
Guide
What is the EU AI Act?
Who it binds, the four risk tiers, what is in force today, and what the Digital Omnibus moved to 2027 and 2028.
The EU AI Act is Regulation (EU) 2024/1689, the first comprehensive law anywhere governing artificial intelligence. Two things about it are less understood than they should be. It reaches organisations outside the Union, including plenty in the United Kingdom, whenever a system is placed on the EU market or its output is used there. And the deadline most programmes were built around has moved: high-risk obligations were deferred to December 2027 and August 2028, while three other sets of duties, including the transparency rules that bit on 2 August 2026, did not move at all.
Last reviewed:
What it is, and who it binds
The EU AI Act is Regulation (EU) 2024/1689, the first comprehensive statute anywhere governing artificial intelligence. It entered into force on 1 August 2024 and applies in stages, several of which have already passed.
Two things about its scope are more important than anything in the risk tiers, and both are routinely missed.
It is a product safety law, not a technology law. Obligations attach to the role you occupy in relation to a specific AI system, not to what you build in general. The same company can be a provider of one system, a deployer of another and an importer of a third, with different duties on each.
It reaches outside the Union. It applies to providers placing an AI system on the EU market regardless of where they are established, and to providers and deployers outside the Union where the output of the system is used in the Union. A UK company with EU customers is very often in scope without having a European entity at all.
Provider
- Develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trade mark.
- Carries the bulk of the obligations: risk management, data governance, technical documentation, logging, conformity assessment, registration.
- Includes the case that surprises people: put your own name on somebody else’s model and you become its provider.
Deployer
- Uses an AI system under its own authority, in the course of a professional activity.
- Fewer obligations, but real ones: use it as instructed, assign competent human oversight, keep logs, and inform affected workers.
- Most organisations reading this are deployers, and most of them have not written down which systems they deploy.
An importer or distributor placing a system on the EU market has its own, lighter set of checks. And a deployer that substantially modifies a high-risk system, or puts its own name on one, becomes a provider of it.

- 1Where you are established Not the test, and not a defence
- 2Placed on the EU market Applies regardless of where the provider sits
- 3Output used in the Union Reaches providers and deployers outside it
- 4The contract route EU customers pass their obligations down
The four tiers
The Act sorts systems by what they could do to people, not by how sophisticated they are. A simple rule-based tool used to screen job applicants is high risk. A technically remarkable model used to generate holiday photographs is not.
Risk tiers, and what each one means in practice
| Tier | Examples | What the Act requires |
|---|---|---|
| Unacceptable | Social scoring by public authorities, untargeted scraping of facial images, emotion inference in workplaces and schools, certain predictive policing | Prohibited outright. In force since 2 February 2025 |
| High risk | Annex III uses: employment and worker management, education, credit scoring, essential public and private services, law enforcement, migration, biometrics, critical infrastructure. Plus AI as a safety component of a product already regulated under Annex I | Risk management system, data governance, technical documentation, record keeping, transparency to deployers, human oversight, accuracy and robustness, conformity assessment, registration |
| Limited risk | Chatbots, emotion recognition, biometric categorisation, synthetic image, audio, video and text | Transparency. Tell people they are interacting with an AI system, and mark synthetic content in a machine-readable way |
| Minimal risk | Everything else, which is most of it | No obligations under the Act. Voluntary codes of conduct are encouraged |
General-purpose AI models sit outside this ladder and carry their own chapter, covered below.
What applies now, and what moved
This is the part where most published material is out of date, including a good deal that was written after the change.
Everyone building an AI governance programme over the last two years was working towards 2 August 2026, the date the high-risk obligations were due to apply. That date has moved.
The Commission tabled the Digital Omnibus on AI on 19 November 2025. Following political agreement in May 2026 and formal adoption in June, the high-risk obligations were deferred: standalone systems under Annex III to 2 December 2027, and AI embedded in products already regulated under Annex I to 2 August 2028.
The stated reason was not a change of policy. It was that the harmonised standards, the national supervisory authorities and the conformity assessment infrastructure were not ready, and applying obligations that cannot be evidenced against standards that do not exist helps nobody.
What moved, and what did not
What did not move matters more than what did, because it is in force today and is being widely overlooked in the noise about the deferral.
Prohibited practices have applied since 2 February 2025. These are not obligations to manage, they are things you may not do. A separate ban on so-called nudifier applications and related material was added by the Omnibus with a transitional period to 2 December 2026.
General-purpose AI model obligations have applied since 2 August 2025.
Article 50 transparency duties apply from 2 August 2026, exactly as originally scheduled. If you operate a customer-facing chatbot, or you publish synthetic images, audio, video or text, this one is live now and it is the obligation most organisations will encounter first.
Article 50, the one that is live
Because it is easy to miss underneath the high-risk headlines, it is worth stating plainly what Article 50 requires.
Take this with you
Transparency duties in force from 2 August 2026
- Tell people when they are interacting with an AI system, unless it is obvious to a reasonably well-informed person.
- Mark synthetic audio, image, video and text in a machine-readable format that is detectable as artificially generated or manipulated.
- Disclose deep fakes: content that appreciably resembles real people, objects, places or events and would falsely appear authentic.
- Disclose AI-generated text published to inform the public on matters of public interest, unless a human reviewed it and someone holds editorial responsibility.
- Inform people exposed to emotion recognition or biometric categorisation, and handle their personal data lawfully.
Two practical consequences. A chatbot on a marketing site is in scope, and a line of small print in a privacy notice is not the disclosure the Article asks for. And the machine-readable marking requirement is a technical task rather than a copy task, which means it needs to reach whoever owns the publishing pipeline.
General-purpose AI models
Chapter V governs models rather than systems, and it has applied since 2 August 2025.
Every provider of a general-purpose AI model owes technical documentation, a policy on complying with Union copyright law, and a sufficiently detailed public summary of the content used for training. Open-source models released under a free and open licence are relieved of some, though not all, of these duties.
A model is presumed to carry systemic risk where the cumulative compute used to train it exceeds 10 to the power 25 floating point operations. The Commission may amend that threshold, and may designate a model as systemic on other grounds. Providers of systemic-risk models owe additional duties: model evaluation including adversarial testing, assessment and mitigation of systemic risks, incident reporting, and cybersecurity protection for the model and its physical infrastructure.
For most organisations the significance is indirect but real. You are almost certainly not training a model above that threshold. You are almost certainly using one, which makes the documentation and copyright position of your supplier part of your own compliance evidence.
The high-risk obligations, and why the deferral changes less than it seems
The deferral moves a date. It does not reduce the work, and it does not make the work faster to do later.
A high-risk system needs a risk management system that runs across its lifecycle, data governance covering training, validation and testing sets, technical documentation, automatic logging, information and instructions for deployers, human oversight designed in rather than asserted, and appropriate accuracy, robustness and cybersecurity. It then needs a conformity assessment, a CE marking, and registration in an EU database.
Almost none of that can be produced retrospectively. A risk management system is evidenced by having operated. Data governance is evidenced by decisions recorded at the time the data was chosen. An organisation that stops now and restarts in 2027 will find that the first year of its programme has to happen before the deadline rather than at it.
How this sits beside UK law
There is no UK AI Act, and at the time of writing none is before Parliament. The United Kingdom has taken a different route: a set of cross-sector principles applied by existing regulators within their own remits, rather than one statute with one supervisory structure.
That difference is often reported as the UK having lighter obligations. For a UK organisation with any European exposure it usually works the other way round, and produces more work rather than less.
An organisation operating only in the EU has one law, one classification exercise and one set of authorities. A UK organisation selling into the EU has the Act reaching it directly through the market and output tests, plus whatever its own sector regulator expects, plus the data protection regime, plus the contractual terms its EU customers pass down. Four overlapping demands rather than one, none of which is a subset of another.
The practical answer is not to compare regimes but to build once against the most demanding of them. Nearly everything the Act asks for is evidence an organisation should be able to produce anyway: what AI it uses, who owns each system, what it decides, what data it was built on, who is watching it, and what happens when it is wrong. A regulator that is not the Commission will still ask most of those questions, in a different order.
The Act is also not a data protection law and does not replace one. A system can be entirely outside the high-risk tier and still require a data protection impact assessment. The two regimes overlap in evidence and differ in purpose, which is why an AI system impact assessment is not a relabelled DPIA.
What the Act does not do
Three misreadings come up often enough to be worth naming.
It does not ban AI, and it does not licence it. There is no permission to apply for and no approval to wait on. Outside the prohibited practices, the Act sets conditions on how a system is built, documented and overseen, and leaves the decision to deploy with you.
It does not regulate models by capability. A more capable model does not attract more obligations because it is more capable. What decides the tier is the use, and a technically simple system used to sift job applications carries far more weight than a sophisticated one used to generate marketing images. The general-purpose model chapter is the one exception, and even there the compute threshold is a proxy for reach rather than a judgement about quality.
It does not give an individual a right to compensation. It is enforced by market surveillance authorities and by fines. A person harmed by an AI decision looks to data protection law, consumer law, employment law or the courts, not to this Regulation. That distinction matters when writing an impact assessment, because the question is not only whether you have breached the Act.
Penalties
Fines are set as the higher of a fixed sum or a percentage of total worldwide annual turnover, which is what makes them consequential for large groups.
Article 99 penalties
| Infringement | Maximum fine |
|---|---|
| Prohibited practices under Article 5 | 35 million euros or 7% of total worldwide annual turnover |
| Most other obligations, including those on providers, deployers, importers, distributors and notified bodies | 15 million euros or 3% |
| Supplying incorrect, incomplete or misleading information to authorities | 7.5 million euros or 1% |
What to do now
Four things, none of which depends on the deferred deadline.
Build the inventory. You cannot classify what you have not listed, and the list is almost always longer than expected because a great deal of AI arrives switched on inside software licensed for something else.
Fix your role for each system. Provider, deployer, importer or distributor. The answer decides which obligations apply, and it is the question every subsequent decision depends on.
Meet Article 50 now, because it is in force. Disclosure on interaction, machine-readable marking on synthetic content.
Ask your suppliers for their documentation. If you deploy a general-purpose model, its provider's technical documentation and copyright policy are part of your evidence. Requesting them costs nothing and reveals a great deal about which suppliers have done the work.
Where to go next
The free regulatory scope checker on this site works out whether NIS2, DORA or the UK Cyber Security and Resilience Bill reaches you, which is the adjacent question for most organisations that have just answered this one.
The ISO 42001 guide covers the management system that produces most of the evidence this Act asks for, and is honest about where a certificate stops.
Common questions
›Does the EU AI Act apply to UK companies?
Frequently, yes. It applies to providers placing an AI system on the EU market regardless of where they are established, and to providers and deployers outside the Union where the output produced by the system is used in the Union. A UK company serving EU customers is often in scope without holding any European entity. It also arrives commercially, through EU customers passing their obligations down in contracts.
›What are the four risk levels in the EU AI Act?
Unacceptable risk, which is prohibited outright and has been since 2 February 2025. High risk, which carries the bulk of the compliance obligations and covers Annex III uses such as employment, credit scoring and education, plus AI acting as a safety component in products already regulated. Limited risk, which carries transparency duties under Article 50. And minimal risk, which is most systems and carries no obligations under the Act.
›When does the EU AI Act actually apply?
In stages, and several have passed. Prohibited practices since 2 February 2025. General-purpose AI model obligations since 2 August 2025. Article 50 transparency duties from 2 August 2026. High-risk obligations were deferred by the Digital Omnibus to 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
›Why were the high-risk obligations delayed?
Not because the policy changed. The harmonised standards, the national supervisory authorities and the conformity assessment infrastructure were not ready, and obligations cannot sensibly be enforced against standards that do not yet exist. The Commission tabled the Digital Omnibus on AI on 19 November 2025; political agreement followed in May 2026 and formal adoption in June.
›What is the difference between a provider and a deployer?
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trade mark. A deployer uses a system under its own authority in a professional activity. Providers carry most of the obligations. The trap is that putting your own name on somebody else’s model, or substantially modifying a high-risk system, makes you its provider.
›What are the fines under the EU AI Act?
The higher of a fixed sum or a percentage of total worldwide annual turnover. Up to 35 million euros or 7% for prohibited practices under Article 5. Up to 15 million euros or 3% for most other obligations. Up to 7.5 million euros or 1% for supplying incorrect, incomplete or misleading information to authorities.
›Does ISO 42001 certification satisfy the EU AI Act?
No. The Act imposes legal obligations and the standard is a voluntary management system. Holding the certificate means you run AI governance as a managed process, which generates much of the evidence the Act asks for and makes compliance considerably more tractable, but a certificate is not a defence and nobody should sell it as one.
Where to go next