Free Consultation
Home Regulations EU Artificial Intelligence Act (Reg. 2024/1689)
Regulation

EU Artificial Intelligence Act (Reg. 2024/1689)

European Union · EU / EEA · Law

This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.

Authority
European Union
Jurisdiction
EU / EEA
Type
Law
Status
In force
Maximum penalty
Up to €35M or 7% of global annual turnover (GPAI-specific: up to €15M or 3%)
Catalogue reviewed
2026-08-15
Official source checked
2026-08-23 — unchanged since our last read
Official text

Status

In force, phased — prohibitions since Feb 2025; GPAI since Aug 2025; Art. 50 transparency since 2 Aug 2026 (Commission/AI Office enforcement powers over GPAI providers also became applicable that day); Annex III high-risk 2 Dec 2027; embedded/Annex I 2 Aug 2028. The later high-risk dates are now settled law: the Digital Omnibus was adopted 8 July 2026, published in the Official Journal 24 July 2026 as Regulation (EU) 2026/1744, and entered into force 27 July 2026 — the first formal amendment of the AI Act.

Requirements (15)

Art. 5 mandatory

Prohibited AI practices

Practices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market.

Satisfied by: Prohibited practices screen
Art. 9 mandatory

Risk-management system

Establish, document and maintain a continuous risk-management system across the AI lifecycle.

Satisfied by: Risk management system · Equivalent: NIST AI RMF 1.0 MANAGE 1.2, NIST AI RMF 1.0 MANAGE 1.3, NIST AI RMF 1.0 MAP 5.1, ISO/IEC 42001:2023 Annex A A.5.2, NIST AI RMF 1.0 GOVERN 1.3, NIST AI RMF 1.0 GOVERN 1.4, NIST AI RMF 1.0 MAP 1.5, NIST AI RMF 1.0 MANAGE 1.4
Art. 10 mandatory

Data & data governance

Training, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness.

Satisfied by: Data & data governance · Equivalent: NIST AI RMF 1.0 MEASURE 2.11, NIST AI RMF 1.0 MAP 2.3, ISO/IEC 42001:2023 Annex A A.7.2, ISO/IEC 42001:2023 Annex A A.7.4, ISO/IEC 42001:2023 Annex A A.7.5, NIST AI RMF 1.0 MEASURE 2.10, ISO/IEC 42001:2023 Annex A A.4.3, ISO/IEC 42001:2023 Annex A A.7.3, ISO/IEC 42001:2023 Annex A A.7.6
When this failed: Amazon recruiting tool biased against women · Apple Card credit-limit gender-bias claims · Ad-delivery algorithm enabled housing discrimination · Model data poisoning (PoisonGPT)
Art. 11 / Annex IV mandatory

Technical documentation

Draw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file).

Art. 12 mandatory

Record-keeping (logging)

Automatically record events (logs) over the system lifetime to ensure traceability.

Satisfied by: Record-keeping (logging) · Equivalent: ISO/IEC 42001:2023 Annex A A.6.2.8
Art. 13 mandatory

Transparency & instructions for use

Provide deployers with clear instructions: capabilities, limitations, and required human oversight.

Satisfied by: Instructions for use · Equivalent: NIST AI RMF 1.0 MAP 2.2, NIST AI RMF 1.0 MEASURE 2.8, ISO/IEC 42001:2023 Annex A A.8.2, NIST AI RMF 1.0 MAP 1.1, NIST AI RMF 1.0 MAP 3.3, NIST AI RMF 1.0 MEASURE 2.9, NIST AI RMF 1.0 MANAGE 1.4
Art. 14 mandatory

Human oversight

Design the system so humans can effectively oversee it, intervene, and stop it.

Satisfied by: Human oversight · Equivalent: NIST AI RMF 1.0 GOVERN 3.2, NIST AI RMF 1.0 MAP 3.5, NIST AI RMF 1.0 MANAGE 2.4, ISO/IEC 42001:2023 Annex A A.9.2, NIST AI RMF 1.0 MAP 2.2, NIST AI RMF 1.0 MAP 3.4, NIST AI RMF 1.0 MEASURE 2.6
When this failed: COMPAS recidivism scores racially biased · Dutch benefits-fraud algorithm discriminated · Over-reliance on driver-assist automation · Coding agent deleted a production database · AI hiring tool auto-rejected older applicants · UK A-level grading algorithm downgraded students · Algorithm auto-denied insurance claims at scale · Air Canada chatbot gave a false refund policy · Lawyer filed AI-hallucinated case citations · Solely-automated decision without safeguards
Art. 15 mandatory

Accuracy, robustness & cybersecurity

Achieve appropriate accuracy, robustness and cybersecurity, and declare metrics.

Satisfied by: Accuracy, robustness & cybersecurity · Equivalent: NIST AI RMF 1.0 MEASURE 2.5, NIST AI RMF 1.0 MEASURE 2.7, ISO/IEC 42001:2023 Annex A A.6.2.4, NIST AI RMF 1.0 MEASURE 1.1, NIST AI RMF 1.0 MEASURE 2.3, NIST AI RMF 1.0 MEASURE 2.6
When this failed: Knight Capital runaway trading algorithm · Over-reliance on driver-assist automation · Indirect prompt-injection data exfiltration · $25M lost to a deepfake video-call CEO · Model data poisoning (PoisonGPT) · Microsoft Tay turned toxic within hours · Hallucinated package names enable supply-chain attacks
Art. 27 mandatory

Fundamental Rights Impact Assessment

Certain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use.

Satisfied by: Fundamental rights impact assessment · Equivalent: NIST AI RMF 1.0 MAP 5.1, ISO/IEC 42001:2023 Annex A A.5.2, ISO/IEC 42001:2023 Annex A A.5.4
When this failed: Dutch benefits-fraud algorithm discriminated · UK A-level grading algorithm downgraded students
Art. 43 mandatory

Conformity assessment

Undergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry.

Satisfied by: Conformity assessment · Equivalent: NIST AI RMF 1.0 MEASURE 1.3, ISO/IEC 42001:2023 Annex A A.6.2.5
Art. 49 mandatory

EU database registration

Register the high-risk system in the EU database before placing it on the market.

Satisfied by: EU database registration · Equivalent: NIST AI RMF 1.0 GOVERN 1.6
Art. 50 mandatory

Transparency for certain systems

Inform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content.

Satisfied by: Transparency obligations · Equivalent: NIST AI RMF 1.0 MEASURE 2.8
When this failed: Dealer chatbot jailbroken into a $1 car offer
Art. 72 mandatory

Post-market monitoring

Operate a post-market monitoring system to collect and review performance data after deployment.

Satisfied by: Post-market monitoring · Equivalent: NIST AI RMF 1.0 MEASURE 2.4, NIST AI RMF 1.0 MANAGE 4.1, ISO/IEC 42001:2023 Annex A A.6.2.6, NIST AI RMF 1.0 GOVERN 1.5, NIST AI RMF 1.0 MEASURE 3.1, NIST AI RMF 1.0 MEASURE 4.3
When this failed: Zillow Offers iBuying model drift
Art. 73 mandatory

Serious-incident reporting

Report serious incidents and malfunctioning to the competent market-surveillance authority.

Satisfied by: Serious-incident reporting · Equivalent: NIST AI RMF 1.0 MANAGE 2.3, NIST AI RMF 1.0 MANAGE 4.3, ISO/IEC 42001:2023 Annex A A.8.4, NIST AI RMF 1.0 GOVERN 4.3

Dates that matter

Deadline 2025-02-02 · in force

EU AI Act — prohibited practices in force

Eight unacceptable-risk practices (social scoring, manipulative AI, untargeted face-scraping, most real-time biometric ID) are banned.

Action: Confirm none of your use cases fall under a prohibited practice.

Guidance 2025-07-10 · in force

EU AI Act — GPAI Code of Practice published

The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.

Action: Track and consider adhering to the GPAI code of practice; use its Model Documentation Form.

Enforcement 2025-08-02 · in force

EU AI Act — governance bodies & penalties live

National competent authorities and fines (up to 7% of global turnover for prohibited use) become enforceable.

Action: Confirm your EU market roles (provider/deployer) and an accountable owner.

Deadline 2025-08-02 · in force

EU AI Act — general-purpose AI (GPAI) obligations apply

GPAI providers owe transparency, technical documentation, copyright policy, and systemic-risk duties for capable models.

Action: Inventory GPAI/foundation models you build or rely on and keep model documentation.

Enforcement 2026-08-02 · in force

EU AI Act — Art. 50 transparency obligations in force

Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.

Action: These duties are already binding — audit your live products for AI disclosure now, and close the Art. 50(2) marking gap before 2 Dec 2026.

Deadline 2026-12-02 · in 100 days

EU AI Act — NCII/CSAM ban + end of marking grace period

The Digital Omnibus adds a prohibition on AI systems for non-consensual intimate imagery/CSAM and ends the synthetic-content marking grace period for pre-existing systems.

Action: Confirm generation guardrails block NCII/CSAM and that legacy systems mark synthetic content.

Deadline 2027-12-02 · in 465 days

EU AI Act — serious-incident reporting (Art. 73)

Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).

Action: Stand up an incident-detection, triage and reporting playbook with those clocks.

Deadline 2027-12-02 · in 465 days

EU AI Act — Annex III high-risk obligations apply

Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.

Action: Start the Annex IV technical file, risk-management system, and conformity plan now.

Deadline 2028-08-02 · in 709 days

EU AI Act — Annex I embedded high-risk obligations apply

High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.

Action: If your AI is a safety component of a regulated product, fold it into the sectoral conformity procedure.

Get told when this changes

Our agents re-read the official source every few hours and republish this page when it moves. Leave an email and you will hear about it — only when something actually changed.

Double opt-in. One confirmation email, then nothing until this regulation moves. Unsubscribe in one click.

Real incidents citing this regulation

Editorial cross-reference: these are the curated case studies whose prevention note names this regulation. It is not a finding of legal breach.

critical Art. 72 2021

Zillow Offers iBuying model drift

Zillow

Concept drift

Prevention: Post-market drift monitoring + human gatekeeping on price thresholds

critical Art. 14 · Annex III §8 2016

COMPAS recidivism scores racially biased

Northpointe

Disparate impact

Prevention: Fairness audit across groups + explainability + human oversight

critical Art. 15 2012

Knight Capital runaway trading algorithm

Knight Capital

Runaway autonomous action

Prevention: Kill switch + blast-radius limits + staged rollout

critical Art. 27 · Art. 14 2021

Dutch benefits-fraud algorithm discriminated

Netherlands govt

Bias + over-reliance

Prevention: Fundamental-rights impact assessment + human oversight

critical Art. 14 · Art. 15 2023

Over-reliance on driver-assist automation

Tesla

Automation over-reliance

Prevention: Effective human oversight + enforced operational design domain

critical Art. 14 2025

Coding agent deleted a production database

Reported (AI coding agent)

Unauthorized tool use

Prevention: Approval gates + least-privilege + backups + kill switch

critical Art. 10 2018

Amazon recruiting tool biased against women

Amazon

Training-data bias

Prevention: Pre-deployment bias audit + representative, examined training data

critical Art. 10 2019

Apple Card credit-limit gender-bias claims

Goldman Sachs

Disparate impact

Prevention: 4/5ths disparate-impact testing before launch

critical Art. 15 2023

Indirect prompt-injection data exfiltration

Multiple (Bing/Copilot demos)

Prompt injection

Prevention: Input/output filtering + least-privilege tool access

critical Annex III §1 2022

Clearview AI unlawful biometric scraping

Clearview AI

Unlawful processing

Prevention: Lawful basis + DPIA + biometric-use restrictions

critical Art. 14 2023

AI hiring tool auto-rejected older applicants

iTutorGroup

Age discrimination

Prevention: Bias audit + ADEA/ADA review + human review of rejections

critical Art. 15 2024

$25M lost to a deepfake video-call CEO

Arup

Deepfake social engineering

Prevention: Out-of-band verification + approval controls on payments

critical Art. 10 2022

Ad-delivery algorithm enabled housing discrimination

Meta

Discriminatory targeting

Prevention: Fairness constraints on delivery + ongoing audit

critical Art. 27 · Art. 14 2020

UK A-level grading algorithm downgraded students

Ofqual (UK)

Bias

Prevention: FRIA + transparency + an appeal/override path

critical Art. 10 · Art. 15 2023

Model data poisoning (PoisonGPT)

Research (Mithril)

Data / model poisoning

Prevention: Data & model provenance + supply-chain integrity

critical Art. 14 · Annex III §5 2023

Algorithm auto-denied insurance claims at scale

Health insurer

Automation harm / over-reliance

Prevention: Human review of adverse decisions + audit trail

major Art. 14 2024

Air Canada chatbot gave a false refund policy

Air Canada

Hallucination

Prevention: Ground answers in approved sources (RAG) + human oversight on policy claims

major Art. 15 2016

Microsoft Tay turned toxic within hours

Microsoft

Manipulation / toxic output

Prevention: Output guardrails + abuse red-teaming before release

major Art. 14 2023

Lawyer filed AI-hallucinated case citations

Law firm (Mata v. Avianca)

Hallucination

Prevention: Grounding with citations + mandatory human verification

major Art. 15 2024

Hallucinated package names enable supply-chain attacks

Research

Hallucination → supply chain

Prevention: Dependency allow-listing + SBOM + provenance checks

major Art. 14 2023

Solely-automated decision without safeguards

Various (GDPR fines)

Unlawful automated decision

Prevention: Art. 22 safeguards: meaningful human review + contest

major Art. 50 2023

Dealer chatbot jailbroken into a $1 car offer

Auto dealer

Jailbreak / prompt injection

Prevention: Output boundaries + topic guardrails + no binding actions