What is the EU AI Act?
The EU AI Act, or Artificial Intelligence Act, is the European Union's regulation, formally Regulation (EU) 2024/1689, that governs how AI systems are developed, placed on the market, and used within the EU.
It takes a risk-based approach. The obligations placed on an AI system scale with the level of risk that system poses to health, safety, and fundamental rights. Systems that create the highest risk face the strictest rules, while low-risk systems face few or none.
The EU AI Act is widely described as the world's first comprehensive AI law. It entered into force on 1 August 2024 and applies in stages rather than all at once.
What is the main goal of the EU AI Act?
The main goal of the EU AI Act is to make AI used in the EU safe, transparent, traceable, and subject to human oversight, while protecting people's health, safety, and fundamental rights.
The regulation sets out to reduce the harms that poorly governed AI can cause, from discriminatory decisions to manipulation, without blocking the benefits the technology brings.
A second goal sits alongside the first: supporting innovation and a functioning single market. By giving companies one clear rulebook across all member states, the EU AI Act aims to replace a patchwork of national rules with predictable, EU-wide requirements.
Many of these objectives echo long-standing AI ethics principles, now written into binding law.
Who does the EU AI Act apply to?
The EU AI Act applies to a range of roles across the AI value chain, not just the companies that build AI.
The regulation defines obligations for providers (organizations that develop an AI system or general-purpose AI systems and models, and place it on the market), deployers (organizations that use an AI system in a professional capacity) – a role that shapes how you handle AI deployment across your teams – importers, distributors, and product manufacturers who put AI-enabled products on the EU market.
The role you play determines your obligations, and a single organization can hold more than one role. A company that buys a high-risk AI tool and uses it internally is a deployer; a company that builds one and sells it is a provider.
The two points below cover the questions readers ask most: whether non-EU companies are caught, and what falls outside the rules entirely.
Does the EU AI Act apply to US companies?
Yes, the EU AI Act applies to US companies in many common situations.
The regulation reaches beyond EU-based organizations to any provider or deployer whose AI system's output is used in the EU, regardless of where that company is headquartered. A US firm that offers an AI product to EU customers, or whose AI-generated results reach people in the EU, generally falls within scope.
This extraterritorial reach mirrors the approach EU regulators took with data protection, so teams familiar with cross-border privacy rules will recognize the pattern. Location of the company is not the deciding factor; where the AI output lands is.
Exemptions and out-of-scope uses
Several uses fall outside the EU AI Act.
The regulation does not apply to AI systems used exclusively for military, defense, or national security purposes, nor to AI used purely for scientific research and development before a system is placed on the market.
Personal, non-professional use by individuals is also out of scope, and free and open-source AI components carry lighter obligations except where they qualify as high-risk or fall under general-purpose AI rules.
These carve-outs narrow the field but do not shrink it much for most businesses. If you use AI in a commercial or professional context and it touches people in the EU, assume the regulation is relevant until you confirm otherwise.
The four risk tiers of the EU AI Act
The EU AI Act sorts AI systems into four risk tiers, and this framework is the part most people come to understand.
Each tier carries a different level of obligation, from an outright ban at the top to almost no rules at the bottom. The tiers below run from highest risk to lowest.
Unacceptable risk (banned practices)
Unacceptable-risk practices are AI uses the EU AI Act prohibits outright because they pose a clear threat to people's rights and safety. These bans on prohibited AI practices have applied since 2 February 2025.
Prohibited practices include social scoring by public authorities, manipulative techniques that exploit vulnerabilities, untargeted scraping of facial images to build recognition databases, and certain uses of real-time remote biometric identification in public spaces.
A 2026 amendment added a new prohibition to this tier: AI systems that generate non-consensual intimate imagery or child sexual abuse material. Providers of general-purpose image and video tools must assess foreseeable misuse at the design stage, with a transitional period running until 2 December 2026.
High risk (strictly regulated)
High-risk AI systems are permitted but face the strictest set of requirements under the EU AI Act.
This tier covers AI used in sensitive areas such as recruitment and CV-ranking, credit scoring, education, law enforcement purposes, border control, and critical infrastructure, plus AI embedded as a safety component in regulated products like medical devices, machinery, and vehicles.
Providers of certain generative AI systems must meet obligations that include risk management, data governance, technical documentation, logging, human oversight, accuracy, and cybersecurity. Deployers carry duties too, such as using the system according to instructions and maintaining human oversight.
The application dates for this tier were pushed back by the 2026 amendments, covered in the timeline section below.
Limited risk (transparency obligations)
Limited-risk AI systems face transparency obligations rather than the heavy requirements placed on high-risk systems.
The EU AI Act requires that people know when they are dealing with AI. Chatbots must act as trustworthy AI, and disclose that users are interacting with a machine, and AI-generated or manipulated content such as deepfakes must be labeled as artificial.
These transparency rules under Article 50 apply from 2 August 2026. AI systems generating synthetic content that were already on the market before that date get a short grace period, until 2 December 2026, to meet the machine-readable watermarking requirement.
Minimal risk
Minimal-risk AI systems are largely unregulated under the EU AI Act.
This tier covers the vast majority of AI in everyday use, including spam filters, AI in video games, and inventory management tools. These systems carry no specific obligations under the AI regulation, though providers are encouraged to follow voluntary codes of conduct.
Most AI a typical business uses will land here. The practical task is confirming that classification rather than assuming it, since the same underlying technology can move into a higher tier depending on how it is used.
General-purpose AI (GPAI) rules
General-purpose AI models are AI models trained on broad data that can perform a wide range of tasks, such as the large language models behind popular chatbots.
The EU AI Act sets a separate set of rules for GPAI providers, and these obligations have applied since 2 August 2025.
GPAI providers must maintain technical documentation, publish a summary of the training data, and put a copyright compliance policy in place.
Models judged to carry systemic risk (broadly, the most capable models) face additional duties, including model evaluations, adversarial testing, incident reporting, and cybersecurity protections. The European AI Office oversees GPAI models directly, and the 2026 amendments gave it a clearer competence scope and stronger enforcement tools.
EU AI Act deadlines and implementation timeline
The EU AI Act applies in phases, and the 2026 Digital Omnibus on AI amendments moved several high-risk dates later. Anyone tracking EU AI Act implementation news today needs the current schedule, not the original one.
The table below reflects the timeline as published by the EU AI Act Service Desk, which already incorporates the Omnibus changes. Verify each date against the official EU source before relying on it, since this area continues to move.
Date | What applies |
|---|---|
1 Aug 2024 | EU AI Act enters into force |
2 Feb 2025 | General provisions, AI literacy obligations, and prohibitions on unacceptable-risk practices apply |
2 Aug 2025 | GPAI model rules apply; EU-level governance (AI Office, AI Board, Scientific Panel) operational; national penalties in place |
2 Aug 2026 | Article 50 transparency rules apply; enforcement begins for GPAI, prohibitions, transparency, and AI literacy |
2 Dec 2026 | New prohibition on non-consensual intimate imagery and CSAM takes full effect; watermarking grace period ends for existing synthetic-content systems |
2 Aug 2027 | Member states must have at least one AI regulatory sandbox operational |
2 Dec 2027 | High-risk rules for standalone Annex III systems apply |
2 Aug 2028 | High-risk rules for AI embedded in Annex I regulated products apply |
The headline change from the Omnibus is the deferral of high-risk obligations. Standalone high-risk systems and AI providers (Annex III) now apply from 2 December 2027 instead of the original 2 August 2026, and AI embedded in regulated products (Annex I) applies from 2 August 2028.
The 2 August 2026 date stays live, though, because the Article 50 transparency obligations largely proceed on the original schedule. Because guidance continues to evolve, check EU AI Act news updates and official EU AI Act guidance news before acting on any single date.
EU AI Act fines and enforcement
The EU AI Act uses a tiered penalty structure, with the size of the maximum fine matching the severity of the violation.
EU AI Act enforcement began in August 2025 for general-purpose AI obligations, and it widens from 2 August 2026 to cover prohibitions, transparency, and AI literacy. The figures below are set as the higher of a fixed amount or a percentage of global annual turnover.
Type of violation | Maximum fine |
|---|---|
Prohibited (unacceptable-risk) practices | Up to €35M or 7% of global annual turnover |
Most other violations (including high-risk non-compliance) | Up to €15M or 3% of global annual turnover |
Supplying incorrect or misleading information to authorities | Up to €7.5M or 1% of global annual turnover |
A carve-out applies to SMEs and startups: for them, the lower of the two amounts (the fixed sum or the percentage) applies, rather than the higher.
Enforcement is shared between the EU AI Office, which supervises general-purpose AI models and certain other systems, and national competent authorities in each member state, which handle most other cases. The Omnibus amendments strengthened the AI Office's powers, adding the ability to run investigations, conduct on-site inspections, accept binding commitments, and impose fines.
EU AI Act vs GDPR
The EU AI Act and GDPR are separate regulations that can both apply to the same system, so it helps to see how they differ.
GDPR governs personal data; the EU AI Act governs AI systems and the risk they pose. Where GDPR takes a rights-based approach centered on how personal data is collected and used, the EU AI Act takes a risk-based, tiered approach centered on what an AI system does and how much harm it could cause.
GDPR | EU AI Act | |
|---|---|---|
Focus | Personal data protection | AI systems and their risk |
Approach | Rights-based | Risk-based (tiered) |
Applies extraterritorially | Yes | Yes |
Max fines | Up to €20M or 4% turnover | Up to €35M or 7% turnover |
Both apply beyond EU borders, which means a global company can owe duties under each at the same time.
If you already run a GDPR program, that governance foundation will help, but the EU AI Act adds obligations GDPR does not cover, so the two need to be handled together, not as one. For a closer look at where the two overlap, see our article on GDPR and AI.
How organizations can prepare for the EU AI Act
Preparing for the EU AI Act works best as a structured, role-aware process rather than a scramble before a deadline.
The extra time the 2026 amendments gave to high-risk systems is real headroom, but a compliance framework takes months to build properly, so starting now is the sensible move.
The four steps below give a practical starting point. This is general guidance, not legal advice.
Build an inventory of the AI systems you use
Start by building a complete inventory of every AI system your organization uses, buys, or builds.
Many teams underestimate how much AI is already running across departments, including tools brought in without formal approval, often called shadow AI. You cannot classify or govern what you cannot see, so a full inventory comes first. Uncontrolled AI use can make transparency and oversight harder, and issues such as shadow AI start to appear.
Classify each system by risk tier
Once you have the inventory, classify each system against the four risk tiers.
Work out which systems are prohibited, which count as high-risk, which carry transparency obligations, and which are minimal-risk. This classification drives everything that follows, since a system's tier determines the obligations you owe and the deadline you work toward.
Put oversight, logging, and transparency controls in place
For systems that need them, put human oversight, logging, and transparency controls in place.
High-risk systems require records of activity, meaningful human review of decisions, and clear documentation. Transparency obligations mean users must be told when they are interacting with AI or viewing AI-generated content. Setting these controls up early makes later audits far smoother.
Coordinating these controls across many models is where AI orchestration helps, keeping oversight consistent instead of tool-by-tool.
Meet AI literacy obligations
Meet your AI literacy obligations by making sure staff who work with AI understand it well enough to use it responsibly.
This duty has applied since 2 February 2025, and the 2026 amendments softened its wording so that providers and deployers must support the development of AI literacy among staff rather than guarantee a fixed level. A solid internal AI policy underpins this; our article on AI policy for companies maps directly to the risk tiers.
How nexos.ai supports EU AI Act readiness
nexos.ai gives you one place to see and control every AI model your people use, which is exactly where EU AI Act readiness starts.
You can't govern what you can't see, and scattered AI tools across a company make that visibility almost impossible to get. A unified, model-agnostic AI gateway closes that gap. It shows you which models your teams are actually using, so your inventory reflects reality instead of guesswork.
From there, you decide who can use what.
Apply access controls across leading models, set policies at the AI governance layer around what each model can do.
Centralized LLM observability records the activity you need for audit-readiness, so when a deadline arrives you already have the logs rather than having to reconstruct them.
None of this replaces legal counsel, and nexos.ai does not guarantee compliance. What it does is help you operationalize the governance work the EU AI Act asks for, and provide the visibility that makes every other step easier.