# EU AI Act Application Dates

The EU AI Act, in force since 1 August 2024, applies gradually over 6-36 months, banning unacceptable-risk AI, regulating high-risk systems, and imposing transparency duties on limited-risk and general-purpose AI.

The Artificial Intelligence Act (AI Act) is a European Union regulation establishing a common regulatory and legal framework for [artificial-intelligence](https://www.wikiprompt.org/wiki/artificial-intelligence) within the EU. It entered into force on 1 August 2024, with provisions becoming applicable gradually over the following 6 to 36 months. The Act covers most AI systems across sectors, exempting those used only for military, national security, research, or non-professional purposes. As product regulation, it does not create individual rights but places duties on AI providers and professional users.

The regulation classifies non-exempt AI applications by risk of harm into four levels - unacceptable, high, limited, minimal - plus a separate category for general-purpose AI. Unacceptable-risk applications are banned; high-risk ones must meet security, transparency, and quality obligations and undergo conformity assessments; limited-risk applications face only transparency duties; minimal-risk ones are unregulated. For general-purpose AI, transparency requirements apply, with reduced duties for open-source models and extra evaluations for high-capability systems. The Act also establishes a European Artificial Intelligence Board to promote national cooperation and compliance. Like the EU's General Data Protection Regulation, it can apply extraterritorially to providers outside the EU with users within the EU.

The European Commission proposed the Act on 21 April 2021. It passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024. The draft was revised to address the rise of [generative-ai](https://www.wikiprompt.org/wiki/generative-ai) systems like [ChatGPT](https://www.wikiprompt.org/wiki/openai), whose general-purpose capabilities did not fit the main framework.

## Entry into Force and Phased Application

The AI Act entered into force on 1 August 2024, twenty days after its publication in the Official Journal of the EU. Its provisions apply in stages, giving stakeholders time to adapt. The first key date was 2 February 2025, when prohibitions on unacceptable-risk AI systems became applicable. This included bans on AI that manipulates human behaviour, uses real-time remote biometric identification in public spaces (with narrow exemptions), or enables social scoring.

By 2 August 2025, obligations for general-purpose AI models took effect, including transparency requirements for providers. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines chapters on transparency, copyright, and safety and security to help providers demonstrate compliance; participation is voluntary. Most remaining provisions, including those for high-risk systems, become applicable on 2 August 2026. High-risk AI systems embedded in regulated products already subject to EU sectoral legislation have an extended deadline of 2 August 2027. These staggered dates reflect the Act's aim to balance innovation with oversight, as noted in the Commission's impact assessment.

## Risk Categories and Obligations

The Act's risk-based scheme follows a product-safety model, assigning regulatory duties to providers and deployers that intensify with potential impact on health, safety, or fundamental rights. This structure focuses oversight on systems likely to create significant risks while allowing lighter approaches for less sensitive uses.

**Unacceptable risk** - Applications in this category are banned, except for specific exemptions. This includes AI that manipulates human behaviour, real-time remote biometric identification in public spaces, and social scoring. No exemptions apply for these uses in most cases.

**High risk** - AI systems expected to pose significant threats to health, safety, or fundamental rights fall here. Examples include systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice. They must comply with quality, transparency, human oversight, and safety obligations. Some require a Fundamental Rights Impact Assessment (FRIA) before deployment - an ex ante review to identify and mitigate impacts on fundamental rights. FRIA builds on earlier algorithmic impact assessment work, which suggested such tools should identify affected individuals and communities, describe possible harms, and provide a basis for public scrutiny. High-risk systems must be evaluated before market placement and throughout their life cycle. The list of high-risk applications can be expanded without amending the Act itself. Citizens have rights to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI affecting their rights.

**Limited risk** - These systems have transparency obligations, ensuring users know they are interacting with AI and can make informed choices. This category includes AI that generates or manipulates images, sound, or videos, such as deepfakes.

**Minimal risk** - Examples include AI in video games or spam filters. Most AI applications are expected to fall here. These systems are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules. Existing national laws on such systems are overridden, though a voluntary code of conduct is suggested.

## General-Purpose AI Category

Added in 2023, the general-purpose AI category covers foundation models like [large language models](https://www.wikiprompt.org/wiki/large-language-model) that can perform a wide range of tasks. If a model's weights and design are open source, developers must publish a training data summary and a copyright policy. Closed-source models must meet broader transparency requirements. High-impact models posing systemic risks - defined as requiring more than 10^25 floating-point operations to train - must undergo extra evaluation.

Providers of general-purpose AI models must publish a training data summary, adopt a copyright compliance policy, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure adequate cybersecurity.

## Exemptions

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the Act. The regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for those ends. Research and development activities are also outside scope, as are non-professional uses. These exemptions are narrow; commercial deployments of AI in civilian contexts remain covered even if developed with military or research origins.

## Enforcement and Governance

The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Each member state designates a national supervisory authority to oversee implementation. The Board coordinates these authorities and advises the Commission on technical and regulatory matters. Enforcement mechanisms include fines for non-compliance, scaled by the severity of the violation and the size of the undertaking. The Act's extraterritorial reach means providers outside the EU must comply if their AI systems are used by people within the EU, mirroring the GDPR's approach.

## Legislative History and Context

The European Commission proposed the AI Act on 21 April 2021, following extensive stakeholder consultations and research comparisons documented in an impact assessment. The European Parliament passed it on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The final text incorporated revisions from 2023 to address generative AI systems like ChatGPT, whose general-purpose capabilities did not fit the original risk framework. This led to the dedicated general-purpose AI category. The Act's phased application gives providers and deployers time to implement compliance measures, with the first bans effective in February 2025 and full application for most high-risk systems by August 2026.

## Impact and Interpretation

Legal scholars have noted that the Act frames "trustworthy AI" as systems demonstrating compliance with safety and risk thresholds. The risk-based approach draws on product-safety regulation, assigning duties to those placing AI on the market and those using it professionally. The European Parliamentary Research Service's initial appraisal praised the Commission's impact assessment for its stakeholder engagement and comparative policy analysis. As the application dates pass, the Act's practical effects will depend on how national authorities and the Board interpret its provisions, particularly for high-risk and general-purpose AI. The voluntary code of conduct for minimal-risk systems and the mandatory obligations for higher-risk categories aim to create a harmonised EU market for AI while protecting fundamental rights.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-application
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-12T16:23:43.224565+00:00
