EU AI Act (Regulation (EU) 2024/1689)¶
Provenance & licence
Source: EUR-Lex ELI permalink ·
Last observed: 2026-09-05 ·
Version: Base regulation in force 2024-08-01; amended by Digital Omnibus Reg. (EU) 2026/1744, in force 2026-07-27 ·
Status: planned — automated watch adapter not yet live; this page is updated manually (see provenance chain) ·
Licence: © European Union (EUR-Lex), Decision 2011/833/EU (open-attribution)
Now law — Digital Omnibus, Reg. (EU) 2026/1744 (in force 27 July 2026)
The Digital Omnibus on AI — proposed 19 November 2025, provisionally agreed in the May 2026 trilogue — was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Headline change: the high-risk regime is deferred — stand-alone Annex III systems to 2 December 2027, Annex I product-embedded AI to 2 August 2028 (fixed dates, replacing the proposal's conditional "standards-ready" trigger). It also adds an Art. 5 prohibition on CSAM/NCII generation, grants a marking grace period, strengthens the AI Office's enforcement powers over GPAI-based systems, softens the Art. 4 AI-literacy duty from guaranteeing to supporting, extends the Art. 10(5) bias-detection ground to all AI systems, reinstates registration for Art. 6(3) carve-outs, narrows "safety component" and extends SME simplifications to small mid-caps — all dates in the application timeline below. The Omnibus also amends Reg. (EU) 2018/1139 (aviation) and Reg. (EU) 2023/1230 (machinery).
Summary¶
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive, horizontal AI law. It classifies AI systems by risk — unacceptable (prohibited), high-risk, limited-risk (transparency), and minimal — and imposes obligations scaled to that tier, with separate rules for general-purpose AI (GPAI) models. It entered into force on 1 August 2024 and applies in phases. As of August 2026, prohibitions, GPAI model rules and the Art. 50 transparency duties are in force; the high-risk regime has been deferred to December 2027 / August 2028 by the Digital Omnibus (Reg. (EU) 2026/1744 — see box above).
In plain language¶
Our explanation, not the official text
Plain-language summary in our own words — not the normative text. Follow the source for the authoritative wording. This is general information, not legal advice.
The EU AI Act is a binding law that sorts AI systems by how risky they are and attaches duties to each level: some uses are banned, "high-risk" uses carry heavy obligations, and general-purpose models have their own rules. In short — the riskier the use, the more you must document, test, and supervise it. A 2026 "Digital Omnibus" amendment — in force since 27 July 2026 — pushed the high-risk deadlines to December 2027 / August 2028, so always check the amended timeline, not the original one.
Key terms¶
- High-risk system — an AI use listed in Annex III (or a safety component of a regulated product) that triggers the heaviest duties.
- GPAI — a general-purpose AI model, with its own transparency and copyright duties.
- Conformity assessment — the check (self- or third-party) that a high-risk system meets the rules before market.
- FRIA — a fundamental-rights impact assessment some deployers must perform.
- CETS 225 — the Council of Europe AI Convention; the EU approved it in 2026 and implements it exclusively through the AI Act (Council Decision (EU) 2026/1080, Art. 3). See the CETS 225 page.
Application timeline (as amended by the Omnibus)¶
The dates below reflect Art. 113 as amended by Reg. (EU) 2026/1744 — the anchor an auditor checks first, because it decides which obligations are actually in force at the engagement date.
| Date | What applies |
|---|---|
2024-08-01 |
Entry into force of Reg. (EU) 2024/1689. |
2025-02-02 |
Art. 4 AI literacy + Art. 5 prohibitions + general provisions. |
2025-08-02 |
GPAI rules (Art. 51 ff.), governance (AI Office, AI Board), notified-body chapter, penalties framework (Art. 99) except Art. 101. |
2026-08-02 |
General application (except the deferred high-risk regime) — incl. Art. 50 transparency and Art. 101 GPAI fines. |
2026-12-02 |
Grace periods end: Art. 50(2) marking for pre-Aug-2026 systems; the new Art. 5 CSAM/NCII prohibition fully applies. |
2027-08-02 |
National regulatory sandboxes operational (Omnibus: moved from 2026). Legacy GPAI models placed on the market before 2 Aug 2025 must comply. |
2027-12-02 |
Annex III stand-alone high-risk obligations (Omnibus: was 2026-08-02). |
2028-08-02 |
Annex I product-embedded high-risk obligations (Omnibus: was 2027-08-02). |
2030-08-02 |
Legacy high-risk systems in use by public authorities: providers and deployers must be compliant (Art. 111(2)). |
2030-12-31 |
Legacy AI components of large-scale EU IT systems (Annex X) must comply; other pre-existing high-risk systems come into scope only upon significant modification (Art. 111). |
In depth: what counts as an "AI system"¶
Reading guide: the boxed “Source text” is the Act's own wording (verbatim; EU law is reusable under EUR-Lex Decision 2011/833/EU with source acknowledgement). Text marked “In our words” is our explanation.
Source text — EU AI Act, Art. 3(1) (© European Union, EUR-Lex)
‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
In our words — this single sentence decides whether the whole Act applies to you. The load-bearing phrases are “machine-based”, “varying levels of autonomy”, “may exhibit adaptiveness” and especially “infers … how to generate outputs”. A fixed, deterministic script usually falls outside; a model that infers its outputs falls inside. Once you are in scope, the risk tier — prohibited · high-risk · limited (transparency) · minimal — decides how heavy your duties are.
From my training — University of Oxford · Managing Enterprise AI Risks (2026)
For high-risk systems the audit pivot I practise is evidence over intent: risk classification, Model Cards, an AI-SBOM, a living risk register and Human-in-the-Loop (HITL) controls mapped to Art. 9 / 14 / 15 — and I treat the EU AI Act, NIST AI RMF and ISO/IEC 42001 as one control set, not three. Verify certificate ↗
In depth: machine-readable transparency (Art. 50 + Recital 133)¶
Source text — EU AI Act, Recital 133, excerpt (© European Union, EUR-Lex)
… it is appropriate to require providers of those systems to embed technical solutions that enable marking in a machine readable format and detection that the output has been generated or manipulated by an AI system and not a human. Such techniques and methods should be sufficiently reliable, interoperable, effective and robust as far as this is technically feasible, taking into account available techniques or a combination of such techniques, such as watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques, as may be appropriate.
In our words — the Act does not stop at "label your AI content". The binding duty sits in Art. 50(2): providers of generative systems must mark synthetic output in a machine-readable format; Recital 133 then names the technique families the legislator has in mind — watermarks, metadata identification, cryptographic provenance/authenticity proofs, logging methods and fingerprints. A recital is interpretive, not operative — but it signals where compliance practice is heading: provenance signals embedded in the content itself and travelling along the digital value chain (in practice, C2PA-style "Content Credentials" metadata combined with watermarking). Two timeline anchors: Art. 50 applies since 2 August 2026; systems already on the market before that date have a marking grace period until 2 December 2026 (Digital Omnibus, Reg. (EU) 2026/1744). Note the scope carve-out in the recital: purely assistive/standard-editing functions that do not substantially alter the input are not covered. Cross-framework: the NIST GenAI Profile (600-1) makes information integrity / content provenance a primary focus area — see NIST AI RMF.
Key Sections¶
- Art. 5 — Prohibited practices — manipulative, exploitative, social-scoring, untargeted scraping, and (per the Omnibus) CSAM/NCII generation.
- Art. 6 + Annex III — High-risk classification — the test for whether a system is high-risk; Art. 6(1) treated separately in the timeline.
- Art. 16 — Provider obligations — risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity.
- Art. 26 — Deployer obligations — using the system per instructions, assigning competent human oversight, input-data control, operation monitoring, log retention.
- Art. 27 — Fundamental Rights Impact Assessment (FRIA) — required of certain deployers of high-risk systems.
- Art. 40 — Harmonised standards — presumption of conformity when applying harmonised standards; their CEN/CENELEC delay was the driver of the Omnibus deferral.
- Art. 43 — Conformity assessment — internal control vs notified-body routes.
- Art. 50 — Transparency & content marking — AI-interaction disclosure, machine-readable marking of synthetic content (Rec. 133), deep-fake labelling.
- GPAI (Art. 51 ff.) — model documentation, copyright policy, training-data summary; systemic-risk models carry added duties.
- Council Decision (EU) 2026/1080 — CETS 225 implemented through the AI Act — why "CETS 225 compliance" in the EU means AI Act compliance; the Convention itself is on the CETS 225 page.
Guidance & codes of practice (soft law)¶
Not legally binding, but the Commission-endorsed compliance path — in practice the documents clients work with first:
- GPAI Code of Practice (July 2025) — the voluntary route for GPAI providers to demonstrate Art. 53/55 compliance (transparency, copyright, safety & security chapters).
- Guidelines on prohibited AI practices (Feb 2025) — the Commission's interpretation of the Art. 5 bans, with practical examples.
- Guidelines on the AI-system definition (Feb 2025) — which software falls inside the Art. 3(1) definition quoted above.
- Guidelines on transparency obligations — Art. 50 (July 2026) — the final reading of the four Art. 50 duties and their exceptions (published 2026-07-20).
- Commission opinion on the Code of Practice on AI-generated content (July 2026) — the Commission's assessment of the voluntary marking/labelling code (2026-07-09).
- Draft guidelines on high-risk classification — Art. 6 (May 2026) — draft, under targeted consultation; do not cite as final.
Penalties¶
The Act's enforcement teeth — the national fine bands of Art. 99, applicable since 2 August 2025:
| Violation | Maximum fine |
|---|---|
| Art. 5 prohibited practices | €35 m or 7 % of worldwide annual turnover (whichever is higher) |
| Most other obligations — incl. Art. 16, Art. 26, Art. 50 | €15 m or 3 % |
| Incorrect, incomplete or misleading information to authorities | €7.5 m or 1 % |
For SMEs and start-ups each cap is the lower of the two amounts. GPAI-model providers face separate Commission fines of up to 3 % of worldwide annual turnover or €15 m (Art. 101, applicable since 2 August 2026). By construction, fines for the deferred high-risk obligations can only bite once those obligations themselves apply (December 2027 / August 2028 — see the timeline above).
Audit-Relevant Anchors¶
- Annex III — the high-risk use-case list that scopes most conformity work.
- Art. 16 + Annex IV — the technical documentation an auditor inspects.
- Art. 27 (FRIA) — directly relevant to the external-auditor engagement model.
- Art. 43 + Annex VI/VII — which conformity route applies, and the evidence each requires.
- Art. 72 + Art. 73 — post-market monitoring plan and the serious-incident reporting clock; core operating evidence after go-live.
- Governance: Art. 64 (AI Office) + Art. 65 (AI Board) + Art. 70 (national authorities) — who supervises what: AI Office for GPAI, national market surveillance for deployed systems; the escalation path for audit findings.
- Implementation timeline — see the application timeline table above.
- Enforcement live since 2 August 2026 — Commission release (2026-07-31) — the official marker that the regime is being enforced, and the signatory list against which a provider's claimed code adherence is checked.
Auditor Checklist¶
Evidence-oriented checks for a high-risk AI engagement under the Act:
- The system is correctly classified (prohibited / high-risk per Art. 6 + Annex III / limited / minimal).
- A risk-management system is documented and maintained (Art. 9).
- Data governance — training/validation/test data quality and bias — is examined (Art. 10).
- Technical documentation per Annex IV is present and current (Art. 11).
- Logging/record-keeping (Art. 12) and human oversight (Art. 14) are implemented.
- Accuracy, robustness, and cybersecurity are evidenced (Art. 15).
- Deployer duties are evidenced: use per instructions, assigned competent human oversight, input-data control, operation monitoring, log retention (Art. 26).
- A FRIA is performed where required (Art. 27).
- The conformity-assessment route is chosen and evidenced (Art. 43); CE marking (Art. 48) and EU-database registration (Art. 49) done.
- Synthetic output is marked in a machine-readable way — watermark, metadata, cryptographic provenance proof, logging or fingerprint (Art. 50(2) + Rec. 133); grace period for pre-Aug-2026 systems ends 2026-12-02.
- A post-market monitoring plan exists and demonstrably feeds back into the risk-management system (Art. 72).
- A serious-incident process covers detection, assessment and reporting within the Art. 73 deadlines (max. 15 days; shorter for severe cases).
- For GPAI: model documentation, copyright policy, training-data summary (Art. 53+).
- Which obligations are actually in force at the engagement date (Digital Omnibus timeline).
Cross-Framework Mapping¶
Indicative cross-references, not authoritative equivalences.
Cells link to the direct source where readable (ISO clauses are paywalled, so only the ISO catalogue entry is public — see the ISO/IEC 42001 and ISO/IEC 23894 pages).
| EU AI Act | NIST AI RMF | ISO/IEC 42001 | ISO/IEC 23894 |
|---|---|---|---|
| Art. 9 (risk management) | MAP + MANAGE | Cl. 6.1 + Cl. 8 | Cl. 6 (risk process) |
| Art. 10 (data governance) | MAP / MEASURE | Annex A (data controls) | Annex B (data risk sources) |
| Art. 11 + Annex IV (technical documentation) | GOVERN | Cl. 7.5 (documented information) | Cl. 6.7 (recording & reporting) |
| Art. 12 (record-keeping / logging) | MEASURE | Annex A (traceability controls) | Cl. 6.7 (recording & reporting) |
| Art. 14 (human oversight) | MANAGE | Annex A (oversight controls) | Annex B (human involvement) |
| Art. 15 (accuracy/robustness/cyber) | MEASURE | Cl. 8 + Annex A | Annex B (security & robustness) |
| Art. 17 (quality management system) | GOVERN | Cl. 4–10 (whole AIMS) | — (guidance, not an MS) |
| Art. 72 (post-market monitoring) | MANAGE | Cl. 9 (performance evaluation) | Cl. 6.6 (monitoring & review) |
Recent Changes (rolling, last 5)¶
| Date | Severity | What changed |
|---|---|---|
2026-09-05 |
substantive | Commission soft law caught up with Art. 50, and enforcement started. Final Guidelines on transparency obligations for providers and deployers published 2026-07-20; Commission opinion assessing the Code of Practice on transparency of AI-generated content published 2026-07-09; draft Guidelines on the classification of high-risk AI systems (Art. 6) published 2026-05-19 for targeted consultation — still a draft. Per the Commission release of 2026-07-31, from 2026-08-02 the AI Office and national authorities enforce the Act, a first list of more than 180 signatories of the AI-generated-content code is public, and the complaints tool, whistleblower tool and GPAI downstream-provider complaints channel are live; related: the EU Action Plan on Cybersecurity and AI (2026-07-07). Application timeline and penalties unchanged since the Omnibus entry. Council Decision (EU) 2026/1080 added as an anchor: the EU implements the CETS 225 Convention exclusively through this Act — see the new CETS 225 page. |
2026-08-02 |
version_bump | Digital Omnibus is now law. Reg. (EU) 2026/1744 (adopted 2026-07-08, OJ 2026-07-24) entered into force 2026-07-27, amending Reg. 2024/1689: Annex III high-risk → 2027-12-02; Annex I product-embedded AI → 2028-08-02; Art. 50(2) marking grace period for pre-existing systems → 2026-12-02; new Art. 5 CSAM/NCII prohibition (transition to 2026-12-02); sandbox deadline → 2027-08-02. Art. 50 transparency itself applies from 2026-08-02 as scheduled; GPAI rules unchanged. |
2026-06-16 |
baseline | Initial baseline. Captured base regulation plus the 2026-05-07 Digital Omnibus provisional agreement (high-risk deferral to 2027/2028, new Art. 5 prohibition) — pending OJ publication. |
Sources¶
- Primary (web): EUR-Lex ELI permalink · EC policy hub · AI Act Service Desk + Compliance Checker · Article-by-article (FLI, curated)
- Digital Omnibus (primary): EUR-Lex — Reg. (EU) 2026/1744 ELI permalink (Digital Omnibus on AI; OJ 2026-07-24, in force 2026-07-27) · Consilium press release — final Council green light, 2026-06-29
- Soft law (web): GPAI Code of Practice · Guidelines on prohibited practices · Guidelines on the AI-system definition
- Digital Omnibus (analysis): Gibson Dunn analysis · Bird & Bird — May trilogue agreement · Lewis Silkin — entry into force, 2026-07-27
- Update 2026-09-05: Art. 50 guidelines · Opinion on the AI-generated-content code · Draft high-risk classification guidelines — retrieved 2026-09-05 from the EC policy hub.
- Council of Europe (web): EUR-Lex — Council Decision (EU) 2026/1080 · EUR-Lex — CETS 225 text, OJ L 2026/1081 — retrieved 2026-09-05; treaty status is maintained on the CETS 225 page.
- Update 2026-09-05 (2): EC — Commission starts enforcing AI Act rules (2026-07-31) · EC — press release IP/26/1714 — retrieved 2026-09-05.