Last updated: 9 August 2026.
As of 2 August 2026, the EU AI Act’s transparency rules are live. Chatbots, deepfakes, emotion-recognition systems and AI-generated content now carry concrete disclosure duties across the European Union. At the same time, the most demanding obligations — those for high-risk AI — are no longer expected in August 2026. Following the AI Digital Omnibus, they are now scheduled to arrive in December 2027. This guide explains, in plain terms, what the EU AI Act requires, who it binds, what applies today, and how organisations should prepare.
The EU AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024 and applies in stages. It is the world’s first comprehensive, horizontal law for artificial intelligence, and — like the GDPR — it reaches well beyond the EU’s borders. If your AI systems touch the European market, this regulation almost certainly concerns you.
What is the EU AI Act?
The EU AI Act is a risk-based regulation. Rather than treating all artificial intelligence identically, it sorts systems into tiers according to the harm they could cause and attaches heavier obligations to higher risk. The aim is twofold: to protect health, safety and fundamental rights, and to give businesses legal certainty so that trustworthy AI can be developed and deployed across the single market.
The Act defines an AI system broadly, in line with the OECD approach: a machine-based system that operates with some degree of autonomy, may adapt after deployment, and — from inputs it receives — infers how to generate outputs such as predictions, content, recommendations or decisions that influence physical or virtual environments. This deliberately wide definition captures modern machine-learning models, including generative and general-purpose AI.
Who does the AI Act apply to?
The AI Act has extraterritorial reach. It applies where a provider places an AI system on the EU market or puts it into service in the EU, and — critically — where a provider or deployer is established outside the EU but the output of the system is used within the EU. A US or UK company serving European users can therefore fall squarely within scope.
The Act distinguishes several actors, each with distinct duties:
- Providers — those who develop an AI system (or a general-purpose AI model) and place it on the market or put it into service under their own name or trademark. Providers carry the heaviest compliance load.
- Deployers — those who use an AI system under their authority in a professional context (for example, an employer running an AI hiring tool). Purely personal, non-professional use falls outside these duties.
- Importers and distributors — those who bring a third-party system into the EU market or make it available along the supply chain, with verification and record-keeping responsibilities.
- Product manufacturers, and in some cases authorised representatives, who may inherit provider-level obligations.
A deployer can also be re-classified as a provider — inheriting the stricter duties — if it substantially modifies a high-risk system or puts its own name on it.
The four risk tiers
The AI Act is built around four levels of risk.
1. Unacceptable risk (prohibited)
Some uses are considered incompatible with EU values and are banned outright under Article 5. These include manipulative or deceptive techniques that materially distort behaviour and cause harm; exploitation of vulnerabilities (age, disability, socio-economic situation); social scoring by public authorities; untargeted scraping of facial images to build recognition databases; emotion recognition in the workplace and in education (save for medical or safety reasons); certain biometric categorisation revealing sensitive traits; and — subject to narrow, safeguarded exceptions — real-time remote biometric identification in public spaces for law-enforcement purposes. Under the Digital Omnibus, a further prohibition targets AI used to generate non-consensual intimate imagery and child sexual abuse material.
2. High risk
High-risk systems are permitted but tightly regulated. They fall into two groups. The first (Annex I) covers AI that is a safety component of, or is itself, a product already regulated under EU harmonisation law — medical devices, machinery, lifts, toys and the like. The second (Annex III) lists standalone use cases in sensitive domains: biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services, law enforcement, migration and border control, and the administration of justice and democratic processes. These systems must satisfy the technical and governance requirements described below.
3. Limited risk (transparency)
Certain systems are not high-risk but can mislead people, so they carry transparency duties under Article 50. Users must be told when they are interacting with a chatbot; AI-generated or manipulated audio, image, video and text (including deepfakes) must be disclosed and marked; and people must be informed when subject to permitted emotion-recognition or biometric-categorisation systems. These obligations are now in force (see the timeline below).
4. Minimal risk
The vast majority of AI — spam filters, recommendation engines, AI in video games — falls here. It faces no mandatory obligations under the Act, though voluntary codes of conduct are encouraged.
What applies when: the updated AI Act timeline (after the Digital Omnibus)
Timing is where most organisations get the AI Act wrong, and it is where the law has recently moved. The Act applies in phases from its entry into force on 1 August 2024. In early May 2026 the AI Digital Omnibus reached a provisional political agreement, endorsed by member-state representatives on 13 May 2026. Formal adoption and Official Journal publication are still pending, but the package is now the realistic planning baseline — and it postponed the high-risk deadlines.
| Milestone | Applicable from | Status (8 Aug 2026) |
|---|---|---|
| Regulation enters into force | 1 August 2024 | In force |
| Prohibited practices (Art. 5) + AI-literacy duty (Art. 4) | 2 February 2025 | In force |
| GPAI obligations (Arts. 51–55), governance and penalties | 2 August 2025 | In force |
| Transparency obligations (Art. 50) | 2 August 2026 | In force (new) |
| Marking of existing generative-AI output (grace period) | by 2 December 2026 | Upcoming |
| High-risk Annex III systems | 2 December 2027 (was 2 Aug 2026) | Postponed by Omnibus |
| High-risk AI in Annex I regulated products | 2 August 2028 (was 2 Aug 2027) | Postponed by Omnibus |
The postponed dates above depend on the final adoption of the Omnibus. The dates already passed are settled law.
Two practical points. First, transparency duties are not a future concern — they became applicable on 2 August 2026, roughly a week ago. Providers of generative AI systems already on the market have until 2 December 2026 to bring existing output into line with the machine-readable marking and watermarking requirements. Second, the extra breathing room for high-risk AI is welcome, but it is a deferral, not a reprieve: the substantive obligations are unchanged, and readiness work is best started now.
Obligations by role
Providers of high-risk systems carry the core burden. They must establish a risk-management system across the lifecycle; apply data-governance measures to training, validation and testing data; prepare detailed technical documentation and keep it current; design systems for automatic logging and traceability; ensure transparency and clear instructions for use; enable effective human oversight; and achieve appropriate accuracy, robustness and cybersecurity. Before market entry they must run the relevant conformity assessment, draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Post-market monitoring and serious-incident reporting continue afterwards.
Deployers of high-risk systems must use the system in accordance with the provider’s instructions, assign competent human oversight, ensure input data is relevant, monitor operation and keep logs, and inform affected persons where required. In several sensitive contexts deployers must also conduct a fundamental rights impact assessment. Employers deploying AI that affects workers have additional information duties.
Importers and distributors must verify that the provider has met its obligations — conformity assessment, documentation, CE marking — before making a system available, and must act (and notify authorities) if they believe a system is non-compliant.
Across every tier, the Act’s AI-literacy duty (Art. 4) requires organisations to ensure staff who deal with AI have a sufficient level of understanding. The Omnibus softened the wording of this obligation, but the underlying expectation of competent, informed use remains.
Technical and governance requirements for high-risk AI
The high-risk requirements translate abstract principles into engineering and governance practice. In summary, providers must be able to demonstrate: a documented, iterative risk-management process; data quality and governance appropriate to the intended purpose, with attention to bias and representativeness; comprehensive technical documentation sufficient for authorities to assess compliance; record-keeping through automatic event logging; transparency and usable instructions; meaningful human oversight designed into the system; and demonstrable accuracy, robustness and cybersecurity. Together these form the evidence base for the conformity assessment — and, in practice, the material a regulator will ask to see first.
General-purpose AI (GPAI) obligations
General-purpose AI models — the large, versatile models underpinning many downstream applications — have their own regime under Articles 51–55, applicable since 2 August 2025. All GPAI providers must maintain technical documentation, publish a sufficiently detailed summary of training content, put in place a copyright policy, and cooperate down the value chain with those building on the model. Models presenting systemic risk face heightened duties: model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident tracking and reporting, and robust cybersecurity. Adherence to the official Code of Practice is a recognised route to demonstrating compliance.
Transparency obligations now in force (Article 50)
Because Article 50 became applicable on 2 August 2026, three duties now demand immediate attention. Chatbots and conversational agents must make clear that the user is dealing with a machine. AI-generated or manipulated content — text on matters of public interest, plus synthetic audio, image and video, including deepfakes — must be disclosed and marked in a machine-readable format so it can be detected as artificial. And people exposed to permitted emotion-recognition or biometric-categorisation systems must be informed. Organisations already operating generative-AI features should treat the 2 December 2026 grace period for marking existing output as a firm internal deadline.
Penalties and fines
Enforcement carries serious financial exposure, with penalties scaled to the severity of the breach:
- Prohibited practices (Art. 5): up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
- Breaches of high-risk and most other obligations: up to €15 million or 3% of worldwide annual turnover.
- Supplying incorrect, incomplete or misleading information to authorities: up to €7.5 million or 1% of worldwide annual turnover.
For SMEs and start-ups, the fine is the lower of the fixed amount or the percentage — a proportionality safeguard for smaller organisations. National market-surveillance authorities enforce the Act, coordinated at EU level, and further remedies may follow under national law.
How the AI Act fits with the GDPR and NIS2
The AI Act does not stand alone. Where an AI system processes personal data, the GDPR applies in full — lawful basis, purpose limitation, data-subject rights and, frequently, a data protection impact assessment. The AI Act’s fundamental-rights impact assessment and the GDPR’s DPIA often overlap and are best run together. Where AI supports essential or important services, the NIS2 Directive adds cybersecurity risk-management and incident-reporting duties that reinforce the AI Act’s robustness and security requirements. Treating these regimes as a single, integrated compliance programme — rather than three parallel projects — saves effort and reduces the risk of contradictory controls.
AI Act compliance checklist
- Inventory every AI system you provide or deploy, including embedded and third-party tools.
- Classify each system into a risk tier (unacceptable, high, limited, minimal).
- Confirm your role — provider, deployer, importer or distributor — for each system.
- Screen for prohibitions under Article 5 and stop any banned use immediately.
- Apply transparency measures now for chatbots, deepfakes and AI-generated content, and plan output marking ahead of 2 December 2026.
- Map high-risk obligations and build the technical file, risk-management and human-oversight controls ahead of the December 2027 deadline.
- Address GPAI duties if you provide or fine-tune general-purpose models.
- Deliver AI-literacy training to relevant staff.
- Integrate with GDPR and NIS2 — align DPIAs, impact assessments and security controls.
- Assign governance — clear ownership, documentation and monitoring — and keep records audit-ready.
Frequently asked questions
Is the EU AI Act in force yet?
Yes. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. Prohibitions and AI-literacy duties applied from 2 February 2025, GPAI and governance rules from 2 August 2025, and transparency obligations from 2 August 2026.
When do the high-risk rules start?
Following the AI Digital Omnibus, high-risk obligations for Annex III systems are now expected on 2 December 2027, and for AI embedded in Annex I regulated products on 2 August 2028. These postponed dates depend on final adoption of the Omnibus.
Do the transparency rules apply to my chatbot today?
Yes. Since 2 August 2026, users must be told they are interacting with AI, and AI-generated or manipulated content must be disclosed and marked. Existing generative-AI output must meet the marking requirements by 2 December 2026.
What are the maximum fines?
Up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for high-risk breaches; and up to €7.5 million or 1% for incorrect or incomplete information. SMEs pay the lower of the fixed amount or the percentage.
Does the AI Act apply to non-EU companies?
Yes, where an AI system is placed on the EU market or its output is used in the EU — even if the provider or deployer is established elsewhere.
Key takeaways
- The EU AI Act is Regulation (EU) 2024/1689, in force since 1 August 2024 and applying in phases.
- Transparency duties (Art. 50) are live as of 2 August 2026; existing generative-AI output must be marked by 2 December 2026.
- The Digital Omnibus postponed high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) — subject to final adoption.
- Fines reach €35m or 7% of global turnover; SMEs pay the lower amount.
- The Act works alongside the GDPR and NIS2 — plan compliance as one integrated programme.
Get an AI Act readiness scan
The AI Act rewards organisations that act early — and its transparency rules already bite. The technology and privacy lawyers at Law & More help providers and deployers classify their systems, correct prohibited or non-compliant uses, meet the live transparency duties, and build a defensible path to the 2027 high-risk deadline, fully aligned with the GDPR and NIS2. Contact Law & More for an AI Act readiness scan and turn a moving regulatory target into a clear, prioritised action plan.