The EU AI Act, Regulation (EU) 2024/1689, is the world's first comprehensive horizontal AI law. It sorts AI systems into four tiers by risk: unacceptable uses are banned, high-risk uses carry heavy obligations, limited-risk uses face transparency duties, and minimal-risk uses are left alone. It entered into force on August 1, 2024 and applies in phases through 2028. It reaches any provider or deployer whose systems are used in the EU, wherever they are based.
Key points
- Prohibited practices and AI-literacy duties have applied since February 2, 2025.
- General-purpose AI model obligations have applied since August 2, 2025.
- Article 50 transparency duties, including chatbot disclosure and content marking, apply from August 2, 2026.
- The 2026 Digital Omnibus deferred stand-alone high-risk (Annex III) obligations to December 2, 2027 and product-embedded (Annex I) obligations to August 2, 2028.
- Penalties reach up to EUR 35 million or 7% of worldwide annual turnover for prohibited-practice violations.
- The guidance layer for the August 2026 transparency deadline is complete: the Commission adopted the final Article 50 guidelines on July 20, 2026 and assessed the Code of Practice on Transparency as adequate. Content generated before August 2 never needs retroactive marking, and transparency violations carry their own fine tier of 15 million euros or 3 percent of worldwide turnover.
Laws and instruments
EU Artificial Intelligence Act
Regulation (EU) 2024/1689
Phasing inThe core regulation. Bans a defined set of practices, imposes lifecycle obligations on high-risk systems, sets transparency duties for limited-risk systems, and creates a separate regime for general-purpose AI models.
Effective: In force Aug 1, 2024; phased to 2028
Digital Omnibus on AI (AI Act simplification)
2025 Commission proposal; political agreement May 7, 2026; adopted mid-2026
In forceAmends the AI Act. Defers high-risk deadlines, narrows the 'safety component' definition, softens the AI-literacy duty to a best-efforts standard, and adds a new prohibition on AI that generates non-consensual intimate imagery and child sexual abuse material, effective December 2, 2026.
Effective: Adopted mid-2026
Code of Practice on marking and labelling AI-generated content
Published June 10, 2026
In forceVoluntary guidance from the Commission on how to satisfy the Article 50 marking and disclosure obligations for synthetic content.
Effective: Supports Article 50 from Aug 2, 2026
Timeline
- Aug 1, 2024
AI Act enters into force.
- Feb 2, 2025
Prohibited practices and AI-literacy obligations apply.
- Aug 2, 2025
Governance rules and general-purpose AI model obligations apply.
- Mar 5, 2026
Second draft of the Code of Practice on Transparency of AI-Generated Content published.
- May 7, 2026
Digital Omnibus political agreement reached, deferring high-risk deadlines.
- May 8, 2026
Commission publishes draft Article 50 transparency guidelines; consultation closes June 3.
- Jul 20, 2026
Final Article 50 transparency guidelines adopted; the Code of Practice on Transparency assessed as adequate.
- Aug 2, 2026
Article 50 transparency obligations apply; Commission enforcement powers over GPAI begin.
- Dec 2, 2026
New nudifier / CSAM prohibition takes effect; watermarking grace period ends.
- Dec 2, 2027
Stand-alone high-risk (Annex III) obligations apply.
- Aug 2, 2028
Product-embedded high-risk (Annex I) obligations apply.
Who it applies to
Providers, deployers, importers, distributors, and product manufacturers of AI systems, plus providers of general-purpose AI models. Extraterritorial: it applies wherever the provider or deployer is established if the system's output is used in the EU. Military, national-security, and pure research uses are largely out of scope.
Penalties
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. The higher figure applies.
Recent developments
July 20, 2026
European Commission
Commission adopts final Article 50 transparency guidelines, thirteen days before the deadline
The European Commission adopted the final 51-page guidelines on the AI Act's transparency obligations and assessed the Code of Practice on Transparency of AI-Generated Content as adequate. The final text softens the draft in one important place: image, audio, and video deepfakes generated before August 2, 2026 never need retroactive marking, with the date of generation governing, while AI-written text on matters of public interest is judged by its publication date, so older text published after the deadline must be labeled. Open-source systems get no exemption. Transparency violations carry fines up to 15 million euros or 3 percent of worldwide turnover.
July 10, 2026
European Commission
EU AI Act transparency phase goes live; chatbot disclosure now enforceable
The AI Act's Article 50 transparency duties are now in effect. Any business deploying a chatbot or conversational system for EU users has to disclose that the user is dealing with AI, and providers of generative systems must mark synthetic output. Machine-readable marking for content from systems already on the market has a grace period to December 2, 2026.
July 9, 2026
European Commission
Digital Omnibus receives final green light, locking in high-risk delay
The AI Act simplification package cleared its final approval. It confirms the deferral of stand-alone high-risk obligations to December 2, 2027 and product-embedded ones to August 2, 2028, narrows the 'safety component' test, and adds the nudifier and CSAM prohibition taking effect in December 2026.
July 7, 2026
European Commission
Commission presents EU Action Plan on Cybersecurity and AI
The Commission set out a coordinated plan to help member states and businesses handle the security risks of the most advanced AI models, and signaled a call to build EU capacity to evaluate models before they reach the market, expected operational by 2027.
Common questions
Does European Union have a comprehensive AI law?
European Union has a dedicated AI regime. The EU AI Act, Regulation (EU) 2024/1689, is the world's first comprehensive horizontal AI law. It sorts AI systems into four tiers by risk: unacceptable uses are banned, high-risk uses carry heavy obligations, limited-risk uses face transparency duties, and minimal-risk uses are left alone. It entered into force on August 1, 2024 and applies in phases through 2028. It reaches any provider or deployer whose systems are used in the EU, wherever they are based.
What are the penalties for AI violations in European Union?
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. The higher figure applies.
Who does AI regulation in European Union apply to?
Providers, deployers, importers, distributors, and product manufacturers of AI systems, plus providers of general-purpose AI models. Extraterritorial: it applies wherever the provider or deployer is established if the system's output is used in the EU. Military, national-security, and pure research uses are largely out of scope.
Cite this page
Artificial Intelligence Regulations, "AI Regulation in European Union," reviewed July 15, 2026, https://artificialintelligenceregulations.com/jurisdictions/european-union.html.
Entries state the position as of the review date and link to the primary text for verification.