Direct Answer: The EU AI Act (Regulation 2024/1689) is the world’s first binding law regulating artificial intelligence. It classifies AI systems by risk level from banned to minimal and imposes fines up to €35 million or 7% of global annual turnover for violations. As of 2026, its core rules are actively being enforced across the European Union, and the law applies to any company whose AI systems affect people in the EU, regardless of where that company is based.
EU AI Act explained in plain terms: the European Union passed a law that tells companies what they can and cannot do with artificial intelligence. If an AI system makes decisions about your job application, your loan, your medical care, or your freedom of movement, this law now sets rules for how that system must work and what happens when it fails.
Whether the company behind that AI is in Berlin, San Francisco, or Shanghai makes no difference. If the output reaches someone in the EU, the rules apply.
If AI copyright questions also concern you, take a look at our breakdown of who owns AI-generated content.
The Short Version
- The EU AI Act is the first binding AI law in the world. It entered into force on 1 August 2024 and is being rolled out in phases through 2027.
- AI systems are sorted into four risk categories: unacceptable (banned), high-risk (heavily regulated), limited risk (transparency rules), and minimal risk (no special rules).
- Certain AI practices like social scoring, manipulative AI, and mass facial recognition have been outright banned since February 2025.
- Fines for the worst violations can reach €35 million or 7% of a company’s total worldwide revenue, whichever is higher. That exceeds even GDPR penalties.
What the EU AI Act Actually Says
The EU AI Act formally known as Regulation (EU) 2024/1689 was adopted on 21 May 2024 and published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024.
But “entered into force” does not mean every rule kicked in overnight. The law uses a phased rollout, with different obligations taking effect at different times between 2025 and 2028.
The core idea behind the law is risk-based regulation. Instead of trying to regulate every AI tool the same way, the EU created a system that asks one question: how much harm could this AI cause?
The answer places each AI system into one of four buckets, and the rules get stricter as the risk goes up.
Here is how the European Commission describes the logic: AI that can be misused for manipulation, surveillance, or discrimination deserves the strictest controls. AI that plays a background role say, a spam filter or a video game recommendation engine needs little to no special regulation.
Who Does the EU AI Act Apply To?
The law applies to anyone in the AI supply chain whose systems touch the EU market. In the Act’s language, these are called operators, and they include:
Providers companies that build or develop AI systems. Think of a company creating an AI-powered hiring platform.
Deployers organizations that use AI systems in their operations. An HR department running an AI screening tool on job applicants is a deployer.
Importers and distributors businesses that bring AI products into the EU market or sell them within EU borders.
The law also has extraterritorial reach a concept borrowed from the GDPR. A company based in the United States or China still falls under the EU AI Act if its AI system is placed on the EU market or if its output is used within the EU. This mirrors how GDPR applies to any company handling EU residents’ data, regardless of where the company sits.
How the EU AI Act Sorts AI by Risk Level
This is the backbone of the entire regulation. Every obligation, every fine, every compliance requirement flows from where an AI system falls on this scale.
Unacceptable Risk Banned Outright
These are AI practices the EU considers fundamentally incompatible with human rights and democratic values. They cannot be placed on the market, put into service, or used in the EU. Period.
The bans under Article 5 of the EU AI Act have been enforceable since 2 February 2025. Here is what is prohibited:
Manipulative or deceptive AI systems that use subliminal techniques or intentionally deceptive methods to distort someone’s behavior in ways that cause significant harm. An AI that tricks elderly users into making purchases they do not understand falls here.
Exploitation of vulnerabilities AI that targets people based on age, disability, or socio-economic conditions to distort their behavior. The key word is “distort” the AI must alter decision-making in a way that causes or is likely to cause harm.
Social scoring AI that evaluates or classifies people based on their social behavior or personal characteristics, where this scoring leads to unfair or disproportionate treatment. This applies to both government and private sector systems.
Predictive policing based on profiling AI that assesses someone’s risk of committing a crime based solely on their personality traits or personal profile, without any objective evidence of criminal activity. Location-based crime mapping (predicting high-crime areas) is not banned, but profiling individuals is.
Untargeted facial recognition scraping AI systems that build facial recognition databases by scraping images from the internet or CCTV footage without specific authorization. This is the practice that led to major GDPR fines against companies like Clearview AI.
Workplace and school emotion recognition AI that tries to infer employees’ or students’ emotions, except for medical or safety reasons. The ban reflects scientific concerns about whether emotion-detection AI actually works reliably.
Biometric categorization for sensitive traits AI that uses biometric data to infer someone’s race, political opinions, religious beliefs, sexual orientation, or trade union membership.
Real-time biometric identification in public spaces remote biometric identification (like live facial recognition cameras) for law enforcement, except in very narrow situations involving terrorism, missing persons, or serious crime and only with prior judicial authorization.
Additionally, as part of the Digital Omnibus amendments agreed in May 2026, two new prohibited practices are being added: AI-generated non-consensual intimate images (so-called “nudification” tools) and AI-generated child sexual abuse material. These prohibitions are expected to take effect on 2 December 2026.
High-Risk AI Systems Allowed, but Heavily Regulated
High-risk AI systems are not banned, but they come with extensive requirements for testing, documentation, transparency, and human oversight.
The law defines high-risk AI in two ways:
Annex I systems AI embedded in products already covered by EU safety regulations. Medical devices with AI components, AI in vehicles, AI in toys if the product sector already has safety rules, the AI inside it falls under the AI Act too.
Annex III systems standalone AI used in sensitive areas. This is the broader category, covering eight domains:
- Biometric identification and categorization
- Management of critical infrastructure (energy, water, transport)
- Education and vocational training (AI that grades exams, determines school placement)
- Employment (AI that screens CVs, ranks job candidates, decides promotions)
- Access to essential services like credit scoring, insurance, or public benefits
- Law enforcement (excluding the banned practices above)
- Migration and border control
- Administration of justice
For these systems, providers must complete conformity assessments formal evaluations proving the AI meets safety, transparency, and governance standards before placing them on the EU market. They must also register the system in the EU’s public database and maintain detailed technical documentation about how the system was designed, trained, and tested.
Under the original timeline, these obligations for Annex III systems were set to apply from 2 August 2026. However, the Digital Omnibus on AI a package of amendments agreed on 7 May 2026 between the European Council, Parliament, and Commission has pushed this deadline to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems.
The delay was not a reward for industry. It was an acknowledgment that the regulatory infrastructure harmonized standards, conformity assessment bodies, national enforcement authorities was not yet fully ready.
Limited Risk Transparency Rules
AI systems that interact with people must be transparent about it. Under Article 50 of the Act, this means:
- Chatbots must tell users they are interacting with an AI, not a human
- AI-generated content (text, images, audio, video) must be labeled as such
- Deepfakes AI-generated or manipulated content showing real people must carry clear disclosures
These transparency rules apply from August 2026, with the Digital Omnibus adjusting the deadline for synthetic-content marking to 2 December 2026.
For more on deepfake rules, see our article on deepfakes: what’s illegal and what’s not in 2026.
Minimal Risk No Special Rules
Most AI systems in use today spam filters, recommendation algorithms, AI in video games, inventory management tools fall here. The EU AI Act does not impose specific obligations on these systems, though existing laws like the GDPR and consumer protection regulations still apply.

Real-World Examples
Scenario 1: AI Hiring Tool Rejects Candidates
A tech company in Germany uses an AI system to screen job applications. The AI analyzes CVs and ranks candidates. Under the EU AI Act, this is a high-risk AI system (Annex III employment). The company must document how the system makes decisions, conduct a fundamental rights impact assessment (FRIA), keep humans in the loop for final decisions, and register the system in the EU database. If the AI discriminates against applicants based on age or gender, the company faces fines up to €15 million or 3% of global turnover.
Scenario 2: Social Media Platform Uses Emotion Recognition
A social media platform tests an AI feature that reads users’ facial expressions through their webcam to gauge emotional reactions and adjust content accordingly. In the EU, this would likely fall under the banned practice of emotion recognition for non-medical purposes. The platform would need to disable this feature for EU users or face fines up to €35 million or 7% of global turnover.
Scenario 3: A US-Based SaaS Company Sells AI Credit Scoring in France
A fintech startup headquartered in Austin, Texas, sells an AI credit-scoring tool to a French bank. Even though the company is American, its AI system affects people in the EU — making it subject to the EU AI Act. The company is the provider, and the French bank is the deployer. Both have separate obligations under the law.
What Rights Do People Have Under the EU AI Act?
The law creates several protections for individuals affected by AI decisions, particularly from high-risk systems:
Right to an explanation Under Article 86, anyone significantly affected by a decision made by a high-risk AI system has the right to a clear, meaningful explanation of how that decision was reached. This goes beyond GDPR’s existing right to explanation by specifically targeting AI-driven decisions.
Right to lodge a complaint Individuals can file complaints with their national market surveillance authority (MSA) if they believe an AI system violates the Act. Each EU member state must designate at least one such authority.
Right to an effective remedy People who suffer harm from an AI system that violates the EU AI Act can seek compensation through their national courts.
Transparency rights If an AI is interacting with you (a chatbot, for example), you have the right to know it is an AI. If content was generated or manipulated by AI, that fact must be disclosed.
These rights sit alongside not in place of existing protections under GDPR, the EU Charter of Fundamental Rights, and national consumer protection laws.
The EU AI Act Timeline Key Dates to Know
The law does not apply all at once. Here are the milestones:
1 August 2024 The AI Act enters into force. No obligations apply yet.
2 February 2025 Bans on prohibited AI practices (Article 5) take effect. AI literacy obligations (Article 4) also begin companies must train their staff on AI systems they use.
2 August 2025 Rules for general-purpose AI models (GPAI) large foundation models like GPT, Claude, Gemini, and Llama become applicable. This includes transparency requirements and, for models with systemic risk, additional safety testing and incident reporting obligations.
2 August 2026 The majority of the Act’s remaining provisions take effect. Penalty enforcement powers for national authorities begin. Transparency rules under Article 50 apply.
2 December 2026 New prohibitions on AI nudification tools and CSAM generation take effect. Adjusted deadline for synthetic content marking.
2 December 2027 Obligations for high-risk Annex III systems now apply (deferred from August 2026 by the Digital Omnibus).
2 August 2028 Obligations for high-risk Annex I systems (AI embedded in regulated products) apply.
What People in This Situation Typically Do
If you are wondering how this law affects your daily life, your work, or a business you run, here are the most common steps people take:
1. Identify whether you are affected. If you use, build, sell, or import AI systems that affect people in the EU, you likely fall under the Act. The law covers providers, deployers, importers, and distributors.
2. Classify your AI systems by risk. Determine whether any AI tools you use or build fall under the prohibited, high-risk, limited-risk, or minimal-risk categories. The European Commission published guidelines on prohibited practices in February 2025 and is developing further guidance for high-risk classification.
3. Check your compliance deadlines. Prohibited practices are already banned. GPAI rules are already live. High-risk obligations are coming in 2027-2028 depending on the category.
4. Document everything. For high-risk systems, maintaining detailed technical documentation, risk management records, and training data logs is not optional. A conformity assessment completed today does not guarantee compliance next year if the system changes.
5. Assign human oversight. High-risk AI systems must include meaningful human review mechanisms. A human must be able to override or stop the system.
6. Stay updated. The Digital Omnibus amendments show this law is already evolving. National implementation varies by member state, and harmonized technical standards from CEN-CENELEC are expected in late 2026 or 2027.
The EU AI Act vs. the Rest of the World
The EU is the first jurisdiction to pass a binding, horizontal AI law. But it is not the only place where AI regulation is happening.
In the United States, there is no single federal AI law. Regulation comes from a patchwork of state laws (like Colorado’s AI consumer protection law), executive orders, and sector-specific agency guidance from the FTC, FDA, and others. The approach is largely voluntary and sector-by-sector.
In the United Kingdom, the government has taken a “pro-innovation” approach, relying on existing regulators (the ICO, FCA, Ofcom) to apply AI principles within their existing mandates rather than creating a new law. This means AI regulation in the UK is less centralized and carries fewer hard penalties compared to the EU.
In China, several AI regulations are already in force, including rules on deepfakes, recommendation algorithms, and generative AI. China’s approach tends to focus on content control and state security rather than individual rights.
The EU AI Act’s extraterritorial reach and its economic gravity the so-called “Brussels Effect” mean that many global companies are likely to adopt EU-compliant practices worldwide rather than maintaining separate systems for different markets. The same thing happened with GDPR.
Tools That Can Help
At this stage, the EU AI Act is still new and most compliance work involves legal review, internal audits, and documentation. There are no consumer-facing privacy tools like data-deletion services that directly apply here but if AI-driven data processing concerns you, services like DeleteMe and Incogni can help remove personal data from data brokers, reducing the data that AI systems can train on or use for profiling.
Related Articles
- Who Owns AI-Generated Content? If AI creates something, who holds the copyright? The answer is complicated.
- Deepfakes: What’s Illegal and What’s Not in 2026 Where deepfake laws stand across the EU, US, and UK.
- AI Screening Job Applicants What Are Your Rights? What happens when AI decides who gets the interview.
Frequently Asked Questions
When does the EU AI Act take full effect?
The EU AI Act entered into force on 1 August 2024 and is being applied in phases. Bans on prohibited AI practices have been active since February 2025. Rules for general-purpose AI models applied from August 2025. Most remaining provisions, including penalty enforcement, take effect on 2 August 2026. The Digital Omnibus amendments of May 2026 pushed high-risk system obligations to December 2027 (Annex III) and August 2028 (Annex I).
Does the EU AI Act apply to companies outside Europe?
Yes. The law has extraterritorial scope, similar to GDPR. Any company that places an AI system on the EU market or whose AI system produces output used within the EU falls under the regulation regardless of where that company is headquartered. A US tech firm selling an AI hiring tool to a German company is subject to the Act.
What AI systems are banned under the EU AI Act?
Article 5 bans AI used for social scoring, manipulative or deceptive practices that cause harm, exploitation of vulnerable groups, criminal-risk profiling based solely on personality traits, untargeted facial image scraping, workplace and school emotion recognition, biometric categorization to infer sensitive personal traits, and most forms of real-time remote biometric identification in public spaces. Two new bans on AI nudification tools and AI-generated child sexual abuse material are expected to take effect in December 2026.
What are my rights if an AI makes a decision about me?
Under the EU AI Act, individuals affected by a high-risk AI system have the right to a clear explanation of the decision, the right to file a complaint with their national market surveillance authority, and the right to seek compensation through national courts. These rights exist alongside existing protections under GDPR, which gives individuals the right not to be subject to fully automated decision-making in certain situations.
The Bottom Line
The EU AI Act explained in one sentence: if artificial intelligence affects your rights, the EU now has a law that sets boundaries on what that AI can do, how it must be built, and what happens when things go wrong.
This law is not theoretical. Prohibited practices are already banned. Fines are already possible. The regulatory machinery is moving. Whether you are a person affected by an AI decision, a business deploying AI tools, or a developer building the next generation of AI products the EU AI Act is now part of the landscape, and understanding where you stand is worth the time.
This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.
Sources & Further Reading
- EU AI Act Official Text (EUR-Lex) The full regulation as published in the Official Journal of the EU
- AI Act Implementation Timeline Detailed breakdown of all key compliance dates
- European Commission AI Act Overview The Commission’s official summary of the regulation and related policy measures
- Commission Guidelines on Prohibited AI Practices Non-binding guidance on interpreting Article 5 prohibitions
- Council of the EU Digital Omnibus Agreement (May 2026) Press release on the provisional agreement amending AI Act timelines


