EU AI Act
iAs of: September 2026
This section reflects implementation status as of September 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, 2026 and noticeably changed the timeline: the high-risk obligations were postponed, while the transparency obligations and enforcement have applied since August 2, 2026. Anyone who was waiting for the delay is nonetheless already bound by Article 50.
Wissen
The EU AI Act entered into force on August 2, 2024, and will become fully applicable in phases through 2028. It is the world's first comprehensive regulation of AI systems and sets the global benchmark. Companies outside the EU are also affected if they deploy AI systems on the EU market -- similar to the GDPR.
The core principle: Risk-based approach. Not all AI systems are regulated equally. The higher the risk to health, safety, and fundamental rights, the stricter the requirements.
The Four Risk Classes
Hover oder klickeTippe auf eine Ebene, um Details zu sehen
Level 1: Unacceptable Risk -- Prohibited. Social scoring, real-time biometric mass surveillance (with narrow law enforcement exceptions: searching for missing persons, preventing imminent terrorist threats, identifying suspects of serious crimes), manipulation of vulnerable groups, emotion recognition in workplaces. These systems simply must not exist.
Level 2: High Risk -- Strictly Regulated. Biometric identification, critical infrastructure, education, employment, creditworthiness, law enforcement, judicial support.
Level 3: Limited Risk -- Transparency Obligations. Chatbots, AI-generated media, deepfakes. Users must know they are interacting with AI.
Level 4: Minimal Risk -- No Special Obligations. Spam filters, search engines, recommendation systems, AI in video games.
Obligations for High-Risk Systems
| Obligation | Description |
|---|---|
| Risk management | Documented risk management system across the entire lifecycle |
| Data quality | Training only with quality-assured, representative datasets |
| Technical documentation | Detailed description of the system, its intended purpose, and performance limitations |
| Logging & audit trail | Automatic logging of all decisions for traceability |
| Transparency | Clear user information that they are interacting with an AI system |
| Human oversight | Human-in-the-loop or human-on-the-loop for critical decisions |
| Accuracy & robustness | Demonstrated accuracy, cybersecurity, and resilience |
| Conformity assessment | Before market placement: conformity proof (partially by third parties) |
Penalties
| Violation | Penalty |
|---|---|
| Deploying prohibited AI systems | Up to EUR 35M or 7% of global annual turnover |
| Violating high-risk obligations | Up to EUR 15M or 3% of global annual turnover |
| Providing false information to authorities | Up to EUR 7.5M or 1% of global annual turnover |
Reduced caps apply for SMEs and startups to avoid stifling innovation.
!Comparison with GDPR
The GDPR provides for a maximum penalty of 4% of annual turnover. The EU AI Act goes significantly beyond that at 7%. Companies that took the GDPR seriously should take the AI Act even more seriously.
Timeline
| Date | Milestone | Status (September 2026) |
|---|---|---|
| August 2, 2024 | EU AI Act enters into force | ✅ active |
| February 2, 2025 | Bans on unacceptable AI systems take effect | ✅ active |
| July 2025 | Code of Practice for GPAI published | ✅ signatories benefit on fines |
| August 2, 2025 | Obligations for new GPAI models (GPT, Claude, Gemini) | ✅ active |
| July 27, 2026 | Digital Omnibus on AI (Reg. (EU) 2026/1744) in force | ✅ postpones high-risk deadlines |
| August 2, 2026 | Transparency obligations (Art. 50) + enforcement by the AI Office and member states (Art. 99/101) | ✅ active |
| December 2, 2026 | End of the grace period for marking pre-existing systems | ⏳ |
| August 2, 2027 | Existing GPAI models must be fully compliant | ⏳ transition period |
| December 2, 2027 | High-risk obligations for stand-alone systems (Annex III) | ⏳ postponed by the Omnibus |
| August 2, 2028 | High-risk obligations for AI in regulated products (Annex I) | ⏳ postponed by the Omnibus |
General Purpose AI (GPAI) -- Special Rules
Since August 2025, special rules apply to foundation models and general purpose AI:
- All GPAI providers: Technical documentation, copyright compliance, transparency about training data
- GPAI with systemic risk (>10^25 FLOPs training): Additional red-teaming, cybersecurity, energy reporting, incident reporting
*Code of Practice — fine mitigation
In July 2025, the European Commission published a Code of Practice for General-Purpose AI in cooperation with industry and civil society. Providers who voluntarily sign it have benefited from a milder enforcement approach since August 2, 2026: the Commission will focus its enforcement on adherence to the Code and may take Code commitments into account as mitigating factors when setting fines.
Verstehen
A company develops an AI system that automatically pre-sorts resumes and recommends candidates for interviews. Which risk class does this system fall into under the EU AI Act?
A startup develops an AI chatbot for customer service at an online shop. The chatbot answers questions about orders and returns. What obligation does the startup have under the EU AI Act?
iWhat This Means for You
If you're building a high-risk system, start documentation NOW. Introducing risk management, data quality, and audit trails retroactively is expensive and error-prone. Plan them from the start.
Anwenden
For Developers
- Risk classification first -- Before writing a single line of code, determine your system's risk class
- Data governance -- Document training data, sources, quality measures, and potential biases from the start
- Build audit trails -- Logging is not optional. Every decision must be traceable
- Test for bias and fairness -- Especially for high-risk systems, systematic bias testing is mandatory
For Organizations
- Create an AI inventory -- What AI systems do you use? What risk class do they fall into?
- Build a compliance team -- AI governance needs dedicated owners
- Vet suppliers -- If you use third-party AI systems, you're co-responsible as a "deployer"
- Mind the timeline -- Transparency obligations and enforcement have applied since August 2, 2026. For the high-risk obligations the Digital Omnibus bought time: Annex III applies from December 2, 2027, Annex I from August 2, 2028. That is a postponement, not an all-clear -- conformity assessment and technical documentation realistically need more than a year of lead time.
Reflect
The EU AI Act creates the world's first comprehensive legal framework for AI. The risk-based classification system determines what requirements your system must meet. Early compliance is not optional but mandatory. In the next section, you will learn how to concretely test for bias.