EU AI Act
The AI Act is the global reference point — the 'Brussels effect' means its risk categories, conformity assessments and GPAI rules shape corporate AI governance far beyond Europe. Every multinational deploying AI in the EU market must map its systems against it.
What it is
The world's first comprehensive, risk-based AI law. It bans a set of unacceptable practices (social scoring, manipulative AI, most real-time remote biometric ID), imposes heavy obligations on high-risk systems, regulates general-purpose AI models, and requires transparency for generative and interactive AI.
Phased application: prohibitions & AI literacy Feb 2025; GPAI model duties Aug 2025; transparency Aug 2026; high-risk (Annex III) Dec 2027 and embedded (Annex I) Aug 2028 after the 2026 Digital Omnibus.
Who is affected
Providers of GPAI models released before August 2025
Key obligations
- Prohibited practices banned since 2 Feb 2025 (fines up to 7% of global turnover)
- General-purpose AI model providers: technical documentation, copyright policy, training-data summaries since Aug 2025; systemic-risk models face evaluation and incident-reporting duties
- Transparency from 2 Aug 2026: disclose AI interaction, machine-readable marking of AI-generated content, deepfake labeling
- High-risk systems: risk management, data governance, human oversight, CE conformity — applying Dec 2027 (Annex III) / Aug 2028 (Annex I)
Compliance dates
EU AI Act — legacy GPAI models must comply
General-purpose AI models placed on the market before 2 August 2025 must be brought into full compliance with the AI Act's GPAI obligations by this date.
EU AI Act — high-risk obligations apply (Annex III)
Post-Omnibus application date for standalone high-risk AI systems (employment, credit, education, essential services, law enforcement): full risk-management, data-governance, human-oversight and conformity obligations.
EU AI Act — high-risk obligations apply (Annex I, embedded)
Post-Omnibus application date for AI systems embedded in regulated products (machinery, medical devices, vehicles): AI Act high-risk duties integrate with sectoral conformity regimes.
EU AI Act — transparency obligations applied
Chatbot disclosure, AI-content marking and deepfake labeling duties became applicable across the EU — alongside the deadline for member states to designate market surveillance authorities and the end of the GPAI Code of Practice enforcement grace period.
Recent signals
Commission designates ChatGPT a very large online search engine under the DSA
ChatGPT becomes the first generative AI service brought inside the Digital Services Act's strictest tier, alongside Reddit and Roblox as very large online platforms. Systemic-risk assessment, mitigation, audit and data-access duties follow four months after notification.
EU AI Act transparency obligations become applicable
Chatbot disclosure, machine-readable AI-content marking and deepfake labeling duties now apply EU-wide; the GPAI Code of Practice enforcement grace period ends the same day.
Digital Omnibus on AI enters into force, delaying high-risk deadlines
Regulation (EU) 2026/1744 pushes high-risk AI Act obligations to Dec 2027 (Annex III) and Aug 2028 (Annex I) and simplifies documentation duties — the EU's first formal AI Act correction.
EU AI Act GPAI model obligations become applicable
General-purpose model providers must maintain technical documentation, publish training-content summaries and comply with EU copyright law; systemic-risk models face safety duties.
Related instruments
- EUEU Digital OmnibusThe first formal simplification of the AI Act. Adopted July 2026, it delays high-risk obligations to December 2027 (standalone Ann…
- EUGPAI Code of PracticeA voluntary code operationalizing the AI Act's GPAI chapter across transparency, copyright and safety/security. Major model provid…
- EUGDPR × AIThe EU's data-protection regime remains a primary AI constraint: legal bases for training data, automated-decision rights (Art. 22…
- EUAI Liability DirectiveThe Commission withdrew its proposed AI Liability Directive in February 2025, citing no foreseeable agreement. Civil liability for…
- ITItaly AI LawItaly became the first EU member state with a national AI law, layering sector rules (healthcare, work, justice, public administra…
Related reading
- Issue 17Denmark met the deadline. Sweden is late. Norway is outside the regime.A model classified Critical for cyber capability shipped this month and no Nordic AI authority has issued operational guidance in response. What policymakers, businesses and citizens should do — and what the region is getting right.
- Issue 16OpenAI will stop scaling at a line it has not publishedGPT-6 Astra is the first model its maker classifies as Critical for cyber capability, and the first whose monitorability has gone backwards. The stated safeguard is a private judgement about an unstated number.
- Issue 11Pakistan's National AI Policy at one yearSix pillars, a national fund, and one million trained professionals by 2030. Twelve months on, the question is what has been built and what has drifted.