Zum Inhalt springen

EU AI Act

iAs of: September 2026

This section reflects implementation status as of September 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, 2026 and noticeably changed the timeline: the high-risk obligations were postponed, while the transparency obligations and enforcement have applied since August 2, 2026. Anyone who was waiting for the delay is nonetheless already bound by Article 50.

Wissen

The EU AI Act entered into force on August 2, 2024, and will become fully applicable in phases through 2028. It is the world's first comprehensive regulation of AI systems and sets the global benchmark. Companies outside the EU are also affected if they deploy AI systems on the EU market -- similar to the GDPR.

The core principle: Risk-based approach. Not all AI systems are regulated equally. The higher the risk to health, safety, and fundamental rights, the stricter the requirements.

The Four Risk Classes

Unacceptable RiskHigh RiskLimited RiskMinimal Risk

Tippe auf eine Ebene, um Details zu sehen

Level 1: Unacceptable Risk -- Prohibited. Social scoring, real-time biometric mass surveillance (with narrow law enforcement exceptions: searching for missing persons, preventing imminent terrorist threats, identifying suspects of serious crimes), manipulation of vulnerable groups, emotion recognition in workplaces. These systems simply must not exist.

Level 2: High Risk -- Strictly Regulated. Biometric identification, critical infrastructure, education, employment, creditworthiness, law enforcement, judicial support.

Level 3: Limited Risk -- Transparency Obligations. Chatbots, AI-generated media, deepfakes. Users must know they are interacting with AI.

Level 4: Minimal Risk -- No Special Obligations. Spam filters, search engines, recommendation systems, AI in video games.

Obligations for High-Risk Systems

ObligationDescription
Risk managementDocumented risk management system across the entire lifecycle
Data qualityTraining only with quality-assured, representative datasets
Technical documentationDetailed description of the system, its intended purpose, and performance limitations
Logging & audit trailAutomatic logging of all decisions for traceability
TransparencyClear user information that they are interacting with an AI system
Human oversightHuman-in-the-loop or human-on-the-loop for critical decisions
Accuracy & robustnessDemonstrated accuracy, cybersecurity, and resilience
Conformity assessmentBefore market placement: conformity proof (partially by third parties)

Penalties

ViolationPenalty
Deploying prohibited AI systemsUp to EUR 35M or 7% of global annual turnover
Violating high-risk obligationsUp to EUR 15M or 3% of global annual turnover
Providing false information to authoritiesUp to EUR 7.5M or 1% of global annual turnover

Reduced caps apply for SMEs and startups to avoid stifling innovation.

!Comparison with GDPR

The GDPR provides for a maximum penalty of 4% of annual turnover. The EU AI Act goes significantly beyond that at 7%. Companies that took the GDPR seriously should take the AI Act even more seriously.

Timeline

DateMilestoneStatus (September 2026)
August 2, 2024EU AI Act enters into force✅ active
February 2, 2025Bans on unacceptable AI systems take effect✅ active
July 2025Code of Practice for GPAI published✅ signatories benefit on fines
August 2, 2025Obligations for new GPAI models (GPT, Claude, Gemini)✅ active
July 27, 2026Digital Omnibus on AI (Reg. (EU) 2026/1744) in force✅ postpones high-risk deadlines
August 2, 2026Transparency obligations (Art. 50) + enforcement by the AI Office and member states (Art. 99/101)✅ active
December 2, 2026End of the grace period for marking pre-existing systems⏳
August 2, 2027Existing GPAI models must be fully compliant⏳ transition period
December 2, 2027High-risk obligations for stand-alone systems (Annex III)⏳ postponed by the Omnibus
August 2, 2028High-risk obligations for AI in regulated products (Annex I)⏳ postponed by the Omnibus

General Purpose AI (GPAI) -- Special Rules

Since August 2025, special rules apply to foundation models and general purpose AI:

  • All GPAI providers: Technical documentation, copyright compliance, transparency about training data
  • GPAI with systemic risk (>10^25 FLOPs training): Additional red-teaming, cybersecurity, energy reporting, incident reporting

*Code of Practice — fine mitigation

In July 2025, the European Commission published a Code of Practice for General-Purpose AI in cooperation with industry and civil society. Providers who voluntarily sign it have benefited from a milder enforcement approach since August 2, 2026: the Commission will focus its enforcement on adherence to the Code and may take Code commitments into account as mitigating factors when setting fines.

Verstehen

A company develops an AI system that automatically pre-sorts resumes and recommends candidates for interviews. Which risk class does this system fall into under the EU AI Act?

A startup develops an AI chatbot for customer service at an online shop. The chatbot answers questions about orders and returns. What obligation does the startup have under the EU AI Act?

iWhat This Means for You

If you're building a high-risk system, start documentation NOW. Introducing risk management, data quality, and audit trails retroactively is expensive and error-prone. Plan them from the start.

Anwenden

For Developers

  1. Risk classification first -- Before writing a single line of code, determine your system's risk class
  2. Data governance -- Document training data, sources, quality measures, and potential biases from the start
  3. Build audit trails -- Logging is not optional. Every decision must be traceable
  4. Test for bias and fairness -- Especially for high-risk systems, systematic bias testing is mandatory

For Organizations

  1. Create an AI inventory -- What AI systems do you use? What risk class do they fall into?
  2. Build a compliance team -- AI governance needs dedicated owners
  3. Vet suppliers -- If you use third-party AI systems, you're co-responsible as a "deployer"
  4. Mind the timeline -- Transparency obligations and enforcement have applied since August 2, 2026. For the high-risk obligations the Digital Omnibus bought time: Annex III applies from December 2, 2027, Annex I from August 2, 2028. That is a postponement, not an all-clear -- conformity assessment and technical documentation realistically need more than a year of lead time.

Reflect

The EU AI Act creates the world's first comprehensive legal framework for AI. The risk-based classification system determines what requirements your system must meet. Early compliance is not optional but mandatory. In the next section, you will learn how to concretely test for bias.