top of page

EU AI Act Explained

Introduction


The EU AI Act, formally Regulation (EU) 2024/1689, is the first comprehensive legal framework for artificial intelligence adopted anywhere in the world. It entered into force on August 1, 2024, and its obligations have arrived in stages: bans on the most harmful practices in February 2025, rules for general-purpose AI models in August 2025, and transparency duties in August 2026, when the bulk of the Regulation became applicable and enforcement began (European Commission, 2026). The high-risk regime, the heaviest part of the framework, now applies from December 2, 2027, after the 2026 Digital Omnibus amendments postponed it.


The Act matters well beyond Europe. It binds providers in third countries whose systems or outputs reach the EU market, it has become the reference point against which other jurisdictions draft their own AI statutes, and it has already been amended once, a reminder that even landmark legislation is renegotiated when implementation proves harder than adoption. Understanding the Regulation therefore requires attention to three things at once: its rules, its scope, and the revised timetable on which it actually operates.


1. Legal Foundations and Regulatory Design


1.1 From Proposal to Regulation (EU) 2024/1689


The European Commission proposed the Regulation in April 2021, before generative AI reached mass adoption. The release of large chatbots in late 2022 reshaped the negotiations and forced the co-legislators to add an entire chapter on general-purpose AI models that the original draft did not contain. The European Parliament adopted its position on March 13, 2024, by 523 votes to 46 (European Parliament, 2024), the Council approved the text in May, and the Regulation was signed on June 13, 2024, and published in the Official Journal on July 12, 2024.


Its principal legal basis is Article 114 of the Treaty on the Functioning of the European Union, the internal-market harmonization power, supplemented by Article 16 TFEU for provisions touching personal data. Because it is a regulation rather than a directive, it applies directly in every member state without national transposition. Member states retain implementation tasks, chiefly designating supervisory authorities and setting penalty regimes within the Act's limits.


1.2 A Product-Safety Statute with Fundamental-Rights Aims


Article 1 states a double purpose: improve the functioning of the internal market and promote human-centric, trustworthy AI while protecting health, safety, and fundamental rights. The instrument chosen to deliver that purpose is not a rights charter but the EU's product-safety toolkit, known as the New Legislative Framework: conformity assessment, CE marking, harmonized technical standards, market surveillance, and an EU-wide registration database.


This design choice has a practical consequence. Much of what compliance means in detail is written not in the Regulation itself but in harmonized standards drafted by the European standardization bodies CEN and CENELEC. When a provider follows a harmonized standard, its system is presumed to conform. The slow progress of that standardization work became one of the main reasons the high-risk deadlines were later postponed.


2. Scope: Systems, Actors, and Territory


2.1 What Counts as an AI System


Article 3(1) defines an AI system as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions capable of influencing physical or virtual environments. The wording tracks the OECD's revised definition, a deliberate alignment intended to ease international interoperability.


The definition is broad by design. It captures generative models, machine-learning classifiers, and hybrid systems alike. It is not unlimited: Commission guidelines published in February 2025 clarify that conventional software executing only fixed, human-defined rules falls outside it. The boundary matters because the definition is the gate to every other obligation in the Act.


2.2 Operators Along the AI Value Chain


The Act distributes duties among categories of operator. Providers develop an AI system or general-purpose model and place it on the EU market under their own name, whether or not for payment. Deployers use an AI system under their own authority in a professional context. Importers and distributors bring third-country systems into the market or make them available within it, and authorized representatives act for providers established abroad (A&L Goodbody, 2024).


Providers carry the heaviest burdens. Deployers face lighter but genuine duties, including human oversight and monitoring, and public-sector deployers of high-risk systems must complete a fundamental-rights impact assessment under Article 27. The roles are not fixed: under Article 25, a deployer that rebrands a high-risk system or substantially modifies it becomes its provider, with everything that follows.


2.3 Extraterritorial Reach and Exclusions


Article 2 gives the Act reach comparable to the GDPR. It applies to providers placing systems or models on the EU market wherever they are established, and to providers and deployers located in third countries where the output produced by the system is used in the Union. A hiring tool run from outside the EU that scores applicants for EU-based positions is inside the Act's scope.


The exclusions are equally consequential. The Act does not apply to systems placed on the market or used exclusively for military, defense, or national-security purposes, to activity conducted solely for scientific research and development, or to purely personal, non-professional use. Free and open-source AI benefits from a partial carve-out that does not extend to prohibited practices, high-risk systems, or the transparency duties of Article 50.


3. The Four-Tier Risk Classification


3.1 Prohibited Practices


Article 5 bans practices judged incompatible with EU values, and the bans have applied since February 2, 2025. The original list covers eight practices: subliminal or manipulative techniques that materially distort behavior; exploitation of vulnerabilities linked to age, disability, or social and economic situation; social scoring that produces unjustified or disproportionate detrimental treatment; predicting the risk of an individual committing a criminal offense based solely on profiling or personality traits; untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases; emotion recognition in workplaces and educational institutions, except for medical or safety reasons; biometric categorization to infer race, political opinions, trade-union membership, religious beliefs, sex life, or sexual orientation; and real-time remote biometric identification in publicly accessible spaces for law enforcement (Regulation (EU) 2024/1689, Art. 5).


The last of these is a qualified rather than absolute ban. Real-time biometric identification remains possible in narrow cases, such as searching for victims of abduction, preventing an imminent threat to life, or locating suspects of serious listed offenses, and only with prior judicial or independent administrative authorization.


A ninth prohibition was added by the 2026 amendments: AI systems that generate non-consensual sexually explicit imagery or child sexual abuse material, the category that includes so-called nudification apps. It takes effect in December 2026 (European Commission, 2026).


3.2 High-Risk Systems and Their Obligations


An AI system becomes high-risk by one of two routes under Article 6. The first covers AI that is a product, or the safety component of a product, already regulated by the EU harmonization legislation listed in Annex I and subject to third-party conformity assessment: machinery, toys, lifts, medical devices, and similar categories. The second covers stand-alone systems used in the sensitive areas listed in Annex III: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including credit scoring and pricing in life and health insurance; law enforcement; migration, asylum, and border control; and the administration of justice and democratic processes.


Annex III classification is rebuttable. A provider that concludes its system poses no significant risk of harm to health, safety, or fundamental rights may document that assessment and register the system, though profiling of natural persons always remains high-risk.


For systems that are high-risk, Articles 8 to 15 set the substantive requirements. Providers must run a documented risk-management system across the product lifecycle; govern training, validation, and testing data for quality and bias; prepare technical documentation; build in automatic event logging; supply clear instructions to deployers; design the system for effective human oversight; and achieve appropriate accuracy, robustness, and cybersecurity. Before the system reaches the market it must pass conformity assessment, carry CE marking, and be registered in the EU database. After it is on the market, providers owe post-market monitoring and serious-incident reporting, while deployers must use the system according to its instructions and keep oversight in human hands.


3.3 Transparency Duties for Specific Uses


Article 50 attaches disclosure duties to particular uses of AI regardless of risk class. People must be told when they are interacting with an AI system unless that is obvious. Providers of generative systems must ensure synthetic audio, image, video, and text output is marked machine-readable as artificially generated. Deep fakes must be visibly labeled, as must AI-generated text published to inform the public on matters of public interest. Individuals exposed to emotion recognition or biometric categorization must be informed.


These duties became applicable on August 2, 2026, supported by Commission guidelines and a code of practice on marking published in July 2026. Generative models already on the market before that date have until December 2, 2026, to implement content marking.


3.4 Minimal Risk and the AI Literacy Duty


Most AI in use in Europe, from spam filters to game engines, sits in the minimal-risk tier and attracts no new obligations beyond voluntary codes of conduct. One horizontal duty still applies across all tiers: Article 4 has required providers and deployers, since February 2025, to ensure that staff operating AI systems on their behalf have a sufficient level of AI literacy for the context of use.


4. General-Purpose AI Models


The GPAI chapter is the Act's most improvised and most watched part. A general-purpose AI model is one that displays significant generality and can competently perform a wide range of distinct tasks, typically a large model trained on broad data. Since August 2, 2025, its providers must maintain technical documentation, give downstream system builders the information they need to comply with their own duties, adopt a policy to respect EU copyright law, including rights holders' text-and-data-mining opt-outs, and publish a summary of training content using the AI Office template.


A subset of models carries systemic risk. The Act presumes systemic risk when the compute used in training exceeds 1025 floating-point operations, and the Commission can designate models below that threshold. Providers of such models must additionally perform state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks, report serious incidents, and protect the model with adequate cybersecurity.


A voluntary General-Purpose AI Code of Practice, published in July 2025, gives providers a presumption-friendly route to demonstrating compliance, and most major model developers signed it. The Commission's enforcement powers over GPAI providers became exercisable on August 2, 2026, and models placed on the market before August 2025 have until August 2, 2027, to conform.


5. Governance, Enforcement, and Penalties


5.1 A Two-Level Supervisory Architecture


Supervision is split between Brussels and the capitals. The AI Office, created within the Commission, exclusively supervises general-purpose AI models, drafts codes of practice and templates, and coordinates implementation. A European Artificial Intelligence Board of member-state representatives steers consistency, advised by a stakeholder forum and a scientific panel of independent experts empowered to alert the AI Office to emerging systemic risks.


Everything else is enforced nationally. Each member state has designated market surveillance authorities and notifying authorities, and each must operate at least one AI regulatory sandbox, a supervised testing environment, by August 2027. Enforcement of the generally applicable rules began on August 2, 2026 (European Commission, 2026).


5.2 Penalties


The fine structure is tiered by gravity. Engaging in a prohibited practice exposes an operator to fines of up to €35 million or 7 percent of worldwide annual turnover, whichever is higher. Breach of most other obligations, including the high-risk requirements, carries up to €15 million or 3 percent. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1 percent. For small and medium-sized enterprises the lower of the two amounts applies. GPAI providers face Commission-imposed fines of up to €15 million or 3 percent of turnover, and authorities can also order corrective measures, including withdrawal or recall of a non-compliant system.


6. The Digital Omnibus and the Revised Timetable


By late 2025 it was clear the original calendar would not hold. The harmonized standards on which high-risk conformity assessment depends were behind schedule, and industry warned that obligations would land before the tools to meet them existed. On November 19, 2025, the Commission proposed the Digital Omnibus on AI as part of a wider simplification package; the Parliament and Council reached political agreement on May 7, 2026, and the amending act was adopted before the original August 2026 deadline (Council of the European Union, 2026).


The headline change is timing. Obligations for stand-alone Annex III high-risk systems now apply from December 2, 2027, and those for high-risk AI embedded in Annex I regulated products from August 2, 2028, as fixed dates no longer conditional on standards availability. The package also removed the Machinery Regulation from the Act's scope in favor of sector-specific safety rules, lightened technical documentation for companies with fewer than 750 employees, gave pre-existing generative models a short grace period for content marking, and added the ninth prohibition described above.


What did not move is just as telling. The prohibitions, the AI literacy duty, the GPAI rules, the Article 50 transparency regime, the risk classification, and the penalty ceilings all stand unchanged. The amendment defers the heaviest compliance regime; it does not dilute it.

Date

What applies

Aug 1, 2024

Entry into force

Feb 2, 2025

Prohibited practices; AI literacy duty

Aug 2, 2025

GPAI model obligations; governance bodies; national penalty rules

Aug 2, 2026

Article 50 transparency; general applicability; enforcement begins

Dec 2, 2026

Ninth prohibition; content marking for legacy generative models

Aug 2, 2027

Legacy GPAI models compliant; sandboxes operational

Dec 2, 2027

High-risk obligations, Annex III systems

Aug 2, 2028

High-risk obligations, Annex I embedded systems


7. The EU AI Act's Global Impact


7.1 The Brussels Effect, Tested


The expectation that the EU AI Act would set a global default rests on the Brussels effect: the combination of a large single market, strict standards, and companies' preference for one worldwide product line tends to export EU rules de facto, and often de jure as other legislatures copy them (Bradford, 2020). The GDPR is the standard illustration. The Act's extraterritorial scope reinforces the mechanism, since any provider whose output reaches EU users is already inside the regime, and machine-readable marking of synthetic content is the kind of requirement most cheaply implemented once, globally.


The first two years suggest the effect is real but weaker than it was for data protection. AI regulation touches national security and industrial policy, domains where governments resist importing foreign rules. The United States has moved in a deregulatory direction at the federal level, and several major providers have delayed EU launches or shipped region-limited versions rather than globalize EU compliance. The Digital Omnibus shows influence running the other way too: competitiveness pressure from abroad helped persuade the EU to soften its own calendar.


7.2 Convergence and Divergence Beyond the EU


The Act now sits within a widening field of instruments. The Council of Europe's Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, adopted on May 17, 2024, and opened for signature that September, is the first binding international treaty on AI; it is principles-based and open to non-European states, and the EU, the United Kingdom, and the United States were among its first signatories (Council of Europe, 2024). South Korea enacted a framework act on AI in January 2025, effective from January 2026, the first comprehensive national statute after the EU's and visibly influenced by it, though lighter in its obligations. Brazil's risk-based bill follows the EU architecture closely.


Divergence is just as visible. The United Kingdom relies on sector regulators applying cross-cutting principles without a horizontal statute. The United States combines a patchwork of state laws with shifting federal executive policy and no comprehensive federal legislation. China regulates vertically, through targeted rules on recommendation algorithms, generative AI services, and content labeling. The practical bridge among these models is being built in technical venues, notably international management-system standards and the G7's Hiroshima process, rather than in treaty text.


Also read


Conclusion


Two years of implementation have tested the EU AI Act's architecture and its calendar, and only the calendar gave way. The risk-based structure, the prohibitions, the GPAI regime, and the penalty framework all survived the first amendment cycle intact; what changed was when the hardest obligations bite. That points to the Act's real dependency: a product-safety statute is only as operational as the standards, notified bodies, and national authorities beneath it, and those foundations were not ready on the original schedule.


The decisive period is now 2027 to 2028, when the high-risk regime becomes enforceable and conformity assessment moves from paper to practice. Supervision of general-purpose models is already live and will produce the first significant enforcement signals. For legislatures elsewhere, the lesson of the first two years concerns sequencing as much as substance: obligations that outrun their supporting infrastructure invite delay, and delay carries its own political cost. The Regulation remains the most complete statement of how a major jurisdiction proposes to govern AI, which is precisely why its revisions are read as closely as its text.


References


A&L Goodbody (2024) Guide to the AI Act – a detailed breakdown of what you need to know. Dublin: A&L Goodbody.


Bradford, A. (2020) The Brussels Effect: How the European Union Rules the World. New York: Oxford University Press.


Council of Europe (2024) Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, adopted 17 May 2024, opened for signature 5 September 2024, CETS No. 225.


Council of the European Union (2026) Artificial Intelligence: Council gives final green light to simplify and streamline rules [online]. Available at: https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/ (Accessed: 8 August 2026).


European Commission (2026) AI Act | Shaping Europe's digital future [online]. Available at: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai (Accessed: 8 August 2026).


European Parliament (2024) Artificial Intelligence Act: European Parliament legislative resolution of 13 March 2024, TA-9-2024-0138.


Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12 July 2024.

Diplomacy and Law Logo
bottom of page