Regulation (EU) 2024/1689 In force: 1 Aug 2024 Status: phased application

The EU AI Act

The AI Act is a product-safety law, passed in 2024. It regulates AI by the risk of its use, sorting systems into four tiers with escalating duties. Penalties reach €35M or 7% of global turnover. The rules phase in through 2028, but the 2026 Digital Omnibus Regulation just pushed back the timeline for high-risk uses.

The compliance clock · what is live now, what is still ahead
€35M / 7%
Top fine, whichever is higher
10²⁵ FLOPs
GPAI systemic-risk threshold
The mental model

Duties follow the use

The Act assigns duties by what an AI system is used for, in proportion to the risk that use poses to health, safety, and fundamental rights. The underlying technology rarely matters. The same model, whether a vision network or a large language model, can sit in any tier depending on how it is deployed.

Classification drives everything else. Once a use falls into a tier, the bans, the obligations, and the fines all follow from that placement. General-purpose AI models get a parallel regime on top, because a single model feeds many downstream uses at once.

Four tiers, escalating duties

Each use falls into one of four tiers, and the duty rises with the tier: outright prohibition, a full compliance regime, a light disclosure rule, or nothing at all.

§1 · The four tiers

The risk pyramid

Click each for what it covers and its core obligations.

§2 · Try it

Classify a system

Interactive · risk classifier

Pick a system, see where it lands

Eight real deployments, sorted by the Act's logic. Select one to see its tier, why it falls there, and the duties that follow.

Illustrative routing of the statutory logic — not legal advice. Edge cases (e.g. high-risk exemptions under Art 6(3)) need the full text.

§3 · Unacceptable risk

Practices the Act bans outright

Article 5 prohibits a short list of uses deemed incompatible with EU rights. The original list has been enforceable since 2 February 2025 and carries the top fine; the Digital Omnibus adds one more ban, effective 2 December 2026.

§4 · High-risk

Permitted, but tightly regulated

High-risk systems are legal, but they carry the Act's full compliance regime. A system arrives here by one of two routes.

Route 1 · Annex I

A safety component of a regulated product

AI embedded in products already covered by EU product-safety law, assessed through those existing regimes.

Applies 2 Aug 2028 deferred from 2 Aug 2027
Route 2 · Annex III

A stand-alone use in a sensitive domain

Systems whose use bears directly on people's rights, safety, or access to essential services.

Applies 2 Dec 2027 deferred from 2 Aug 2026
Worked example · high-risk obligations

What compliance actually takes

Every high-risk system carries the same nine obligations, but the work each one demands varies by system. Pick one to see each duty turned into concrete steps.

And on the deployer's side

Using a high-risk system carries its own duties. Public bodies and certain private deployers must run a Fundamental Rights Impact Assessment before first use, register the deployment in the EU database, keep meaningful human oversight in live operation, and inform the people subject to it.

§5 · Limited risk

A duty to disclose

Some uses are low-stakes but can deceive, so the Act adds only a transparency duty (Article 50), applying from 2 August 2026:

  • People must be told when they're interacting with an AI system (e.g. a chatbot), unless it's obvious.
  • Synthetic audio, image, video and text must be machine-readable and marked as AI-generated; deepfakes must be disclosed.
  • Emotion-recognition and biometric-categorisation systems must notify the people exposed to them.

Systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty (Article 50(2)); systems placed on the market after that date must comply immediately.

§6 · Minimal risk

No new duties

Everything else — spam filters, recommender systems, inventory optimisation, AI in video games — sits in minimal risk and carries no obligations under the Act. This is the vast majority of AI in use.

One cross-cutting exception

AI-literacy duties (Article 4) apply to providers and deployers across all tiers, in force since 2 February 2025: staff using AI must have adequate understanding of it.

§7 · The parallel regime

General-purpose AI models

Foundation models do not fit the use-based tiers, because one model feeds thousands of downstream uses. The Act governs them directly, with rules live since 2 August 2025.

Every GPAI model owes baseline transparency: technical documentation for the AI Office and downstream providers, a policy to respect EU copyright, and a public summary of training-data sources.

A model crosses into systemic risk when its training compute exceeds 10²⁵ FLOPs (a rebuttable presumption of high-impact capability). The frontier labs sit here.

Systemic-risk add-ons

Model evaluations and adversarial red-teaming · serious-incident reporting to the AI Office · state-of-the-art cybersecurity · systemic-risk assessment and mitigation. Backed by a GPAI Code of Practice.

§8 · Try it

What a breach costs

Fines scale with the violation and are the higher of a fixed cap or a percentage of global annual turnover. Drag your turnover to see which cap applies.

€1M€500B

For SMEs and start-ups the cap is the lower of the two figures, not the higher.

§9 · Phased application

The timeline, after the Omnibus

Drawn to scale across 2024–2028. The 2026 Digital Omnibus (provisional deal 7 May 2026, Parliament endorsed 16 June 2026) pushed the heavy high-risk duties well to the right.

§10 · Check yourself

Five questions

Sources & caveats

Where this comes from

General explanation of Regulation (EU) 2024/1689 as amended, current to early July 2026, not legal advice. The Digital Omnibus was endorsed by Parliament on 16 June 2026 and formally adopted by the Council on 29 June 2026; it enters into force on the third day after Official Journal publication. Confirm against the consolidated text for any compliance decision.