In Force

The EU AI Act: Complete Guide (2026)

The world's first comprehensive AI regulation. Everything you need to know about compliance, risk classification, prohibited practices, and enforcement.

Last updated: March 2026

Overview

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on August 1, 2024, with a phased implementation extending through 2027. The Act establishes a risk-based approach to regulating AI systems within the European Union.

Risk Classification System

Unacceptable Risk — Prohibited

Social scoring by governments, real-time remote biometric identification in public spaces (with exceptions), manipulation of vulnerable groups, and emotion recognition in workplaces and schools.

High Risk — Strict Requirements

AI in critical infrastructure, education, employment, law enforcement, migration, and justice. Requires conformity assessments, risk management systems, data governance, and human oversight.

Limited Risk — Transparency Obligations

Chatbots, deepfakes, and emotion recognition systems must disclose they are AI-powered. Users must know they are interacting with AI.

Minimal Risk — No Restrictions

AI-enabled video games, spam filters, and other low-risk applications. No regulatory requirements, but voluntary codes of conduct are encouraged.

General-Purpose AI Models (GPAI)

The Act introduces specific rules for general-purpose AI models (like GPT, Claude, and Llama). All GPAI providers must:

  • Provide technical documentation and training data summaries
  • Comply with EU copyright law (including text and data mining opt-out)
  • High-impact models (above 10^25 FLOPs threshold) face additional obligations including adversarial testing and incident reporting

Penalties

Non-compliance carries significant financial penalties:

  • Prohibited AI practices: Up to 35 million EUR or 7% of global annual turnover
  • High-risk non-compliance: Up to 15 million EUR or 3% of global annual turnover
  • Misinformation to authorities: Up to 7.5 million EUR or 1% of global annual turnover

Implementation Timeline

Date Milestone
Aug 2024Entry into force
Feb 2025Prohibited AI practices apply
Aug 2025GPAI model obligations apply
Aug 2026Most provisions fully applicable
Aug 2027High-risk AI in Annex I fully applicable