← All laws
EU AI ActIn forceEuropean Union

EU Artificial Intelligence Act (Regulation (EU) 2024/1689)

Last reviewed Sep 25, 2026.

In short

The EU AI Act is the first comprehensive AI law. It bans a short list of practices (social scoring, manipulative systems, most real-time public biometric ID), imposes strict duties on 'high-risk' uses such as hiring and credit scoring, sets transparency rules for chatbots and synthetic media, and regulates general-purpose AI models. It applies in stages from 2025 to 2028. The 2026 Digital Omnibus pushed the high-risk deadlines back and softened the AI-literacy duty.

Who it applies to

  • Organisations that build or use AI systems in European Union.
  • Any use case — it is not limited to specific applications.
  • Size: everyone, including solo operators.
  • Applies to providers and deployers whose AI is placed on the EU market or whose outputs are used in the EU, wherever you are based. Heaviest duties fall on general-purpose AI model providers and on Annex III high-risk uses such as hiring, credit, education and public services.

Key dates

  1. Aug 1, 2024✓Entered into force
  2. Feb 2, 2025✓Prohibited practices (Art. 5) and AI-literacy duty (Art. 4) apply
  3. Aug 2, 2025✓General-purpose AI model obligations, governance and penalty rules apply
  4. Jul 27, 2026✓Digital Omnibus on AI (Reg. (EU) 2026/1744) in force: deadlines moved, new prohibitions added
  5. Aug 2, 2026✓Art. 50 transparency duties apply (chatbot disclosure, deepfake labelling); Commission may enforce against GPAI providers
  6. Dec 2, 2026UpcomingEnd of marking grace period for generative systems already on the market; new bans on AI generating CSAM or non-consensual intimate imagery apply
  7. Dec 2, 2027UpcomingAnnex III high-risk obligations apply (hiring, credit, education, public services, etc.)
  8. Aug 2, 2028UpcomingAnnex I high-risk obligations apply (AI embedded in regulated products)

What you have to do

  • Inventory every AI system you build or use and classify it: prohibited, high-risk, limited-risk (transparency) or minimal.
  • Stop any prohibited practice now: social scoring, manipulation causing harm, emotion recognition at work or school, untargeted face scraping, and (from 2 Dec 2026) generating CSAM or non-consensual intimate imagery.
  • Tell people when they are talking to a chatbot, and label deepfakes and AI-generated audio, image and video content.
  • If you provide a generative AI system, mark outputs in a machine-readable way (new systems from 2 Aug 2026; existing systems by 2 Dec 2026).
  • Take measures to support AI literacy among staff who operate or oversee AI.
  • For high-risk uses, prepare a risk-management system, data-governance controls, technical documentation, logging, human oversight and a conformity assessment before the applicable deadline.
  • If you build a general-purpose AI model, publish training-data summaries, keep technical documentation and respect EU copyright law.

Penalties

Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. For SMEs and start-ups the lower of the two figures applies. Enforced by national market-surveillance authorities; the Commission's AI Office enforces against general-purpose AI model providers from 2 Aug 2026.

Related lessons

Real cases

  • Ruling2024 · CA-BC
    Moffatt v. Air Canada — airline liable for its chatbot's wrong answer

    Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.

  • Ban2023 · US-federal
    FTC v. Rite Aid — five-year ban on facial recognition surveillance

    Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.

  • Lawsuit2025 · US-federal
    Mobley v. Workday — collective action over AI hiring screens (ongoing)

    Ongoing as of September 2026. In July 2024 the court refused to dismiss the case, accepting the agent theory. On 16 May 2025 it conditionally certified a nationwide ADEA collective of applicants aged 40+ rejected via Workday's platform since September 2020; the opt-in notice period closed on 7 March 2026. In June 2026 the court let California FEHA claims and a proxy-discrimination disability claim proceed. No trial date, judgment or settlement has been reported.

  • Fine2024 · EU
    Clearview AI — EUR 90 million-plus in GDPR fines across Europe

    Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.

  • Settlement2024 · US-federal
    Louis v. SafeRent — $2.275 million settlement over algorithmic tenant scoring

    Settlement approved by the court on 20 November 2024: SafeRent pays $2.275 million (up to $1.175 million to class members) and, for five years, will not produce a SafeRent Score or accept/deny recommendation for applicants using housing vouchers unless a fair-housing expert validates a new model. The court awarded $1.1 million in attorneys' fees.

Industries where it matters

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.