Artificial IntelligenceRegulations

European Union

Phasing inApproach: Comprehensive, horizontal, risk-based statute

The EU AI Act, Regulation (EU) 2024/1689, is the world's first comprehensive horizontal AI law. It sorts AI systems into four tiers by risk: unacceptable uses are banned, high-risk uses carry heavy obligations, limited-risk uses face transparency duties, and minimal-risk uses are left alone. It entered into force on August 1, 2024 and applies in phases through 2028. It reaches any provider or deployer whose systems are used in the EU, wherever they are based.

Key points

  • Prohibited practices and AI-literacy duties have applied since February 2, 2025.
  • General-purpose AI model obligations have applied since August 2, 2025.
  • Article 50 transparency duties, including chatbot disclosure and content marking, apply from August 2, 2026.
  • The 2026 Digital Omnibus deferred stand-alone high-risk (Annex III) obligations to December 2, 2027 and product-embedded (Annex I) obligations to August 2, 2028.
  • Penalties reach up to EUR 35 million or 7% of worldwide annual turnover for prohibited-practice violations.
  • The guidance layer for the August 2026 transparency deadline is complete: the Commission adopted the final Article 50 guidelines on July 20, 2026 and assessed the Code of Practice on Transparency as adequate. Content generated before August 2 never needs retroactive marking, and transparency violations carry their own fine tier of 15 million euros or 3 percent of worldwide turnover.

Laws and instruments

EU Artificial Intelligence Act

Regulation (EU) 2024/1689
Phasing in

The core regulation. Bans a defined set of practices, imposes lifecycle obligations on high-risk systems, sets transparency duties for limited-risk systems, and creates a separate regime for general-purpose AI models.

Effective: In force Aug 1, 2024; phased to 2028
Primary source: EUR-Lex, full text ↗

Digital Omnibus on AI (AI Act simplification)

2025 Commission proposal; political agreement May 7, 2026; adopted mid-2026
In force

Amends the AI Act. Defers high-risk deadlines, narrows the 'safety component' definition, softens the AI-literacy duty to a best-efforts standard, and adds a new prohibition on AI that generates non-consensual intimate imagery and child sexual abuse material, effective December 2, 2026.

Effective: Adopted mid-2026

Code of Practice on marking and labelling AI-generated content

Published June 10, 2026
In force

Voluntary guidance from the Commission on how to satisfy the Article 50 marking and disclosure obligations for synthetic content.

Effective: Supports Article 50 from Aug 2, 2026
Primary source: European Commission ↗

Timeline

  • Aug 1, 2024
    AI Act enters into force.
  • Feb 2, 2025
    Prohibited practices and AI-literacy obligations apply.
  • Aug 2, 2025
    Governance rules and general-purpose AI model obligations apply.
  • Mar 5, 2026
    Second draft of the Code of Practice on Transparency of AI-Generated Content published.
  • May 7, 2026
    Digital Omnibus political agreement reached, deferring high-risk deadlines.
  • May 8, 2026
    Commission publishes draft Article 50 transparency guidelines; consultation closes June 3.
  • Jul 20, 2026
    Final Article 50 transparency guidelines adopted; the Code of Practice on Transparency assessed as adequate.
  • Aug 2, 2026
    Article 50 transparency obligations apply; Commission enforcement powers over GPAI begin.
  • Dec 2, 2026
    New nudifier / CSAM prohibition takes effect; watermarking grace period ends.
  • Dec 2, 2027
    Stand-alone high-risk (Annex III) obligations apply.
  • Aug 2, 2028
    Product-embedded high-risk (Annex I) obligations apply.

Who it applies to

Providers, deployers, importers, distributors, and product manufacturers of AI systems, plus providers of general-purpose AI models. Extraterritorial: it applies wherever the provider or deployer is established if the system's output is used in the EU. Military, national-security, and pure research uses are largely out of scope.

Penalties

Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. The higher figure applies.

Recent developments

July 20, 2026
European Commission

Commission adopts final Article 50 transparency guidelines, thirteen days before the deadline

The European Commission adopted the final 51-page guidelines on the AI Act's transparency obligations and assessed the Code of Practice on Transparency of AI-Generated Content as adequate. The final text softens the draft in one important place: image, audio, and video deepfakes generated before August 2, 2026 never need retroactive marking, with the date of generation governing, while AI-written text on matters of public interest is judged by its publication date, so older text published after the deadline must be labeled. Open-source systems get no exemption. Transparency violations carry fines up to 15 million euros or 3 percent of worldwide turnover.

July 10, 2026
European Commission

EU AI Act transparency phase goes live; chatbot disclosure now enforceable

The AI Act's Article 50 transparency duties are now in effect. Any business deploying a chatbot or conversational system for EU users has to disclose that the user is dealing with AI, and providers of generative systems must mark synthetic output. Machine-readable marking for content from systems already on the market has a grace period to December 2, 2026.

July 9, 2026
European Commission

Digital Omnibus receives final green light, locking in high-risk delay

The AI Act simplification package cleared its final approval. It confirms the deferral of stand-alone high-risk obligations to December 2, 2027 and product-embedded ones to August 2, 2028, narrows the 'safety component' test, and adds the nudifier and CSAM prohibition taking effect in December 2026.

July 7, 2026
European Commission

Commission presents EU Action Plan on Cybersecurity and AI

The Commission set out a coordinated plan to help member states and businesses handle the security risks of the most advanced AI models, and signaled a call to build EU capacity to evaluate models before they reach the market, expected operational by 2027.

Common questions

Does European Union have a comprehensive AI law?
European Union has a dedicated AI regime. The EU AI Act, Regulation (EU) 2024/1689, is the world's first comprehensive horizontal AI law. It sorts AI systems into four tiers by risk: unacceptable uses are banned, high-risk uses carry heavy obligations, limited-risk uses face transparency duties, and minimal-risk uses are left alone. It entered into force on August 1, 2024 and applies in phases through 2028. It reaches any provider or deployer whose systems are used in the EU, wherever they are based.
What are the penalties for AI violations in European Union?
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. The higher figure applies.
Who does AI regulation in European Union apply to?
Providers, deployers, importers, distributors, and product manufacturers of AI systems, plus providers of general-purpose AI models. Extraterritorial: it applies wherever the provider or deployer is established if the system's output is used in the EU. Military, national-security, and pure research uses are largely out of scope.
Cite this page

Artificial Intelligence Regulations, "AI Regulation in European Union," reviewed July 15, 2026, https://artificialintelligenceregulations.com/jurisdictions/european-union.html.

Entries state the position as of the review date and link to the primary text for verification.