Regulation (EU) 2024/1689 · EU AI Act
What the EU AI Act asks of you, and by when
The Act sorts AI systems by risk. Some uses are banned, high-risk systems carry the most duties, and the duties apply on staggered dates. This page sets out each tier, date, fine and article, with the law quoted.
Next enforcement · new Article 5 prohibitions · 2 Dec 2026
Unacceptable
Banned outright · Art. 5
Since 2 Feb 2025 · €35M or 7%
High risk
Chapter III duties · Arts. 9 to 15, 19
From 2 Dec 2027 (Annex III) · €15M or 3%
Limited risk
Transparency · Art. 50
Since 2 Aug 2026 · systems already on the market meet Art. 50(2) by 2 Dec 2026 · €15M or 3%
Minimal risk
No tier duties · AI literacy (Art. 4) applies to every provider and deployer
Voluntary codes of conduct · Art. 95
Does this apply to me?
Find your case
The Act regulates by what your AI does, not by industry. Each case shows the tier, the date and the maximum fine.
Article 113 · staggered application
What applies when
Three deadlines have passed. Three are ahead.
2 Feb 2025
Bans and AI literacy apply
Art. 4 and Art. 5 apply. Art. 113(a)In force2 Aug 2025
GPAI duties and governance apply
Art. 53 duties and the penalty chapter apply. Art. 113(b)In force2 Aug 2026
GPAI fining powers attach
Commission fines under Art. 101, up to €15M or 3%. Art. 113, second paragraph and point (b)In force2 Dec 2026
New prohibitions apply
Art. 5(1)(ba) and (bb) apply. Generative systems already on the market meet Art. 50(2). Art. 113(a) and Art. 111(4), as amendedNext2 Dec 2027
Annex III high-risk systems comply
Annex III systems: Chapter III, Sections 1 to 3. Deferred by the Digital Omnibus. Art. 113(c)(i), as amendedUpcomingMoved2 Aug 2028
Annex I high-risk systems comply
Product-embedded systems under Annex I: Chapter III, Sections 1 to 3. Deferred by the Digital Omnibus. Art. 113(c)(ii), as amendedUpcomingMoved
2 Aug 2030: high-risk systems intended for use by public authorities, already on the market, comply by this date. Art. 111(2), as amended
Regulation (EU) 2026/1744 · in force 27 Jul 2026
What changed
The Digital Omnibus on AI amends the Act. These four changes move dates, add prohibitions or change fines. Each diff quotes EUR-Lex: removed lines are the 2024 text, added lines the new text.
High-risk dates move to 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I)
Change in lawArticle 113, third paragraph, point (c) It shall apply from 2 August 2026.Removed: (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.Added: (c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:Added: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; andAdded: (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;The context line is the second paragraph of Article 113, which set the date for Annex III systems before the change. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.
Source: Regulation (EU) 2026/1744, Article 1, point (40), verified 4 Oct 2026
Two new prohibitions: points (ba) and (bb)
Change in lawArticle 5(1), first subparagraph, points (ba) and (bb) Added: (ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;Added: (bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a “without right” defence applies under national law;The same point also inserts paragraphs 1a and 1b into Article 5. These apply from 2 Dec 2026. Added lines quote the amending Regulation.
Source: Regulation (EU) 2026/1744, Article 1, point (7), verified 4 Oct 2026
Small mid-caps (SMCs) get the lower of the two fine caps
Change in lawArticle 99(6a) 6. In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.Added: 6a. In the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower.The context line is Article 99(6), the existing rule for SMEs. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.
Source: Regulation (EU) 2026/1744, Article 1, point (38), verified 4 Oct 2026
Generative systems already on the market: Article 50(2) by 2 Dec 2026
Change in lawArticle 111(4) Added: 4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.Added lines quote the amending Regulation.
Source: Regulation (EU) 2026/1744, Article 1, point (39), verified 4 Oct 2026
The regulation amends other articles too. Read Regulation (EU) 2026/1744 on EUR-Lex.
Articles 99 and 101
What a breach can cost
Each band is a euro cap or a share of total worldwide annual turnover, whichever is higher. Bars are drawn to scale.
Article 5 prohibited practices
Operator and notified-body obligations
Providers of general-purpose AI models
Incorrect, incomplete or misleading information to authorities
Smaller companies. For SMEs, including start-ups, each fine is capped at whichever of the two is lower (Art. 99(6)). Since 27 Jul 2026, small mid-cap enterprises get the same lower cap for the fines in Article 99(4) and (5) (Art. 99(6a)).
Articles
Pick an article
Each card shows the status, the date, the tool and how much of the article it covers. Open one for the quoted text and key facts.
Scope
High-risk systems and GPAI models
Article 6 and Annex III
What counts as high-risk
Article 6(2) treats the systems listed in Annex III as high-risk, and Article 6(3) sets the exceptions. Article 6(1) adds AI systems that are, or are safety components of, products under the Annex I legislation that need a third-party conformity assessment. The Annex III areas:
- 1.Biometrics, in so far as their use is permitted under relevant Union or national law
- 2.Critical infrastructure
- 3.Education and vocational training
- 4.Employment, workers’ management and access to self-employment
- 5.Access to and enjoyment of essential private services and essential public services and benefits
- 6.Law enforcement, in so far as their use is permitted under relevant Union or national law
- 7.Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law
- 8.Administration of justice and democratic processes
Area headings quoted from Annex III, Regulation (EU) 2024/1689.
Articles 51 to 56
General-purpose AI models
A separate chain for model providers, from baseline duties to the Commission’s fines.
- Art. 53Every GPAI provider: technical documentation (Annex XI), information for providers who build on the model (Annex XII), a copyright policy and a public training-content summary.
- Art. 51(2)A model is presumed to have high-impact capabilities when its training compute is greater than 10²⁵ floating point operations.
- Art. 55Models with systemic risk add model evaluation with adversarial testing, systemic-risk assessment, serious-incident reporting and cybersecurity protection.
- Art. 101The Commission can fine providers up to €15M or 3%.
Context
Other jurisdictions
Where other regions stand on binding AI law. Each row lists the pages its claims were read from, and the date.
| Jurisdiction | Status | What applies | Checked |
|---|---|---|---|
| European Union | Binding law in force | Regulation (EU) 2024/1689 (AI Act), amended by Regulation (EU) 2026/1744 In force since 1 Aug 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 Jul 2026 and has been in force since 27 Jul 2026. It moves Annex III high-risk obligations to 2 Dec 2027 and Annex I high-risk obligations to 2 Aug 2028. | Primary sources 4 Oct 2026 |
| China | Binding law in force | Interim Measures for the Management of Generative AI Services (2023) and Measures for Labeling AI-Generated Synthetic Content (2025) Binding and in force. The Interim Measures (CAC Order No. 15, issued with six other bodies, dated 10 Jul 2023) took effect on 15 Aug 2023. The Labeling Measures took effect on 1 Sep 2025 and require implicit labels in the file metadata of generated content, and explicit labels in the cases they set out. | Primary sources 4 Oct 2026 |
| United States | Soft law and partial rules | No comprehensive federal AI statute. NIST AI RMF 1.0 (voluntary) and state laws (Texas HB 149; Colorado SB 26-189) Executive Order 14110 was rescinded on 20 Jan 2025, and the NIST AI RMF is for voluntary use. Binding rules come from states: the Texas Responsible Artificial Intelligence Governance Act took effect on 1 Jan 2026, and Colorado SB 26-189, signed on 14 May 2026, repealed and re-enacted SB 24-205. | Primary sources 4 Oct 2026 |
| UAE and Saudi Arabia | Soft law and partial rules | No horizontal AI statute. UAE: Charter for AI (2024, non-binding) and DIFC Data Protection Regulation 10 (binding in the DIFC only). Saudi Arabia: SDAIA AI Ethics Principles (non-binding) The UAE has no dedicated AI law. It works through non-binding instruments, the National Strategy for AI 2031, and DIFC Regulation 10, enacted in Sep 2023, which covers personal data processed by autonomous and semi-autonomous systems inside the DIFC free zone. Saudi Arabia relies on non-binding SDAIA principles and has declared 2026 its Year of Artificial Intelligence. | Primary and secondary sources 4 Oct 2026 |
| India | Soft law and partial rules | India AI Governance Guidelines (2025, non-binding); IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026; Digital Personal Data Protection Act 2023 No AI-specific statute. MeitY released the India AI Governance Guidelines on 5 Nov 2025; they are not a compliance requirement and lean on existing law. On 10 Feb 2026 MeitY notified the IT Amendment Rules, 2026, which require intermediaries offering tools that create synthetic content to label it prominently. The DPDP Act 2023 (rules notified 13 Nov 2025) governs personal data and is not AI-specific. | Secondary sources 4 Oct 2026 |
| Australia | Proposed, not adopted | Proposed mandatory guardrails for AI in high-risk settings (2024 proposals paper), not adopted The government consulted on mandatory guardrails in Sep 2024 and will not proceed with them at this time. The National AI Plan, launched on 2 Dec 2025, relies on existing technology-neutral law and guidance, and commits to an AI Safety Institute. | Primary and secondary sources 4 Oct 2026 |
Content verified 4 Oct 2026 · Not legal advice.