European Regulation

EU AI Act · Artificial Intelligence

The world's first comprehensive artificial intelligence regulation. Risk classification, obligations and penalties for AI developers and users. Updated following the AI Digital Omnibus (July 2026).

Entry into force: August 1, 2024 Applies to: Developers, distributors and users of AI in the EU Fines: up to €35M or 7% of global turnover

What is the AI Act?

The EU AI Act is the world's first comprehensive artificial intelligence regulation. It establishes a legal framework for the development, marketing and use of AI systems in the European Union.

The AI Act's approach is based on risk classification: the higher the risk of the AI system, the stricter the obligations.

Key change: The AI Act establishes differentiated obligations depending on the type of system and the organization's role, including, where applicable, risk management, documentation, human oversight, registration and specific assessments.

Risk classification

In simplified terms, the AI Act's framework can be understood through different risk levels and categories:

  • Unacceptable risk: Prohibited. Includes AI systems that manipulate human behavior, exploit vulnerabilities or use social scoring systems.
  • High risk: Strict obligations. Includes AI in critical infrastructure, education, employment, access to essential services, immigration and administration of justice.
  • Limited risk: Transparency obligations. Includes chatbots and content generation systems. Emotion recognition is prohibited in the workplace and educational settings (art. 5.1.f); outside those contexts, it is subject to transparency obligations (art. 50).
  • Other AI systems: not subject, by that fact alone, to the specific obligations of high-risk systems, without prejudice to other obligations that may apply depending on the system, the organization's role and the context of use. Includes most current AI applications.

Obligations for high-risk systems

High-risk AI systems must comply with:

  • Risk management system: Continuous process of identifying and mitigating risks.
  • Training data: Relevant, representative and, as far as possible, complete and error-free data (art. 10).
  • Technical documentation: Detailed record of the system and its operation.
  • Human oversight: Human supervision and control mechanisms.
  • Security and accuracy: Adequate levels of security, accuracy and robustness.
  • Event logging: Automatic logging of events during operation.

Key deadlines

  • August 1, 2024: AI Act entry into force.
  • February 2, 2025: Application of article 4 (AI literacy). ⚠️ Already enforceable.
  • August 2, 2025: Application of obligations for general-purpose AI systems (GPAI).
  • July 27, 2026: The AI Digital Omnibus enters into force, postponing the high-risk timelines.
  • August 2, 2026: Application of general transparency obligations (art. 50).
  • December 2, 2026: Application of the new prohibition on certain systems generating non-consensual sexually explicit or intimate content or child sexual abuse material, and the end of the transitional period for the marking and detection obligations of article 50.2 for certain systems placed on the market before August 2, 2026.
  • December 2, 2027: Application for Annex III high-risk AI systems (critical infrastructure, education, employment, etc.) — postponed from August 2026.
  • August 2, 2028: Application for Annex I high-risk AI systems (regulated products) — postponed from August 2027.
⚠️ Updated: the AI Digital Omnibus (in force since July 27, 2026) postponed the application of Annex III high-risk obligations to December 2027 and Annex I to August 2028. The obligations on prohibited practices, AI literacy and GPAI remain in effect from their original dates.

Consequences of non-compliance

Infringement Maximum fine
Prohibited practices (art. 5) €35M or 7% of global turnover
Other infringements (art. 99.4) €15M or 3% of global turnover
Incorrect or misleading information €7.5M or 1% of global turnover

How can I help you with the AI Act?

AI Act Gap Analysis

We analyze your AI systems, classify them by risk and design a compliance roadmap based on the organization's role, the system's classification and applicable obligations.

View service →

ISO 42001 · AI Governance

We implement an AI Management System aligned with the AI Act and ISO 42001.

View service →

Impact Assessment

We carry out the impact assessments that are required or appropriate depending on the system, the organization's role and the context of use.

View service →

Do you need to prepare your company for the AI Act?

Request an assessment meeting →

20–30 minutes · No commitment · We review context, need and next steps.