EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
Last reviewed Sep 25, 2026.
In short
The EU AI Act is the first comprehensive AI law. It bans a short list of practices (social scoring, manipulative systems, most real-time public biometric ID), imposes strict duties on 'high-risk' uses such as hiring and credit scoring, sets transparency rules for chatbots and synthetic media, and regulates general-purpose AI models. It applies in stages from 2025 to 2028. The 2026 Digital Omnibus pushed the high-risk deadlines back and softened the AI-literacy duty.
Who it applies to
- Organisations that build or use AI systems in European Union.
- Any use case — it is not limited to specific applications.
- Size: everyone, including solo operators.
- Applies to providers and deployers whose AI is placed on the EU market or whose outputs are used in the EU, wherever you are based. Heaviest duties fall on general-purpose AI model providers and on Annex III high-risk uses such as hiring, credit, education and public services.
Key dates
- Aug 1, 2024✓Entered into force
- Feb 2, 2025✓Prohibited practices (Art. 5) and AI-literacy duty (Art. 4) apply
- Aug 2, 2025✓General-purpose AI model obligations, governance and penalty rules apply
- Jul 27, 2026✓Digital Omnibus on AI (Reg. (EU) 2026/1744) in force: deadlines moved, new prohibitions added
- Aug 2, 2026✓Art. 50 transparency duties apply (chatbot disclosure, deepfake labelling); Commission may enforce against GPAI providers
- Dec 2, 2026UpcomingEnd of marking grace period for generative systems already on the market; new bans on AI generating CSAM or non-consensual intimate imagery apply
- Dec 2, 2027UpcomingAnnex III high-risk obligations apply (hiring, credit, education, public services, etc.)
- Aug 2, 2028UpcomingAnnex I high-risk obligations apply (AI embedded in regulated products)
What you have to do
- Inventory every AI system you build or use and classify it: prohibited, high-risk, limited-risk (transparency) or minimal.
- Stop any prohibited practice now: social scoring, manipulation causing harm, emotion recognition at work or school, untargeted face scraping, and (from 2 Dec 2026) generating CSAM or non-consensual intimate imagery.
- Tell people when they are talking to a chatbot, and label deepfakes and AI-generated audio, image and video content.
- If you provide a generative AI system, mark outputs in a machine-readable way (new systems from 2 Aug 2026; existing systems by 2 Dec 2026).
- Take measures to support AI literacy among staff who operate or oversee AI.
- For high-risk uses, prepare a risk-management system, data-governance controls, technical documentation, logging, human oversight and a conformity assessment before the applicable deadline.
- If you build a general-purpose AI model, publish training-data summaries, keep technical documentation and respect EU copyright law.
Penalties
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. For SMEs and start-ups the lower of the two figures applies. Enforced by national market-surveillance authorities; the Commission's AI Office enforces against general-purpose AI model providers from 2 Aug 2026.
Related lessons
- Level 1What AI compliance is (and who the rules target)6 min
- Level 1The world map of AI rules: EU, US patchwork, Canada, standards8 min
- Level 1Why it matters: what enforcement actually looks like7 min
- Level 2Build your AI inventory6 min
- Level 2Risk classification: prohibited, high-risk, limited, minimal8 min
- Level 2Data and privacy basics for AI7 min
- Level 2Transparency and disclosure: telling people AI is involved7 min
- Level 3Human oversight that actually works6 min
- Level 3Bias and fairness testing, including bias audits8 min
- Level 3Vendors and contract clauses6 min
- Level 3Documenting decisions: records and impact assessments7 min
- Level 4Governance structure and roles6 min
- Level 4Incident response and monitoring7 min
- Level 4Security and robustness7 min
- Level 4Training and AI literacy programmes6 min
- Level 5Management systems in practice: ISO 42001, NIST AI RMF and continuous assurance8 min
- Level 5Preparing for enforcement, investigations and appeals7 min
- Level 5Staying current: key dates ahead and how to track change6 min
Real cases
- Ruling2024 · CA-BCMoffatt v. Air Canada — airline liable for its chatbot's wrong answer
Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
- Lawsuit2025 · US-federalMobley v. Workday — collective action over AI hiring screens (ongoing)
Ongoing as of September 2026. In July 2024 the court refused to dismiss the case, accepting the agent theory. On 16 May 2025 it conditionally certified a nationwide ADEA collective of applicants aged 40+ rejected via Workday's platform since September 2020; the opt-in notice period closed on 7 March 2026. In June 2026 the court let California FEHA claims and a proxy-discrimination disability claim proceed. No trial date, judgment or settlement has been reported.
- Fine2024 · EUClearview AI — EUR 90 million-plus in GDPR fines across Europe
Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.
- Settlement2024 · US-federalLouis v. SafeRent — $2.275 million settlement over algorithmic tenant scoring
Settlement approved by the court on 20 November 2024: SafeRent pays $2.275 million (up to $1.175 million to class members) and, for five years, will not produce a SafeRent Score or accept/deny recommendation for applicants using housing vouchers unless a fair-housing expert validates a new model. The court awarded $1.1 million in attorneys' fees.
Industries where it matters
Sources
- Regulation (EU) 2024/1689 (AI Act) — EUR-Lex ↗
- Article 99: Penalties — artificialintelligenceact.eu ↗
- EU AI Act News: Digital Omnibus on AI and new guidance — Mayer Brown (July 2026) ↗
- AI Act — European Commission policy page ↗
Last reviewed Sep 25, 2026.