Skip to main content

01 · Regulation Overview

What it is

Regulation (EU) 2024/1689 — the world's first comprehensive legal framework on AI. Adopted 13 June 2024, published in the Official Journal 12 July 2024, in force 1 August 2024. Full title: "laying down harmonised rules on artificial intelligence" (the Artificial Intelligence Act).

Structure: ~180 recitals, 113 articles, 13 annexes. Amends several prior EU regulations (machinery, transport, product safety directives).

Core logic: risk-based approach

Four tiers, descending from most to least regulated:

TierWhat it coversConsequence
Unacceptable risk8 prohibited practices have applied since 2 February 2025; Regulation (EU) 2026/1744 adds prohibitions concerning non-consensual intimate material and child sexual abuse material from 2 December 2026Prohibited outright. Fines can reach €35M / 7% global annual turnover
High riskAnnex I (safety products) + Annex III (sector use cases)Chapter III, Sections 1–3 apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems
Transparency riskSpecified interactive, biometric, emotion-recognition and generative AI systemsArticle 50 disclosure, marking or labelling duties applicable since 2 August 2026
Minimal / no riskSystems without prohibited, high-risk or Article 50 usesNo additional risk-tier-specific duties; operator-wide provisions and other EU law can still apply

Who must comply

RoleObligation levelGeographic scope
Providers (developers)Heaviest — risk management, technical docs, conformityAnywhere, if system used in EU
Deployers (professional users)Role- and system-specific duties, including following instructions, human oversight, monitoring, log retention and incident reporting where applicableLocated in EU, or output used in EU
Importers & distributorsVerify provider compliance before marketEU market

Key definitions

TermDefinition
AI systemMachine-based system that operates with varying autonomy, infers from inputs to generate outputs (predictions, content, recommendations, decisions) that can influence physical or virtual environments
ProviderEntity that develops and places an AI system on the market or puts it into service
DeployerEntity that uses an AI system in a professional context — not the end user
GPAI modelModel trained on large data via self-supervision, capable of a wide range of tasks, integrable into downstream systems
Systemic riskRisk arising from GPAI models with compute > 10²⁵ FLOPs or designated high-impact capability by the Commission

Relationship to GDPR

The AI Act doesn't replace GDPR. They overlap where AI processes personal data. DPAs are recommended as market surveillance authorities for rights-impacting high-risk AI. Fines can stack.

The Digital Omnibus amendment (Regulation (EU) 2026/1744)

The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It:

  • applies Chapter III, Sections 1–3 to Annex III high-risk systems from 2 December 2027 and Annex I high-risk systems from 2 August 2028;
  • adds Article 5 prohibitions concerning non-consensual intimate material and child sexual abuse material, applying from 2 December 2026;
  • replaces Article 4 with an obligation for providers and deployers to take measures that support the development of AI literacy;
  • creates an exceptional, safeguard-bound legal basis in Article 4a for processing special-category personal data when strictly necessary for bias detection and correction;
  • reinforces AI Office powers for AI systems under Article 75 supervision;
  • extends simplified technical documentation and some penalty proportionality provisions to SMEs, start-ups and small mid-cap enterprises (SMCs);
  • moves the national AI regulatory sandbox deadline to 2 August 2027 and allows an EU-level AI Office sandbox for Article 75 systems.
FormatLink
HTML (English)EUR-Lex HTML
PDF (authentic OJ)EUR-Lex PDF
CELEX (all languages)CELEX:32024R1689
Digital Omnibus on AIRegulation (EU) 2026/1744