European Union Regulation Partially applicable Binding

EU AI Act: requirements, deadlines and compliance actions

Regulation (EU) 2024/1689 — Artificial Intelligence Act

What is the EU AI Act?

The EU AI Act is a binding regulation that sets rules for developing, placing on the market and using AI systems in the European Union. It bans a small set of practices considered unacceptable, imposes detailed requirements on "high-risk" AI systems used in areas such as employment, education, credit, essential services, law enforcement and safety-critical products, requires transparency for chatbots and synthetic content, and creates separate duties for providers of general-purpose AI models. Obligations apply in phases between 2025 and 2027.

Status note: Dates below follow Article 113 of the adopted text. The European Commission proposed a "Digital Omnibus" package in November 2025 that would adjust the application dates for some high-risk obligations; a reviewer must confirm whether that proposal has been adopted and update the deadlines accordingly.

Who does it apply to?

Applies to providers placing AI systems or general-purpose AI models on the EU market or putting them into service, to deployers established in the EU, and to providers and deployers in third countries where the system's output is used in the EU (Article 2). Excludes AI used exclusively for military, defence or national-security purposes, and activities of purely personal non-professional use. Free and open-source models get partial relief unless they are general-purpose models with systemic risk.

Providers (developers), deployers (organisations using AI under their authority), importers, distributors, authorised representatives of non-EU providers, product manufacturers integrating AI, and providers of general-purpose AI models. Public authorities are covered as deployers and have extra duties for fundamental-rights impact assessments.

When do the requirements apply?

Entry into force 1 August 2024. Prohibitions and AI literacy from 2 February 2025. General-purpose AI model duties, governance and penalties from 2 August 2025. General application, including Annex III high-risk systems and Article 50 transparency, from 2 August 2026. High-risk AI that is a safety component of Annex I products from 2 August 2027. Adjustments proposed in the 2025 Digital Omnibus are not reflected until verified.

Key dates and deadlines for EU AI Act
DateMilestoneSource referenceStatus
Entry into force
Twentieth day after publication in the Official Journal.
Article 113 Passed
Prohibited practices and AI literacy apply (Chapters I and II)
Article 5 bans and Article 4 literacy duties apply.
Article 113(a) Passed
General-purpose AI, governance, notified bodies and penalties apply
Chapter V (GPAI models), Chapter III Section 4, Chapter VII, Chapter XII (except Article 101) and Article 78 apply.
Article 113(b) Passed
General application, including Annex III high-risk systems and Article 50 transparency
Default application date for the remainder of the Regulation, as set in the adopted text. Subject to any adopted amendment from the 2025 Digital Omnibus proposal, which a reviewer must confirm.
Article 113 Scheduled
confidence: medium
High-risk AI as safety components of Annex I products
Article 6(1) obligations for AI in products covered by Annex I harmonisation legislation.
Article 113(c) Scheduled
General-purpose models placed on the market before 2 August 2025 must comply
Transitional period for models already on the market.
Article 111(3) Scheduled
confidence: medium
Large-scale IT systems listed in Annex X placed on the market before 2 August 2027
Transitional period for certain EU large-scale IT systems in the area of freedom, security and justice.
Article 111(1) Scheduled
confidence: medium

"applies_from" shows the general application date in Article 113. Earlier and later dates apply to specific chapters; see the deadlines table.

What must organisations do?

Inventory AI systems and determine your role for each; screen against prohibited practices now; classify systems against Annex I and Annex III; for high-risk systems build a risk-management system, data-governance controls, technical documentation, logging, human-oversight measures and a quality-management system, then complete conformity assessment and register in the EU database before placing on the market; deployers must use systems as instructed, assign trained human oversight, keep logs and, where required, complete a fundamental-rights impact assessment; label AI interactions and synthetic content under Article 50; general-purpose model providers must publish training-content summaries, maintain documentation and a copyright policy.

Legal requirement Do not deploy or provide AI for prohibited practices Article 5

Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.

Practical action: Add a prohibited-practice screen to your AI intake or design-review process and document the outcome for every system already in use.

Evidence examples: Prohibited-practice screening record; AI system inventory

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.2 and Annex A control on AI system impact assessment; NIST AI RMF 1.0 GOVERN 1.1, MAP 1.1

Obligation pageApplies from 2 Feb 2025 Source-linked

Legal requirement Ensure AI literacy of staff operating AI systems Article 4

Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.

Practical action: Run role-based AI training and keep attendance and content records; the Commission's AI Office has indicated that literacy will be assessed proportionately.

Evidence examples: AI literacy training programme

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 7.2 Competence and 7.3 Awareness; NIST AI RMF 1.0 GOVERN 2.2

Obligation pageApplies from 2 Feb 2025 Source-linked

Legal requirement Establish a risk management system for high-risk AI Article 9

Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.

Practical action: Set up a lifecycle risk register per high-risk system with test evidence and residual-risk acceptance.

Evidence examples: Risk register and treatment plan; Pre-market test reports

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk; NIST AI RMF 1.0 MAP, MEASURE and MANAGE functions

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Apply data governance and quality criteria to training, validation and testing data Article 10

High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.

Practical action: Produce a data-provenance and bias-assessment record for each data set used to build the system.

Evidence examples: Dataset documentation (datasheet); Bias examination report

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on data for AI systems; NIST AI RMF 1.0 MAP 2.3, MEASURE 2.1, MEASURE 2.11

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Draw up technical documentation before placing a high-risk system on the market Article 11 and Annex IV

Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.

Practical action: Maintain an Annex IV-structured technical file under version control.

Evidence examples: Annex IV technical file

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 7.5 Documented information; Annex A control on system documentation; NIST AI RMF 1.0 GOVERN 1.4, MAP 3.x

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Design high-risk systems to log events automatically Article 12; Article 26(6) for deployers

High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.

Practical action: Define the log schema, retention and access controls, and confirm deployer retention meets the minimum.

Evidence examples: Logging specification and retention policy

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A control on event logging; NIST AI RMF 1.0 MEASURE 2.x, MANAGE 4.1

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Provide deployers with clear instructions for use Article 13

High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.

Practical action: Ship an Article 13-structured instructions-for-use document with every high-risk system release.

Evidence examples: Instructions for use

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on information for interested parties; NIST AI RMF 1.0 GOVERN 4.x, MAP 1.x

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Enable and assign effective human oversight Article 14; Article 26(2) for deployers

High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.

Practical action: Document oversight roles, the "stop" mechanism and override paths for each high-risk deployment.

Evidence examples: Human oversight procedure and role assignment

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A control on human oversight; NIST AI RMF 1.0 GOVERN 3.2, MANAGE 2.x

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Achieve appropriate accuracy, robustness and cybersecurity Article 15

High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.

Practical action: Include AI-specific threat modelling and adversarial testing in your security programme.

Evidence examples: Accuracy metrics and test evidence; AI security assessment

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on AI system verification and validation; ISO/IEC 27001:2022 Clause 8 and Annex A security controls; NIST AI RMF 1.0 MEASURE 2.5, 2.6, 2.7

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Operate a quality management system Article 17

Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.

Practical action: Extend an existing ISO 9001 or ISO/IEC 42001 management system to cover the Article 17 elements.

Evidence examples: QMS manual and procedures

Framework mapping (original, editorial): ISO/IEC 42001:2023 Whole management system (Clauses 4–10); NIST AI RMF 1.0 GOVERN function

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Complete conformity assessment, CE marking and EU database registration Articles 43, 47, 48 and 49; Annex VIII

Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.

Practical action: Determine the assessment route early; notified-body capacity may be limited around application dates.

Evidence examples: EU declaration of conformity; EU database registration record

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 9 Performance evaluation; internal audit

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Use high-risk AI as instructed, monitor it and inform affected people Article 26

Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.

Practical action: Create a deployer checklist per high-risk system and a notice for affected individuals and workers.

Evidence examples: Deployment checklist and oversight assignment; Worker and affected-person notices

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on responsible use of AI systems; NIST AI RMF 1.0 MANAGE 3.x, GOVERN 5.x

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Carry out a fundamental rights impact assessment before deployment Article 27

Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.

Practical action: Reuse GDPR DPIA workflows and extend them with the Article 27 elements; the AI Office is to provide a template.

Evidence examples: Fundamental rights impact assessment report

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment; NIST AI RMF 1.0 MAP 5.1, MAP 5.2

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Disclose AI interaction and label synthetic content Article 50

Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.

Practical action: Implement provenance marking (for example content credentials) and user-facing AI disclosures in product UX.

Evidence examples: Disclosure and watermarking design record

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A control on communication with interested parties; NIST AI RMF 1.0 GOVERN 4.x; NIST AI 600-1 content provenance suggestions

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Meet general-purpose AI model provider obligations Article 53 and Annexes XI–XII

Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.

Practical action: Prepare the Commission's training-content summary template and a documented copyright policy before release.

Evidence examples: Public summary of training content; Copyright compliance policy

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on data provenance and documentation; NIST AI RMF 1.0 NIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risks

Obligation pageApplies from 2 Aug 2025 Source-linked

Legal requirement Manage systemic risk for high-impact general-purpose models Articles 51, 52 and 55

A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.

Practical action: Track training compute against the threshold and prepare a safety and security framework before launch.

Evidence examples: Model evaluation and red-teaming reports; Commission notification record

Framework mapping (original, editorial): NIST AI RMF 1.0 MEASURE 2.x; NIST AI 600-1

Obligation pageApplies from 2 Aug 2025 Source-linked

Legal requirement Operate a post-market monitoring system Article 72

Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.

Practical action: Define performance and drift indicators, feedback channels and review cadence in a monitoring plan.

Evidence examples: Post-market monitoring plan and periodic reports

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 9.1 Monitoring, measurement, analysis and evaluation; NIST AI RMF 1.0 MANAGE 4.1, MEASURE 3.x

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Report serious incidents to market surveillance authorities Article 73

Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.

Practical action: Add AI serious-incident criteria and time limits to your existing incident-response playbook.

Evidence examples: AI incident response procedure; Incident log and authority notifications

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 10 Improvement; Annex A control on incident handling; NIST AI RMF 1.0 MANAGE 4.3

Obligation pageApplies from 2 Aug 2026 Source-linked

Legal requirement Verify conformity before importing or distributing high-risk AI Articles 23 and 24

Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.

Practical action: Build AI Act checks into supplier onboarding and contract clauses.

Evidence examples: Supplier due-diligence checklist

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on third parties and suppliers; NIST AI RMF 1.0 GOVERN 6.1, GOVERN 6.2

Obligation pageApplies from 2 Aug 2026 Source-linked

Penalties

Article 99 sets administrative fines of up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 % for most other obligations, and up to EUR 7.5 million or 1 % for supplying incorrect information, with the lower amount applying to SMEs. Article 101 allows the Commission to fine general-purpose AI model providers up to EUR 15 million or 3 %.

Key sections and articles

Sections of EU AI Act
ReferenceTitleSummary
Article 2ScopeWho and what the Regulation covers, including extraterritorial reach and exclusions.
Article 3DefinitionsDefines AI system, provider, deployer, general-purpose AI model and other key terms.
Article 4AI literacyProviders and deployers must ensure sufficient AI literacy of staff and others operating AI on their behalf.
Article 5Prohibited AI practicesBans manipulative and exploitative techniques, certain social scoring, some predictive policing, untargeted facial-image scraping, emotion recognition in workplaces and schools (with exceptions), certain biometric categorisation, and real-time remote biometric identification in public spaces for law enforcement subject to narrow exceptions.
Article 6Classification rules for high-risk AI systemsHigh-risk if a safety component or product under Annex I legislation requiring third-party assessment, or listed in Annex III, subject to the Article 6(3) derogation.
Articles 8–15Requirements for high-risk AI systemsRisk management, data governance, technical documentation, record keeping, transparency, human oversight, accuracy, robustness and cybersecurity.
Articles 16–27Obligations of operators of high-risk AIDuties of providers, authorised representatives, importers, distributors and deployers, including the fundamental-rights impact assessment in Article 27.
Article 50Transparency obligations for certain AI systemsDisclosure for AI interaction, marking of synthetic content, deepfake labelling and emotion-recognition or biometric-categorisation notices.
Articles 51–56General-purpose AI modelsClassification of systemic-risk models, provider obligations, and codes of practice.
Article 72Post-market monitoringProviders must operate a post-market monitoring system proportionate to the AI technology and risks.
Article 73Reporting of serious incidentsProviders of high-risk AI must report serious incidents to market-surveillance authorities within set time limits.
Article 99PenaltiesAdministrative fine ceilings by category of infringement.
Article 113Entry into force and applicationPhased application dates.

Public-sector rules and enforcement

  • Public-authority deployers must register high-risk AI use and assess fundamental-rights impact — Public bodies deploying Annex III high-risk systems must register their use in the EU database (Article 49(4)) and complete a fundamental-rights impact assessment before deployment (Article 27). The Commission has also published model contractual clauses for public procurement of AI (non-binding). (applies to: Public authorities and bodies governed by public law in the EU)

Official sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act) — consolidated ELI page
    Publications Office of the European Union · 12 Jul 2024 · Tier 1 source
  2. AI Act policy page and implementation timeline
    European Commission, DG CONNECT · Tier 1 source
  3. General-Purpose AI Code of Practice
    European Commission, AI Office · 10 Jul 2025 · Tier 2 source
  4. Commission Guidelines on prohibited AI practices
    European Commission · 4 Feb 2025 · Tier 2 source

Change history

Record version 1: Initial structured record from the adopted text; Digital Omnibus adjustments not yet reflected.. Full edit history is in the GitHub repository.

Frequently asked questions

What is the EU AI Act?
Regulation (EU) 2024/1689 is a binding EU law that sets risk-based rules for AI systems and general-purpose AI models placed on the EU market or used in the EU. It bans a few practices, imposes detailed requirements on high-risk systems, adds transparency duties for chatbots and synthetic content, and regulates general-purpose models.
When do the EU AI Act requirements apply?
In phases under Article 113: prohibitions and AI literacy from 2 February 2025, general-purpose AI and governance rules from 2 August 2025, general application from 2 August 2026, and Annex I product-embedded high-risk AI from 2 August 2027. The 2025 Digital Omnibus proposal may change some high-risk dates; check the official sources.
Who does the EU AI Act apply to?
Providers, deployers, importers, distributors and authorised representatives of AI systems, product manufacturers, and providers of general-purpose AI models, including organisations outside the EU whose systems or outputs are used in the EU.
What are the penalties under the EU AI Act?
Up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 % for most other infringements, and up to EUR 7.5 million or 1 % for incorrect information, with lower caps for SMEs (Article 99).

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.