EU AI Act
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
World's first comprehensive risk-based regulatory framework for AI systems. Classifies AI by risk level with escalating requirements from prohibited practices to high-risk obligations.
Jurisdiction
European Union
Enacted
Jul 12, 2024
Effective
Aug 1, 2024
Enforcement
AI Office (European Commission) + national authorities
Phased implementation through 2028. High-risk timelines were deferred by the Digital Omnibus on AI (in force 2026-07-27, tracked separately as eu-digital-omnibus-ai).
EUR-LexWhy It Matters
Article 5(1)(b) prohibits AI that exploits vulnerabilities (including age) to distort behavior causing significant harm. Sets global precedent for risk-based AI regulation.
Recent Developments
Code of Practice on AI-Generated Content (Article 50): now finalized with over 180 signatory organizations as of July 31, 2026. First EU AI standard (EN 18286, Quality Management System) published July 22, 2026. On August 2, 2026, the AI Office's enforcement powers formally activated (system-change requests, fines, EU market-access blocks) and Article 50 transparency/disclosure obligations became binding — but the Digital Omnibus on AI deferred the high-risk system requirements that were originally due this date: Annex III high-risk obligations now apply from December 2, 2027, and Annex I high-risk (regulated products) from August 2, 2028. Each Member State must still establish at least one AI regulatory sandbox by August 2, 2026 per the base Act.
At a Glance
Applies to
Harms addressed
Who Must Comply
- AI system providers
- Deployers
- Importers/distributors of in-scope AI
Safety Provisions
- Prohibited: AI exploiting vulnerabilities (age, disability) causing psychological harm
- Prohibited: Social scoring, predictive policing based on profiling, emotion recognition in schools/workplaces
- High-risk systems require: risk management, data governance, human oversight, transparency
- Conformity assessments before market placement
- Post-market monitoring and incident reporting
Compliance & Enforcement
Key Dates
Feb 2, 2025
Prohibited AI practices enforceable; AI literacy obligations
Aug 2, 2025
GPAI model obligations; Member States designate authorities
Aug 2, 2026
AI Office enforcement powers activate; Article 50 transparency/AI-generated-content disclosure obligations become binding; Member States must have at least one AI regulatory sandbox established
Dec 2, 2027
Annex III high-risk AI system requirements (deferred from 2026-08-02 by the Digital Omnibus on AI)
Aug 2, 2028
Annex I high-risk AI in regulated products (deferred from 2027-08-02 by the Digital Omnibus on AI)
Penalties
€35M or 7% revenue (whichever higher)
Primary Source
EUR-Lex
https://eur-lex.europa.eu/eli/reg/2024/1689/oj
View on map
European Union
Focus Areas
Cite This
APA
European Union. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act).
Related Regulations
EU Digital Omnibus (AI)
Amendments to the EU AI Act (Regulation (EU) 2026/1744, in force July 27, 2026) that delay high-risk AI system obligations by up to 16 months, make compliance timing conditional on availability of harmonised standards and support tools, and add a new Article 5 prohibition on AI systems for generating non-consensual intimate imagery (nudification tools) and CSAM.
EU CRA
Mandatory cybersecurity requirements for all products with digital elements placed on the EU market, including AI software. Requires security by design, vulnerability handling, incident reporting to ENISA, software bills of materials, and CE marking for market access.
Germany KI-MIG
German national law implementing the EU AI Act, designating the Bundesnetzagentur (BNetzA) as the lead market surveillance authority under a centralized hybrid model.
NZ Biometric Code
Sets specific legal requirements under Privacy Act for collecting and using biometric data such as facial recognition and fingerprint scans. Prohibits particularly intrusive uses including emotion prediction and inferring protected characteristics like ethnicity or sex.
TX Healthcare AI Law
Requires healthcare practitioners using AI for diagnosis to review all AI-generated records and disclose AI use to patients. Mandates EHR data localization (Texas patient data must be physically stored in US). Applies to covered entities and third-party vendors.
AU Privacy Amendment 2024
Strengthens Privacy Act requirements for biometric data collection, raising the standard of conduct for collecting biometric information used for automated verification or identification. Cannot collect such information unless individual has consented and it is reasonably necessary.
Last updated August 2, 2026. Verify against primary sources before relying on this information.