EU AI Act
Regulation (EU) 2024/1689
The European Union's binding regulation that classifies AI systems by risk, bans some practices, sets obligations for high-risk systems and transparency rules, and adds separate rules for general-purpose AI models.
Regulation (EU) 2024/1689, the AI Act, is the first comprehensive horizontal law on artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. As a regulation, it applies directly in every member state.
Its logic is risk-based: obligations follow the intended purpose, not the technology: - Unacceptable risk (prohibited): the practices in Article 5 — for example harmful manipulation, exploiting vulnerabilities, social scoring, emotion recognition at work and in education (except for medical or safety reasons), untargeted scraping of facial images for recognition databases. The 2026 amendment added systems that generate non-consensual intimate content or child sexual abuse material (e.g. "nudification" apps). - High risk: AI in products covered by EU product safety law (Annex I: machinery, toys, medical devices, etc.) and sensitive use cases (Annex III: biometrics, critical infrastructure, education, employment, access to essential services/credit, law enforcement, migration, justice). Requires risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and cybersecurity, a quality management system and conformity assessment. - Transparency risk (limited risk): Article 50. Tell people they are talking to an AI, mark generated content in a machine-readable way, label deepfakes. - Minimal risk: the vast majority of systems, like spam filters or game AI; no additional rules.
There is also a separate regime for general-purpose AI (GPAI) models: technical documentation, information for downstream providers, a copyright policy and a public summary of training content. Models trained with more than 10^25 FLOPs are presumed to carry systemic risk and face extra evaluation, incident reporting and cybersecurity duties. The Commission-published GPAI Code of Practice is a voluntary route to compliance.
Extraterritorial scope: the Act applies to providers placing AI on the EU market wherever they are established, and can reach non-EU providers and deployers whose output is used in the EU (Article 2). A Turkish company selling into the EU can be in scope.
Fines (Article 99): up to €35M or 7% of worldwide turnover for prohibited practices, €15M or 3% for most other obligations, €7.5M or 1% for supplying incorrect information to authorities (whichever is higher; for SMEs, whichever is lower). The Commission can fine GPAI providers up to €15M or 3% (Article 101).
Timeline — as of October 2026: in November 2025 the Commission proposed the "Digital Omnibus on AI" to push back some dates. It was adopted as Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July 2026 — it is now law, not a proposal: - 2 February 2025 — prohibitions and AI literacy (Article 4) apply. The Omnibus softened literacy from guaranteeing a level to "taking measures to support" staff literacy. - 2 August 2025 — GPAI obligations, governance structure and penalty provisions apply. GPAI models already on the market before that date have until 2 August 2027. - 2 August 2026 — the rest of the Act applies, including Article 50 transparency. Generative systems already on the market before that date have until 2 December 2026 for content marking (Article 50(2)). - 2 December 2026 — the new nudification/CSAM prohibition. - 2 December 2027 — Annex III high-risk systems (was 2 August 2026). - 2 August 2028 — high-risk AI embedded in Annex I products (was 2 August 2027).
This page is informational, not legal advice; dates and details may change again with further amendments.
Like food safety law. Some substances can't be sold at all (prohibited), risky products like baby formula need strict checks and paperwork (high risk), packaged food must carry an ingredient label (transparency), and most items on the shelf follow only general rules (minimal risk). If you sell in the EU, the rules apply wherever your factory is.
An HR-tech startup in Istanbul sells a CV-scoring product to customers in Germany. Its analysis in October 2026:
1. Role: it places the AI system on the EU market under its own name, so it is the provider. The German customer is the deployer. 2. Class: evaluating candidates in recruitment is listed in Annex III → high risk. Obligations start on 2 December 2027; but a quality management system, technical documentation and data governance take months, so preparation starts now. 3. Transparency: the product also has a chat assistant that talks to candidates. Under Article 50 candidates must be told they are talking to an AI; that has applied since 2 August 2026. 4. Prohibition check: emotion recognition in video interviews was on the roadmap; emotion recognition in the workplace is banned under Article 5, so the feature is dropped. 5. KVKK: Turkish candidates' data is also subject to Turkey's data protection law; the AI Act doesn't replace it.
# AI Act pre-assessment — System: AI-017 (October 2026)
## 1. Scope
- [ ] Is this an "AI system"? (Commission definition guidelines)
- [ ] Placed on the EU market, or output used in the EU?
- [ ] Our role: provider / deployer / importer / distributor?
## 2. Prohibited practices (Article 5) — any YES means STOP
- [ ] Manipulation or exploitation of vulnerabilities
- [ ] Social scoring
- [ ] Emotion recognition at work / in education
- [ ] Generating non-consensual intimate content / CSAM
## 3. High risk
- [ ] Covered by Annex I product safety law? → 2 Aug 2028
- [ ] Annex III area? (employment, education, credit…) → 2 Dec 2027
- [ ] Could the Article 6(3) derogation apply? Document why
## 4. Transparency (Article 50) — applies since 2 Aug 2026
- [ ] Do users know they are interacting with AI?
- [ ] Is generated content marked in a machine-readable way?
## 5. Are we providing a GPAI model?
- [ ] Technical docs, copyright policy, training content summary
- [ ] Training compute > 10^25 FLOPs? → systemic risk- You place an AI system, or a product containing AI, on the EU market
- You are outside the EU but your system's output is used in the EU
- EU customers ask about AI Act compliance in vendor assessments
- You train a general-purpose model and make it available to others
- A purely domestic use with no EU link doesn't have to follow the AI Act — though it is a useful reference for good practice
- Systems used exclusively for military, defence or national security purposes, and systems developed solely for scientific research, are excluded
- Calling every chatbot 'high-risk' on sight — the class depends on intended purpose, not technology
Treating postponement as exemption
The Omnibus pushed back the high-risk dates, but prohibitions, AI literacy, GPAI rules and Article 50 transparency already apply. Work like a quality management system takes months; waiting for December 2027 means being late.
An outdated timeline
The AI Act's dates have changed once and may change again. Check the consolidated text on EUR-Lex and the Commission's page rather than blog posts, and keep a 'last verified' date in your register.
Getting your role wrong
Taking an off-the-shelf model and offering it under your brand, or changing its intended purpose, can turn you from a deployer into a provider. Obligations differ a lot by role.
Not legal advice
This summary is informational. For the classification and obligations of a specific system, go to the text itself and to a lawyer.