Regulation EU 2024/1689, Post-Omnibus Edition

EU AI Act: The Complete Compliance Guide

Everything organisations need to understand, assess, and act on the EU AI Act, from the legal framework to practical compliance steps. Updated for the EU AI Act's phased enforcement timeline (2025–2028).

Updated for the post-Omnibus phased timeline (12 May 2026)  ·  5,200 words  ·  25 min read
→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →

1. What Is the EU AI Act?

The EU AI Act, formally Regulation (EU) 2024/1689 of the European Parliament and of the Council, is the world's first comprehensive legal framework specifically governing artificial intelligence. Published in the EU Official Journal on 12 July 2024 and entering into force on 1 August 2024, it establishes legally binding requirements for the development, deployment, and use of AI systems across the European Union.

The regulation emerged from a recognition that AI systems carry risks qualitatively different from prior technology categories. Unlike sector-specific legislation that governs AI incidentally (such as GDPR or the Medical Devices Regulation), the EU AI Act creates a horizontal framework applicable across all sectors and use cases, from healthcare AI to recruitment algorithms to AI-generated content.

The Act is built around a central principle: compliance obligations should be proportionate to risk. A spam filter and a tool used by courts to assess recidivism risk should not face identical regulatory burdens. The Act therefore classifies all AI systems into four tiers and imposes requirements accordingly.

📋
Direct Answer: The EU AI Act (Regulation EU 2024/1689) is the EU's binding AI regulation, active since August 2024, imposing risk-based compliance obligations on AI developers, deployers, and importers with penalties up to €35M or 7% of global turnover.

2. Who Does the EU AI Act Apply To?

The EU AI Act has broad territorial scope, applying to four categories of actor:

  • Providers, organisations that develop AI systems and place them on the EU market or put them into service in the EU, regardless of whether the provider is established in the EU or a third country.
  • Deployers, organisations and individuals that use AI systems under their authority for professional purposes. Deployers face distinct obligations from providers, particularly for high-risk AI systems.
  • Importers, organisations established in the EU that place an AI system on the EU market where the provider is established outside the EU.
  • Distributors, organisations that make an AI system available on the EU market without being the provider or importer.

Critically, the Act applies to third-country organisations if their AI system output affects EU-based individuals. A US company deploying an AI recruitment tool that screens applications from EU candidates must comply, even without any EU establishment. This extra-territorial scope mirrors the GDPR model.

The Act exempts AI systems used exclusively for military and national security purposes, scientific research, and personal non-professional use. Open-source model providers benefit from reduced obligations, though providers of open-source GPAI models with systemic risk remain fully subject to obligations under Chapter V.

3. The Risk Classification Framework

The Act's risk-based architecture is its defining structural feature. All AI systems must be classified into one of four tiers, and compliance obligations flow from that classification.

Tier 1: Prohibited AI Practices (Article 5)

Certain AI applications are categorically prohibited as incompatible with EU values. The prohibition list includes: AI systems that deploy subliminal techniques to manipulate behaviour; systems that exploit psychological vulnerabilities; government social scoring systems; real-time remote biometric identification in public spaces (with narrow law enforcement exceptions); AI systems that infer emotions in workplace or education contexts; untargeted scraping of facial images from the internet for biometric databases; and AI that predicts criminal offences based solely on profiling.

These prohibitions have been in force since 2 February 2025 and carry the highest penalty tier.

Tier 2: High-Risk AI Systems

High-risk classification is the central compliance category, covering AI systems listed in Annex III across eight domains (detailed in Section 5 below) and AI systems embedded in regulated products listed in Annex I (medical devices, machinery, vehicles, aviation). High-risk AI faces the full compliance burden under Chapter III of the Act.

Tier 3: Limited-Risk AI

AI systems that interact directly with humans, chatbots, virtual assistants, or that generate synthetic content face transparency obligations. Users must be informed they are interacting with an AI. Deepfakes must be labelled as AI-generated.

Tier 4: Minimal-Risk AI

The majority of AI systems, spam filters, recommendation engines, AI in video games, inventory optimisation tools, face no mandatory requirements. Voluntary codes of conduct are encouraged but not required.

4. Prohibited AI Practices Under Article 5

Article 5 sets out the prohibited practices effective from 2 February 2025. These are not subject to compliance programmes or risk management systems, they are absolute prohibitions. Key categories:

  • Subliminal manipulation: AI that influences behaviour through techniques that bypass conscious awareness, in ways likely to cause harm.
  • Exploitation of vulnerabilities: AI targeting individuals based on age, disability, or social/economic situation to distort behaviour.
  • Social scoring: Government-operated AI systems that evaluate or classify natural persons based on social behaviour, leading to detrimental treatment.
  • Real-time remote biometric ID: Live facial recognition in publicly accessible spaces by law enforcement, with narrow exceptions for missing children, terrorism prevention, and prosecution of serious crime, subject to prior judicial or independent administrative authorisation.
  • Post-hoc biometric ID: Retrospective remote biometric identification, with limited law enforcement exceptions.
  • Emotion inference in workplaces/education: Systems inferring emotional states of individuals in workplace or educational settings, with exceptions for medical and safety reasons.
  • Biometric categorisation: Systems categorising individuals based on sensitive characteristics such as political opinion, religion, or sexual orientation from biometric data.
  • Facial image scraping: Building or expanding facial recognition databases by indiscriminate scraping of internet or CCTV images.
🚫
Enforcement active since 2 February 2025. Violation of Article 5 carries a maximum penalty of €35 million or 7% of global annual turnover, the highest tier under the Act.

5. High-Risk AI: Annex III and the 2 December 2027 Deadline

Annex III lists the eight domains where AI systems are presumed high-risk, triggering the full compliance framework under Chapter III. The eight domains are:

  1. Biometric identification and categorisation, remote biometric identification systems, emotion recognition, biometric categorisation based on sensitive attributes
  2. Critical infrastructure, AI in safety components of water, gas, heating, electricity, road traffic, and digital infrastructure
  3. Education and vocational training, AI determining access to educational institutions, evaluating students, monitoring examination integrity
  4. Employment and workers management, AI for recruitment, selection, task allocation, performance monitoring, termination decisions
  5. Essential private and public services, AI for creditworthiness assessment, life/health insurance, social benefits eligibility, emergency service dispatch
  6. Law enforcement, AI for individual risk assessment, polygraph tools, evidence reliability evaluation, profiling in crime prevention
  7. Migration, asylum, and border control, AI for risk assessment, document authentication, examination applications, monitoring illegal crossings
  8. Administration of justice and democratic processes, AI assisting judicial fact-finding, influencing elections, targeted political advertising

High-risk AI providers must meet requirements including: a documented risk management system maintained throughout the system lifecycle (Article 9); data governance covering training, validation, and testing datasets (Article 10); complete technical documentation per Annex IV (Article 11); automatic logging for traceability (Article 12); transparency to users (Article 13); human oversight measures that allow intervention and override (Article 14); and demonstrated accuracy, robustness, and cybersecurity (Article 15).

Deployers of high-risk AI bear separate obligations including: monitoring system operation per instructions; where applicable, conducting a Fundamental Rights Impact Assessment (Article 27); and logging system use.

6. General-Purpose AI (GPAI), Articles 51–56

Chapter V addresses GPAI models, large foundation models and LLMs capable of performing a broad range of tasks. GPAI obligations became enforceable on 2 August 2025.

All GPAI model providers must: maintain technical documentation; provide downstream providers with usage information and instructions; comply with EU copyright law, particularly the Text and Data Mining Directive; and publish a sufficiently detailed summary of training data.

GPAI models with systemic risk, defined as models trained on computation exceeding 10²⁵ FLOPs, face additional obligations including: adversarial testing and red-teaming; cybersecurity measures; reporting serious incidents to the European AI Office within 15 working days; and mitigating identified systemic risks.

The AI Office has published a voluntary Code of Practice (July 2025) providing practical guidance on GPAI compliance. While voluntary, adherence is expected to be treated by regulators as evidence of good faith compliance.

7. Transparency Obligations for Limited-Risk AI

Limited-risk AI systems face targeted transparency requirements under Articles 50 and 52. Providers and deployers of AI systems that interact with humans must ensure users are informed they are interacting with an AI, unless this is obvious from context. Systems generating AI content (deepfakes, synthetic media, AI-generated text intended to influence) must label that content as artificially generated or manipulated.

The transparency obligation for emotion recognition systems and biometric categorisation systems requires informing exposed individuals. Search engines and social media platforms using recommender systems must provide options to adjust personalisation parameters.

8. Fines and Penalties Under the EU AI Act

Administrative penalties are structured in three tiers, with the final penalty calculated as the higher of the fixed amount or the percentage of global annual turnover:

Violation Category Fixed Maximum % of Turnover Legal Basis
Prohibited practices (Article 5) €35,000,000 7% Art. 99(3)
High-risk AI / GPAI non-compliance €15,000,000 3% Art. 99(4)
Providing incorrect or misleading information €7,500,000 1% Art. 99(5)

For SMEs and startups, Article 99(6) permits national competent authorities to impose penalties that are proportionate to their size and economic capacity, while still ensuring deterrence. This does not create an exemption, but may reduce the absolute penalty amount relative to the maximum.

The "whichever is higher" mechanism is significant. For a company with €10 billion in global revenue, a 7% fine would reach €700 million, far above the €35 million fixed cap. The regulation therefore scales with the organisation's economic capacity.

9. Full Enforcement Timeline

The EU AI Act implements its requirements through a phased schedule designed to give organisations time to build compliance programmes:

12 July 2024
Regulation Published
Published in EU Official Journal. 20-day countdown to entry into force.
1 August 2024
Entered Into Force
Regulation became binding EU law. National implementation structures began.
2 February 2025, NOW ACTIVE
Article 5 Prohibited Practices
Complete prohibition on listed AI practices. Maximum fine: €35M / 7% turnover.
2 August 2025, NOW ACTIVE
GPAI Obligations (Arts. 51–56)
GPAI providers must comply with transparency, documentation, copyright, and systemic risk obligations.
2 August 2026, STILL APPLIES
Article 50 Transparency (most) + Article 49 Registration + MSA Powers
Article 50 transparency (chatbots, deepfakes, emotional-recognition disclosure), Article 49 EU database registration, and national MSA enforcement powers apply as enacted. Only Article 50(2) watermarking shifted under the Omnibus.
2 December 2026, NEW UNDER OMNIBUS
Article 50(2) Watermarking + New Article 5 CSAM/NCII Prohibition
Synthetic-content watermarking shifted from 2 Aug 2026 to 2 Dec 2026. New Article 5 prohibition on AI generating non-consensual intimate imagery or CSAM applies from this date.
2 December 2027, ANNEX III DEADLINE
Annex III High-Risk AI Full Enforcement
Moved from 2 Aug 2026 under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), a 16-month deferral. All Annex III systems must comply: risk management, technical documentation, human oversight, FRIA, conformity assessment, EU database registration, post-market monitoring.
2 August 2028, ANNEX I DEADLINE
Annex I Embedded High-Risk AI
AI embedded in regulated products (medical devices, machinery, vehicles under Annex I) must comply. Moved from 2 Aug 2027 under the Omnibus, a 12-month deferral.
2 August 2030
Public Sector Legacy Systems (Art. 111)
Legacy AI systems already in operation by public authorities benefit from extended transition period.

10. Your EU AI Act Compliance Action Plan

For organisations subject to the Act, an effective compliance programme involves five sequential phases:

  1. AI inventory and mapping. Catalogue every AI system in use across the organisation, including third-party and embedded AI. The AI System Inventory Template in our Checklist Pack provides the structure for this exercise.
  2. Risk classification. Apply the Annex III classification criteria to each system. Determine whether any systems fall within Article 5 prohibited categories. For systems near the boundary, seek legal advice on classification.
  3. Gap analysis. For high-risk systems, assess current documentation and governance against the requirements of Articles 9–15. Our 58-Point Compliance Checklist maps this gap systematically.
  4. Remediation programme. Address gaps: build the risk management system (Art. 9), complete Annex IV technical documentation, establish data governance protocols, and implement human oversight mechanisms.
  5. Ongoing compliance. Establish post-market monitoring (Art. 72), logging, and a regular review cycle. The post-2026 monitoring calendar in our Full Bundle provides the structure for this.
Time is the constraint. Building a compliant risk management system, completing Annex IV documentation, and establishing human oversight mechanisms for complex AI systems typically takes 3–9 months. Organisations that have not already started face real time pressure: Article 50 transparency and Article 49 registration apply from 2 August 2026, with Annex III high-risk obligations following on 2 December 2027.

11. ISO/IEC 42001:2023 and the EU AI Act

ISO/IEC 42001:2023, the international standard for AI Management Systems, was published in December 2023 and provides a recognised framework for implementing the organisational governance structures required by the EU AI Act. While the Act does not mandate ISO 42001 certification, the standard's requirements map closely to Article 17 (Quality Management System) obligations for high-risk AI providers.

Organisations that have already implemented ISO 42001 will find significant overlap with EU AI Act compliance requirements, particularly around risk management processes, documentation practices, and governance structures. Our ISO 42001 / EU AI Act Mapping Matrix (included in the Full Bundle) provides a systematic cross-reference of both frameworks.

12. EU AI Act and GDPR: Parallel Obligations

The EU AI Act and GDPR operate in parallel and frequently intersect. Most high-risk AI systems process personal data, creating dual compliance obligations. Key intersections include:

  • The FRIA (Article 27, AI Act) complements the DPIA (Article 35, GDPR). Both are mandatory for many high-risk AI deployments, though they assess different dimensions of risk.
  • Data governance obligations under Article 10 of the AI Act require datasets to be processed lawfully, a requirement that integrates with GDPR's lawful basis requirements.
  • Supervisory authority competence may overlap: Data Protection Authorities, notified bodies, and national AI authorities may all have jurisdiction over the same system.
  • The "right to explanation" under GDPR Article 22 and the transparency requirements of the AI Act create a layered set of information obligations for automated decision-making.

Organisations should ensure their AI Act and GDPR compliance programmes are coordinated rather than siloed. A combined project approach avoids duplication and ensures no obligation falls between the two regimes.

Read the Full EU AI Act vs GDPR Comparison →


This guide reflects Regulation EU 2024/1689 as amended by the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026). Content is for informational purposes and does not constitute legal advice. Always consult qualified legal counsel for compliance decisions specific to your organisation.

Free Resource

Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes

Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.

No spam. No marketing lists. PDF delivered immediately after submit. Privacy Policy

✓   Your checklist is downloading now. Check your inbox for a copy.