Français

EU AI Act: the complete guide to the European AI regulation in 2026

What actually applies today, what the Digital Omnibus postponed, and the full timeline to 2030. A reference guide, sourced article by article from the consolidated text.

The European Artificial Intelligence Act, the EU AI Act, is Regulation (EU) 2024/1689. It has been applying in stages since February 2025, and it was amended on 27 July 2026 by Regulation (EU) 2026/1744, known as the Digital Omnibus.

The state of play in one sentence: the Article 50 transparency obligations have applied since 2 August 2026, while the high-risk obligations were postponed to December 2027 and August 2028.

The most common misreading

News of the postponement left the impression that “the AI Act has been delayed”. That is wrong for the part touching the largest number of organisations: Article 50 has applied since 2 August 2026, and the prohibitions since February 2025. Regulation (EU) 2026/1744 postponed three blocks: Annex III high-risk, Annex I high-risk, and national regulatory sandboxes. It postponed no other date of application, and it added several new ones, beginning with 2 December 2026.

Has the EU AI Act passed, and what applies today?

It has. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and has been generally applicable since 2 August 2026. It was amended on 27 July 2026 by Regulation (EU) 2026/1744, the Digital Omnibus. Applying today: the prohibitions, AI literacy, the general-purpose AI model obligations, the penalty regime and the Article 50 transparency duties. The high-risk obligations were postponed to December 2027 and August 2028.

Each deadline, its legal basis and the traps in reading this timeline are set out on the dedicated page.

Who has to comply with the EU AI Act?

Any organisation that develops, places on the market or uses an AI system in a professional capacity, whatever its size, subject to the Article 2 exclusions — exclusively military, defence or national-security use, scientific research, pre-market development, and systems released under a free and open-source licence outside high risk, Article 5 and Article 50. The Regulation is directly applicable in every Member State: it needs no national transposition to bind you, and there is no threshold of turnover or headcount below which it stops applying. What changes with your situation is not whether it applies, but which role you hold.

The Regulation reasons by role, defined in Article 3. One organisation often holds several at once, and the qualification is not a formality: it determines the whole set of obligations that follow.

A provider, Article 3(3), is:

“a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge”

Two cumulative conditions, then: develop or have developed, and place on the market or put into service under your own name. Charging for it is irrelevant.

A deployer, Article 3(4), is a person or body “using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”. Authorised representatives, importers and distributors complete the list.

Two points deserve flagging to any organisation building on someone else’s model.

Integrating a model into a product you place on the market makes you the provider of the system, with the obligations that follow, even if you never trained a model. It does not make you the provider of the model unless you modify it significantly. Either way you are a downstream provider within the meaning of Article 3(68) — the definition covers a system provider integrating a model “whether the AI model is provided by themselves and vertically integrated or provided by another entity” — and Article 89(2) gives you a right to lodge a complaint against the model provider, the only remedy the text hands you against them.

Does the EU AI Act apply to companies outside the EU?

Often, yes, and not only when you sell into Europe. Article 2(1)(c) catches a provider or deployer established in a third country as soon as the output produced by the system is used in the Union. Neither your place of incorporation nor the location of your servers is the test: the use of the output is. A third-country provider must in addition appoint an authorised representative established in the Union before making a high-risk system available, under Article 22.

Being established outside the Union is not a way out. What decides is where the output lands, not where the company sits.

What are the risk tiers of the EU AI Act?

Four, often drawn as a pyramid: unacceptable risk, high risk, limited risk subject only to the Article 50 transparency duties, and minimal risk. Two regimes escape that grid and apply regardless: AI literacy under Article 4, which depends on no tier at all, and general-purpose AI models, which form a chapter of their own. The pyramid is a reading aid, not the structure of the text.

The AI Act does not regulate artificial intelligence as a technology. It regulates uses, graded by risk.

TierWhat it coversConsequence
UnacceptableTen practices prohibited by Article 5: manipulation, exploitation of vulnerabilities, non-consensual intimate material, child sexual abuse material or performance (subject to a without-right defence under national law), social scoring, predicting criminal offences, untargeted scraping of facial images, emotion inference at work and in education, sensitive biometric categorisation, and real-time remote biometric identification in publicly accessible spaces for law enforcementEight have applied since 2 February 2025; the two added by Regulation (EU) 2026/1744 apply from 2 December 2026
High riskEight areas in Annex III: biometrics, critical infrastructure, education, employment, essential services and creditworthiness, law enforcement, migration, justice and democratic processes; plus an AI system used as a safety component of a product, or that is itself a product, covered by Annex I and subject to third-party conformity assessmentHeavy obligations, applying 2 December 2027 and 2 August 2028
Limited riskDirect interaction with a person, synthetic content generation, deep fakes, emotion recognitionArticle 50 transparency, applying since 2 August 2026
Minimal riskEverything elseNo specific obligation under these tiers

Two cumulative conditions for Annex I, not one. The first covers a system used as a safety component of an Annex I product or that is itself such a product; the second requires that product to undergo third-party conformity assessment. A system that meets the first but not the second is not high-risk on that basis.

Regulation (EU) 2026/1744 added three further filters to Article 6, and they are its most business-favourable changes. Systems “solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control” do not qualify as safety components. But systems “the failure or malfunctioning of which would endanger health and safety” do qualify, notwithstanding that. And a product required to undergo third-party assessment “solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety” does not meet the second condition.

Two further points that the pyramid diagram almost always erases.

AI literacy does not depend on any tier. Article 4 requires providers and deployers of AI systems, whatever the risk of those systems, to take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. It has applied since 2 February 2025, but its current wording dates from 27 July 2026: Regulation (EU) 2026/1744 added that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. Quoting today’s text and dating it to February 2025 is an anachronism of seventeen months.

Like the rest of the Regulation, Article 4 applies subject to the exclusions in Article 2: purely personal non-professional use, scientific research, pre-market development, defence and national security, and systems released under a free and open-source licence outside high risk, Article 5 and Article 50.

General-purpose AI models sit in a separate regime, Chapter V, which fits none of the four tiers. It covers models, not systems, and has applied since 2 August 2025.

Being listed in Annex III is not enough to be high risk

This is the most misread provision in the Regulation, and it changes the answer for a great many organisations.

“By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.”

Source: Article 6(3), first subparagraph

The second subparagraph lists four situations: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns or deviations from prior patterns, not meant to replace or influence the previously completed human assessment, absent proper human review; and performing a preparatory task.

How the two subparagraphs fit together is unsettled. One reading makes the absence of significant risk a free-standing test, with the four situations as gateways; the other treats those four situations as exhausting the assessment. The Commission’s draft guidelines on high-risk classification, put online on 19 May 2026, lean towards the second, but they are not adopted, they carry neither a C() reference nor a date of their own, and the 2 February 2026 deadline the Regulation set the Commission for publishing them has passed.

Two safeguards, on the other hand, admit no argument.

Profiling bars the exemption in all cases. A system referred to in Annex III “shall always be considered to be high-risk where the AI system performs profiling of natural persons”.

And leaving the high-risk category is not leaving the Regulation. Article 6(4) requires a provider relying on this derogation to document its assessment before the system is placed on the market or put into service, and to register under Article 49(2).

One more thing the timeline alone will not tell you. Article 111(2) exempts most of the installed base: the Regulation applies to operators of high-risk systems placed on the market before the date of application of Chapter III “only if, as from that date, those systems are subject to significant changes in their designs”. The exemption is not open-ended for systems intended to be used by public authorities, which must comply by 2 August 2030 in any event. And Article 5 is never covered: paragraphs 1 and 2 both open with that reservation.

What does Article 50 of the EU AI Act require?

Article 50 has applied since 2 August 2026. The draft guidelines on Article 50, whose content the Commission approved on 20 July 2026 and which are not yet formally adopted, read it as carrying four transparency obligations. The text itself counts nothing.

The grid is convenient, provided you keep what matters in it: these obligations do not fall on the same actors. The table below has five rows because it separates the two subparagraphs of paragraph 4, which those draft guidelines group under one obligation but which follow different regimes.

ObligationWho carries itBasis
Inform the person that they are interacting with an AI system, unless this is obvious, or where authorised by law for law enforcement purposes, unless the system is available for the public to report a criminal offenceProviderArt. 50(1)
Mark synthetic content in a machine-readable format and make it detectable as artificially generated or manipulatedProviderArt. 50(2)
Inform people exposed to an emotion recognition or biometric categorisation system of the operation of the system, and process their personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680DeployerArt. 50(3)
Disclose that a deep fake has been artificially generated or manipulatedDeployerArt. 50(4), 1st subpara.
Disclose that text published to inform the public on matters of public interest has been artificially generated or manipulatedDeployerArt. 50(4), 2nd subpara.

The exemption that decides the question for any newsroom. The second subparagraph of paragraph 4 carries two alternative exceptions. The first is law-enforcement use authorised by law. The second is editorial, and it is cumulative: the content must have “undergone a process of human review or editorial control” and “a natural or legal person holds editorial responsibility for the publication of the content”. One without the other is not enough.

A short deadline is still ahead, and it is wider than it is usually reported. Providers of systems generating synthetic content placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2): that is, with marking and detectability, the two distinct obligations that paragraph carries. This catch-up rule binds neither deployers, nor systems that do not generate synthetic content. Note also what it says: Article 111(4) covers systems placed on the market, and says nothing about putting into service.

General-purpose AI models

Chapter V covers models, not systems, and it was not postponed: provider obligations have applied since 2 August 2025. Technical documentation, information for downstream providers, a policy to comply with Union copyright law, and a publicly available summary of the content used for training.

Two qualifications matter. Models placed on the market before 2 August 2025 (that is, most of what is in service) have until 2 August 2027 to comply.

And Article 53(2) exempts only the first two obligations, on cumulative conditions: the model must be released under a free and open-source licence allowing “the access, usage, modification, and distribution of the model”, and its “parameters, including the weights, the information on the model architecture, and the information on model usage” must be made publicly available. The exemption never applies where the model presents a systemic risk.

Above 10²⁵ cumulative floating-point operations used for training, a model is presumed to have high impact capabilities, which brings it into the systemic-risk regime. The presumption can be rebutted: Article 52(2) lets the provider present, with its notification, “sufficiently substantiated arguments” that the model does not present systemic risks despite meeting the threshold.

If you read the GPAI guidelines in English, read this first

The Commission adopted its guidelines on the scope of the obligations for general-purpose AI model providers on 19 November 2025, as C(2025) 7719 final, with 141 numbered points. The file the Commission publishes in English is not that text: it is the July 2025 draft, C(2025) 5045 final, with 144 points. Twenty-three other language versions carry the adopted text. Two consequences: point numbers do not carry across languages (they diverge from point 21 onwards) and an English-language article citing “the Commission’s guidelines” from that PDF is citing a draft.

What are the penalties under the EU AI Act?

Three ceilings, not one. EUR 35 000 000 or 7 % of total worldwide annual turnover for breaching the Article 5 prohibitions, under Article 99(3). EUR 15 000 000 or 3 % for the breaches listed in Article 99(4), which expressly include the Article 50 transparency obligations. EUR 7 500 000 or 1 % for supplying incorrect information to notified bodies or national authorities in reply to a request. The higher figure applies, except for SMEs, where the Regulation reverses the rule.

The Article 99 scale rests on figures worth knowing.

Up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, for breaching the prohibitions in Article 5, under Article 99(3), whichever is higher.

Up to EUR 15 000 000 or 3 % of the same turnover for the breaches listed in Article 99(4), which expressly include the Article 50 transparency obligations, alongside the obligations of providers, deployers, importers, distributors and authorised representatives.

Up to EUR 7 500 000 or 1 % of the same turnover for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request. That last restriction is in the text: it is not every inaccurate statement that is caught.

For SMEs the rule reverses: the lower figure applies. For small mid-cap companies the reversal is narrower: Article 99(6a) covers only paragraphs 4 and 5, so a small mid-cap that breaches Article 5 remains exposed to the highest ceiling.

One point of timing deserves flagging: an obligation can be enforceable before its penalty regime is. The prohibitions have applied since 2 February 2025, Article 99 since 2 August 2025 (with Article 101, the fines for general-purpose AI model providers, excepted from that date).

A question about your situation?Describe your context in a few lines. We answer on what applies to you, with the articles and the dates.

How do you become compliant with the EU AI Act, and where do you start?

By inventorying, then qualifying your role, then classifying — in that order. The order of operations matters more than speed: each step feeds the next, and doing them backwards means redoing them. What follows is the sequence, with the enforceable-today obligations placed where they belong in it.

The order of operations matters more than speed.

  1. Inventory the AI systems used or developed, including the informal uses that appeared in teams.
  2. Qualify your role, system by system: provider, deployer, or both. That qualification drives everything else.
  3. Classify each system, forgetting neither the Article 6(3) filter nor the fact that relying on it has to be documented.
  4. Check Article 5: the prohibitions have been enforceable since February 2025 and carry the highest penalty ceiling.
  5. Document AI literacy, enforceable since February 2025 and rarely formalised.
  6. Handle Article 50, enforceable since 2 August 2026, with 2 December 2026 as the only short deadline.
  7. Build the path to December 2027 for whatever is high risk, while checking whether Article 111(2) exempts your installed base in the meantime.

What this guide rests on

Every statement on this page is anchored in the text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, in its consolidated version of 27 July 2026, on the understanding that the authentic text is the one published in the Official Journal, the consolidated version having documentary value only. Quotations from the Regulation are reproduced from the official English text, never translated from another language version. Where a reading is the Commission’s rather than the text’s, this page says so: Commission guidelines are not binding, and where they are still in draft, that is stated too.

Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026. The Commission’s page on the guidelines on the transparency obligations in Article 50, consulted on the same date.

In this guide

Frequently asked questions

Has the EU AI Act been delayed?

Three blocks only. High-risk systems under Annex III moved to 2 December 2027, those under Annex I to 2 August 2028, and national regulatory sandboxes to 2 August 2027. Everything else applies: prohibited practices since February 2025, AI literacy since February 2025, general-purpose AI model obligations since August 2025, and the Article 50 transparency obligations since 2 August 2026. The 2026 amending regulation also added new deadlines, starting with 2 December 2026.

What are the penalties?

Up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, for breaching the prohibitions in Article 5, under Article 99(3). Up to EUR 15 000 000 or 3 % for the breaches listed in Article 99(4), which expressly include the Article 50 transparency obligations. And up to EUR 7 500 000 or 1 % for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request. That last restriction is in the text, and dropping it widens the breach. The higher figure applies, except for SMEs, where the Regulation reverses the rule and the lower figure applies.

Does the AI Act apply to companies established outside the EU?

Yes, and not only where the system is placed on the EU market. Article 2(1)(c) also catches a provider or deployer in a third country where the output produced by the system is used in the Union. Being established elsewhere is not by itself a way out.

Does my company fall in scope if it only uses ChatGPT?

Yes. Using a system under your own authority in a professional context makes you a deployer within the meaning of Article 3(4), and the AI literacy obligation in Article 4 has applied to deployers since 2 February 2025, subject to the exclusions in Article 2. Watch the split of roles in Article 50 though: telling users they are interacting with an AI, and marking synthetic content, fall on the provider of the system, not on you. What falls on you as deployer is disclosing that a deep fake was AI-generated, and doing the same for text published to inform the public on matters of public interest, unless that text underwent human review or editorial control and someone holds editorial responsibility for it.

I build a product on a model API. Am I a provider?

Of the system, yes, if you develop it or have it developed and place it on the market or put it into service under your own name or trademark. Those are the two cumulative conditions in Article 3(3), and charging for it is irrelevant. Of the model, no, as long as you do not modify it significantly: the model provider carries the Chapter V obligations. You are then a downstream provider within the meaning of Article 3(68), and Article 89(2) gives you a right to lodge a duly reasoned complaint alleging an infringement of the Regulation by the model provider.

This content is a technical and regulatory information resource. It does not constitute legal advice.