What does the EU AI Act require?
The EU AI Act sets rules according to the risk an AI system poses: some practices are prohibited, high-risk systems must meet strict requirements, certain systems carry transparency obligations, and the rest is minimal risk with no specific obligations. General-purpose AI models have separate rules.
The four levels overlap: a high-risk system can also carry transparency duties (Art. 50(6)).
Legal requirement (EU, Regulation (EU) 2024/1689). The AI Act applies in stages. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, moved several dates.
The four risk levels of the EU AI Act
Prohibited practices (Art. 5)
Since 2 February 2025 it has been prohibited to place on the market, put into service or use AI systems for the practices below. This summary omits conditions and exceptions: use it to flag use cases for a legal check, not as a classifier.
- manipulating or deceiving people in ways that materially distort their behaviour and cause, or are likely to cause, significant harm;
- exploiting vulnerabilities linked to age, disability or a person’s social or economic situation, under the same conditions;
- social scoring that leads to unfair or disproportionate treatment;
- predicting that a person will commit a crime based solely on profiling or personality traits;
- building facial recognition databases by untargeted scraping of images from the internet or CCTV;
- recognising emotions or intentions from biometric data (Art. 3(39)) at work or in education, except for medical or safety reasons; inferring emotions from text content is not automatically covered (Commission guidelines on prohibited practices), though the GDPR and employment law can apply;
- biometric categorisation to infer sensitive characteristics such as political opinions, religious beliefs or sexual orientation;
- real-time remote biometric identification in publicly accessible spaces for law enforcement, apart from narrow exceptions.
From 2 December 2026, using AI to generate child sexual abuse material or non-consensual intimate deepfakes is also prohibited.
High-risk systems (Art. 6, Annex I and Annex III)
Article 6 sets two routes:
- Annex I: the AI system is a safety component of a product, or is itself a product, covered by the EU legislation listed in Annex I, and that product must undergo a third-party conformity assessment. Being AI in a regulated product is not enough on its own.
- Annex III: the system is used in a listed area, such as recruitment, education, access to credit and several public-sector uses. Art. 6(3) exempts a listed use that poses no significant risk of harm, including by not materially influencing a decision. Do not remove an Annex III use from the high-risk category merely because its impact seems small. Check the conditions in Article 6(3) and document the provider’s assessment under Article 6(4). An Annex III system that profiles people remains high-risk.
For Annex I products, distinguish Section A from Section B. Section B includes machinery, vehicles, aviation, rail and marine equipment and follows the sector-specific route in Article 2(2). The direct high-risk duties summarised below concern Annex III systems and Annex I Section A products, such as toys and medical devices.
Provider duties for high-risk systems include managing data quality (Art. 10), preparing technical documentation (Art. 11), enabling record-keeping (Art. 12), giving deployers instructions (Art. 13) and designing for human oversight (Art. 14). Deployers follow the instructions and assign human oversight (Art. 26); some must carry out a fundamental rights impact assessment (FRIA, Art. 27). Which duties are yours depends on whether you are a provider or a deployer.
| Obligation | Where | Applies from |
|---|---|---|
| Classification, requirements, provider and deployer obligations, incl. FRIA (Art. 6–27, except Art. 6(5), which concerns Commission guidelines) | Ch. III, Sections 1–3 | 2 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I Section A) |
| Post-market monitoring (Art. 72), serious incident reporting (Art. 73), right to explanation (Art. 86) | Ch. IX | not expressly postponed; timing for a specific system needs a legal assessment (classification, Art. 111) |
Transparency obligations (Art. 50)
Since 2 August 2026, people must be told when they are interacting with AI unless this is obvious, AI-generated content must be marked in a machine-readable way, and deepfakes must be disclosed. See what AI transparency requires.
Minimal risk
Most everyday AI, such as spam filters (AI Act overview), carries no specific obligations. The AI literacy duty (Art. 4) still applies to all providers and deployers.
General-purpose AI models
A general-purpose AI (GPAI) model, such as a large language model, can perform a wide range of tasks. Since 2 August 2025, GPAI model providers have had their own obligations, including a copyright policy (Art. 53). Models placed on the market before 2 August 2025 must comply by 2 August 2027.
What already applies and what comes next
Already applies:
- 2 February 2025: prohibited practices (Art. 5) and AI literacy (Art. 4).
- 2 August 2025: obligations for GPAI models and the penalties framework, except fines for GPAI providers (Art. 101), which apply from 2 August 2026.
- 2 August 2026: general application, including transparency obligations (Art. 50).
Coming next:
- 2 December 2026: the new prohibitions; the marking deadline for systems placed on the market before 2 August 2026.
- 2 August 2027: GPAI models placed on the market before 2 August 2025 must comply.
- 2 December 2027: Chapter III, Sections 1–3 for high-risk systems under Annex III.
- 2 August 2028: the same for high-risk systems under Annex I (Section A products; Section B follows Art. 2(2)).
What the Digital Omnibus changed
- High-risk dates: Chapter III, Sections 1–3 moved from 2 August 2026 (Annex III) and 2 August 2027 (Annex I) to the dates above.
- AI literacy: Art. 4 now requires measures to support the development of AI literacy, not a guaranteed level for each employee; see what AI literacy training staff need.
- New prohibitions, the content-marking deadline and SME and SMC relief, as described here.
Relief for SMEs and small mid-caps
Relief for small and medium-sized enterprises (SMEs) and small mid-caps (SMCs) is not uniform:
- SMEs, including start-ups, and SMCs may provide technical documentation in a simplified form provided by the Commission (Art. 11);
- the quality management system must be proportionate to the provider’s size, in particular for SMEs and SMCs (Art. 17);
- Article 63 permits eligible SMEs, including start-ups, to simplify certain elements of the quality management system. Eligibility excludes SMEs with partner or linked enterprises as defined by Recommendation 2003/361/EC; it does not extend to SMCs;
- penalties are reduced, and access to regulatory sandboxes, supervised environments for testing AI with a regulator, is prioritised.
Penalties
The penalties framework has applied since 2 August 2025, with the highest fines for prohibited practices; fines for GPAI providers (Art. 101) apply from 2 August 2026.
Next step: for each use case in your AI inventory, record prohibited-practice screening, high-risk classification with its rationale, and Art. 50 duties, using “Not yet determined” where needed. Review possibly prohibited or high-risk entries first.
Sources and further reading
- Regulation (EU) 2024/1689 (AI Act) — Articles 2, 3, 4, 5, 6, 10–17, 26, 27, 50, 53, 63, 72, 73, 86, 101 and 111, Annexes I and III
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- EU AI Act Service Desk — Article 3
- EU AI Act Service Desk — Article 6
- EU AI Act Service Desk — Article 50
- European Commission — AI Act overview
- European Commission — Guidelines on prohibited AI practices
This article is for general information and is not legal advice.
AI Horizon Conference
The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.