We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
Regulatory developments as they land: provisional agreements, adopted texts, enforcement dates, and guidance from the AI Office and national authorities. Each item links to the guide that explains it.
Providers and deployers must disclose AI interaction and mark certain AI-generated content; synthetic-media marking under 50(2) follows later in the year.
Member states must give effect to Dir. 2024/2853; software and AI become products under strict, no-fault liability.
The Digital Omnibus moved the standalone high-risk date here from August 2026. The full high-risk duty set lands for Annex III systems.
Systems that are safety components of products under Union harmonisation law come into scope, integrated through existing conformity assessment.
The simplification package defers standalone high-risk obligations to December 2027 and adjusts parts of the transparency regime.
Clarifications on documentation and systemic-risk classification for general-purpose model providers continue to issue.
Implementation across member states remains staggered, leaving cross-border essential and important entities on differing timelines.
Financial entities continue operationalising the ICT risk, incident-reporting, and third-party oversight standards in force since January 2025.
Transparency and documentation duties for general-purpose AI model providers begin to apply.
Article 5 prohibited practices and the organisation-wide AI literacy obligation become applicable, the first duties to bite.
The Digital Operational Resilience Act applies to financial entities across the EU.