Skip to main content

Artificial Intelligence Act (AI Act)

In force AI Regulation Adopted: 13 June 2024 · Applies from: 2 August 2026

AI-assisted content notice: this page includes AI-assisted summaries, FAQs, and glossary entries prepared for navigation purposes. Verify the underlying legal text before relying on this content.

Current position & sources

Sources checked:

The AI Act is in force and its general application date has passed. This page incorporates Regulation (EU) 2026/1744: high-risk requirements remain phased through 2027–2028, and specified new prohibitions and synthetic-content transition duties apply on 2 December 2026.

Summary

The AI Act regulates AI systems and general-purpose AI models through prohibitions, transparency duties and risk-based requirements. The 2026 Digital Omnibus on AI amended its implementation rules, including later application dates for the main high-risk requirements.

Who is affected?

Providers, professional deployers, importers, distributors and authorised representatives are covered according to their role, including certain operators outside the EU where the Act’s territorial conditions are met.

Scope

AI systems and general-purpose AI models within Article 2, with exclusions including exclusively military, defence or national-security uses and specified research activities; research is not a blanket exemption from all deployment rules.

Key Points

  • Prohibited practices, general-purpose AI models and transparency requirements have separate application schedules.
  • The main Chapter III Sections 1–3 high-risk rules apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, subject to the amended provisions.
  • High-risk requirements cover risk management, data governance, documentation, human oversight, accuracy, robustness and cybersecurity.
  • GPAI providers face documentation, copyright-policy and training-content transparency duties, with additional obligations for systemic-risk models and specific exceptions.
  • Amended Article 4 requires providers and deployers to take measures supporting staff AI literacy; it does not simply remove their role.
  • The new prohibitions concerning specified non-consensual intimate material and child sexual abuse material apply from 2 December 2026, under their defined scope and safeguards.

Key Deadlines

  • — Original regulation entered into force
  • — Original Chapters I and II began to apply
  • — GPAI and specified governance rules began to apply
  • — Digital Omnibus on AI amendment entered into force
  • — General application date, including Article 50 subject to transition rules
  • — New intimate-material/CSAM prohibitions; Article 50(2) compliance for relevant systems marketed before 2 August 2026
  • — Compliance deadline for GPAI models marketed before 2 August 2025
  • — Main Chapter III Sections 1–3 requirements for Annex III high-risk systems
  • — Main Chapter III Sections 1–3 requirements for Annex I high-risk systems

Related Regulations

Frequently Asked Questions

Did the high-risk timetable change?

Yes. Regulation (EU) 2026/1744 deferred the main Chapter III Sections 1–3 requirements to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Other provisions have their own dates.

Does In force mean every obligation already applies?

No. The original Act entered into force on 1 August 2024, but its obligations apply in stages.

Are AI literacy duties abolished?

No. Amended Article 4 requires providers and deployers to take measures supporting the development of staff AI literacy, with support from the Commission and Member States.

When do synthetic-content transparency duties apply?

Article 50 generally applies from 2 August 2026. Providers of relevant systems marketed before that date have until 2 December 2026 to comply with Article 50(2).

Do older GPAI models have a transition period?

Providers of GPAI models placed on the market before 2 August 2025 must comply by 2 August 2027 under Article 111(3).

Does the Act replace the GDPR?

No. AI Act compliance does not remove applicable personal-data protection duties.

Key Terms

Provider
An entity developing, or having developed, an AI system or GPAI model and placing it on the market or putting the system into service under its name or trademark.
Deployer
An entity using an AI system under its authority, except in a personal non-professional activity.
Annex III high-risk system
An AI system classified under Article 6(2), with the qualifications in Article 6, for a listed use such as employment or access to essential services.
Annex I high-risk system
An AI system classified under Article 6(1) through its relationship to listed product-safety legislation and third-party conformity assessment.
General-purpose AI model
A model with significant generality capable of competently performing a wide range of distinct tasks and integration into downstream systems.
AI literacy
Skills, knowledge and understanding enabling informed use of AI and awareness of its opportunities, risks and potential harm.