Home › EU AI Act Guide
Regulation (EU) 2024/1689, as amended by (EU) 2026/1744

EU AI Act: Complete Business Guide 2026

The world's first comprehensive AI law is now in force. Understand your obligations, key deadlines, and how to find compliant AI tools — all in one place.

✅ Verified Information 📅 Updated August 2026 🇪🇺 EU Official Sources
⚠️ Informational Content Only — Not Legal Advice
The information on this page is of a general nature only and is not intended to address the specific circumstances of any particular individual or entity. It is not necessarily comprehensive, complete, accurate, or up to date. It does not constitute legal advice, legal opinion, regulatory guidance, or a legal interpretation of any legislation. No attorney-client relationship is created by accessing or relying on this content. GateOnAI, the AI Decision Platform for Business, is an independent AI tools directory — not a law firm, regulatory body, or compliance consultancy. For advice specific to your organisation's obligations under the EU AI Act or any other regulation, consult a qualified legal professional specialising in EU technology law or contact your national competent authority.

You are solely responsible for how you use this information. It is your responsibility to independently verify anything on this page against the official sources linked below before relying on it, and to seek information from qualified, authoritative sources — especially where safety, legal compliance, or regulatory risk is involved.
📢 Update (July 2026): High-Risk Deadlines Postponed
On 24 July 2026, the EU published Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), which entered into force 27 July 2026 and amends the AI Act. The most significant change: the compliance deadline for stand-alone high-risk AI systems (Annex III) is deferred from 2 August 2026 to 2 December 2027. High-risk systems embedded in regulated products (Annex I) move from 2 August 2027 to 2 August 2028. National AI regulatory sandboxes are now due by 2 August 2027. A new prohibition on AI-generated non-consensual intimate imagery ("nudifiers") and CSAM was also added to Article 5.

Article 50 transparency obligations are NOT delayed — chatbot disclosure, deepfake labelling, and AI-generated content marking still apply from 2 August 2026 as originally scheduled.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive, horizontal legal framework governing artificial intelligence. Adopted by the European Parliament and Council, it entered into force on 1 August 2024 and applies a risk-based approach: the stricter the potential harm of an AI system, the more stringent the obligations.

Unlike sector-specific regulations, the AI Act applies across all industries and use cases — from healthcare and hiring to marketing automation and customer service. Crucially, it has extraterritorial reach: any organisation providing or deploying AI systems that affect people in the EU must comply, regardless of where that organisation is headquartered.

Official Reference: Regulation (EU) 2024/1689 of the European Parliament and of the Council — Published in the Official Journal of the European Union, 13 June 2024. Amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI") — published 24 July 2026, in force since 27 July 2026.
📖 Full Legal Text (EUR-Lex) 🔍 AI Act Explorer 🏢 European AI Office

Implementation Timeline

The AI Act follows a phased implementation schedule. Different obligations apply at different dates depending on the type of AI system and your role in the supply chain.

1 August 2024 — In Force
EU AI Act Enters into Force

The regulation was published in the Official Journal and became binding EU law. The phased implementation timeline begins.

2 February 2025 — Enforced
Prohibited AI Practices Banned

Article 5 prohibitions took effect. Unacceptable-risk AI systems — including social scoring, subliminal manipulation, and certain biometric surveillance — are now banned. Violations face fines of up to €35M or 7% of global turnover. AI literacy obligations (Article 4) also apply from this date.

2 August 2025 — Active
GPAI Model Obligations

General-Purpose AI (GPAI) model providers must comply with transparency requirements, technical documentation standards, and copyright policies. New GPAI models released after this date must comply immediately. Member States designate national competent authorities.

2 August 2026 — In Force
Transparency Obligations (Article 50)

Chatbot and AI-assistant disclosure, deepfake labelling, and marking of AI-generated content took effect from this date as originally scheduled — these obligations were not affected by the 2026 Digital Omnibus delay. See the dedicated section below for what this means in practice.

2 December 2026
Extended GenAI Content-Labelling Deadline

For generative AI models released before 2 August 2026, the deadline to label outputs as AI-generated (e.g. via watermarking) is extended from 2 August 2026 to 2 December 2026 under Regulation (EU) 2026/1744.

2 August 2027
National AI Regulatory Sandboxes

Each EU Member State must have at least one AI regulatory sandbox operational. This obligation was postponed by one year, from 2 August 2026, under Regulation (EU) 2026/1744.

2 December 2027 Critical Deadline
High-Risk AI System Obligations (Annex III)

The most significant milestone for most businesses. Stand-alone high-risk AI systems (Annex III — e.g. recruitment, credit scoring, education, critical infrastructure) must complete conformity assessments, establish risk management systems, maintain technical documentation, ensure human oversight, and register in the EU database. This deadline was deferred from 2 August 2026 by Regulation (EU) 2026/1744, published 24 July 2026.

2 August 2028
Full Application (Annex I Embedded Systems)

Obligations extend to high-risk AI systems embedded in regulated products already covered by EU product-safety law (medical devices, machinery, toys, automotive systems). Deferred from 2 August 2027 by Regulation (EU) 2026/1744.

🧭

Which sections of this guide are worth reading?

Tick anything that applies to your situation. This only highlights which parts of the AI Act text on this page may be relevant — it does not tell you whether you comply. Nothing you select is stored, saved, or sent anywhere — it runs entirely in your own browser and disappears when you close this page.

How do I know that's true?
This tool doesn't contact GateOnAI's servers at all — it never makes a network request of any kind while you use it. It doesn't use cookies, browser storage, or any other way of saving data on your device either. It only checks "is this box ticked?" inside your browser's own memory and shows or hides text already on this page — the same as opening and closing a drawer that's already in your room. Close or refresh this page and your answers are gone completely, as if they never existed. You can verify this yourself: open your browser's developer tools (Network tab) while using the checklist above and you'll see zero requests fire.

Risk Categories Explained

The AI Act classifies AI systems into four risk tiers. Your compliance obligations depend entirely on which tier your AI system falls into.

🧭
Walk through the four tiers step by step

Answer honestly based on the public criteria quoted below — this narrows down which tier card to read first, it does not classify your AI system for you. Nothing here is stored, saved, or sent anywhere — it runs entirely in your browser.

Question 1 of 3
Does your AI system do any of the following: social scoring by a public authority, real-time remote biometric surveillance in public spaces, subliminal manipulation, exploiting vulnerable people, emotion recognition at work or school, predictive policing based only on profiling, or generating non-consensual intimate imagery?
🚫
Tier 1
Unacceptable Risk — Prohibited

These AI systems are completely banned under Article 5. No compliance pathway exists — they must not be developed, deployed, or used.

Prohibited examples:
  • Social scoring systems by public authorities
  • Real-time remote biometric identification in public spaces (with narrow exceptions)
  • Subliminal manipulation causing harm
  • Exploitation of vulnerability of persons (age, disability, social situation)
  • Emotion recognition in workplace or education
  • Predictive policing based solely on profiling
  • AI-generated non-consensual intimate imagery ("nudifiers") and CSAM — added to Article 5 by Regulation (EU) 2026/1744, July 2026
Penalty: Up to €35M or 7% of global annual turnover
⚠️
Tier 2
High Risk — Strictly Regulated

Permitted, but subject to extensive obligations before market placement. Deadline: 2 December 2027 (deferred from 2 August 2026 by Regulation (EU) 2026/1744, in force since 27 July 2026).

High-risk use cases (Annex III):
  • Biometric identification and categorisation systems
  • AI in recruitment, CV screening, interview assessment
  • Credit scoring and insurance risk assessment
  • AI in medical devices and clinical decision support
  • Education: student assessment and performance evaluation
  • Law enforcement: evidence evaluation, criminal risk profiling
  • Migration and border control systems
  • Critical infrastructure: water, gas, electricity, road traffic
Required obligations: Risk management system • Data governance • Technical documentation • Transparency • Human oversight • Accuracy & robustness • Conformity assessment • EU database registration
Penalty: Up to €15M or 3% of global annual turnover
💬
Tier 3
Limited Risk — Transparency Obligations

Permitted with transparency requirements under Article 50. Users must be clearly informed they are interacting with an AI.

Examples:
  • Customer service chatbots and virtual assistants
  • AI-generated content (text, images, audio, video)
  • Deepfake generation tools
  • Emotion recognition systems (limited contexts)
  • Spam filters with direct user interaction
Obligation: Disclose AI nature to users. Label AI-generated content.
Tier 4
Minimal Risk — Largely Unregulated

The vast majority of AI tools fall here. The European Commission estimates approximately 85% of AI systems in the EU market are minimal risk. No mandatory obligations apply, though voluntary codes of conduct are encouraged.

Examples:
  • AI-enabled video games
  • Content recommendation systems
  • Writing assistants and productivity tools
  • Image generation for creative use
  • SEO and marketing analytics tools
Obligation: None mandatory. AI literacy (Article 4) still applies to all businesses.

AI-Generated Content Labelling: What Changed on 2 August 2026

On 20 July 2026, the European Commission adopted formal guidelines on the Article 50 transparency obligations, which took effect on 2 August 2026 as originally scheduled. These rules require clear disclosure across four areas: direct interaction with an AI system, AI-generated or AI-manipulated content, emotion recognition and biometric categorisation, and deepfakes or AI-generated text on matters of public interest. Non-compliance can attract fines of up to €15 million or 3% of worldwide annual turnover.

Alongside the guidelines, the AI Office published a voluntary Code of Practice on Transparency of AI-Generated Content, setting out concrete technical measures for marking and watermarking AI outputs. Signing the Code is treated by the Commission and the AI Board as an adequate way for organisations to demonstrate Article 50(2), (4) and (5) compliance, though signing it does not by itself guarantee compliance with the Act's other obligations.

The largest AI labs have begun adapting. OpenAI uses Google DeepMind's SynthID to embed an invisible watermark in AI-generated images, since extended to audio. Anthropic announced that all Claude models released from 2 August 2026 onward embed a watermark directly in generated text — imperceptible to readers and preserved when the text is copied elsewhere, since it is part of the text itself rather than a separate marker. Both companies have adopted the C2PA (Coalition for Content Provenance and Authenticity) standard for storing and transmitting content-provenance metadata.

For businesses that use AI tools to generate marketing copy, images, or other public-facing content, this matters directly: as a deployer of a generative AI system, you may have your own disclosure obligations under Article 50(4) when publishing AI-generated or AI-manipulated content, separate from the AI provider's own marking obligations as the tool's provider.

What Every Business Must Do Now

Regardless of your AI risk tier, Article 4 (AI literacy) applies to all organisations using AI as of February 2025. Here is a practical action plan:

📋
Step 1: Build an AI Inventory

Catalogue every AI system your organisation provides, deploys, or uses — including embedded AI in third-party tools (HR software, CRM, marketing platforms). Over 50% of enterprises lack a systematic AI inventory, creating immediate compliance risk.

🎯
Step 2: Classify by Risk Tier

Apply the four-tier classification to each system. Use the official AI Act Explorer or the EU Commission's compliance checker. Pay particular attention to HR, credit, medical, and education use cases — these are almost always high-risk under Annex III.

🚫
Step 3: Discontinue Prohibited Practices Immediately

Article 5 prohibitions have been in force since February 2025. If any of your AI systems fall under unacceptable risk — emotion recognition in the workplace, social scoring, certain biometric surveillance — discontinue them without delay. Enforcement is active.

📚
Step 4: Train Your Team (AI Literacy)

Article 4 requires that all staff using or overseeing AI systems have sufficient AI literacy. Document your training programme — without evidence of training, you cannot demonstrate compliance even if your systems are technically sound.

🔍
Step 5: Audit High-Risk Systems Before August 2026

For each high-risk AI system, complete: risk management documentation, data governance assessment, technical documentation, conformity assessment, and EU database registration. Implementation typically takes 12–18 months for complex organisations. Start now.

💬
Step 6: Add Transparency Notices

For limited-risk systems (chatbots, AI-generated content), ensure users are clearly informed they are interacting with AI. Label all AI-generated content. This applies immediately.

🇪🇺
Step 7: Choose Compliant Tools Going Forward

If Step 3 means retiring a prohibited-practice tool, or you're simply choosing new AI tools with EU compliance in mind, GateOnAI's EU-hosted & GDPR-flagged AI tools directory lets you filter specifically for that — a practical starting point, not a substitute for your own due diligence on each tool's actual compliance posture.

Official Resources & Further Reading

📖
Full Legal Text
EUR-Lex — Official EU Portal
The complete Regulation (EU) 2024/1689 in all 24 EU languages. The authoritative source.
🔍
AI Act Explorer
artificialintelligenceact.eu
Browse and search the full Act text with article-by-article navigation, implementation timeline, and compliance tools.
🇪🇺
European AI Office
European Commission
The official enforcement body responsible for GPAI model supervision, established February 2024. Publishes guidance and codes of practice.
💧
Code of Practice on AI-Generated Content
European Commission
The official voluntary framework for Article 50 marking, labelling, and watermarking obligations, in force from 2 August 2026.
📅
Implementation Timeline
artificialintelligenceact.eu
Updated timeline of all key dates and deadlines, linked to specific articles of the Act.
⚙️
AI Act Compliance Checker
artificialintelligenceact.eu
Free tool to assess whether your AI system falls under the Act's scope and which obligations apply.
🏛️
European Parliament Overview
European Parliament
Official European Parliament summary of the AI Act, its goals, and key provisions.
🎯 The AI Decision Platform for Business

GateOnAI Ecosystem

One platform. Every AI tool, workflow, and comparison you need — EU-hosted, independent, always free.

Frequently Asked Questions

What is the EU AI Act?

The EU AI Act (Regulation EU 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and establishes binding rules for AI systems placed on the EU market or used within the EU, regardless of where the provider is headquartered.

Who does the EU AI Act apply to?

The Act applies to any organisation — EU-based or not — that provides, deploys, or uses AI systems affecting people within the European Union. This includes software vendors, businesses using third-party AI tools, importers, and distributors. If your AI system touches EU users, you are in scope.

What are the key deadlines?

2 February 2025: Prohibited AI practices banned. 2 August 2025: GPAI model obligations and national authority designation. 2 August 2026: Article 50 transparency obligations (chatbot disclosure, deepfake labelling) - unaffected by the 2026 delay. 2 December 2026: Extended deadline for labelling generative AI content from models released before August 2026. 2 August 2027: National AI regulatory sandboxes. 2 December 2027: High-risk AI system obligations (Annex III) - deferred from the original 2 August 2026 date by Regulation (EU) 2026/1744, in force since 27 July 2026. 2 August 2028: Full compliance for high-risk AI embedded in regulated products (Annex I).

What are the penalties for non-compliance?

Fines reach up to EUR 35 million or 7% of global annual turnover for prohibited practices — exceeding GDPR levels. High-risk non-compliance: up to EUR 15 million or 3% of turnover. Providing incorrect information to authorities: up to EUR 7.5 million or 1% of turnover. SMEs and startups benefit from proportionate caps.

What is a high-risk AI system?

High-risk AI systems include those used in biometrics, recruitment and HR decisions, credit scoring, medical devices, education assessment, law enforcement, migration, and critical infrastructure. These systems must meet strict requirements including risk management, data governance, transparency, human oversight, and conformity assessment. Following Regulation (EU) 2026/1744 (July 2026), the deadline for stand-alone (Annex III) high-risk systems is 2 December 2027, and for high-risk systems embedded in regulated products (Annex I) it is 2 August 2028.

Does the EU AI Act apply to AI tools I use (not build)?

Yes. Businesses that deploy third-party AI tools — such as HR screening tools, customer service chatbots, or credit assessment software — are considered deployers and have obligations under the Act. This includes maintaining an inventory of AI systems, ensuring AI literacy among staff, and verifying that high-risk tools meet compliance requirements.

What should my business do right now?

Start with an AI inventory: catalogue every AI system you use or provide. Classify each by risk tier. For prohibited practices (already banned since February 2025), discontinue immediately. For high-risk systems, begin conformity assessment and documentation. Ensure AI literacy training for staff — Article 4 is already in force.

⚠️ Legal Notice
This page is provided for general informational and educational purposes only. GateOnAI makes no representations or warranties of any kind, express or implied, regarding the completeness, accuracy, reliability, or suitability of the information contained herein. GateOnAI accepts no responsibility or liability whatsoever with regard to any decisions made or actions taken in reliance on the information on this page. The binding interpretation of EU legislation is the exclusive competence of the Court of Justice of the European Union. Laws and regulations change frequently — always verify with official EU sources before making compliance decisions. External links are provided for convenience only; GateOnAI has no control over and assumes no responsibility for the content of external sites.

By using this page, you acknowledge and accept that you are responsible for what you read here and for where you go to verify it. Always cross-check against the official sources linked on this page, and for compliance, safety, or legal decisions, consult a qualified professional or your national competent authority rather than relying on this page alone.

Sources: Regulation (EU) 2024/1689 (Official Journal, 13 June 2024) • Regulation (EU) 2026/1744 (Official Journal, 24 July 2026) • artificialintelligenceact.euEuropean AI OfficeEUR-Lex