EU AI Act: requirements, deadlines and compliance actions
Regulation (EU) 2024/1689 — Artificial Intelligence Act
What is the EU AI Act?
The EU AI Act is a binding regulation that sets rules for developing, placing on the market and using AI systems in the European Union. It bans a small set of practices considered unacceptable, imposes detailed requirements on "high-risk" AI systems used in areas such as employment, education, credit, essential services, law enforcement and safety-critical products, requires transparency for chatbots and synthetic content, and creates separate duties for providers of general-purpose AI models. Obligations apply in phases between 2025 and 2027.
Status note: Dates below follow Article 113 of the adopted text. The European Commission proposed a "Digital Omnibus" package in November 2025 that would adjust the application dates for some high-risk obligations; a reviewer must confirm whether that proposal has been adopted and update the deadlines accordingly.
Who does it apply to?
Applies to providers placing AI systems or general-purpose AI models on the EU market or putting them into service, to deployers established in the EU, and to providers and deployers in third countries where the system's output is used in the EU (Article 2). Excludes AI used exclusively for military, defence or national-security purposes, and activities of purely personal non-professional use. Free and open-source models get partial relief unless they are general-purpose models with systemic risk.
Providers (developers), deployers (organisations using AI under their authority), importers, distributors, authorised representatives of non-EU providers, product manufacturers integrating AI, and providers of general-purpose AI models. Public authorities are covered as deployers and have extra duties for fundamental-rights impact assessments.
- Actors
- Provider / developerDeployer / user organisationImporterDistributorAuthorised representativePublic authority / government bodyGeneral-purpose AI model provider
- Sectors
- Cross-sector / all sectorsEmployment and HRFinancial services and creditHealthcare and life sciencesEducation and trainingPublic services and governmentLaw enforcement and justiceCritical infrastructure and utilitiesMigration, asylum and border control
- AI use cases
- AI in hiring and employmentBiometrics and facial recognitionAI in healthcareAI in finance, credit and insuranceAI in educationAI in public servicesAI in law enforcementGenerative AI and foundation modelsCustomer service and chatbotsSafety-critical and infrastructure
When do the requirements apply?
Entry into force 1 August 2024. Prohibitions and AI literacy from 2 February 2025. General-purpose AI model duties, governance and penalties from 2 August 2025. General application, including Annex III high-risk systems and Article 50 transparency, from 2 August 2026. High-risk AI that is a safety component of Annex I products from 2 August 2027. Adjustments proposed in the 2025 Digital Omnibus are not reflected until verified.
| Date | Milestone | Source reference | Status |
|---|---|---|---|
| Entry into force Twentieth day after publication in the Official Journal. |
Article 113 | Passed | |
| Prohibited practices and AI literacy apply (Chapters I and II) Article 5 bans and Article 4 literacy duties apply. |
Article 113(a) | Passed | |
| General-purpose AI, governance, notified bodies and penalties apply Chapter V (GPAI models), Chapter III Section 4, Chapter VII, Chapter XII (except Article 101) and Article 78 apply. |
Article 113(b) | Passed | |
| General application, including Annex III high-risk systems and Article 50 transparency Default application date for the remainder of the Regulation, as set in the adopted text. Subject to any adopted amendment from the 2025 Digital Omnibus proposal, which a reviewer must confirm. |
Article 113 | Scheduled confidence: medium |
|
| High-risk AI as safety components of Annex I products Article 6(1) obligations for AI in products covered by Annex I harmonisation legislation. |
Article 113(c) | Scheduled | |
| General-purpose models placed on the market before 2 August 2025 must comply Transitional period for models already on the market. |
Article 111(3) | Scheduled confidence: medium |
|
| Large-scale IT systems listed in Annex X placed on the market before 2 August 2027 Transitional period for certain EU large-scale IT systems in the area of freedom, security and justice. |
Article 111(1) | Scheduled confidence: medium |
"applies_from" shows the general application date in Article 113. Earlier and later dates apply to specific chapters; see the deadlines table.
What must organisations do?
Inventory AI systems and determine your role for each; screen against prohibited practices now; classify systems against Annex I and Annex III; for high-risk systems build a risk-management system, data-governance controls, technical documentation, logging, human-oversight measures and a quality-management system, then complete conformity assessment and register in the EU database before placing on the market; deployers must use systems as instructed, assign trained human oversight, keep logs and, where required, complete a fundamental-rights impact assessment; label AI interactions and synthetic content under Article 50; general-purpose model providers must publish training-content summaries, maintain documentation and a copyright policy.
Legal requirement Do not deploy or provide AI for prohibited practices Article 5
Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.
Practical action: Add a prohibited-practice screen to your AI intake or design-review process and document the outcome for every system already in use.
Evidence examples: Prohibited-practice screening record; AI system inventory
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.2 and Annex A control on AI system impact assessment; NIST AI RMF 1.0 GOVERN 1.1, MAP 1.1
Obligation pageApplies from 2 Feb 2025 Source-linked
Legal requirement Ensure AI literacy of staff operating AI systems Article 4
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.
Practical action: Run role-based AI training and keep attendance and content records; the Commission's AI Office has indicated that literacy will be assessed proportionately.
Evidence examples: AI literacy training programme
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 7.2 Competence and 7.3 Awareness; NIST AI RMF 1.0 GOVERN 2.2
Obligation pageApplies from 2 Feb 2025 Source-linked
Legal requirement Establish a risk management system for high-risk AI Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Practical action: Set up a lifecycle risk register per high-risk system with test evidence and residual-risk acceptance.
Evidence examples: Risk register and treatment plan; Pre-market test reports
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk; NIST AI RMF 1.0 MAP, MEASURE and MANAGE functions
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Apply data governance and quality criteria to training, validation and testing data Article 10
High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.
Practical action: Produce a data-provenance and bias-assessment record for each data set used to build the system.
Evidence examples: Dataset documentation (datasheet); Bias examination report
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on data for AI systems; NIST AI RMF 1.0 MAP 2.3, MEASURE 2.1, MEASURE 2.11
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Draw up technical documentation before placing a high-risk system on the market Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Practical action: Maintain an Annex IV-structured technical file under version control.
Evidence examples: Annex IV technical file
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 7.5 Documented information; Annex A control on system documentation; NIST AI RMF 1.0 GOVERN 1.4, MAP 3.x
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Design high-risk systems to log events automatically Article 12; Article 26(6) for deployers
High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.
Practical action: Define the log schema, retention and access controls, and confirm deployer retention meets the minimum.
Evidence examples: Logging specification and retention policy
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A control on event logging; NIST AI RMF 1.0 MEASURE 2.x, MANAGE 4.1
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Provide deployers with clear instructions for use Article 13
High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.
Practical action: Ship an Article 13-structured instructions-for-use document with every high-risk system release.
Evidence examples: Instructions for use
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on information for interested parties; NIST AI RMF 1.0 GOVERN 4.x, MAP 1.x
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Enable and assign effective human oversight Article 14; Article 26(2) for deployers
High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.
Practical action: Document oversight roles, the "stop" mechanism and override paths for each high-risk deployment.
Evidence examples: Human oversight procedure and role assignment
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A control on human oversight; NIST AI RMF 1.0 GOVERN 3.2, MANAGE 2.x
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Achieve appropriate accuracy, robustness and cybersecurity Article 15
High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.
Practical action: Include AI-specific threat modelling and adversarial testing in your security programme.
Evidence examples: Accuracy metrics and test evidence; AI security assessment
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on AI system verification and validation; ISO/IEC 27001:2022 Clause 8 and Annex A security controls; NIST AI RMF 1.0 MEASURE 2.5, 2.6, 2.7
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Operate a quality management system Article 17
Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.
Practical action: Extend an existing ISO 9001 or ISO/IEC 42001 management system to cover the Article 17 elements.
Evidence examples: QMS manual and procedures
Framework mapping (original, editorial): ISO/IEC 42001:2023 Whole management system (Clauses 4–10); NIST AI RMF 1.0 GOVERN function
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Complete conformity assessment, CE marking and EU database registration Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Practical action: Determine the assessment route early; notified-body capacity may be limited around application dates.
Evidence examples: EU declaration of conformity; EU database registration record
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 9 Performance evaluation; internal audit
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Use high-risk AI as instructed, monitor it and inform affected people Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Practical action: Create a deployer checklist per high-risk system and a notice for affected individuals and workers.
Evidence examples: Deployment checklist and oversight assignment; Worker and affected-person notices
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on responsible use of AI systems; NIST AI RMF 1.0 MANAGE 3.x, GOVERN 5.x
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Carry out a fundamental rights impact assessment before deployment Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Practical action: Reuse GDPR DPIA workflows and extend them with the Article 27 elements; the AI Office is to provide a template.
Evidence examples: Fundamental rights impact assessment report
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment; NIST AI RMF 1.0 MAP 5.1, MAP 5.2
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Disclose AI interaction and label synthetic content Article 50
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
Practical action: Implement provenance marking (for example content credentials) and user-facing AI disclosures in product UX.
Evidence examples: Disclosure and watermarking design record
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A control on communication with interested parties; NIST AI RMF 1.0 GOVERN 4.x; NIST AI 600-1 content provenance suggestions
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Meet general-purpose AI model provider obligations Article 53 and Annexes XI–XII
Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.
Practical action: Prepare the Commission's training-content summary template and a documented copyright policy before release.
Evidence examples: Public summary of training content; Copyright compliance policy
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on data provenance and documentation; NIST AI RMF 1.0 NIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risks
Obligation pageApplies from 2 Aug 2025 Source-linked
Legal requirement Manage systemic risk for high-impact general-purpose models Articles 51, 52 and 55
A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.
Practical action: Track training compute against the threshold and prepare a safety and security framework before launch.
Evidence examples: Model evaluation and red-teaming reports; Commission notification record
Framework mapping (original, editorial): NIST AI RMF 1.0 MEASURE 2.x; NIST AI 600-1
Obligation pageApplies from 2 Aug 2025 Source-linked
Legal requirement Operate a post-market monitoring system Article 72
Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.
Practical action: Define performance and drift indicators, feedback channels and review cadence in a monitoring plan.
Evidence examples: Post-market monitoring plan and periodic reports
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 9.1 Monitoring, measurement, analysis and evaluation; NIST AI RMF 1.0 MANAGE 4.1, MEASURE 3.x
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Report serious incidents to market surveillance authorities Article 73
Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.
Practical action: Add AI serious-incident criteria and time limits to your existing incident-response playbook.
Evidence examples: AI incident response procedure; Incident log and authority notifications
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 10 Improvement; Annex A control on incident handling; NIST AI RMF 1.0 MANAGE 4.3
Obligation pageApplies from 2 Aug 2026 Source-linked
Legal requirement Verify conformity before importing or distributing high-risk AI Articles 23 and 24
Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.
Practical action: Build AI Act checks into supplier onboarding and contract clauses.
Evidence examples: Supplier due-diligence checklist
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on third parties and suppliers; NIST AI RMF 1.0 GOVERN 6.1, GOVERN 6.2
Obligation pageApplies from 2 Aug 2026 Source-linked
Penalties
Article 99 sets administrative fines of up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 % for most other obligations, and up to EUR 7.5 million or 1 % for supplying incorrect information, with the lower amount applying to SMEs. Article 101 allows the Commission to fine general-purpose AI model providers up to EUR 15 million or 3 %.
Key sections and articles
| Reference | Title | Summary |
|---|---|---|
| Article 2 | Scope | Who and what the Regulation covers, including extraterritorial reach and exclusions. |
| Article 3 | Definitions | Defines AI system, provider, deployer, general-purpose AI model and other key terms. |
| Article 4 | AI literacy | Providers and deployers must ensure sufficient AI literacy of staff and others operating AI on their behalf. |
| Article 5 | Prohibited AI practices | Bans manipulative and exploitative techniques, certain social scoring, some predictive policing, untargeted facial-image scraping, emotion recognition in workplaces and schools (with exceptions), certain biometric categorisation, and real-time remote biometric identification in public spaces for law enforcement subject to narrow exceptions. |
| Article 6 | Classification rules for high-risk AI systems | High-risk if a safety component or product under Annex I legislation requiring third-party assessment, or listed in Annex III, subject to the Article 6(3) derogation. |
| Articles 8–15 | Requirements for high-risk AI systems | Risk management, data governance, technical documentation, record keeping, transparency, human oversight, accuracy, robustness and cybersecurity. |
| Articles 16–27 | Obligations of operators of high-risk AI | Duties of providers, authorised representatives, importers, distributors and deployers, including the fundamental-rights impact assessment in Article 27. |
| Article 50 | Transparency obligations for certain AI systems | Disclosure for AI interaction, marking of synthetic content, deepfake labelling and emotion-recognition or biometric-categorisation notices. |
| Articles 51–56 | General-purpose AI models | Classification of systemic-risk models, provider obligations, and codes of practice. |
| Article 72 | Post-market monitoring | Providers must operate a post-market monitoring system proportionate to the AI technology and risks. |
| Article 73 | Reporting of serious incidents | Providers of high-risk AI must report serious incidents to market-surveillance authorities within set time limits. |
| Article 99 | Penalties | Administrative fine ceilings by category of infringement. |
| Article 113 | Entry into force and application | Phased application dates. |
Public-sector rules and enforcement
- Public-authority deployers must register high-risk AI use and assess fundamental-rights impact — Public bodies deploying Annex III high-risk systems must register their use in the EU database (Article 49(4)) and complete a fundamental-rights impact assessment before deployment (Article 27). The Commission has also published model contractual clauses for public procurement of AI (non-binding). (applies to: Public authorities and bodies governed by public law in the EU)
Official sources
-
Regulation (EU) 2024/1689 (Artificial Intelligence Act) — consolidated ELI page
Publications Office of the European Union · 12 Jul 2024 · Tier 1 source
-
AI Act policy page and implementation timeline
European Commission, DG CONNECT · Tier 1 source
-
General-Purpose AI Code of Practice
European Commission, AI Office · 10 Jul 2025 · Tier 2 source
-
Commission Guidelines on prohibited AI practices
European Commission · 4 Feb 2025 · Tier 2 source
Change history
- — European Commission proposes Digital Omnibus adjustments to AI Act timelines
- — EU AI Act general-purpose AI, governance and penalty provisions start to apply
- — European Commission publishes the General-Purpose AI Code of Practice
- — EU AI Act prohibited practices and AI-literacy duties start to apply
- — EU AI Act published in the Official Journal
- 12 Jul 2024 — Adopted text (OJ L, 12 July 2024) (source)
- 21 Apr 2021 — Commission proposal COM(2021) 206 (source)
Record version 1: Initial structured record from the adopted text; Digital Omnibus adjustments not yet reflected.. Full edit history is in the GitHub repository.
Frequently asked questions
- What is the EU AI Act?
- Regulation (EU) 2024/1689 is a binding EU law that sets risk-based rules for AI systems and general-purpose AI models placed on the EU market or used in the EU. It bans a few practices, imposes detailed requirements on high-risk systems, adds transparency duties for chatbots and synthetic content, and regulates general-purpose models.
- When do the EU AI Act requirements apply?
- In phases under Article 113: prohibitions and AI literacy from 2 February 2025, general-purpose AI and governance rules from 2 August 2025, general application from 2 August 2026, and Annex I product-embedded high-risk AI from 2 August 2027. The 2025 Digital Omnibus proposal may change some high-risk dates; check the official sources.
- Who does the EU AI Act apply to?
- Providers, deployers, importers, distributors and authorised representatives of AI systems, product manufacturers, and providers of general-purpose AI models, including organisations outside the EU whose systems or outputs are used in the EU.
- What are the penalties under the EU AI Act?
- Up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 % for most other infringements, and up to EUR 7.5 million or 1 % for incorrect information, with lower caps for SMEs (Article 99).
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.