Fello AI thumbnail with the headline “EU AI ACT EXPLAINED” in bold amber and white text beside a glowing EU AI regulation shield, risk-tier icons, and a €35M fine badge on a dark blue European tech background.

EU AI Act Explained: What It Is and How It Affects the AI Tools You Use

The EU AI Act is the world’s first comprehensive law on artificial intelligence, formally Regulation (EU) 2024/1689, and it sorts every AI system into four risk tiers with fines reaching €35 million or 7% of global annual turnover. It entered into force on 1 August 2024, and on 2 August 2026 the European Commission’s AI Office and national authorities started enforcing it. The bulk of the Act, including the transparency rules that cover chatbots and AI-generated content, now applies.

The rollout has not been smooth. A simplification package called the Digital Omnibus pushed the toughest high-risk deadlines back by one to two years, and it became law as Regulation (EU) 2026/1744 auf 27 July 2026, six days before enforcement began. The rules touch the everyday AI tools you already use, from ChatGPT to Gemini to Claude. This guide breaks down what the EU AI Act says, when each part kicks in, what the Omnibus changed, and how the law affects you whether you build AI, deploy it at work, or just chat with it.

The Key Takeaways

  • The EU AI Act is the first major comprehensive AI law in the world, Regulation (EU) 2024/1689.
  • It uses four risk tiers, from unacceptable (banned) down to high, limited, and minimal risk.
  • Maximum fines hit €35 million or 7% of worldwide annual turnover, dropping to €15 million or 3% for most other breaches.
  • Enforcement began on 2 August 2026, but high-risk obligations were pushed to December 2027 and August 2028 by the Digital Omnibus, now Regulation (EU) 2026/1744.
  • Generative AI tools like ChatGPT and Gemini fall under transparency rules, and AI-made content such as deepfakes must be labelled.

What Is the EU AI Act?

The EU AI Act is the world’s first comprehensive law on artificial intelligence, formally Regulation (EU) 2024/1689. It sorts AI systems into four risk tiers, unacceptable, high, limited, and minimal, then sets rules, transparency duties, and fines based on how risky each system is. It applies to anyone offering AI in the European Union, even companies based outside the bloc.

The goal is what Brussels calls “trustworthy AI.” Instead of regulating the technology itself, the law regulates how AI is used and the harm it could cause. A spam filter and a hiring algorithm are both AI, but only one can quietly decide whether you get a job, so they face very different rules.

The Act was proposed in 2021, agreed by EU institutions in 2024, and published in the Official Journal in July 2024. Because it is a regulation and not a directive, it applies directly across all 27 member states without each country passing its own version.

The Four Risk Tiers Explained

The whole law is built on a risk-based approach. The higher the potential harm, the heavier the rules. Most AI you use every day sits in the bottom tier and faces almost nothing.

Risk tierWhat it meansExamplesRules
UnacceptableBanned outrightSocial scoring, manipulative AI, untargeted facial-image scraping, emotion recognition at work or schoolProhibited since 2 Feb 2025
High riskAllowed but tightly controlledHiring tools, credit scoring, biometric ID, medical devices, critical infrastructureRisk management, documentation, human oversight, conformity checks
Limited riskTransparency onlyChatbots, deepfakes, AI-generated contentMust tell users they are dealing with AI
Minimal riskUnregulatedSpam filters, AI in video games, recommendation enginesNo obligations

The vast majority of AI applications on the market today fall into the minimal risk bucket and carry no new duties. The real weight of the law lands on high-risk systems, which must pass conformity assessments before they reach the market.

EU AI Act Timeline: Key Dates

The EU AI Act does not switch on all at once. It phases in over several years, and the 2026 Digital Omnibus reshuffled some of the later deadlines.

DateWhat appliesStatus
1 August 2024Act enters into forceIn force
2 February 2025Bans on prohibited AI + AI literacy dutiesApplies
2 August 2025General-purpose AI (GPAI) rules, governance, penaltiesApplies
2 August 2026Bulk of the Act, including Article 50 transparency rulesApplies, enforcement started
2 December 2026New bans on AI-made intimate imagery and CSAM, plus marking duties for generative systems already on the marketAdded by the Digital Omnibus
2 December 2027High-risk Annex III systems (hiring, credit, etc.)Delay confirmed, in force
2 August 2028High-risk AI embedded in regulated productsDelay confirmed, in force

So if you want the short answer on when the EU AI Act takes effect, the headline date is 2 August 2026, and that date has now passed. The strictest high-risk rules arrive later, in 2027 and 2028, under the Digital Omnibus amendments that entered into force on 27 July 2026.

Latest Updates (August 2026): The Digital Omnibus Is Now Law

The biggest change to the Act since it passed is the Digital Omnibus on AI, and it is finished. Negotiators reached a provisional deal on 7 May 2026, the European Parliament approved the text on 16 June 2026 by 423 votes to 57, and the Council gave its final green light on 29 June 2026.

The Digital Omnibus is law. Signed on 8 July 2026 as Regulation (EU) 2026/1744, it was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the Commission began enforcing the AI Act. Read the text at EUR-Lex.

Here is what the package changed. High-risk Annex III systems, covering recruitment, credit scoring, law enforcement, education, and border control, moved from August 2026 to 2 December 2027. High-risk AI built into regulated products under Annex I moved to 2 August 2028. The deadline for member states to run at least one AI regulatory sandbox slipped by a year to 2 August 2027.

The Omnibus is not all relief. It adds two new bans to the prohibited list, covering AI used to generate non-consensual intimate imagery, so-called “nudifier” apps, and child sexual abuse material. Both take effect on 2 December 2026, a direct response to cases like Grok being used to undress women on X without consent. That same date is the cut-off for generative systems already on the market to start marking their output, a grace period the Omnibus trimmed from six months to three.

What the Omnibus did not touch matters just as much. The Article 50 transparency rules, the prohibitions that took effect in February 2025, and the GPAI obligations from August 2025 all kept their original dates. Those transparency duties are the part that reaches ordinary users, and they are live now.

How the EU AI Act Affects the AI Tools You Use

For most readers, the practical question is simple. What does this mean for ChatGPT, Gemini, Claude, and the other tools you open every day? The answer runs through a category the law calls general-purpose AI, or GPAI.

Transparency for chatbots and generative AI

Models like GPT, Gemini, and Claude are treated as general-purpose AI. They are not automatically “high risk,” but their makers face transparency obligations, including technical documentation and a summary of the data used to train them, plus respect for EU copyright law. When you chat with an AI, the provider must make it clear you are talking to a machine, not a person.

Deepfakes and AI-generated content must be labelled

Under the limited-risk transparency rules, AI-generated images, audio, and video must be disclosed as artificial. That covers deepfakes and synthetic media made with the kind of tools we cover often. If you want to spot this content yourself, our guide on how to detect AI deepfakes walks through the tell-tale signs.

The strictest rules hit the biggest models

The most powerful models face an extra layer. A GPAI model is flagged for systemic risk when the compute used to train it tops 10^25 floating-point operations (FLOPs), a threshold that captures only a handful of frontier models. Those providers must run adversarial testing, assess and mitigate systemic risks, and report serious incidents to the EU’s new AI Office.

To show good faith, the major labs signed a voluntary GPAI Code of Practice in 2025. OpenAI, Google, Anthropic, Microsoft, Amazon, and IBM signed on, while Meta declined und xAI signed only the safety and security chapter. Signing buys a “presumption of conformity,” which means lighter audits down the line. If you are weighing how much to trust these tools, our look at the future of AI, its opportunities and risks puts the regulation in context.

Who Does the EU AI Act Apply To?

The law reaches further than many people expect. It applies based on the EU market, not where your company is headquartered, so a US or Asian firm offering AI to European users is firmly in scope.

You are likely affected if any of these apply to you.

  • You are a provider who develops or places an AI system on the EU market.
  • You are a deployer who uses an AI system in a professional context within the EU.
  • You are based outside the EU but your AI’s output is used in the EU.
  • You import or distribute AI systems into the European market.

Everyday consumers chatting with AI do not have to “comply” with anything. The duties fall on the companies that build and deploy these systems. That said, the law is the reason you increasingly see “this content was AI-generated” labels and clearer disclosures. For a broader take on protecting yourself, see our guide on how to use AI without giving up your privacy.

Penalties for Breaking the EU AI Act

The fines are designed to sting even the largest companies. They scale with the severity of the violation and are calculated as a flat sum or a percentage of worldwide annual turnover, whichever is higher.

ViolationMaximum fine
Using prohibited AI practices€35 million or 7% of global turnover
Breaching most other obligations€15 million or 3% of global turnover
Supplying incorrect information to authorities€7.5 million or 1% of global turnover

Enforcement runs through national competent authorities in each member state, coordinated by the European Commission’s AI Office for general-purpose AI, and it started on 2 August 2026. The Commission confirmed the date in its enforcement announcement, noting the transparency duties bind existing systems too, not just ones launched after that date. Smaller companies and startups face proportionally capped fines, a nod to the worry that heavy rules could crush European innovation.

How to Comply With the EU AI Act

Compliance starts with knowing which tier your AI falls into. If you only use minimal-risk tools, you have almost nothing to do beyond basic AI literacy for staff. The work scales up sharply from there.

A practical first pass looks like this. Map every AI system you build or use, classify each one by risk tier, and confirm whether you act as a provider or a deployer. High-risk systems then need risk management, quality data, technical documentation, human oversight, and a conformity assessment before launch. For generative AI, the priority is transparency, labelling AI output and documenting training data.

Schlussfolgerung

The EU AI Act is the most ambitious attempt yet to put guardrails on artificial intelligence, and as of 2 August 2026 it has moved from theory to enforcement. The four risk tiers, that enforcement date, and fines up to €35 million or 7% of turnover are the facts worth remembering, while the Digital Omnibus delays give high-risk builders breathing room into 2027 and 2028.

If you use AI tools rather than build them, the takeaway is reassuring. The burden sits with the companies, and the visible result for you is more transparency, clearer labels, and stronger limits on the most harmful uses. The next date to watch is 2 December 2026, when the new bans land and older generative systems lose their grace period on content marking.

FAQ

When was the EU AI Act passed?

EU institutions reached final agreement in 2024, and the Act was published in the Official Journal in July 2024. It entered into force on 1 August 2024, and was first amended by the Digital Omnibus, Regulation (EU) 2026/1744, in July 2026.

When does the EU AI Act take effect?

Different parts phase in over time. Bans on prohibited AI applied from February 2025, GPAI rules from August 2025, and the bulk of the law from 2 August 2026, the day the Commission began enforcing it. High-risk obligations arrive in December 2027 and August 2028 under Regulation (EU) 2026/1744.

Who does the EU AI Act apply to?

It applies to providers, deployers, importers, and distributors of AI systems used in the EU, including companies based outside the EU whose AI output reaches European users.

Does the EU AI Act apply to ChatGPT?

Yes. Models behind ChatGPT, Gemini, and Claude are treated as general-purpose AI and must meet transparency and documentation duties, with extra rules for the most powerful systems.

What are the penalties under the EU AI Act?

Fines reach €35 million or 7% of global annual turnover for prohibited practices, with lower bands of €15 million or 3% for most other breaches, and €7.5 million or 1% for supplying incorrect information to authorities under Article 99.

Share Now!

Facebook
X
LinkedIn
Threads
E-Mail

Erhalten Sie exklusive AI-Tipps in Ihrem Posteingang!

Bleiben Sie mit den Erkenntnissen von KI-Experten, auf die sich die besten Technikexperten verlassen, immer einen Schritt voraus!