Regulation (EU) 2024/1689 · EU AI Act

What the EU AI Act asks of you, and by when

The Act sorts AI systems by risk. Some uses are banned, high-risk systems carry the most duties, and the duties apply on staggered dates. This page sets out each tier, date, fine and article, with the law quoted.

Next enforcement · new Article 5 prohibitions · 2 Dec 2026

  • Unacceptable

    Banned outright · Art. 5

    Since 2 Feb 2025 · €35M or 7%

  • High risk

    Chapter III duties · Arts. 9 to 15, 19

    From 2 Dec 2027 (Annex III) · €15M or 3%

  • Limited risk

    Transparency · Art. 50

    Since 2 Aug 2026 · systems already on the market meet Art. 50(2) by 2 Dec 2026 · €15M or 3%

  • Minimal risk

    No tier duties · AI literacy (Art. 4) applies to every provider and deployer

    Voluntary codes of conduct · Art. 95

How the Act sorts AI systems

Does this apply to me?

Find your case

The Act regulates by what your AI does, not by industry. Each case shows the tier, the date and the maximum fine.

Your product has a chatbot or generates contentArt. 50TierLimited risk: transparencyWhenSince 2 Aug 2026Maximum fine€15M or 3%ToolNo AiExponent tool
Spam filters and other minimal-risk AIArt. 4TierMinimal riskWhenSince 2 Feb 2025 (AI literacy)Maximum fineNo Art. 99 bandToolVoluntary codes (Art. 95)

Article 113 · staggered application

What applies when

Three deadlines have passed. Three are ahead.

  1. 2 Feb 2025

    Bans and AI literacy apply

    Art. 4 and Art. 5 apply. Art. 113(a)
    In force
  2. 2 Aug 2025

    GPAI duties and governance apply

    Art. 53 duties and the penalty chapter apply. Art. 113(b)
    In force
  3. 2 Aug 2026

    GPAI fining powers attach

    Commission fines under Art. 101, up to €15M or 3%. Art. 113, second paragraph and point (b)
    In force
  4. 2 Dec 2026

    New prohibitions apply

    Art. 5(1)(ba) and (bb) apply. Generative systems already on the market meet Art. 50(2). Art. 113(a) and Art. 111(4), as amended
    Next
  5. 2 Dec 2027

    Annex III high-risk systems comply

    Annex III systems: Chapter III, Sections 1 to 3. Deferred by the Digital Omnibus. Art. 113(c)(i), as amended
    UpcomingMoved
  6. 2 Aug 2028

    Annex I high-risk systems comply

    Product-embedded systems under Annex I: Chapter III, Sections 1 to 3. Deferred by the Digital Omnibus. Art. 113(c)(ii), as amended
    UpcomingMoved

2 Aug 2030: high-risk systems intended for use by public authorities, already on the market, comply by this date. Art. 111(2), as amended

Regulation (EU) 2026/1744 · in force 27 Jul 2026

What changed

The Digital Omnibus on AI amends the Act. These four changes move dates, add prohibitions or change fines. Each diff quotes EUR-Lex: removed lines are the 2024 text, added lines the new text.

  1. High-risk dates move to 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I)

    Change in lawArticle 113, third paragraph, point (c)
    It shall apply from 2 August 2026.
    Removed: (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.Added: (c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:Added: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; andAdded: (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;

    The context line is the second paragraph of Article 113, which set the date for Annex III systems before the change. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.

    Source: Regulation (EU) 2026/1744, Article 1, point (40), verified 4 Oct 2026

  2. Two new prohibitions: points (ba) and (bb)

    Change in lawArticle 5(1), first subparagraph, points (ba) and (bb)
    Added: (ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;Added: (bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a “without right” defence applies under national law;

    The same point also inserts paragraphs 1a and 1b into Article 5. These apply from 2 Dec 2026. Added lines quote the amending Regulation.

    Source: Regulation (EU) 2026/1744, Article 1, point (7), verified 4 Oct 2026

  3. Small mid-caps (SMCs) get the lower of the two fine caps

    Change in lawArticle 99(6a)
    6. In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.
    Added: 6a. In the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower.

    The context line is Article 99(6), the existing rule for SMEs. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.

    Source: Regulation (EU) 2026/1744, Article 1, point (38), verified 4 Oct 2026

  4. Generative systems already on the market: Article 50(2) by 2 Dec 2026

    Change in lawArticle 111(4)
    Added: 4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.

    Added lines quote the amending Regulation.

    Source: Regulation (EU) 2026/1744, Article 1, point (39), verified 4 Oct 2026

The regulation amends other articles too. Read Regulation (EU) 2026/1744 on EUR-Lex.

Articles 99 and 101

What a breach can cost

Each band is a euro cap or a share of total worldwide annual turnover, whichever is higher. Bars are drawn to scale.

€35M or 7%Art. 99(3)

Article 5 prohibited practices

€15M or 3%Art. 99(4)

Operator and notified-body obligations

€15M or 3%Art. 101(1)

Providers of general-purpose AI models

€7.5M or 1%Art. 99(5)

Incorrect, incomplete or misleading information to authorities

Smaller companies. For SMEs, including start-ups, each fine is capped at whichever of the two is lower (Art. 99(6)). Since 27 Jul 2026, small mid-cap enterprises get the same lower cap for the fines in Article 99(4) and (5) (Art. 99(6a)).

Articles

Pick an article

Each card shows the status, the date, the tool and how much of the article it covers. Open one for the quoted text and key facts.

Scope

High-risk systems and GPAI models

Article 6 and Annex III

What counts as high-risk

Article 6(2) treats the systems listed in Annex III as high-risk, and Article 6(3) sets the exceptions. Article 6(1) adds AI systems that are, or are safety components of, products under the Annex I legislation that need a third-party conformity assessment. The Annex III areas:

  1. 1.Biometrics, in so far as their use is permitted under relevant Union or national law
  2. 2.Critical infrastructure
  3. 3.Education and vocational training
  4. 4.Employment, workers’ management and access to self-employment
  5. 5.Access to and enjoyment of essential private services and essential public services and benefits
  6. 6.Law enforcement, in so far as their use is permitted under relevant Union or national law
  7. 7.Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law
  8. 8.Administration of justice and democratic processes

Area headings quoted from Annex III, Regulation (EU) 2024/1689.

Articles 51 to 56

General-purpose AI models

A separate chain for model providers, from baseline duties to the Commission’s fines.

  1. Art. 53Every GPAI provider: technical documentation (Annex XI), information for providers who build on the model (Annex XII), a copyright policy and a public training-content summary.
  2. Art. 51(2)A model is presumed to have high-impact capabilities when its training compute is greater than 10²⁵ floating point operations.
  3. Art. 55Models with systemic risk add model evaluation with adversarial testing, systemic-risk assessment, serious-incident reporting and cybersecurity protection.
  4. Art. 101The Commission can fine providers up to €15M or 3%.

Context

Other jurisdictions

Where other regions stand on binding AI law. Each row lists the pages its claims were read from, and the date.

AI law status by jurisdiction, with sources and the date they were checked
European UnionBinding law in force

Regulation (EU) 2024/1689 (AI Act), amended by Regulation (EU) 2026/1744

In force since 1 Aug 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 Jul 2026 and has been in force since 27 Jul 2026. It moves Annex III high-risk obligations to 2 Dec 2027 and Annex I high-risk obligations to 2 Aug 2028.

Primary sources

4 Oct 2026

ChinaBinding law in force

Interim Measures for the Management of Generative AI Services (2023) and Measures for Labeling AI-Generated Synthetic Content (2025)

Binding and in force. The Interim Measures (CAC Order No. 15, issued with six other bodies, dated 10 Jul 2023) took effect on 15 Aug 2023. The Labeling Measures took effect on 1 Sep 2025 and require implicit labels in the file metadata of generated content, and explicit labels in the cases they set out.

Primary sources

4 Oct 2026

United StatesSoft law and partial rules

No comprehensive federal AI statute. NIST AI RMF 1.0 (voluntary) and state laws (Texas HB 149; Colorado SB 26-189)

Executive Order 14110 was rescinded on 20 Jan 2025, and the NIST AI RMF is for voluntary use. Binding rules come from states: the Texas Responsible Artificial Intelligence Governance Act took effect on 1 Jan 2026, and Colorado SB 26-189, signed on 14 May 2026, repealed and re-enacted SB 24-205.

Primary sources

4 Oct 2026

UAE and Saudi ArabiaSoft law and partial rules

No horizontal AI statute. UAE: Charter for AI (2024, non-binding) and DIFC Data Protection Regulation 10 (binding in the DIFC only). Saudi Arabia: SDAIA AI Ethics Principles (non-binding)

The UAE has no dedicated AI law. It works through non-binding instruments, the National Strategy for AI 2031, and DIFC Regulation 10, enacted in Sep 2023, which covers personal data processed by autonomous and semi-autonomous systems inside the DIFC free zone. Saudi Arabia relies on non-binding SDAIA principles and has declared 2026 its Year of Artificial Intelligence.

Primary and secondary sources

4 Oct 2026

IndiaSoft law and partial rules

India AI Governance Guidelines (2025, non-binding); IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026; Digital Personal Data Protection Act 2023

No AI-specific statute. MeitY released the India AI Governance Guidelines on 5 Nov 2025; they are not a compliance requirement and lean on existing law. On 10 Feb 2026 MeitY notified the IT Amendment Rules, 2026, which require intermediaries offering tools that create synthetic content to label it prominently. The DPDP Act 2023 (rules notified 13 Nov 2025) governs personal data and is not AI-specific.

Secondary sources

4 Oct 2026

AustraliaProposed, not adopted

Proposed mandatory guardrails for AI in high-risk settings (2024 proposals paper), not adopted

The government consulted on mandatory guardrails in Sep 2024 and will not proceed with them at this time. The National AI Plan, launched on 2 Dec 2025, relies on existing technology-neutral law and guidance, and commits to an AI Safety Institute.

Primary and secondary sources

4 Oct 2026

Content verified 4 Oct 2026 · Not legal advice.