Skip to main content

Techné AI · Free reference · Edition 3.0.0

EU AI Act

A scoped guide to EU AI Act roles, risk classes, GPAI duties, transparency and the amended high-risk timetable under Regulation (EU) 2026/1744.

Reviewed Download complete PDF Corrections
On this page
  1. Risk classification
  2. Phased timeline
  3. What applies now
  4. The GPAI Code of Practice
  5. High-risk duties: separate provider and deployer roles
  6. Penalties and enforcement
  7. Practical review checklist

The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. Its requirements depend on the system, intended use, organisation’s role, and applicable exceptions. A general-purpose AI model and a downstream system built with it can have different obligations.1

The Digital Omnibus on AI is enacted, not pending. Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. It changes selected high-risk deadlines and other provisions; it does not postpone the entire Act.23

Risk classification

The familiar four-level summary is a reading aid, not four mutually exclusive legal compartments. Article 50 transparency duties can overlap with high-risk duties, and obligations such as AI literacy can apply outside the high-risk category.1

CategoryWhat to assessIllustrative uses
Prohibited practicesExact Article 5 conditions and exceptionsSpecified social scoring, harmful manipulation, untargeted facial-image scraping, and workplace or education emotion inference, subject to the statutory exceptions
High-risk systemsArticle 6, Annex III and the relevant product legislation; assess exclusions rather than classifying by sector aloneCertain employment, education, credit, insurance, biometric, infrastructure and regulated-product uses
Transparency dutiesThe relevant provider or deployer obligation in Article 50Human interaction with AI, synthetic-content marking, deepfakes, emotion recognition and certain public-interest text
Other systemsWhether particular AI Act provisions or other laws still applyA lower-risk use is not automatically exempt from privacy, consumer, employment or sectoral law

The new prohibitions concerning specified AI systems for child sexual abuse material and non-consensual intimate content apply from 2 December 2026. Their provider/deployer conditions and safeguards matter: they are not a blanket prohibition on every general-purpose content generator.3

Phased timeline

DateMilestonePosition at 7 September 2026
1 August 2024Original Regulation enters into forcePast
2 February 2025Original prohibited-practice and AI-literacy provisions applyApplicable; Article 4 has since been amended
10 July 2025Voluntary GPAI Code of Practice publishedAvailable
2 August 2025GPAI rules and specified governance provisions applyApplicable, with the existing-model transition below
27 July 2026Digital Omnibus enters into forceEnacted
2 August 2026General application date, including Article 50 transparency and Commission GPAI enforcement powersApplicable, subject to scoped transitions
2 December 2026Specified new Article 5 prohibitions; Article 50(2) deadline for relevant systems already marketed before 2 August 2026Future
2 August 2027Compliance deadline for GPAI models placed on the market before 2 August 2025Future
2 December 2027Specified Chapter III Sections 1–3 provisions for Article 6(2)/Annex III systemsFuture; original date was 2 August 2026
2 August 2028Corresponding provisions for Article 6(1) regulated-product systemsFuture; original date was 2 August 2027

The high-risk amendment expressly excepts Article 6(5) from the deferral. Article 111 also contains existing-system transition rules. Establish which provision and system group a date applies to before using it as a launch deadline.132

What applies now

Prohibited practices. The original Article 5 restrictions have applied since February 2025. Social scoring is not confined to government use. Each prohibition has its own elements; for example, the workplace/education emotion-inference restriction includes medical or safety exceptions. Screen the intended and reasonably foreseeable use against the text.1

AI literacy. Amended Article 4 requires providers and deployers to take measures supporting the development of AI literacy among relevant staff and others operating systems on their behalf, accounting for their knowledge, experience and context. It expressly does not require guaranteeing any particular individual’s literacy level. Record role-appropriate learning and support.3

GPAI. Article 53 addresses model documentation, downstream information, copyright policy and a public training-content summary. Article 55 adds duties for models with systemic risk. Check applicable exemptions and the 2 August 2027 transition for models marketed before 2 August 2025; do not assume every model became subject to every duty in August 2025.1

Transparency. Article 50 has applied since 2 August 2026. Providers of interactive systems must address AI-identity disclosure; providers of synthetic-content systems must address machine-readable marking. Deployers have distinct disclosure duties for deepfakes, certain public-interest text, emotion recognition and biometric categorisation. Exceptions and allocation of responsibility differ by paragraph.4

The Article 50(2) extension to 2 December 2026 concerns relevant systems placed on the market before 2 August 2026. It is not a general best-efforts exemption or a grace period for all Article 50 duties.3

The GPAI Code of Practice

The Commission describes the Code, published 10 July 2025, as an adequate voluntary means of demonstrating compliance. Its Transparency and Copyright chapters address Article 53; Safety and Security addresses Article 55 systemic-risk duties.5

The official signatory list includes Google, Microsoft, OpenAI and Anthropic. xAI signed the Safety and Security chapter only and must demonstrate transparency/copyright compliance through other adequate means. Check the current list rather than treating signature status as permanent.5

Signing is not an exemption, certification or automatic presumption of conformity. Actual adherence matters, and non-signatories can demonstrate compliance through other adequate means. The Omnibus expressly distinguishes codes from harmonised standards that can confer a presumption of conformity.3

See Frontier Models for model-level governance and the separate U.S. testing arrangements.

High-risk duties: separate provider and deployer roles

For an in-scope high-risk system, the requirements include lifecycle risk management, appropriate data governance, technical documentation, logging, instructions, human oversight, accuracy, robustness and cybersecurity (Articles 9–15). Providers must also address their Article 16 duties, quality management and the applicable conformity-assessment route. Not every assessment requires a third-party notified body.1

Registration is governed by Article 49, with different obligations and exceptions for providers and certain deployers; Article 71 establishes the database. It is not a universal registration rule for every AI system.1

Deployers have separate operational obligations under Article 26. Article 27’s fundamental-rights impact assessment applies to specified deployers, including public-law bodies, private entities providing public services, and deployers of the specified creditworthiness and life/health-insurance systems. It is not an obligation on every high-risk provider or deployer; the Article 27 scope and exclusions must be checked.1

ISO/IEC 42001 and supporting standards can help organise governance evidence. They do not themselves establish EU AI Act conformity or replace the relevant legal assessment. See ISO standards.

Penalties and enforcement

Article 99 sets ceilings, not automatic fines:1

Specified violationMonetary / turnover ceiling
Article 5 prohibited practicesEUR 35 million / 7%
Listed operator and transparency obligationsEUR 15 million / 3%
Incorrect, incomplete or misleading information supplied to specified authoritiesEUR 7.5 million / 1%

For undertakings, the higher applicable ceiling generally applies; Article 99 includes lower-of-the-two treatment for SMEs, including start-ups. The Omnibus extends specified proportional treatment to small mid-cap enterprises; do not generalise every SME concession to every organisation or violation. Article 101 provides a separate Commission fine regime for GPAI providers, with a ceiling of 3% of worldwide annual turnover.13

National competent authorities enforce within their assigned responsibilities; the AI Office supports Commission oversight, including GPAI, and the European AI Board supports coordination. Commission GPAI enforcement powers, including fines, became applicable on 2 August 2026—not together with all the August 2025 provisions.6

Practical review checklist

  • Inventory systems and models, intended uses, markets and your provider/deployer role.
  • Screen against the original Article 5 restrictions and the specified new December 2026 prohibitions.
  • Record measures supporting relevant staff’s AI literacy under amended Article 4.
  • Check each Article 50 duty now; document eligibility before relying on its narrow marking transition.
  • For GPAI, identify model-market dates, exemptions and any systemic-risk classification.
  • For high-risk systems, record the applicable Annex, assessment route, role-specific duties and transition date.
  • Keep a provision-level evidence map; do not use an ISO certificate or Code signature as a substitute for compliance analysis.

This chapter is a dated overview, not a determination that a particular system is lawful or compliant. Use the original Regulation together with the amending text and applicable implementing measures.

Footnotes

  1. Regulation (EU) 2024/1689, especially Articles 5–6, 9–17, 26–27, 43, 49–55, 99, 101, 111 and 113; read as amended. 2 3 4 5 6 7 8 9 10

  2. European Commission. Regulatory framework on artificial intelligence. 2

  3. Regulation (EU) 2026/1744, especially Article 1(5), (38)–(40), recital 42 and Article 4. 2 3 4 5 6 7

  4. European Commission. (2026, July 20). Guidelines on transparency obligations for providers and deployers of certain AI systems.

  5. European Commission. The General-Purpose AI Code of Practice and official signatory list. 2

  6. European Commission. (2026, July 31). Commission starts enforcing AI Act rules and new transparency requirements on 2 August.

This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.