AI & Tech Intelligence · EU AI Act
The EU AI Act Explained: Risk Categories, Timeline and Penalties
The EU AI Act (Regulation 2024/1689) explained: its four risk tiers, prohibited practices, the phased timeline as amended by the 2026 AI omnibus (high-risk rules from December 2027), and fines up to €35m or 7% of turnover.
TL;DR — The EU AI Act is Regulation (EU) 2024/1689, the world's first comprehensive horizontal law on artificial intelligence, which entered into force on 1 August 2024.
EU AI Act · AI omnibus · European Commission · EU AI Act | 2,092 words · 15 sections | data: CSV + JSON
Executive summary
The EU AI Act — formally Regulation (EU) 2024/1689 — is the world's first comprehensive law governing artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024, though its obligations apply in stages rather than all at once. The Act takes a risk-based approach, sorting AI into four tiers: practices posing an unacceptable risk (such as social scoring by public authorities and most untargeted facial-recognition scraping) are prohibited; high-risk systems (used in areas like medical devices, recruitment, credit scoring and critical infrastructure) face strict obligations on risk management, data governance, human oversight and conformity assessment; limited-risk systems (chatbots, deepfakes) carry transparency duties; and minimal-risk uses are largely unregulated. Prohibitions and AI-literacy duties began applying on 2 February 2025 and obligations for general-purpose AI (GPAI) models on 2 August 2025; the Act became generally applicable on 2 August 2026, including the Article 50 transparency rules. The high-risk requirements were postponed by the AI omnibus, Regulation (EU) 2026/1744 (in force since 27 July 2026): stand-alone Annex III systems now follow on 2 December 2027 and Annex I product-embedded systems on 2 August 2028. Enforcement is backed by tiered fines of up to €35 million or 7% of global annual turnover for banned practices, €15 million or 3% for other breaches, and €7.5 million or 1% for supplying incorrect information. Because the rules apply wherever AI output is used in the EU, the Act reaches providers and deployers worldwide, making it a de facto global benchmark for AI governance.
“The AI Act (Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence) is the first-ever comprehensive legal framework on AI worldwide.”
Key findings
The heaviest fine reaches €35m or 7% of global turnover
The top penalty tier applies to breaches of the Article 5 ban on prohibited AI practices. Other operator obligations carry fines up to €15 million or 3% of turnover, and supplying incorrect, incomplete or misleading information up to €7.5 million or 1%. For SMEs and start-ups, the lower of the fixed amount or the percentage applies.
Source: EU AI Act, Article 99 · 2024 · confidence: High
Four risk tiers determine every obligation
The Act regulates AI in proportion to risk. Unacceptable-risk practices are banned outright; high-risk systems must pass conformity assessment before market entry; limited-risk systems owe transparency to users; and minimal-risk AI, the vast majority of applications, is unrestricted beyond voluntary codes.
Source: European Commission — AI Act · 2024 · confidence: High
Obligations phase in from 2025 to 2028
Rather than a single switch-on date, the Act stages its duties: bans and AI-literacy rules from 2 February 2025, GPAI model obligations and governance from 2 August 2025, and general application from 2 August 2026. The AI omnibus (Regulation (EU) 2026/1744) moved the stand-alone high-risk requirements (Annex III) from 2 August 2026 to 2 December 2027, and those for high-risk AI embedded in regulated products (Annex I) from 2 August 2027 to 2 August 2028.
Source: EU AI Act — Implementation Timeline · 2024 · confidence: High
Where the AI Act stands as of October 2026
As of 4 October 2026, the AI Act is generally applicable: the Article 5 prohibitions and AI-literacy duties have applied since 2 February 2025, the general-purpose AI (GPAI) model obligations since 2 August 2025, and since 2 August 2026 the rest of the Act — including the Article 50 transparency rules and the AI Office's enforcement powers over GPAI providers, fines included. The high-risk timeline has moved: the AI omnibus, Regulation (EU) 2026/1744 (approved by Parliament on 16 June 2026, published in the Official Journal on 24 July and in force since 27 July 2026), postponed the stand-alone high-risk requirements under Annex III to 2 December 2027 and those for high-risk AI embedded in products covered by EU safety legislation (Annex I) to 2 August 2028. It also added a ban on 'nudifier' apps and AI-generated child sexual abuse material from 2 December 2026, gave generative systems placed on the market before 2 August 2026 until 2 December 2026 to add machine-readable marking, and reworded the Article 4 AI-literacy duty to require measures that 'support the development of' staff AI literacy. GPAI models placed on the market before August 2025 have until 2 August 2027, and public-authority high-risk systems already in use until 2 August 2030. The full phased calendar is set out in the timeline table below.
What is the EU AI Act and why does it exist?
The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, the first comprehensive, horizontal legal framework for artificial intelligence anywhere in the world. It was adopted in 2024, published in the Official Journal of the European Union on 12 July 2024, and entered into force on 1 August 2024. As a Regulation, it is directly applicable in all 27 EU member states without needing national transposition.
Its stated purpose is to ensure that AI systems placed on the EU market are safe and respect fundamental rights, while supporting innovation and the free movement of AI-based goods and services across the single market. The Commission frames it as building an 'ecosystem of trust' — giving businesses legal certainty and citizens confidence that AI used in the EU is subject to enforceable safeguards.
The Act is deliberately technology-neutral and risk-based: instead of regulating specific techniques, it regulates uses of AI according to the risk they pose to health, safety and fundamental rights. This structure is designed to age well as the technology changes, and it has become a reference point that other jurisdictions study when drafting their own AI rules.
How does the AI Act classify risk?
The Act's core mechanism is a four-tier risk pyramid. The higher the risk an AI use poses, the stricter the obligations — ranging from an outright ban at the top to no mandatory rules at the base. Most everyday AI, from spam filters to recommendation engines, falls into the minimal-risk tier.
The table below summarises each tier, representative examples, and the obligations that attach to it. Note that general-purpose AI (GPAI) models are governed by a separate dedicated regime that cuts across these tiers.
This proportionate design means the compliance burden concentrates on a comparatively narrow set of high-stakes systems, while the bulk of AI applications remain free of mandatory requirements beyond general product and data-protection law.
| Risk tier | Examples | Obligations |
|---|---|---|
| Unacceptable (prohibited) | Social scoring by public authorities; manipulative or exploitative AI; untargeted facial-image scraping; most real-time remote biometric ID in public spaces | Banned outright under Article 5 |
| High-risk | AI in medical devices, recruitment, credit scoring, critical infrastructure, education, law enforcement, migration | Risk management, data governance, technical documentation, human oversight, conformity assessment before market entry |
| Limited-risk (transparency) | Chatbots, emotion-recognition systems, AI-generated or manipulated content (deepfakes) | Transparency duties — users must be told they are interacting with, or viewing output from, AI |
| Minimal-risk | Spam filters, recommendation engines, AI in video games | No mandatory obligations; voluntary codes of conduct encouraged |
Which AI practices are banned?
Article 5 lists AI practices considered a clear threat to fundamental rights and therefore prohibited across the EU. These bans have been in force since 2 February 2025 — the first substantive obligations of the Act to take effect.
Prohibited practices include: subliminal or purposefully manipulative techniques that materially distort behaviour and cause harm; exploitation of vulnerabilities due to age, disability or socio-economic situation; social scoring by public authorities leading to detrimental treatment; untargeted scraping of facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces and educational institutions (with narrow exceptions); certain predictive-policing profiling; and biometric categorisation inferring sensitive attributes such as race or sexual orientation.
Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes is also prohibited, subject to tightly defined exceptions (for example, searching for specific victims or preventing an imminent terrorist threat) that require prior authorisation. Breaching any Article 5 prohibition triggers the Act's highest fine tier of up to €35 million or 7% of global annual turnover.
What counts as high-risk, and what must providers do?
High-risk systems are the regulatory heart of the Act. Two routes make a system high-risk: it is a safety component of, or itself, a product already covered by EU harmonisation legislation listed in Annex I (for example medical devices, machinery, toys); or it falls within one of the use cases listed in Annex III, such as biometrics, critical infrastructure, education, employment, essential public and private services (including credit scoring), law enforcement, migration, and administration of justice.
Providers of high-risk AI must meet a demanding set of requirements: an operational risk-management system, high-quality and governed training data, detailed technical documentation, automatic record-keeping (logging), transparency and provision of information to deployers, human oversight, and appropriate levels of accuracy, robustness and cybersecurity. Before entering the market, systems must undergo conformity assessment, carry CE marking, and be registered in an EU database.
Obligations also flow down the value chain: deployers (users) of high-risk systems must operate them according to instructions, ensure human oversight, and in some cases carry out a fundamental-rights impact assessment. Under the 2026 AI omnibus, the high-risk obligations apply from 2 December 2027 for Annex III use cases and from 2 August 2028 for Annex I product-embedded systems.
How does the Act regulate general-purpose AI (GPAI)?
General-purpose AI (GPAI) models — foundation models such as large language models that can be adapted to many tasks — are governed by a dedicated regime introduced during the negotiations to address models like GPT-class systems. These obligations have applied since 2 August 2025.
All GPAI providers must maintain up-to-date technical documentation, provide information and documentation to downstream providers who integrate the model, put in place a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training. Providers can demonstrate compliance by adhering to the Commission's General-Purpose AI Code of Practice.
A stricter layer applies to GPAI models deemed to carry 'systemic risk' — presumed where the cumulative compute used for training exceeds 10^25 floating-point operations (FLOP). These providers face additional duties: model evaluations and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and adequate cybersecurity. GPAI models already on the market before 2 August 2025 have until 2 August 2027 to comply.
When does the EU AI Act take effect?
The Act entered into force on 1 August 2024 and became generally applicable on 2 August 2026, but some obligations phase in separately. The AI omnibus, Regulation (EU) 2026/1744 (in force since 27 July 2026), moved the high-risk dates back, so different obligations 'switch on' at different dates through 2030.
The table below sets out each application date and the obligations it activates.
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation enters into force (20 days after OJ publication) |
| 2 February 2025 | Prohibited AI practices (Article 5) and AI-literacy obligations apply |
| 2 August 2025 | GPAI model obligations, governance rules, notified bodies and the penalty framework apply |
| 2 August 2026 | General application, except the high-risk parts: Article 50 transparency rules and AI Office enforcement over GPAI models, including fines (the AI omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026) |
| 2 December 2026 | Ban on 'nudifier' apps and AI-generated child sexual abuse material; deadline for machine-readable marking by generative AI systems placed on the market before 2 August 2026 |
| 2 August 2027 | GPAI models placed on the market before 2 August 2025 must be compliant |
| 2 December 2027 | Stand-alone high-risk obligations (Annex III use cases such as hiring, credit scoring, education and administration of justice) apply — postponed from 2 August 2026 |
| 2 August 2028 | Obligations for high-risk AI embedded in Annex I products apply — postponed from 2 August 2027 |
| 2 August 2030 | High-risk systems already used by public authorities must be brought into compliance |
What are the penalties for non-compliance?
Enforcement is backed by administrative fines set out in Article 99, scaled to the severity of the breach. Fines are calculated as the higher of a fixed euro ceiling or a percentage of the offender's total worldwide annual turnover for the preceding financial year — except for SMEs and start-ups, for whom the lower of the two applies.
The three tiers are shown below. Governance and enforcement are shared between national market-surveillance authorities and, for GPAI models, the European AI Office established within the Commission.
Beyond fines, authorities can require systems to be withdrawn from the market. Separate penalty provisions (Article 101) allow the Commission to fine GPAI providers up to 3% of worldwide annual turnover or €15 million for specified infringements.
| Breach type | Maximum fine |
|---|---|
| Prohibited AI practices (Article 5) | €35 million or 7% of global annual turnover, whichever is higher |
| Non-compliance with other obligations (providers, deployers, importers, etc.) | €15 million or 3% of global annual turnover, whichever is higher |
| Supplying incorrect, incomplete or misleading information | €7.5 million or 1% of global annual turnover, whichever is higher |
Who does the AI Act apply to, and what does it mean for business?
The Act binds a broad range of actors: providers (those who develop an AI system or GPAI model and place it on the EU market), deployers (professional users), importers, distributors, and product manufacturers. It applies regardless of whether these actors are established in the EU.
Its reach is extraterritorial. The rules apply to providers placing AI on the EU market wherever they are located, and — critically — to providers and deployers outside the EU whenever the output produced by the AI system is used within the Union. A US or Asian company whose model is used by EU customers is therefore in scope, which is why the Act is widely described as setting a de facto global standard (a 'Brussels effect').
For business, the practical consequences are concentrated in the high-risk and GPAI tiers: mapping which systems fall into scope, building risk-management and documentation processes, ensuring human oversight, and — for GPAI integrators — obtaining compliance documentation from upstream model providers. Most companies using minimal-risk AI face few new mandatory duties beyond transparency where they deploy chatbots or generate synthetic media, plus a general AI-literacy obligation for staff.
What are the main criticisms and limitations?
The Act has drawn criticism from several directions. Parts of the technology industry and some member states warn that compliance costs and documentation burdens could slow European AI development and disadvantage smaller firms and start-ups relative to better-resourced US and Chinese competitors.
Civil-society and digital-rights groups argue the opposite — that the exceptions carved out for law-enforcement use of remote biometric identification and certain national-security uses weaken the fundamental-rights protections the Act is meant to guarantee. The reliance on self-assessment for many high-risk systems has also been questioned.
There are practical uncertainties too: much depends on forthcoming harmonised standards, Commission guidance and the codes of practice, which were still being finalised as the obligations phased in. The Commission has publicly discussed simplification measures to ease implementation, and the interaction between the AI Act and existing law (notably the GDPR) remains an area businesses must navigate carefully.
Scoreboard (machine-readable data)
Every headline indicator with its value, period, source and confidence. Free to reuse under CC BY 4.0.
| Indicator | Value | Period | Source | Conf. |
|---|---|---|---|---|
| Prohibited AI practices breach | 7 pct_turnover | 2024 | EU AI Act, Article 99 | High |
| Other obligation breach | 3 pct_turnover | 2024 | EU AI Act, Article 99 | High |
| Incorrect/misleading information | 1 pct_turnover | 2024 | EU AI Act, Article 99 | High |
| Prohibited AI practices breach (cap) | 35000000 eur | 2024 | EU AI Act, Article 99 | High |
| GPAI systemic-risk compute threshold | 1e+25 flop | 2024 | EU AI Act, Article 51 | High |
Methodology & verification
This report was compiled directly from the primary legal text — Regulation (EU) 2024/1689 (the EU AI Act) as published in the Official Journal — and the article-by-article and implementation-timeline references maintained at artificialintelligenceact.eu, cross-checked against the European Commission's official AI Act pages. Every date, fine, percentage and article reference was verified against these sources on 30 July 2026. Figures are stated as the maxima set out in the Regulation; actual penalties are determined by national authorities on a case-by-case basis. No figures were estimated or interpolated.
Data dictionary
| Field | Type | Description |
|---|---|---|
| risk_tier | categorical | One of the four AI Act risk levels: unacceptable (prohibited), high, limited (transparency), or minimal. |
| max_fine_pct | number | Maximum administrative fine expressed as a percentage of total worldwide annual turnover under Article 99. |
| application_date | date (ISO 8601) | The calendar date on which a given set of AI Act obligations begins to apply. |
Frequently asked questions
When does the EU AI Act take effect?
The AI Act entered into force on 1 August 2024 and has been generally applicable since 2 August 2026, after prohibited practices (2 February 2025) and general-purpose AI obligations (2 August 2025). Following the 2026 AI omnibus, Regulation (EU) 2026/1744, the high-risk requirements apply from 2 December 2027 for stand-alone Annex III systems and from 2 August 2028 for AI embedded in regulated products, with a final deadline in 2030 for public-authority systems already in use.
What are the risk categories in the EU AI Act?
There are four: unacceptable-risk practices that are banned outright, high-risk systems facing strict obligations, limited-risk systems owing transparency duties, and minimal-risk AI that is largely unregulated.
What are the penalties under the EU AI Act?
Fines reach up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for other breaches, and €7.5 million or 1% for supplying incorrect or misleading information — whichever amount is higher (Article 99).
Does the EU AI Act apply to companies outside the EU?
Yes. It applies to any provider placing AI on the EU market, and to providers and deployers anywhere in the world whenever the AI system's output is used within the European Union — giving it global, extraterritorial reach.
What is a high-risk AI system under the Act?
A high-risk system is one used as a safety component of a regulated product (Annex I) or in a sensitive use case listed in Annex III — such as recruitment, credit scoring, critical infrastructure or law enforcement — and must meet strict requirements on risk management, data, oversight and conformity assessment.
How does the AI Act regulate ChatGPT and other foundation models?
General-purpose AI (GPAI) models face dedicated obligations from 2 August 2025, including technical documentation, a copyright policy and a training-data summary; models with 'systemic risk' (training compute above 10^25 FLOP) must also perform model evaluations, mitigate risks and report serious incidents.
Glossary
- High-risk AI system
- An AI system that is a safety component of a product covered by EU harmonisation law (Annex I) or is used in a sensitive area listed in Annex III; subject to strict pre-market and ongoing obligations. ↗
- General-purpose AI (GPAI) model
- An AI model trained on broad data at scale that can perform a wide range of distinct tasks and be integrated into many downstream systems; governed by a dedicated regime from 2 August 2025. ↗
- Prohibited AI practice
- An AI use banned under Article 5 because it poses an unacceptable risk to fundamental rights, such as social scoring or untargeted facial-image scraping. ↗
- Conformity assessment
- The process by which a high-risk AI provider demonstrates that its system meets the Act's requirements before it is placed on the market, resulting in CE marking. ↗
Embed & cite this report
Free to reuse under CC BY 4.0. Embed the live-updating widget on your site, or cite the report directly — always with attribution to Affärslivet.
Embed (HTML) — auto-updating
<iframe src="https://xn--affrslivet-s5a.com/en/embed/eu-ai-act-explained" width="100%" height="520" style="border:1px solid #e3e3e6" title="The EU AI Act Explained: Risk Categories, Timeline and Penalties — Affärslivet" loading="lazy"></iframe> <p style="font:12px sans-serif">Source: <a href="https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained">Affärslivet</a></p>
APA
Affärslivet Research. (2026). The EU AI Act Explained: Risk Categories, Timeline and Penalties. Affärslivet. Version 1.0. https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained
MLA
Affärslivet Research. "The EU AI Act Explained: Risk Categories, Timeline and Penalties." Affärslivet, 2026-07-30, https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained.
BibTeX
@techreport{affarslivet_eu_ai_act_explained,
title = {The EU AI Act Explained: Risk Categories, Timeline and Penalties},
author = {{Affärslivet Research}},
year = {2026},
note = {Version 1.0},
url = {https://xn--affrslivet-s5a.com/en/reports/eu-ai-act-explained}
} License CC BY 4.0 — free to cite, embed and republish with attribution to Affärslivet. Data also as CSV / JSON.
Sources
Looking to hire? If you're moving from the data in this report to actually building, see our source-cited comparison: Best EU AI Act compliance consultants →
Part of Affärslivet AI Intelligence
This report is one part of Affärslivet's source-cited AI knowledge layer. Start with the big picture:
- The State of AI 2026 — our free, source-cited annual report
- AI Statistics 2026 — 230+ source-cited AI facts & figures
- The AI Intelligence hub — all our indexes, rankings, model & lab profiles
Hiring AI help — our consultant guides
Bringing in external AI expertise? Our source-cited comparisons of consultants, agencies and implementation partners:
Consulting & choosing a firm
AI agents & frameworks
Generative AI, RAG & chatbots
Implementation & delivery
Governance & EU AI Act
Corporate AI training
EU AI Act timeline after the AI Omnibus
The main high-risk deadlines are now 2 December 2027 for Annex III use cases and 2 August 2028 for high-risk AI embedded in Annex I products. The general application date of 2 August 2026 marks the start of the general framework and central enforcement arrangements, not the main deadline for every high-risk obligation.
The prohibitions and AI-competence rules started on 2 February 2025. GPAI obligations and governance rules started on 2 August 2025. Transparency rules for certain systems, including chatbots and synthetic content, apply from August 2026; the Commission’s overview does not state a separate exact day for those requirements.
These dates reflect the AI Omnibus, which entered into force on 27 July 2026.
Source: European Commission — AI Omnibus enters into force and European Commission — AI Act · 2026.