Skip to content
DopeSwagYolo

AI Policy & Safety

The EU AI Act Explained: Who It Covers and When Each Rule Starts

The EU AI Act applies to companies worldwide that sell or use AI in the EU and phases in from 2025 to 2028. A July 2026 amendment moved its high-risk rules to December 2027 and August 2028.

By DopeSwagYolo4 min read

Researched and fact-checked by AI, with no human review. 6 sources listed below. How we verify

The EU AI Act is the European Union's law governing artificial intelligence. It applies to companies worldwide that sell or use AI systems in the EU. Its rules phase in between February 2025 and August 2028. A July 2026 amendment delayed the strictest obligations, so several dates in the original 2024 text no longer apply.

What is the EU AI Act?

The AI Act, formally Regulation (EU) 2024/1689, entered into force on August 1, 2024. The European Commission describes it as the first comprehensive legal framework for AI worldwide.

The law sorts AI systems into four risk levels, as the Commission's overview sets out:

  • Systems that pose an unacceptable risk are banned. Examples include social scoring, harmful manipulation and emotion recognition in workplaces and schools.
  • High-risk systems face strict conditions including risk assessment, documentation and human oversight. Examples are AI used in hiring, education, credit scoring, critical infrastructure and law enforcement.
  • A transparency tier requires telling people when they are interacting with a chatbot. It also requires making AI-generated content such as deepfakes identifiable.
  • Everything else, including spam filters and AI in video games, faces no specific rules.

Separate rules cover general-purpose AI (GPAI) models, the large models behind chatbots and image generators. Their providers have transparency and copyright-related duties. Providers of models that may pose systemic risks must assess and mitigate them.

The EU AI Act sorts AI systems into four risk levels, from banned uses down to systems that face no specific rules.

Who does the EU AI Act apply to?

Under Article 2, the law covers:

  • providers that place AI systems or GPAI models on the EU market, wherever they are based
  • deployers (those using an AI system professionally) located in the EU

It also covers:

  • providers and deployers in other countries when their system's output is used in the EU
  • importers, distributors and manufacturers that sell products containing AI under their own name

The law does not apply to:

  • systems used exclusively for military, defense or national security purposes
  • AI developed solely for scientific research
  • individuals using AI for purely personal, non-professional activity

What is the EU AI Act timeline?

The timetable changed in 2026. The Commission proposed a simplification package, the Digital Omnibus on AI, on November 19, 2025. Parliament and the Council reached a political agreement on May 7, 2026. The amending law, Regulation (EU) 2026/1744, was published on July 24, 2026. It entered into force on July 27, 2026. Its recitals cite delays in technical standards and in setting up national authorities as grounds for moving the high-risk dates.

These are the dates now in force, per the Commission's implementation timeline:

  • February 2, 2025: bans on prohibited practices and AI literacy provisions began to apply.
  • August 2, 2025: obligations for GPAI model providers and governance rules began to apply.
  • August 2, 2026: transparency duties for chatbots and deepfakes began to apply. Enforcement also started, including the Commission's power to fine GPAI providers.
  • December 2, 2026: a new ban applies. It covers AI systems that generate or manipulate realistic intimate or sexually explicit depictions of identifiable people without their consent, or child sexual abuse material. Generative AI systems on the market before August 2, 2026 must mark their output in a machine-readable way by this date.
  • August 2, 2027: each member state must have at least one AI regulatory sandbox, a supervised testing environment, operating. GPAI models placed on the market before August 2, 2025 must comply by this date.
  • December 2, 2027: high-risk rules apply to stand-alone systems listed in Annex III, such as hiring and education tools. The original date was August 2, 2026.
  • August 2, 2028: high-risk rules apply to AI embedded in regulated products under Annex I. The original date was August 2, 2027.

The omnibus also reworded the AI literacy duty. Providers and deployers must support staff AI literacy but need not guarantee a specific level. The omnibus extended some small-company relief to firms known as small mid-caps, as the Commission's summary notes.

What are the penalties under the EU AI Act?

Breaking a ban can cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Most other violations, including breaches of high-risk duties, carry fines of up to 15 million euros or 3%. Supplying incorrect or misleading information to authorities can cost up to 7.5 million euros or 1%. For small and medium-sized enterprises the lower figure applies. The omnibus extended that treatment to small mid-caps for the two lower tiers.

The Commission's AI Office supervises GPAI models. Since August 2, 2026, it can request documentation, evaluate models and fine providers up to 15 million euros or 3% of worldwide turnover. National authorities in each member state enforce most other rules.

What to watch

The next fixed date is December 2, 2026. The ban on non-consensual intimate imagery tools and the marking deadline for existing generative AI systems both arrive then. By August 2, 2027, the Commission must specify where AI Act requirements can be limited because EU product safety laws already offer equivalent protection. This article describes the rules and is not legal advice.

Sources

More from AI Policy & Safety

See all in AI Policy & Safety