AI & Tech Intelligence · EU AI Act
The EU AI Act Explained: Risk Categories, Timeline and Penalties
The EU AI Act (Regulation 2024/1689) explained: its four risk tiers, prohibited practices, the phased 2025–2027 timeline, and fines up to €35m or 7% of turnover.
TL;DR — The EU AI Act is Regulation (EU) 2024/1689, the world's first comprehensive horizontal law on artificial intelligence, which entered into force on 1 August 2024.
EU AI Act · European Commission · EU AI Act · EU AI Act | 1,966 words · 15 sections | data: CSV + JSON
Executive summary
The EU AI Act — formally Regulation (EU) 2024/1689 — is the world's first comprehensive law governing artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024, though its obligations apply in stages rather than all at once. The Act takes a risk-based approach, sorting AI into four tiers: practices posing an unacceptable risk (such as social scoring by public authorities and most untargeted facial-recognition scraping) are prohibited; high-risk systems (used in areas like medical devices, recruitment, credit scoring and critical infrastructure) face strict obligations on risk management, data governance, human oversight and conformity assessment; limited-risk systems (chatbots, deepfakes) carry transparency duties; and minimal-risk uses are largely unregulated. Prohibitions and AI-literacy duties began applying on 2 February 2025, obligations for general-purpose AI (GPAI) models on 2 August 2025, and most high-risk requirements follow on 2 August 2026. Enforcement is backed by tiered fines of up to €35 million or 7% of global annual turnover for banned practices, €15 million or 3% for other breaches, and €7.5 million or 1% for supplying incorrect information. Because the rules apply wherever AI output is used in the EU, the Act reaches providers and deployers worldwide, making it a de facto global benchmark for AI governance.
“The AI Act (Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence) is the first-ever comprehensive legal framework on AI worldwide.”
Key findings
The heaviest fine reaches €35m or 7% of global turnover
The top penalty tier applies to breaches of the Article 5 ban on prohibited AI practices. Other operator obligations carry fines up to €15 million or 3% of turnover, and supplying incorrect, incomplete or misleading information up to €7.5 million or 1%. For SMEs and start-ups, the lower of the fixed amount or the percentage applies.
Source: EU AI Act, Article 99 · 2024 · confidence: High
Four risk tiers determine every obligation
The Act regulates AI in proportion to risk. Unacceptable-risk practices are banned outright; high-risk systems must pass conformity assessment before market entry; limited-risk systems owe transparency to users; and minimal-risk AI, the vast majority of applications, is unrestricted beyond voluntary codes.
Source: European Commission — AI Act · 2024 · confidence: High
Obligations phase in from 2025 to 2027
Rather than a single switch-on date, the Act stages its duties: bans and AI-literacy rules from 2 February 2025, GPAI model obligations and governance from 2 August 2025, and most high-risk requirements from 2 August 2026, with certain embedded high-risk products (Annex I) extending to 2 August 2027.
Source: EU AI Act — Implementation Timeline · 2024 · confidence: High
Where the AI Act stands as of mid-2026
As of 30 July 2026, three of the Act's phases are live: the Article 5 prohibitions and AI-literacy duties (in force since 2 February 2025) and the general-purpose AI (GPAI) model obligations plus the governance and penalty framework (since 2 August 2025). The next major milestone is 2 August 2026, when most high-risk obligations under Annex III begin to apply, followed by 2 August 2027 for high-risk AI embedded in products covered by existing EU safety legislation (Annex I) and for GPAI models placed on the market before August 2025. Public-authority high-risk systems already in use have until 2 August 2030. The full phased calendar is set out in the timeline table below.
What is the EU AI Act and why does it exist?
The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, the first comprehensive, horizontal legal framework for artificial intelligence anywhere in the world. It was adopted in 2024, published in the Official Journal of the European Union on 12 July 2024, and entered into force on 1 August 2024. As a Regulation, it is directly applicable in all 27 EU member states without needing national transposition.
Its stated purpose is to ensure that AI systems placed on the EU market are safe and respect fundamental rights, while supporting innovation and the free movement of AI-based goods and services across the single market. The Commission frames it as building an 'ecosystem of trust' — giving businesses legal certainty and citizens confidence that AI used in the EU is subject to enforceable safeguards.
The Act is deliberately technology-neutral and risk-based: instead of regulating specific techniques, it regulates uses of AI according to the risk they pose to health, safety and fundamental rights. This structure is designed to age well as the technology changes, and it has become a reference point that other jurisdictions study when drafting their own AI rules.
How does the AI Act classify risk?
The Act's core mechanism is a four-tier risk pyramid. The higher the risk an AI use poses, the stricter the obligations — ranging from an outright ban at the top to no mandatory rules at the base. Most everyday AI, from spam filters to recommendation engines, falls into the minimal-risk tier.
The table below summarises each tier, representative examples, and the obligations that attach to it. Note that general-purpose AI (GPAI) models are governed by a separate dedicated regime that cuts across these tiers.
This proportionate design means the compliance burden concentrates on a comparatively narrow set of high-stakes systems, while the bulk of AI applications remain free of mandatory requirements beyond general product and data-protection law.
| Risk tier | Examples | Obligations |
|---|---|---|
| Unacceptable (prohibited) | Social scoring by public authorities; manipulative or exploitative AI; untargeted facial-image scraping; most real-time remote biometric ID in public spaces | Banned outright under Article 5 |
| High-risk | AI in medical devices, recruitment, credit scoring, critical infrastructure, education, law enforcement, migration | Risk management, data governance, technical documentation, human oversight, conformity assessment before market entry |
| Limited-risk (transparency) | Chatbots, emotion-recognition systems, AI-generated or manipulated content (deepfakes) | Transparency duties — users must be told they are interacting with, or viewing output from, AI |
| Minimal-risk | Spam filters, recommendation engines, AI in video games | No mandatory obligations; voluntary codes of conduct encouraged |
Which AI practices are banned?
Article 5 lists AI practices considered a clear threat to fundamental rights and therefore prohibited across the EU. These bans have been in force since 2 February 2025 — the first substantive obligations of the Act to take effect.
Prohibited practices include: subliminal or purposefully manipulative techniques that materially distort behaviour and cause harm; exploitation of vulnerabilities due to age, disability or socio-economic situation; social scoring by public authorities leading to detrimental treatment; untargeted scraping of facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces and educational institutions (with narrow exceptions); certain predictive-policing profiling; and biometric categorisation inferring sensitive attributes such as race or sexual orientation.
Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes is also prohibited, subject to tightly defined exceptions (for example, searching for specific victims or preventing an imminent terrorist threat) that require prior authorisation. Breaching any Article 5 prohibition triggers the Act's highest fine tier of up to €35 million or 7% of global annual turnover.
What counts as high-risk, and what must providers do?
High-risk systems are the regulatory heart of the Act. Two routes make a system high-risk: it is a safety component of, or itself, a product already covered by EU harmonisation legislation listed in Annex I (for example medical devices, machinery, toys); or it falls within one of the use cases listed in Annex III, such as biometrics, critical infrastructure, education, employment, essential public and private services (including credit scoring), law enforcement, migration, and administration of justice.
Providers of high-risk AI must meet a demanding set of requirements: an operational risk-management system, high-quality and governed training data, detailed technical documentation, automatic record-keeping (logging), transparency and provision of information to deployers, human oversight, and appropriate levels of accuracy, robustness and cybersecurity. Before entering the market, systems must undergo conformity assessment, carry CE marking, and be registered in an EU database.
Obligations also flow down the value chain: deployers (users) of high-risk systems must operate them according to instructions, ensure human oversight, and in some cases carry out a fundamental-rights impact assessment. Most high-risk obligations begin to apply on 2 August 2026, with Annex I product-embedded systems following on 2 August 2027.
How does the Act regulate general-purpose AI (GPAI)?
General-purpose AI (GPAI) models — foundation models such as large language models that can be adapted to many tasks — are governed by a dedicated regime introduced during the negotiations to address models like GPT-class systems. These obligations have applied since 2 August 2025.
All GPAI providers must maintain up-to-date technical documentation, provide information and documentation to downstream providers who integrate the model, put in place a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training. Providers can demonstrate compliance by adhering to the Commission's General-Purpose AI Code of Practice.
A stricter layer applies to GPAI models deemed to carry 'systemic risk' — presumed where the cumulative compute used for training exceeds 10^25 floating-point operations (FLOP). These providers face additional duties: model evaluations and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and adequate cybersecurity. GPAI models already on the market before 2 August 2025 have until 2 August 2027 to comply.
When does the EU AI Act take effect?
The Act entered into force on 1 August 2024 but applies in phases, giving organisations time to adapt. The staggered calendar means different obligations 'switch on' at different dates through 2030.
The table below sets out each application date and the obligations it activates.
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation enters into force (20 days after OJ publication) |
| 2 February 2025 | Prohibited AI practices (Article 5) and AI-literacy obligations apply |
| 2 August 2025 | GPAI model obligations, governance rules, notified bodies and the penalty framework apply |
| 2 August 2026 | Most high-risk obligations (Annex III use cases) begin to apply |
| 2 August 2027 | High-risk AI embedded in Annex I products; pre-existing GPAI models must be compliant |
| 2 August 2030 | High-risk systems already used by public authorities must be brought into compliance |
What are the penalties for non-compliance?
Enforcement is backed by administrative fines set out in Article 99, scaled to the severity of the breach. Fines are calculated as the higher of a fixed euro ceiling or a percentage of the offender's total worldwide annual turnover for the preceding financial year — except for SMEs and start-ups, for whom the lower of the two applies.
The three tiers are shown below. Governance and enforcement are shared between national market-surveillance authorities and, for GPAI models, the European AI Office established within the Commission.
Beyond fines, authorities can require systems to be withdrawn from the market. Separate penalty provisions (Article 101) allow the Commission to fine GPAI providers up to 3% of worldwide annual turnover or €15 million for specified infringements.
| Breach type | Maximum fine |
|---|---|
| Prohibited AI practices (Article 5) | €35 million or 7% of global annual turnover, whichever is higher |
| Non-compliance with other obligations (providers, deployers, importers, etc.) | €15 million or 3% of global annual turnover, whichever is higher |
| Supplying incorrect, incomplete or misleading information | €7.5 million or 1% of global annual turnover, whichever is higher |
Who does the AI Act apply to, and what does it mean for business?
The Act binds a broad range of actors: providers (those who develop an AI system or GPAI model and place it on the EU market), deployers (professional users), importers, distributors, and product manufacturers. It applies regardless of whether these actors are established in the EU.
Its reach is extraterritorial. The rules apply to providers placing AI on the EU market wherever they are located, and — critically — to providers and deployers outside the EU whenever the output produced by the AI system is used within the Union. A US or Asian company whose model is used by EU customers is therefore in scope, which is why the Act is widely described as setting a de facto global standard (a 'Brussels effect').
For business, the practical consequences are concentrated in the high-risk and GPAI tiers: mapping which systems fall into scope, building risk-management and documentation processes, ensuring human oversight, and — for GPAI integrators — obtaining compliance documentation from upstream model providers. Most companies using minimal-risk AI face few new mandatory duties beyond transparency where they deploy chatbots or generate synthetic media, plus a general AI-literacy obligation for staff.
What are the main criticisms and limitations?
The Act has drawn criticism from several directions. Parts of the technology industry and some member states warn that compliance costs and documentation burdens could slow European AI development and disadvantage smaller firms and start-ups relative to better-resourced US and Chinese competitors.
Civil-society and digital-rights groups argue the opposite — that the exceptions carved out for law-enforcement use of remote biometric identification and certain national-security uses weaken the fundamental-rights protections the Act is meant to guarantee. The reliance on self-assessment for many high-risk systems has also been questioned.
There are practical uncertainties too: much depends on forthcoming harmonised standards, Commission guidance and the codes of practice, which were still being finalised as the obligations phased in. The Commission has publicly discussed simplification measures to ease implementation, and the interaction between the AI Act and existing law (notably the GDPR) remains an area businesses must navigate carefully.
Scoreboard (machine-readable data)
Every headline indicator with its value, period, source and confidence. Free to reuse under CC BY 4.0.
| Indicator | Value | Period | Source | Conf. |
|---|---|---|---|---|
| Prohibited AI practices breach | 7 pct_turnover | 2024 | EU AI Act, Article 99 | High |
| Other obligation breach | 3 pct_turnover | 2024 | EU AI Act, Article 99 | High |
| Incorrect/misleading information | 1 pct_turnover | 2024 | EU AI Act, Article 99 | High |
| Prohibited AI practices breach (cap) | 35000000 eur | 2024 | EU AI Act, Article 99 | High |
| GPAI systemic-risk compute threshold | 1e+25 flop | 2024 | EU AI Act, Article 51 | High |
Methodology & verification
This report was compiled directly from the primary legal text — Regulation (EU) 2024/1689 (the EU AI Act) as published in the Official Journal — and the article-by-article and implementation-timeline references maintained at artificialintelligenceact.eu, cross-checked against the European Commission's official AI Act pages. Every date, fine, percentage and article reference was verified against these sources on 30 July 2026. Figures are stated as the maxima set out in the Regulation; actual penalties are determined by national authorities on a case-by-case basis. No figures were estimated or interpolated.
Data dictionary
| Field | Type | Description |
|---|---|---|
| risk_tier | categorical | One of the four AI Act risk levels: unacceptable (prohibited), high, limited (transparency), or minimal. |
| max_fine_pct | number | Maximum administrative fine expressed as a percentage of total worldwide annual turnover under Article 99. |
| application_date | date (ISO 8601) | The calendar date on which a given set of AI Act obligations begins to apply. |
Frequently asked questions
When does the EU AI Act take effect?
The AI Act entered into force on 1 August 2024, but its rules apply in phases: prohibited practices from 2 February 2025, general-purpose AI obligations from 2 August 2025, and most high-risk requirements from 2 August 2026, with further deadlines in 2027 and 2030.
What are the risk categories in the EU AI Act?
There are four: unacceptable-risk practices that are banned outright, high-risk systems facing strict obligations, limited-risk systems owing transparency duties, and minimal-risk AI that is largely unregulated.
What are the penalties under the EU AI Act?
Fines reach up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for other breaches, and €7.5 million or 1% for supplying incorrect or misleading information — whichever amount is higher (Article 99).
Does the EU AI Act apply to companies outside the EU?
Yes. It applies to any provider placing AI on the EU market, and to providers and deployers anywhere in the world whenever the AI system's output is used within the European Union — giving it global, extraterritorial reach.
What is a high-risk AI system under the Act?
A high-risk system is one used as a safety component of a regulated product (Annex I) or in a sensitive use case listed in Annex III — such as recruitment, credit scoring, critical infrastructure or law enforcement — and must meet strict requirements on risk management, data, oversight and conformity assessment.
How does the AI Act regulate ChatGPT and other foundation models?
General-purpose AI (GPAI) models face dedicated obligations from 2 August 2025, including technical documentation, a copyright policy and a training-data summary; models with 'systemic risk' (training compute above 10^25 FLOP) must also perform model evaluations, mitigate risks and report serious incidents.
Glossary
- High-risk AI system
- An AI system that is a safety component of a product covered by EU harmonisation law (Annex I) or is used in a sensitive area listed in Annex III; subject to strict pre-market and ongoing obligations. ↗
- General-purpose AI (GPAI) model
- An AI model trained on broad data at scale that can perform a wide range of distinct tasks and be integrated into many downstream systems; governed by a dedicated regime from 2 August 2025. ↗
- Prohibited AI practice
- An AI use banned under Article 5 because it poses an unacceptable risk to fundamental rights, such as social scoring or untargeted facial-image scraping. ↗
- Conformity assessment
- The process by which a high-risk AI provider demonstrates that its system meets the Act's requirements before it is placed on the market, resulting in CE marking. ↗
Embed & cite this report
Free to reuse under CC BY 4.0. Embed the live-updating widget on your site, or cite the report directly — always with attribution to Affärslivet.
Embed (HTML) — auto-updating
<iframe src="https://xn--affrslivet-s5a.com/en/embed/eu-ai-act-explained" width="100%" height="520" style="border:1px solid #e3e3e6" title="The EU AI Act Explained: Risk Categories, Timeline and Penalties — Affärslivet" loading="lazy"></iframe> <p style="font:12px sans-serif">Source: <a href="https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained">Affärslivet</a></p>
APA
Affärslivet Research. (2026). The EU AI Act Explained: Risk Categories, Timeline and Penalties. Affärslivet. Version 1.0. https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained
MLA
Affärslivet Research. "The EU AI Act Explained: Risk Categories, Timeline and Penalties." Affärslivet, 2026-07-30, https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained.
BibTeX
@techreport{affarslivet_eu_ai_act_explained,
title = {The EU AI Act Explained: Risk Categories, Timeline and Penalties},
author = {{Affärslivet Research}},
year = {2026},
note = {Version 1.0},
url = {https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained}
} License CC BY 4.0 — free to cite, embed and republish with attribution to Affärslivet. Data also as CSV / JSON.
Sources
Part of Affärslivet AI Intelligence
This report is one part of Affärslivet's source-cited AI knowledge layer. Start with the big picture:
- The State of AI 2026 — our free, source-cited annual report
- AI Statistics 2026 — 230+ source-cited AI facts & figures
- The AI Intelligence hub — all our indexes, rankings, model & lab profiles