regulation 1 of 58 · Supranational (EU)
EU AI Act
effective 2024-08-01→enacted 2024-06-13
General·providers, deployers, importers and distributors of AI systems in the EU·Up to 35,000,000 EUR or 7% of global annual turnover for prohibited-practice breaches.
Summary
Horizontal, risk-based rules for AI systems placed on or used in the EU market, tiered from prohibited to high-risk to limited and minimal risk, with a separate regime for general-purpose AI models.
Notes
Phased application (original): prohibitions from Feb 2025, GPAI obligations from Aug 2025, most high-risk obligations from Aug 2026, embedded high-risk from Aug 2027. UPDATE (Digital Omnibus on AI): Regulation (EU) 2026/1744, amending the AI Act (Regulation (EU) 2024/1689), was signed 8 July 2026 and published in the Official Journal (L series) on 24 July 2026; per its own entry-into-force clause it took effect on the third day after publication, 27 July 2026 (independently reconfirmed 2026-09-07 via EUR-Lex search results and the European Commission's own AI Act policy page, which also states entry into force was 27 July 2026). Confirmed against the consolidated OJ text: stand-alone high-risk (Annex III) AI Act obligations are deferred to 2 December 2027, and embedded high-risk (Annex I, product-safety-linked) obligations to 2 August 2028. The general Article 50 AI-generated-content transparency obligation applied as scheduled from 2 August 2026; this specific date is confirmed this round directly on the European Commission's own AI Act policy page (digital-strategy.ec.europa.eu). A transitional grace period to 2 December 2026 for the Article 50(2) watermarking/machine-readable-marking duty (limited to generative AI systems already placed on the market before 2 August 2026) was carried over from a prior run's citation to that same Commission page, but a fresh fetch of the page this round did NOT contain this grace-period language at all; it could not be re-confirmed from that source or from EUR-Lex/the Official Journal this round. This specific sub-date (the Article 50(2) grace period) should be treated as unconfirmed pending a fresh primary-source check, not as settled fact, notwithstanding that it was treated as confirmed in a prior run. Article 5(1) new prohibitions on AI-generated non-consensual intimate imagery ('nudification' apps) and CSAM: the substantive text is independently confirmed verbatim this round (2026-09-07) directly against the official EUR-Lex consolidated text (CELEX 02024R1689, consolidated version dated 27.07.2026): point (ba) reads 'the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person's intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person's freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation'; point (bb) separately covers AI-generated material within the meaning of Directive 2011/93/EU (CSAM). On the APPLICATION DATE for these two points: the European Commission's own AI Act policy page states verbatim that 'Prohibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus,' the first official EU-source confirmation, across three validation rounds, that this prohibition applies within December 2026. The specific day, 2 December 2026, could not be verified verbatim from the EUR-Lex consolidated text or the Official Journal text of Regulation (EU) 2026/1744 itself with the tools available this round, and is not asserted here as confirmed to the day; only the month, December 2026, is confirmed via an official EU source. The AI Act itself remains in force; effectiveDate and status fields are unchanged.
- Obligations
- Risk classification; high-risk systems need risk management, data governance, technical documentation, logging, transparency, human oversight and conformity assessment; GPAI models need technical documentation and (for systemic-risk models) evaluation and incident reporting.