The EU AI Act is the European Union’s first comprehensive legal framework specifically for artificial intelligence. It has been in force since August 1, 2024 and uses a risk-based approach to regulate AI systems, general-purpose AI models and certain applications of artificial intelligence across the EU.
The law is already in force, but its obligations apply in stages. The timetable also changed in July 2026, when Regulation (EU) 2026/1744 – Digital Omnibus on AI amended parts of the implementation schedule, Article 4 on AI literacy and other provisions.
That means much of the information about the EU Artificial Intelligence Act published before July 2026 is now out of date.
If your organization uses AI, develops AI systems, integrates third-party models or makes AI-powered tools available to customers, understanding the AI Act is now part of normal technology governance and regulatory compliance.
What You’ll Take From This: EU AI Act 2026
The AI regulatory framework is already operating, but not every obligation started on the same date. The practical position in 2026 is:
- The AI Act regulates AI systems through a risk-based framework.
- The first prohibited AI practices and the Article 4 AI literacy obligation began to apply on February 2, 2025.
- Obligations for providers of general-purpose AI models began to apply on August 2, 2025.
- Much of the EU AI Act applies from August 2, 2026, including certain transparency requirements.
- The main rules for high-risk AI systems under Annex III apply from December 2, 2027.
- Certain high-risk systems embedded in regulated products under Annex I move to August 2, 2028.
- Article 4 still requires providers and deployers of AI systems to take AI literacy measures, but it no longer requires them to guarantee a specific level for every individual.
The European Commission maintains an official AI Act page with the current implementation timeline and guidance.
Not sure which parts of the AI Act may affect your organization? Start with the Founderz AI Act diagnostic, which helps identify the areas worth reviewing based on how your organization uses artificial intelligence.
Has the EU AI Act Passed?
Yes. The EU AI Act is already law. Regulation (EU) 2024/1689 entered into force on August 1, 2024.
What often causes confusion is the difference between a law entering into force and all of its provisions becoming applicable at the same time.
The AI Act uses a phased implementation schedule. Some rules have already applied since 2025, a much larger part applies from 2026, and major obligations for certain high-risk AI systems do not apply until 2027 or 2028.
The Digital Omnibus on AI changed parts of that timetable in July 2026, which is why older summaries may still show dates that are no longer correct.
What Is the EU AI Act?
The EU AI Act is the European Union regulation on artificial intelligence that establishes harmonized rules on artificial intelligence across EU Member States.
Because it is a regulation, it is directly applicable throughout the European Union.
The legislation covers the development, marketing, placing into service and use of certain AI systems and AI models within the EU.
Its objectives include:
- protecting health and safety;
- safeguarding fundamental rights;
- providing legal certainty;
- encouraging safe, human-centric and trustworthy AI;
- supporting AI innovation;
- creating harmonization of law across the EU market.
The Act does not try to regulate AI by prohibiting the technology itself.
Instead, the framework focuses mainly on what an AI system does, how it is used and the level of risk associated with that use.
AI technologies are already used in employment, education, health, critical infrastructure, transportation, justice, public services, data analysis, software and many other business processes.
The purpose of the regulation is to allow AI development and innovation while setting rules on AI that address safety, rights and trust.
Who Does the EU AI Act Apply To, Including Companies Outside the EU?
The AI Act applies to more than technology developers, and its scope can extend to companies outside Europe.
The main categories include:
- Providers of AI systems: organizations that develop, or have developed, an AI system and market it or put it into service under their own name or trademark.
- Deployers of AI systems: organizations that use an AI system under their authority as part of a professional activity.
- Importers and distributors: organizations that introduce or distribute certain AI systems in the EU market.
- Providers of general-purpose AI models: organizations responsible for certain GPAI models.
- Other operators defined by the regulation.
A company can therefore be affected even if it does not build its own AI model.
For example, an organization may be a deployer because its employees use AI systems in business processes, while a technology company may be a provider because it offers its own AI-powered product.
Does the EU AI Act apply to companies in the US or outside Europe?
Potentially, yes.
The AI Act has extraterritorial scope. Certain provisions can apply to organizations established outside the European Union when they place AI systems or models on the EU market or when the output of an AI system is used in the EU.
The starting point is therefore not simply where the company is registered.
Organizations should identify:
- which AI systems are used;
- who provides them;
- who uses them;
- where they are put into service;
- what the output is used for.
The same analysis can be relevant to a multinational company, a US software provider selling into Europe, or small and medium enterprises using third-party AI tools.
For the employee perspective, see AI Act for Employees: What You Need to Know if You Use AI at Work.
Scope of the AI Act: How the Act Classifies AI Systems by Risk
The AI Act classifies AI systems according to the risk created by the use case rather than simply by the technology or brand name.
A common way to understand the categories of AI is:
- prohibited or unacceptable-risk practices;
- high-risk AI systems;
- certain AI systems subject to transparency obligations;
- minimal or no-risk AI applications.
This matters because the same underlying technology can be treated differently depending on what it is being used to do.
Using generative AI to draft an internal summary does not create the same risk as using an AI system to screen employment candidates or make decisions affecting access to essential services.
Prohibited AI Practices Under the EU AI Act
The EU AI Act prohibits certain AI practices considered incompatible with fundamental rights, safety and European values.
Subject to the qualifications and exceptions in the regulation, prohibited AI practices include:
- manipulative or deceptive techniques capable of causing significant harm or influencing behavior in harmful ways;
- AI systems that exploit vulnerabilities of certain people;
- certain forms of social scoring;
- certain individual assessments of the risk that a person will commit a criminal offense;
- creating or expanding a facial recognition database through indiscriminate scraping;
- certain emotion-recognition systems in workplaces and education;
- certain biometric categorization designed to infer sensitive characteristics;
- real-time remote biometric identification for police or law-enforcement purposes in public spaces, except in narrowly defined circumstances.
These first prohibitions began to apply on February 2, 2025.
The Digital Omnibus on AI introduced an additional prohibition involving certain AI systems that generate non-consensual synthetic sexual or intimate content and child sexual abuse material. According to the revised timetable, that prohibition applies from December 2026.
Not every use involving biometrics, surveillance or a facial recognition system is automatically prohibited.
The exact purpose, context and exceptions in the regulation still need to be assessed.
High-Risk AI Systems: Rules, Obligations and Deadlines
High-risk AI systems are use cases that may create significant risks to health, safety or fundamental rights.
Annex III includes sensitive applications of artificial intelligence in areas such as:
- biometrics;
- critical infrastructure;
- education and vocational training;
- employment and worker management;
- access to certain private services and essential public services;
- law enforcement;
- migration, asylum and border control;
- administration of justice.
A recruitment system used to screen resumes, rank candidates or evaluate applicants may, for example, fall within the high-risk framework.
AI systems used in education or certain essential services may also fall within the category depending on their specific function.
The Act also covers certain high-risk AI systems embedded in products already governed by sector-specific legislation.
Rules for high-risk AI systems
Where the obligations apply, high-risk AI systems may need to meet requirements covering:
- risk management;
- data governance and data quality;
- technical documentation;
- logging and traceability;
- information for the deployer;
- human oversight;
- accuracy;
- robustness;
- cybersecurity and computer security.
Human oversight must be meaningful.
The person responsible needs to understand the AI system’s capabilities and limitations and be able to intervene where necessary.
These obligations on high-risk AI systems are intended to make risk management part of the design, deployment and use of AI rather than an afterthought.
When do the high-risk AI rules apply?
The timetable changed in 2026.
Following the Digital Omnibus on AI:
- December 2, 2027: main obligations for systems classified as high risk under Article 6(2) and Annex III.
- August 2, 2028: main obligations for certain systems classified under Article 6(1) and Annex I.
This means August 2026 is no longer the general deadline for the principal Annex III high-risk obligations.
The European Commission’s official AI Act page maintains the current implementation schedule.
Transparency Obligations for Certain AI Systems
From August 2026, certain AI systems are subject to specific transparency obligations under Article 50.
These rules are particularly relevant where people interact with an AI system or where AI systems generate or manipulate content.
Examples include:
- people interacting directly with certain AI systems may need to be told that they are interacting with AI when this is not otherwise obvious;
- certain AI systems that generate synthetic content must make that content identifiable;
- deepfakes are subject to specific disclosure requirements;
- some AI-generated or manipulated material used to inform the public about matters of public interest may require disclosure.
These transparency requirements are particularly important in media, public communications and political contexts.
They do not mean that every internal document partly drafted with generative AI must automatically be labeled as AI-generated.
The relevant rule depends on the type of system and the specific use case.
Minimal-Risk AI Applications and Other Applicable Rules
Most everyday use of AI is not classified under the most demanding parts of the AI Act.
Common examples of lower-risk applications may include:
- spam filtering;
- certain video-game functions;
- low-impact support tools.
However, low risk under the AI Act does not mean no law applies.
Depending on the use case, organizations may still need to consider:
- the General Data Protection Regulation (GDPR);
- intellectual property and copyright;
- confidentiality;
- contracts;
- cybersecurity;
- sector-specific legislation.
AI governance therefore needs to consider more than the AI Act alone.
Rules for General-Purpose AI Models and Generative AI
The EU AI Act creates a separate framework for general-purpose AI models, commonly referred to as GPAI models.
A general-purpose AI model can perform a wide range of tasks and may be used as the foundation for many downstream AI applications and generative AI systems.
Since August 2, 2025, providers of general-purpose AI models have had specific obligations.
The European Commission summarizes these on its page covering general-purpose AI obligations under the AI Act.
Obligations for general-purpose AI models can include:
- preparing technical documentation;
- providing specified information to downstream providers;
- maintaining a policy designed to comply with EU copyright law;
- publishing a sufficiently detailed summary of the content used to train the model.
General-purpose AI models with systemic risk
A general-purpose AI model classified as presenting systemic risk is subject to additional requirements.
These include areas such as:
- risk evaluation and mitigation;
- serious incident reporting;
- cybersecurity.
The EU also has a General-Purpose AI Code of Practice, designed as a voluntary mechanism to help providers work toward compliance.
Providers of general-purpose AI and downstream organizations therefore have different roles.
An organization using a product powered by a GPAI model does not automatically become the provider of that underlying AI model.
Does the EU AI Act Apply to ChatGPT and Similar AI Tools?
The AI Act can apply to the models and systems behind tools such as ChatGPT, while organizations using those tools may have separate obligations of their own.
ChatGPT itself is a product rather than a general-purpose AI model.
However, products of this kind may rely on general-purpose AI models that fall within the rules for general-purpose AI models.
At the same time, an organization whose employees use AI tools may have obligations as a deployer, including the Article 4 AI literacy requirement.
The correct analysis therefore depends on the role:
- model provider;
- AI system provider;
- deployer;
- downstream organization;
- end user.
The AI Office and Implementation of the AI Act
The European AI Office forms part of the European Commission and plays a central role in implementation of the AI Act.
Its responsibilities include:
- supporting consistent application of the AI Act;
- supervising and enforcing rules for general-purpose AI models;
- developing methodologies and tools;
- producing guidance;
- working with national authorities;
- supporting codes of practice;
- encouraging AI innovation across Europe.
The AI Office is not the only body involved in enforcement of the AI Act.
National market surveillance authorities also play an important role in supervising and enforcing obligations within each EU Member State.
The AI Office and national authorities therefore operate within a wider governance structure.
The AI Pact is different. It is a voluntary initiative designed to encourage preparedness, exchange good practices and support early adoption before obligations become applicable.
Article 4 of the AI Act: AI Literacy
Article 4 requires providers and deployers to take measures that support AI literacy among staff and other people using AI systems on their behalf.
The requirement has applied since February 2, 2025.
The original wording referred to ensuring a sufficient level of AI literacy among relevant people.
The July 2026 reform changed that point.
Organizations no longer need to guarantee that each individual achieves a particular or sufficient level of AI literacy.
Instead, they should take measures that reflect factors such as:
- technical knowledge;
- experience;
- education;
- previous training;
- context;
- AI systems used.
This means AI literacy is not simply about teaching employees how to use AI tools.
It also involves understanding capabilities, limitations, risk, safety, information handling and responsible AI use in the relevant professional context.
For a deeper explanation, see AI Literacy: What Article 4 of the AI Act Requires.
Implementation of the AI Act: Key Dates Through 2028
The application of the AI Act is phased, so organizations need to distinguish between the date the regulation entered into force and the dates individual obligations apply.
| Date | What Applies |
|---|---|
| August 1, 2024 | Regulation (EU) 2024/1689 enters into force. |
| February 2, 2025 | First prohibited AI practices and AI literacy obligations apply. |
| August 2, 2025 | Governance provisions and obligations for GPAI models apply. |
| July 27, 2026 | Digital Omnibus on AI enters into force. |
| August 2, 2026 | Much of the AI Act and certain transparency obligations apply, subject to exceptions. |
| December 2, 2026 | New prohibited practice introduced in 2026 and certain transitional provisions apply. |
| December 2, 2027 | Main high-risk obligations for Annex III systems apply. |
| August 2, 2028 | Main obligations for certain Annex I systems embedded in regulated products apply. |
For compliance planning, the relevant deadline depends on the organization’s role and the type of AI system involved.
What Are the Penalties for Non-Compliance With the EU AI Act?
The AI Act sets different maximum penalties depending on the type and seriousness of the infringement.
The principal thresholds described in the regulation include:
- Up to €35 million or 7% of annual worldwide turnover for certain particularly serious infringements, including prohibited practices.
- Up to €15 million or 3% for certain other obligations under the AI Act.
- Up to €7.5 million or 1% for specified incorrect, incomplete or misleading information provided to authorities.
Specific rules apply when penalties involve small and medium enterprises.
These figures should not be interpreted as an automatic fine for every breach.
In particular, failing to provide one specific AI literacy course does not automatically trigger a €35 million or 7% penalty.
For Article 4, enforcement measures must be considered proportionately according to factors such as the nature, severity and circumstances of the infringement.
How to Prepare for the EU AI Act and Improve AI Governance
Organizations can prepare for the AI Act by identifying their AI systems, understanding their regulatory role, classifying use cases and documenting the controls already in place.
A practical implementation process looks like this.
1. Create an inventory of AI systems
Identify the AI systems used across the organization.
Include:
- ChatGPT;
- Microsoft Copilot;
- internal assistants;
- automation tools;
- predictive systems;
- recruitment systems;
- generative AI;
- industry-specific applications.
Do not rely only on software purchased centrally. Teams may already use AI applications outside formal procurement processes.
2. Identify the organization’s role
Determine whether the organization is acting as:
- a provider;
- a deployer;
- an importer;
- a distributor;
- a provider of a general-purpose AI model;
- or a combination of these roles.
3. Document the use of AI systems
Do not classify technology based solely on its brand name.
Document:
- what the AI system does;
- who uses it;
- what data it receives;
- what output it generates;
- what decision or process it supports.
The scope of the AI Act depends heavily on the use cases of AI systems.
4. Review prohibited practices, high risk and transparency
Pay particular attention to AI use in areas such as:
- employment;
- education;
- health;
- credit;
- justice;
- biometrics;
- essential services;
- direct interaction with members of the public.
5. Build AI governance and AI literacy measures
Governance may include:
- employee training;
- internal policy;
- approved-tool lists;
- review procedures;
- data-handling rules;
- human oversight;
- documentation.
Article 4 means that AI literacy should form part of this process rather than being treated as a separate one-off exercise.
For the employee perspective, read AI Act for Employees: What You Need to Know if You Use AI at Work.
6. Keep evidence
Document relevant information such as:
- AI tools and systems;
- intended purpose;
- providers;
- classification;
- training;
- controls;
- responsibilities.
Evidence helps show how the organization approaches governance and risk over time.
7. Review the inventory regularly
AI use changes quickly.
New tools, features, integrations and use cases can alter the organization’s position under the regulation.
AI governance should therefore operate as an ongoing process rather than a one-time compliance exercise.
How Do You Know Which AI Act Obligations Apply to Your Company?
The obligations under the AI Act depend on the organization’s role, the AI system involved and the specific use case.
If you are still unsure what your organization should review, use the Founderz AI Act diagnostic.
It helps organize the main questions according to the way AI systems are used in the organization.
The diagnostic does not replace a legal assessment and does not automatically determine compliance.
Frequently Asked Questions About the EU AI Act
These answers cover the main questions about the status, scope and implementation of the EU AI Act in 2026.
What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689. It establishes harmonized rules for certain AI systems and general-purpose AI models using a risk-based framework.
Has the EU AI Act passed?
Yes. It entered into force on August 1, 2024. Different provisions apply on different dates between 2025 and 2028.
Does the EU AI Act apply outside the EU?
It can. Certain provisions apply to organizations outside the European Union when they place AI systems or models on the EU market or when system output is used within the EU.
Does the EU AI Act apply to every company?
It depends on the organization’s role and its use of AI. A company that does not develop AI may still have obligations as a deployer.
Does the EU AI Act apply to general-purpose AI models used in tools such as ChatGPT?
Yes, the AI Act contains specific rules for general-purpose AI models. Organizations using products built on these models may also have separate obligations as deployers.
When do the rules on high-risk AI systems apply?
The main Annex III obligations apply from December 2, 2027. Certain Annex I systems embedded in regulated products move to August 2, 2028.
What is the maximum AI Act fine?
Certain infringements can carry maximum penalties of €35 million or 7% of annual worldwide turnover. Not every infringement is subject to this threshold.
What does Article 4 require?
Article 4 requires providers and deployers to take measures supporting AI literacy among people who use AI systems on their behalf.
From EU AI Act Compliance to Preparing Your Team
Understanding the EU AI Act requires more than identifying which technology a company uses.
Organizations need to know:
- who uses AI;
- for what purpose;
- what data is involved;
- what risk the use creates;
- what controls exist;
- what employees need to understand.
If your organization needs to develop those capabilities, you can explore the Founderz AI Literacy program.
If you first need to identify which parts of the regulation may be relevant, start with the Founderz AI Act diagnostic.
Disclaimer: This content is provided for informational and educational purposes only and does not constitute legal advice. Application of the AI Act depends on the AI system, the organization’s role, the context of use and any other European or national laws that may apply.
