The EU AI Act (Regulation (EU) 2024/1689) is a comprehensive legal framework for artificial intelligence, adopted by the European Union in 2024. It establishes a risk-based classification system for AI systems, imposing different obligations depending on the level of risk they pose to health, safety, and fundamental rights. Rather than entering into force as a single block, the Act's provisions apply on a staggered timeline, with different requirements becoming mandatory at different dates between February 2025 and August 2027. This phased approach is designed to give providers, deployers, and national authorities time to adapt to the new rules, while prioritizing the most urgent prohibitions and governance structures.
The Act applies to both providers (those who develop AI systems) and deployers (those who use them in a professional capacity), regardless of whether they are based in the EU, as long as the AI system is placed on the EU market or its output is used within the EU. It covers a wide range of AI technologies, including Machine learning models, large language models, and generative AI systems, but excludes certain areas such as national security and military purposes.
Entry into Force and Initial Provisions
The AI Act was published in the Official Journal of the European Union on 12 July 2024 and entered into force twenty days later, on 1 August 2024. The first set of binding obligations, however, did not start until 2 February 2025. This initial phase focused on the provisions that were considered most urgent: the prohibitions on unacceptable risk AI practices and the rules on AI literacy.
From 2 February 2025, the following became applicable:
- Prohibited practices under Article 5, which ban AI systems that deploy subliminal techniques to distort behavior, exploit vulnerabilities of specific groups (such as children or persons with disabilities), evaluate or classify people based on social behavior (social scoring), use real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions), and predict criminal or administrative offenses based solely on profiling.
- AI literacy obligations under Article 4, requiring providers and deployers to ensure that their staff and others involved in operating AI systems have a sufficient level of AI literacy, considering their technical knowledge, experience, education, and training.
- The establishment of the European AI Office within the European Commission, which serves as the central enforcement and coordination body.
General-Purpose AI Models (August 2025)
The second major milestone came on 2 August 2025, when obligations for providers of general-purpose AI (GPAI) models took effect. A GPAI model is defined as an AI model, including those trained with large-scale self-supervision, that is capable of competently performing a wide range of distinct tasks. This category includes most foundation models and large language models such as those developed by OpenAI, Anthropic, and Google DeepMind.
Under these rules, providers of GPAI models must:
- Maintain up-to-date technical documentation, including training data descriptions, model architecture, and evaluation results.
- Provide information and documentation to downstream providers who integrate the model into their own AI systems.
- Establish a copyright policy that respects EU copyright law, particularly regarding text and data mining.
- Publish a sufficiently detailed summary of the training content.
For GPAI models that present systemic risk - defined as models trained with a cumulative compute exceeding 10^25 floating-point operations (FLOPs) - additional obligations apply. These include conducting model evaluations, adversarial testing, and reporting serious incidents to the European AI Office. The Commission may designate a model as systemic-risk even if it falls below the compute threshold, based on its capabilities or impact.
High-Risk Systems and Governance (August 2026)
The most extensive set of obligations became applicable on 2 August 2026. This date covers the requirements for high-risk AI systems under the Act's Article 6 and Annexes I and III. High-risk systems include AI used in critical infrastructure, education and vocational training, employment and worker management, essential private and public services, law enforcement, migration and asylum management, and administration of justice.
From this date, providers of high-risk AI systems must comply with a comprehensive set of requirements:
- Establish a risk management system that runs throughout the system's lifecycle.
- Use training, validation, and testing data that are relevant, representative, and free of errors and biases.
- Create technical documentation demonstrating compliance.
- Enable automatic logging of events to ensure traceability.
- Provide transparency to deployers, including instructions for use.
- Implement human oversight measures.
- Ensure robustness, accuracy, and cybersecurity.
Additionally, from 2 August 2026, the governance framework becomes fully operational. This includes the requirement for Member States to designate national competent authorities and to establish notified bodies responsible for conformity assessments. The European Artificial Intelligence Board, composed of representatives from Member States, also becomes fully active.
Transparency Obligations for Limited-Risk Systems (August 2026)
Also on 2 August 2026, transparency obligations for limited-risk AI systems take effect. These apply to AI systems that interact with humans, such as chatbots, and to systems that generate or manipulate content (deepfakes). Providers must ensure that users are informed that they are interacting with an AI system, unless this is obvious from the circumstances. Content generated or manipulated by AI must be marked in a machine-readable format to indicate its artificial origin. This includes deepfakes and AI-generated text, audio, or video.
High-Risk Systems in Annex I (August 2027)
The final major application date is 2 August 2027. This covers high-risk AI systems that are safety components of products or systems that are already subject to existing EU product safety legislation, such as machinery, toys, medical devices, and vehicles. These systems must comply with the same high-risk requirements as those in Annex III, but the application was delayed to allow manufacturers to align with the relevant sectoral legislation. The Act also requires that the Commission update the technical documentation and conformity assessment procedures for these products.
Post-Market Monitoring and Enforcement
From 2 August 2026, providers of high-risk AI systems must also establish a post-market monitoring system to actively collect and analyze data on the performance of their systems throughout their lifetime. This system must be documented and reported to the relevant authorities. The Act also introduces a procedure for handling serious incidents and malfunctions that may lead to risks to health, safety, or fundamental rights.
Enforcement is carried out by national market surveillance authorities, coordinated by the European AI Office. Penalties for non-compliance are substantial: up to 35 million euros or 7% of a company's total worldwide annual turnover for violations of prohibited practices, up to 15 million euros or 3% of turnover for violations of most other obligations, and up to 7.5 million euros or 1.5% of turnover for supplying incorrect information to authorities. For small and medium-sized enterprises (SMEs) and startups, these fines are capped at the lower of the two amounts.
Codes of Practice and Standards
To support implementation, the European AI Office has facilitated the development of a Code of Practice for general-purpose AI providers, which was finalized in 2025. This code translates the legal obligations into practical commitments, covering areas such as transparency, copyright, and systemic risk management. Providers who adhere to the code are presumed to be in compliance with the Act's requirements.
The Act also relies heavily on harmonized technical standards developed by European standardization organizations (CEN, CENELEC, and ETSI). These standards, which are being drafted through 2025 and 2026, will provide technical specifications for conformity assessment, risk management, and data quality. Until these standards are published, providers may use alternative methods, but they must demonstrate compliance through other means.
Implications for the AI Industry
The staggered application dates have significant implications for companies developing and deploying AI systems. Providers of GPAI models, including major labs like OpenAI, Anthropic, and Google DeepMind, had to prepare for the August 2025 deadline, which required substantial documentation and transparency efforts. Many companies have established internal compliance teams and developed tools to track training data and model behavior.
For high-risk AI applications, the August 2026 and August 2027 deadlines give developers more time, but also require early planning. Companies in sectors such as healthcare (e.g., Intuitive Surgical), autonomous driving (e.g., Waymo, Tesla), and financial services must conduct conformity assessments, often involving third-party notified bodies. The Act also affects cloud service providers like Amazon Web Services, Microsoft Azure, and Google Cloud, which offer AI platforms and may be considered deployers or providers depending on their role.
The Act has also influenced global AI governance, as other jurisdictions have looked to the EU as a regulatory model. However, the complexity of the staggered timeline has been a point of criticism, with some industry groups arguing that the phased approach creates uncertainty and compliance burdens. The European Commission has responded by publishing guidance documents and establishing a stakeholder consultation process to clarify ambiguous provisions.
Future Developments
As of 2025, the European Commission is working on additional implementing acts and guidelines, particularly regarding the definition of systemic risk, the interaction with existing sectoral legislation, and the practical application of transparency requirements. The Commission also plans to review the Act's list of prohibited practices and high-risk areas by 2027, with the possibility of extending the scope to new AI applications. The full impact of the AI Act will only become clear as the various application dates pass and enforcement actions begin.