We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The most comprehensive horizontal AI regime in force. It classifies AI systems by risk, places the heaviest duties on high-risk uses, and reaches any provider or deployer whose system touches the EU market, wherever they are established. Here is what it asks, of whom, and by when.
The Act does not regulate AI as a single thing. It sorts each system into a risk tier and attaches obligations to the tier: a small set of practices are banned outright, a defined list of high-risk uses carry the full compliance burden, a few uses owe only transparency, and everything else is largely unregulated.
It is also extraterritorial. The obligations follow the system into the EU market, so a provider outside the EU placing a system on the market, and a deployer using one whose output is used in the EU, are both in scope. And it is a moving regime: the 2026 Digital Omnibus postponed the heaviest high-risk deadlines while leaving the literacy, transparency, and prohibition duties on their original clock.
Banned practices: social scoring, manipulative or exploitative AI, untargeted scraping for facial recognition, and more.
Employment, credit, education, biometrics, essential services, critical infrastructure. The full obligation set.
Chatbots, emotion recognition, and synthetic or manipulated content must disclose that AI is at work.
Everything else. No mandatory obligations under the Act; voluntary codes of conduct are encouraged.
Application phases in over several years. The Digital Omnibus (political agreement May 2026) moved the standalone high-risk deadline to December 2027, but left the earlier duties in place.
Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply.
General-purpose AI model obligations (Art. 51–55) apply.
Article 50 transparency obligations apply; synthetic-content marking follows in Dec 2026.
Standalone high-risk (Annex III) obligations apply; product-embedded (Annex I) follows 2 Aug 2028.
Source: Official Journal of the EU · EU AI Act as amended by the Digital Omnibus · confirm against consolidated text before relying on any date
The same system carries different duties depending on whether you build it, deploy it, import it, or represent a provider from outside the EU.
The heaviest duties. Risk management, data governance, technical documentation, logging, human oversight, conformity assessment, registration, and post-market monitoring.
Operate it as instructed, keep human oversight, monitor for issues, and run a fundamental-rights impact assessment where required. Data-protection duties run in parallel.
Verify the provider completed conformity assessment, that documentation and the CE marking are in place, before the system reaches the market.
The provider's EU point of contact. Hold the documentation, cooperate with authorities, and be the address the regulator can reach.
Roles and duties render from structured regulatoryProvision records · illustrative, not exhaustive
Fines are set as the higher of a fixed ceiling or a percentage of worldwide annual turnover. For SMEs and start-ups, the lower of the two applies.
| Breach | What it covers |
|---|---|
| €35M / 7%whichever is higher | Deploying a prohibited AI practice under Article 5. |
| €15M / 3%whichever is higher | Non-compliance with most other obligations, including the high-risk provider and deployer duties. |
| €7.5M / 1%whichever is higher | Supplying incorrect, incomplete, or misleading information to authorities. |
Figures per the EU AI Act penalty tiers · confirm the applicable ceiling and any Omnibus adjustment against the consolidated text
"We're not an EU company, so it doesn't apply to us."
The Act is extraterritorial. If your system is placed on the EU market, or its output is used in the EU, you are in scope wherever you are established.
"We don't build AI, we only use it, so the burden is the vendor's."
Deployers carry their own duties: human oversight, monitoring, and a fundamental-rights impact assessment where required. The Article 4 literacy duty has applied to every deployer since February 2025.
"The deadline moved to 2027, so there's time to wait."
Standalone high-risk obligations now apply from 2 December 2027, but literacy is live, transparency lands in August 2026, and prohibitions are already in force. The extra time is for doing the work properly before the standards land, not for delay.
The same high-risk system usually meets the GDPR, NIS2, DORA, sectoral law, and the Product Liability Directive at once. Standard Intelligence maps at the level of the obligation across every regime, so one body of evidence holds across all of them.