The EU AI Act is the first general-purpose law in the world that defines what artificial intelligence is allowed to do in Europe and what it isn’t. It is not a sector-specific document for healthcare or banking — it is a horizontal regulation that covers anything where AI takes decisions, generates content, evaluates people, or affects their rights.
If your bank runs AI-driven credit scoring, your hospital uses AI to read scans, your HR department filters CVs through an AI tool, or you build AI products for the European market — this law applies to you. The Act entered into force on 1 August 2024 and is phased in until 2 August 2027. The most serious breaches are punishable by fines of up to €35 million or 7% of worldwide turnover.
This page is the canonical klarproof guide — every key claim is sourced directly to EUR-Lex or the European Commission.
Quick facts
- Full name: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act)
- Adopted: 13 June 2024
- Published in OJ: 12 July 2024 (OJ L, 2024/1689)
- Entered into force: 1 August 2024 (twentieth day after publication)
- Full applicability: 2 August 2026 (with phased earlier deadlines and one later)
- Penalties: up to €35M / 7% worldwide turnover (Article 5 violations); €15M / 3% (other obligations); €7.5M / 1% (incorrect information)
- Central enforcer: the European AI Office within the Commission for foundation models like GPT and Claude; national authorities in each Member State for everything else
- First to act: Italy passed Law No. 132/2025 on 10 October 2025 — the first national framework complementing the AI Act
- Source of truth on EU side: eur-lex.europa.eu, European Commission AI Office page, AI Act Service Desk
What the AI Act actually is
The AI Act is a horizontal regulation. Sounds dry, but it matters: unlike GDPR (which regulates data protection) or MiCA (which regulates crypto), this Act regulates a way of using technology across all sectors at once. Healthcare, finance, hiring, education, law enforcement, transport, public services — wherever AI shows up, the same baseline rules apply.
The Act does not replace GDPR. The two laws operate in parallel and frequently overlap: GDPR governs the personal data flowing through an AI system, while the AI Act governs how the AI system itself is built, tested and supervised. Most of the first big AI-related fines in Europe are still GDPR fines: the Italian Garante hit OpenAI for €15 million (December 2024) and Replika for €5 million (April 2025). Both cases concern AI training on personal data without lawful basis (see the dedicated klarproof registry of Garante AI cases).
The Act packages two distinct things into one regulation:
- AI systems — concrete software built for a concrete task: a bank’s chatbot, a credit-scoring engine, a face-recognition gate at an office, AI-driven medical imaging. Regulated by how much risk they pose to people (see below).
- General-purpose AI models (GPAI) — large foundation models like GPT (OpenAI), Gemini (Google), Claude (Anthropic), Llama (Meta), Mistral. They are not “AI systems” in themselves but the engines on top of which thousands of other companies build products. They get separate rules in Chapter V, and those rules began applying earlier than most other parts of the Act.
Provider and deployer — the two key roles
The Act keeps using two specific words — “provider” and “deployer”. They look like ordinary English, but here they’re regulatory statuses with different sets of obligations:
- Provider — whoever builds the AI system and puts it on the market under their own name or brand. OpenAI is the provider of GPT. Anthropic is the provider of Claude. A startup that makes an AI résumé-screening tool and sells it to HR departments is the provider of that tool.
- Deployer — the organisation that uses someone else’s AI system in its own operations. The bank running an external AI scoring engine for credit decisions. The hospital running AI on its MRI scans. The HR team filtering CVs through an AI shortlist. Not the same as the end user — the person whose loan application that AI evaluates is not a “deployer” under the Act; the law leaves that person without a separate label.
This split matters because providers and deployers carry different obligations. The provider is responsible for how the product is built (documentation, testing, risk assessment). The deployer is responsible for how the product is used in the real world (human oversight, monitoring, informing users).
The Act is extraterritorial — like GDPR, it applies to companies outside the EU if their outputs are used in Europe. A US-based AI vendor whose system is used by an EU bank for credit scoring is in scope: the US developer is the provider, the bank is the deployer.
The risk-based architecture: four classes
The AI Act regulates outcomes for people, not the underlying technology (neural network vs decision tree vs regression). It looks at how much harm an AI system could cause and sets the obligation level accordingly.
A simple analogy: how medicines are sold. A vitamin tablet sits on any supermarket shelf; an over-the-counter painkiller is behind the pharmacy counter with warnings on the box; an antibiotic needs a doctor’s prescription; an addictive narcotic is banned outright. It’s all “a substance you swallow” — what changes the rules is not the chemistry but how badly it can harm a person. The AI Act sorts AI systems the same way: four buckets, from unregulated up to outright prohibited, by increasing strictness.
1. Prohibited practices (Article 5)
A short list of practices for which the EU has decided that no safeguard is enough — they are simply banned. Eight of them are listed in Article 5(1). They have applied since 2 February 2025. A breach falls under the top fine tier: €35M / 7% turnover.
| Prohibition | What this looks like in practice | |
|---|---|---|
| (a) | Subliminal, manipulative or deceptive techniques | AI that nudges people in ways they aren’t aware of and to their detriment. For example, an AI assistant subtly steering vulnerable users towards financially harmful choices |
| (b) | Exploitation of vulnerabilities | AI that exploits age, disability or socio-economic situation. For example, ad-targeting AI promoting online gambling to people showing signs of addiction |
| (c) | Social scoring | Generalised classification of people based on behaviour or personality, leading to detrimental treatment in unrelated contexts. For example, denying someone a banking service because their “social score” — based on conduct in a completely unrelated setting — is low |
| (d) | Predictive criminal risk assessment | Predicting that someone will commit a crime purely from profiling, without specific evidence. The “police predicts crime by neighbourhood and demographics” script. Narrow exceptions exist |
| (e) | Untargeted facial-image scraping | Building face-recognition databases by scraping random photos from the internet or CCTV footage. This wording landed in the Act directly out of the Clearview AI case |
| (f) | Emotion inference at work or school | AI that decides an employee’s or student’s “mood” from face, voice, posture. Narrow medical exceptions (e.g. patients in coma) |
| (g) | Sensitive biometric categorisation | Inferring race, political opinions, religion or sexual orientation from biometric data (face, fingerprint, voice) |
| (h) | Real-time remote biometric ID for law enforcement | Live face recognition through public cameras for police purposes in publicly accessible spaces. Narrow exceptions for serious specific objectives |
The European Commission’s Guidelines on Article 5 (published 4 February 2025) walk through each prohibition with concrete examples.
2. High-risk (Article 6 + Annex III)
The bulk of the Act’s obligations sits here. An AI system is classified high-risk if it falls into one of two routes:
-
Route 1: AI as a safety component of an already-regulated product. AI inside medical devices, machinery, vehicles, lifts, toys. These products already go through certification under their sector laws — now an AI layer is added. Applies from 2 August 2027.
-
Route 2: AI in one of the eight Annex III categories — a list of “sensitive applications” where AI directly affects people’s rights or access to services. Applies from 2 August 2026. Specifically:
- Biometrics (face recognition outside the prohibited list, identity verification)
- Critical infrastructure (electricity, water, digital infrastructure)
- Education (AI grading work, AI deciding admissions)
- Employment (AI CV-filtering, employee evaluation, promotion or dismissal decisions)
- Access to essential services (credit scoring, insurance, public benefits, emergency response)
- Law enforcement
- Migration, asylum, border control
- Administration of justice and democratic processes
If an AI system falls into one of these scenarios, providers and deployers must run through a full regulatory checklist:
- risk management (a formal process to identify and mitigate risks),
- data governance (controlling training-data quality, removing bias),
- technical documentation,
- transparency to deployers,
- human oversight of decisions,
- accuracy and robustness requirements,
- registration in an EU-wide database of AI systems,
- a formal conformity assessment (the procedure that verifies compliance — either internally or through a certified body),
- post-market monitoring.
Non-compliance: €15M / 3% turnover tier.
3. Limited risk (Article 50 transparency obligations)
AI systems that interact with humans or generate content but don’t fall into the high-risk list. For example:
- chatbots (banking, e-commerce, support),
- AI-generated images, video, audio, including deepfakes,
- AI synthesising voice or text.
The main obligation is transparency. Users must know they’re talking to AI, not a human. AI-generated content must be machine-readably marked — meaning the file must carry metadata that lets a program automatically detect “this was AI-made”. Applies from 2 August 2026 (some provisions earlier).
4. Minimal or no risk
Everything else — spam filters, AI in video games, content recommenders, inventory optimisation, autocomplete in your inbox. Not regulated by the Act, although the EU encourages voluntary codes of conduct.
Rules for foundation models (Chapter V)
General-purpose AI models (GPAI) are GPT, Claude, Gemini, Llama, Mistral and similar. They are not “AI systems” in themselves: they are the engines that thousands of other companies use as a foundation for their own products. So regulating them via the risk-class system doesn’t fit — the same GPT can power both an e-commerce chatbot (minimal risk) and a bank’s credit scoring (high risk).
The Act splits GPAI providers into two tiers:
- Standard GPAI providers must publish: technical documentation (how the model is built), a copyright policy (how they respect rights to training data), a training-data summary (general description of what the model was trained on), and provide information to downstream deployers (companies that integrate the model into their products).
- GPAI with systemic risk — the largest models, capable of causing substantial systemic harm. Defined by training-compute threshold (currently 10²⁵ FLOPs — the GPT-4 scale and above) or by Commission designation. Additional obligations: formal model evaluation, adversarial testing (deliberate attempts to break the model and make it produce something harmful), serious-incident reporting, cybersecurity requirements.
GPAI obligations entered application on 2 August 2025.
The GPAI Code of Practice: what it is and why sign it
The Act sets requirements in general terms: “you need a risk assessment”, “you need technical documentation”, “you need incident reporting”. But what counts as an adequate risk assessment? Which document templates work? What counts as a “serious incident”?
To prevent compliance from collapsing into years of legal back-and-forth on every single point, on 10 July 2025 the Commission published the GPAI Code of Practice — a voluntary document that spells out how exactly providers of foundation models should meet the Act’s requirements. In effect, it’s a “playbook”: here are templates for the risk assessment, criteria for serious incidents, examples of acceptable technical documentation.
Signing the Code gives a company a “presumption of conformity” — by default, the regulator assumes the company is doing things right and only requires evidence to the contrary if there is a specific cause. Not signing means the company has to prove compliance from scratch on every individual point, under closer regulatory scrutiny and with a higher chance of being investigated for each separate step.
23 organisations have signed the Code in full — including the largest foundation-model players (OpenAI, Anthropic, Google, Microsoft, Mistral, IBM, Amazon, Cohere, Aleph Alpha) alongside more than a dozen EU SMEs and start-ups — plus xAI (Elon Musk), which signed only the Safety & Security chapter. Meta is the most prominent non-signatory: it publicly declined to join the Code in July 2025, citing legal and operational concerns. For non-signatories or partial signatories, compliance has to be demonstrated through alternative means on every uncovered topic — which in practice translates into closer regulatory attention to every move.
The phased timeline (Article 113)
The Act doesn’t switch on all at once — it rolls out in waves:
| Date | What starts to apply |
|---|---|
| 1 August 2024 | The Act enters into force — most provisions still dormant |
| 2 February 2025 | Prohibited practices (Article 5) and the AI literacy requirement (Article 4 — companies must train staff who work with AI in basic awareness of its capabilities and risks) |
| 2 August 2025 | GPAI rules (Chapter V); governance bodies stand up (AI Office, Board, Scientific Panel, Advisory Forum); penalties (Chapter XII); confidentiality rules (Article 78); national notifying authority designations |
| 2 August 2026 | Most of the rest — high-risk Annex III categories, Article 50 transparency obligations, conformity assessment for new systems, regulatory sandboxes (controlled “safe zones” where companies can test new AI under a regulator’s supervision without full compliance) |
| 2 August 2027 | The final layer — high-risk AI as a component of products with mandatory certification (medical devices, machinery, lifts — Annex I) |
The key date for most businesses is 2 August 2026. That’s when the operational compliance work for high-risk AI under Annex III kicks in: banks, HR, insurance, education, public services.
Governance: who supervises and who enforces
The AI Act uses the same hybrid model as GDPR: an EU-wide layer plus 27 national regulators. By analogy with GDPR, where coordination across countries is done by the EDPB and national DPAs handle enforcement at home — the AI Act takes a similar shape.
EU level
- European AI Office (Article 64) — a new Commission unit set up specifically for the AI Act. Sits within DG CONNECT (the Commission’s “digital future” directorate). 125+ staff across six units. The AI Office’s main role is supervision and enforcement of GPAI providers. That means OpenAI, Anthropic, Google, xAI and similar are answerable directly to Brussels, not to individual countries. Full profile: Who is the European AI Office.
- European Artificial Intelligence Board (Article 65) — a Board with one representative from each Member State, three-year terms (renewable once), chaired by one of the members. The AI Office and the EDPS (the EU institutions’ data-protection supervisor) attend as non-voting observers. The Board coordinates national regulators and advises the Commission.
- Scientific Panel of Independent Experts (Article 68) — a technical advisory group of academics attached to the AI Office, especially for evaluating systemic-risk GPAI.
- Advisory Forum (Article 67) — industry, SMEs, start-ups, civil society, and academia. Provides expert input to the Board and the Commission.
National level
By 2 August 2025, each Member State was required to designate at least one national competent authority, split across two roles:
- Notifying authority — accredits the independent labs that will then carry out conformity assessment for high-risk AI systems.
- Market surveillance authority — investigates breaches and applies fines.
Implementation differs sharply across countries:
- 🇪🇸 Spain — AESIA (Agencia Española de Supervisión de la Inteligencia Artificial) was legally established by Royal Decree 729/2023 on 22 August 2023 and officially presented on 19 June 2024 in A Coruña — the EU’s first dedicated AI agency. Spain didn’t bolt AI supervision onto its existing DPA; it built a separate body.
- 🇮🇹 Italy — Law No. 132/2025 entered into force on 10 October 2025 — the first national AI law in the EU complementing the AI Act. Designates AgID (notifying), ACN (market surveillance + the EU single point of contact). The Garante’s GDPR remit is preserved — so two regulators now look at AI from two different angles.
- 🇩🇪 Germany — the Federal Network Agency (BNetzA) is designated as the primary market surveillance authority; the BfDI (federal data protection ombudsman) is explicitly excluded. The KI-MIG implementation act has advanced to a government draft — the Federal Cabinet adopted the Regierungsentwurf on 10 February 2026 and it is now in parliamentary procedure (Bundestag, then Bundesrat), but not yet enacted. Germany missed the 2 August 2025 deadline.
- 🇮🇪 Ireland — went the distributed model route: 15 sectoral national competent authorities each handle AI in their own area (DPC for data, Central Bank for finance, Coimisiún na Meán for media, Health and Safety Authority for workplace safety, ComReg for electronic communications, CCPC for consumer protection, HPRA for medical products, etc.). A separate National AI Office (NAIO) sits alongside them as a coordinating body — not itself a market-surveillance authority — and will act as the national Single Point of Contact once formally established in 2026; until then the Minister for Enterprise, Tourism and Employment holds the SPoC role.
- The other 23 Member States — at varying stages of readiness; many are still finalising designations and domestic legislation.
Penalties (Article 99)
Three administrative-fine tiers. For each violation the higher of two amounts applies — a fixed cap or a percentage of worldwide annual turnover:
| Tier | What triggers it | Maximum |
|---|---|---|
| 1 | Article 5 prohibited practices (the eight from the table above) | €35,000,000 or 7% worldwide turnover |
| 2 | Other obligations on providers, deployers and notified bodies: high-risk requirements, GPAI rules, registration, etc. | €15,000,000 or 3% |
| 3 | Providing incorrect, incomplete or misleading information to authorities | €7,500,000 or 1% |
For SMEs and start-ups the rule flips to the lower of the two amounts — a proportional safeguard. Small companies shouldn’t be wiped out by the same numerical fine that would land on OpenAI.
For context: GDPR’s top tier is €20M / 4%. The AI Act’s top tier is €35M / 7% — roughly twice the maximum financial exposure. The drafting choice is deliberate: the EU is signalling that prohibited AI practices — social scoring, manipulative AI, biometric tracking — are, in their judgment, a more serious category of harm than even the worst data-protection violations.
How the AI Act overlaps with GDPR
Often confused. The two laws apply concurrently to any AI system processing personal data:
- AI Act governs the AI system itself: which risk class it sits in, what documentation is needed, how it’s certified, how oversight is set up.
- GDPR governs the personal data flowing through the system: lawful basis, transparency to data subjects, what the rights are, what training data is legal.
The Garante’s actions against OpenAI (€15M, December 2024 — annulled by the Tribunale di Roma on 18 March 2026) and Replika (€5M, April 2025) are GDPR cases (Articles 5, 6 GDPR plus related transparency and accountability provisions), even though the underlying issue is AI. The OpenAI annulment is itself a milestone — it was the only final GDPR enforcement decision in Europe targeting the launch period of generative AI, and a court of first instance has now overturned it. This pattern will continue: most AI-system enforcement in the next 2–3 years will run on GDPR rails, simply because GDPR is already operational while the AI Act process is still settling in.
What’s actually happening as of May 2026
Real AI-Act-specific enforcement (i.e. fines under Article 99) is still minimal. The Article 5 prohibitions only entered application on 2 February 2025; market surveillance authorities are still organising; conformity assessment for high-risk systems doesn’t begin until 2 August 2026.
What is happening:
- GDPR-grounded AI cases — Garante OpenAI €15M (Dec 2024, annulled by Tribunale di Roma 18 Mar 2026), Garante Replika €5M (Apr 2025), CNIL guidance on training data published through 2024–2025 (see cnil.fr for the current list).
- Pressure on those who didn’t sign the GPAI Code of Practice. Foundation-model providers that haven’t joined the Code (xAI partial; some smaller ones not at all) face closer individual regulatory scrutiny: every step is examined separately, without a presumption of conformity. This is not a fine — it’s a continuous oversight overhead.
- National regulatory sandbox applications — opening in 2026 across several countries. These are “safe zones” where companies can test new AI systems under a regulator’s supervision without full compliance with the Act.
The dedicated klarproof registry of Garante’s AI cases now covers both fines in full — the exact articles, corrective measures and the court status of each. For the broader EU picture, enforcementtracker.com (filter by “AI”) lists GDPR fines across all Member States.
What this means for you
If you’re a provider (you build AI):
- Identify your products’ risk class. Most B2B AI is not high-risk; check Article 6 + Annex III carefully against your use cases. Misclassification is the most expensive mistake.
- If you build a foundation model (GPAI), sign the Code of Practice or be ready to prove compliance from scratch on every single point.
- By 2 August 2026 you should have technical documentation, a risk-management process, and post-market monitoring in place.
- Decide your conformity-assessment route in advance: internal control vs. third-party body — this drives both cost and timeline.
If you’re a deployer (you use AI in your business):
- Run an inventory of your AI systems. Map which are high-risk (HR, credit scoring, etc. under Annex III), which are limited-risk (chatbots, content generation), which are minimal.
- For high-risk deployments: write down human-oversight protocols, monitoring procedures, and instructions for staff who interact with the AI.
- For limited-risk: visible disclosure to users that they’re talking to AI; machine-readable marking of AI-generated content (deepfakes, AI text, AI images).
- AI literacy training (Article 4) for staff who work with AI is already required since 2 February 2025.
If you operate in finance, healthcare, hiring, public services, or law enforcement — assume you already have high-risk AI systems and budget for full conformity assessment. The EU is clearly signalling that these sectors are first in line for regulatory attention.
TL;DR
The EU AI Act is the world’s first comprehensive AI regulation, applied in waves: prohibited practices already in force (since 2 February 2025); rules for foundation models like GPT/Claude in force since 2 August 2025; the bulk of high-risk AI requirements from 2 August 2026; AI as a component in certified products (medical devices, machinery) from 2 August 2027. Risk architecture: 8 prohibited practices; high-risk systems (banks, HR, education, healthcare) go through full certification; limited-risk (chatbots, deepfakes) need transparency; minimal-risk is unregulated. Penalties run up to €35M / 7% turnover for prohibited practices — roughly twice the GDPR ceiling. The European AI Office in Brussels supervises foundation models; national authorities cover everything else. National implementation differs sharply: Spain (AESIA, the EU’s first dedicated AI agency), Italy (the first national AI law, 132/2025), Germany (BNetzA, KI-MIG act not yet passed), Ireland (a distributed 15-authority model). Real AI-Act-specific enforcement in 2026 is still minimal; the first AI cases are running through GDPR (Garante: €15M against OpenAI, €5M against Replika).
Sources
- Regulation (EU) 2024/1689 — full text on EUR-Lex — official source of the AI Act
- European AI Office — official Commission page — mandate, structure, contact
- AI Act Service Desk — Commission’s compliance support portal
- Commission Guidelines on prohibited AI practices, 4 February 2025
- GPAI Code of Practice — official text and signatories (EU Commission)
- Italy Law No. 132/2025 analysis (Covington Global Policy Watch) — first national AI law in the EU
- AESIA — Spanish AI supervisory agency — first dedicated EU AI agency
- Article-by-article reference (artificialintelligenceact.eu) — independent comprehensive reference, useful for navigation