EU market, and systems whose output is used in the EU, regardless of where the company is based.
Is ChatGPT or another chatbot a high-risk system?
Not by default. The models behind general-purpose chatbots fall under the rules for general-purpose AI, and chatbots carry transparency duties. A chatbot becomes part of a high-risk system only when it is used for a high-risk purpose, such as screening job candidates.
Were the high-risk rules cancelled?
No. The 2026 amendments postponed them to December 2027 and August 2028. The requirements themselves remain.
Start with an inventory
For most companies, the AI Act is less about banned technology and more about documentation, transparency and oversight. The transparency rules already apply, and the high-risk rules are now due in 2027 and 2028. Starting with a simple inventory now will make each deadline far easier to meet.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
- Regulation (EU) 2026/1744 (AI Omnibus), EUR-Lex
- Artificial intelligence: Council gives final green light to simplify and streamline rules, Council of the EU, 29 June 2026
- EU AI Omnibus enters into force, amending the AI Act, White & Case
- Article 99: Penalties, European Commission AI Act Service Desk



