Brubru
EU policy intelligence
Try Brubru free
EU Canon / Artificial intelligence regulation

The EU AI Act

Regulation (EU) 2024/1689 is the world's first comprehensive, horizontal legal framework for artificial intelligence. It bans a small set of unacceptable practices, subjects high-risk AI systems to mandatory requirements and conformity assessment, and creates a dedicated regime for general-purpose AI models including the largest foundation models.

Adopted 13 June 2024 OJ L, 2024/1689, 12.7.2024 CELEX 32024R1689 Art 114 TFEU
Humanoid robot with glowing blue eyes representing artificial intelligence
Photo: Alex Knight via Pexels | The AI Act sets harmonised rules for AI systems across the EU single market
113
Articles
Across 13 Chapters and 180 recitals, with 13 Annexes. The world's first comprehensive horizontal AI regulation.
180
Recitals
Covering the risk-based rationale, the AI system definition, exclusions from scope, the four risk tiers, GPAI rules and the staggered application dates.
4
Risk tiers
Unacceptable (prohibited), high risk, limited risk (transparency), and minimal risk. Each tier carries a distinct set of obligations calibrated to potential harm.
EUR 35M / 7%
Max fine
The maximum penalty for breaching Article 5 prohibited practices: EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher.

Overview

The world's first comprehensive legal framework for artificial intelligence

Why the AI Act exists

Artificial intelligence presents major economic and societal opportunities but also risks to health, safety and fundamental rights. Without a harmonised EU framework, diverging national rules threatened to fragment the internal market and reduce legal certainty for developers and deployers operating across Member States. The AI Act fills that gap with a single horizontal regulation, built on Article 114 TFEU (internal market approximation) and Article 16 TFEU for the biometric law-enforcement provisions (recitals 3 and 38).

The organising principle is a risk-based approach: rather than regulating all AI uniformly, the Regulation sorts AI systems into four tiers and calibrates obligations to the potential for harm. It is technology-neutral, applying to any AI system regardless of its architecture, training method or deployment modality. Its stated objectives are to promote the development and uptake of human-centric and trustworthy AI while protecting health, safety, fundamental rights, democracy, the rule of law and the environment, and supporting innovation.

Procedural history

The Commission published its proposal as COM(2021) 206 on 21 April 2021, following the 2018 AI strategy and the 2021 Coordinated Plan on AI. The Council adopted a general approach on 6 December 2022. The European Parliament's IMCO and LIBE committees led the Parliament's work in a joint procedure, with co-rapporteurs Brando Benifei (S&D, Italy) and Dragos Tudorache (Renew, Romania). A trilogue political agreement was reached on 8 December 2023; the Parliament formally adopted the text on 13 March 2024 (523 in favour, 46 against, 49 abstentions). The Council formally adopted it on 21 May 2024. The Regulation was published in the Official Journal on 12 July 2024 (OJ L, 2024/1689) and entered into force on 1 August 2024. Lead DG at the Commission: DG CNECT; central enforcement body: the AI Office (established by Commission Decision of 24 January 2024).

Scope and exclusions

The Regulation covers providers placing AI systems on the EU market or putting them into service in the EU, and deployers of AI systems located in the EU. Key exclusions (Article 2): military, defence and national-security uses (recital 24, Art 2(3)); AI developed solely for scientific research and development (recital 25, Art 2(6)); pure research and development prior to placing on the market (Art 2(8)); purely personal non-professional use (Art 2(10)); and free and open-source AI systems, unless they are high-risk, prohibited, or subject to the Article 50 transparency obligations (Art 2(12)).

Structure: 13 Chapters, 13 Annexes

The AI Act contains 113 articles arranged in 13 Chapters, plus 180 recitals and 13 Annexes. The Annexes carry most of the technical and operational detail: Annex I lists the Union harmonisation legislation that triggers the Annex I high-risk route; Annex II provides the list of Annex II legislation; Annex III lists the eight Annex III high-risk use-case areas; Annex IV specifies the mandatory content of technical documentation; Annexes XI and XII set out documentation requirements for GPAI models; and Annex XIII sets out the criteria for designating systemic risk in GPAI models. The Regulation also amends nine existing instruments (regulations and directives in the product-safety and transport-safety acquis), listed in Articles 102 to 110.


The risk pyramid

Four tiers, calibrated obligations: recital 26 and Article 5 onwards

Tier 1: Unacceptable risk
Prohibited practices
Eight specific uses of AI are banned outright under Article 5 because their potential for harm is judged unacceptable in a democratic society governed by the rule of law: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing by profiling, untargeted facial scraping, emotion recognition at work and school, biometric categorisation by sensitive attributes, and real-time remote biometric identification by law enforcement in public spaces (with three narrow exceptions). Penalty: up to EUR 35 million or 7% of global turnover.
Tier 2: High risk
Permitted, subject to requirements
High-risk AI systems are permitted but must meet six mandatory requirements (risk management, data governance, technical documentation, logging, transparency, human oversight) plus accuracy, robustness and cybersecurity. They must undergo a conformity assessment, bear the CE mark and be registered in the EU database before deployment. Two routes to classification: Annex I (safety component in a product subject to Union harmonisation legislation with third-party conformity assessment) and Annex III (eight use-case areas including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice).
Tier 3: Limited risk
Transparency obligations
AI systems at this tier are subject to disclosure obligations under Article 50. Users must be told they are interacting with an AI (chatbot disclosure). Synthetic audio, image, video and text must be marked machine-readable as AI-generated. Deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons. Deepfake content must be labelled as artificially generated or manipulated, with a lighter rule for evidently artistic or satirical works.
Tier 4: Minimal risk
No mandatory obligations
The vast majority of AI systems, including spam filters, recommendation engines for non-sensitive content and AI-enabled video games, fall here. The Regulation imposes no obligations. Providers and deployers are encouraged to adopt voluntary codes of conduct (recital 165), but there is no conformity assessment, CE mark or registration requirement. Innovation is supported through AI regulatory sandboxes (Chapter VI), which must be operational in each Member State by 2 August 2026.

The eight prohibited practices

Article 5: AI uses that are banned outright from 2 February 2025

When prohibitions apply

Chapter II of the Regulation, which contains Article 5, began applying on 2 February 2025, six months after entry into force. Breaching any of the eight prohibitions carries the highest penalty tier: up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher. SMEs and start-ups pay the lower of the percentage or the fixed amount.

(a) Subliminal or manipulative techniques

AI systems that deploy subliminal, deceptive or manipulative techniques operating below the threshold of a person's awareness, or that exploit psychological weaknesses, with the effect of materially distorting a person's behaviour in a manner likely to cause significant harm to that person or another person.

(b) Exploitation of vulnerabilities

AI systems that exploit specific vulnerabilities of a person or group due to their age, disability or a specific social or economic situation, to materially distort their behaviour in a manner likely to cause significant harm to that person or another person.

(c) Social scoring

AI systems for social scoring of natural persons by public or private actors that evaluate or classify individuals based on their social behaviour or personal characteristics, resulting in detrimental or disproportionate treatment that is unrelated to the original data context or that is unjustified.

(d) Predictive policing by profiling

AI systems used by law enforcement that assess the risk of a natural person committing a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics, without a factual basis. This prohibition does not cover risk assessments based on objective facts about the specific person concerned.

(e) Untargeted facial-image scraping

AI systems that create or expand facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. This prohibition targets the mass, indiscriminate collection of biometric data without a specific subject or investigative purpose.

(f) Emotion recognition at work and school

AI systems that infer emotions of natural persons in the workplace and educational institutions. An exception applies for AI systems used for medical or safety reasons (for example detecting driver fatigue in a vehicle).

(g) Biometric categorisation by sensitive attributes

AI systems that categorise natural persons individually based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. This is distinct from the prohibition on real-time RBI: it targets categorisation, not identification.

(h) Real-time remote biometric identification (RBI) by law enforcement

The use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement is prohibited, save three exhaustively listed exceptions: targeted search for victims of abduction, trafficking or sexual exploitation and missing persons; prevention of a specific, substantial and imminent terrorist attack or threat to life; and identification or localisation of a suspect of an Annex II offence punishable by at least four years' imprisonment. All three exceptions require prior authorisation by a judicial or independent administrative authority (within 24 hours in urgent cases), a fundamental-rights impact assessment and registration in the EU database.


High-risk AI systems

Articles 6 to 49, Annexes I and III: two classification routes, six mandatory requirements

Annex I route (Article 6(1)): product-safety legislation

An AI system is high-risk under this route if it is a safety component of a product covered by Union harmonisation legislation listed in Annex I, and that product undergoes third-party conformity assessment. Annex I Section A covers New Legislative Framework legislation including machinery, toys, recreational craft, lifts, ATEX equipment, radio equipment, pressure equipment, personal protective equipment, gas appliances, medical devices and in-vitro diagnostic medical devices. Section B covers civil aviation security, two- and three-wheel vehicles, agricultural and forestry vehicles, marine equipment, rail interoperability, motor vehicles and EASA aviation. Application of this route is deferred to 2 August 2027.

Annex III route (Article 6(2)): eight use-case areas

  1. Biometrics: remote biometric identification, biometric categorisation by sensitive attributes and emotion recognition
  2. Critical infrastructure: safety components in digital infrastructure, road traffic, water, gas, heating and electricity
  3. Education and vocational training
  4. Employment, workers' management and self-employment
  5. Access to essential private and public services: public benefits eligibility, creditworthiness and credit scoring, life and health insurance risk and pricing, emergency-call dispatch and patient triage
  6. Law enforcement
  7. Migration, asylum and border control management
  8. Administration of justice and democratic processes, including systems influencing elections and referenda

A derogation (Art 6(3)) lets an Annex III system escape high-risk status where it does not perform profiling of natural persons and poses no significant risk. The Commission must publish guidelines with practical examples by 2 February 2026 (Art 6(5)).

The six mandatory requirements (Articles 9 to 15)

Providers of high-risk AI systems must ensure their systems meet six requirements, applied throughout the entire lifecycle:

  1. Risk-management system (Article 9): a documented, iterative process run across the whole lifecycle, identifying and mitigating foreseeable risks to health, safety or fundamental rights.
  2. Data and data governance (Article 10): training, validation and testing data sets must be relevant, representative, sufficiently free of errors and, to the best extent possible, complete, and must address applicable biases that could affect health, safety or fundamental rights.
  3. Technical documentation (Article 11, Annex IV): comprehensive documentation prepared before placing on the market, kept up to date, demonstrating compliance with all requirements.
  4. Automatic record-keeping (logging) (Article 12): high-risk AI systems must log events automatically to the extent technically feasible, enabling post-market monitoring and traceability.
  5. Transparency and information to deployers (Article 13): the system must be transparent and accompanied by instructions for use enabling deployers to interpret outputs and apply appropriate human oversight.
  6. Human oversight (Article 14): systems must be designed to allow natural persons to effectively oversee, intervene, interrupt and override the system during the period of use.

In addition, Article 15 requires accuracy, robustness and cybersecurity at an appropriate level, with resilience against unauthorised third-party alteration.

CE marking and EU database registration

High-risk AI systems bear the CE marking (recital 129, Articles 47 to 48), signifying conformity with the Regulation. Most high-risk systems must also be registered in a public EU database (Article 49, recital 131) before deployment. The EU database is operated by the Commission. Entry includes the provider's identity, the system name and version, a description of its intended purpose, the conformity-assessment procedure used, and information about the post-market monitoring plan.

Fundamental rights impact assessment (Article 27)

Deployers that are public bodies, providers of public services, and banking or insurance deployers of Annex III high-risk AI systems must carry out a fundamental rights impact assessment before deployment (Art 27, recital 96). The assessment must identify the rights at risk, the expected harm, the measures to mitigate harm and, where residual risk is identified, consult affected persons or their representatives where feasible. The results must be registered in the EU database (for systems covered by that obligation).


General-purpose AI (GPAI) models

Chapter V, Articles 51 to 56: horizontal rules for foundation models, with extra obligations for systemic-risk providers

What is a GPAI model?

A general-purpose AI model is defined by its generality and capability to perform a wide range of distinct tasks competently (recital 97). Large generative models are the paradigm example (recital 99). The chapter applies to providers of GPAI models, not to deployers or integrators who incorporate those models into their own products, unless they themselves modify a GPAI model and place a new version on the market.

All-provider duties (Article 53)

Every provider of a GPAI model, regardless of size, must:

  • Keep and maintain technical documentation as set out in Annex XI, covering architecture, training data, training methodology, evaluation results and capabilities.
  • Provide information to downstream providers integrating the model into their own AI systems, as set out in Annex XII, enabling those providers to comply with their own AI Act obligations.
  • Adopt and publish a policy to comply with Union copyright law, in particular the text-and-data-mining opt-out in Article 4(3) of Directive (EU) 2019/790 (the Copyright in the Digital Single Market Directive).
  • Publish a sufficiently detailed summary of the content used for training, following a template provided by the AI Office.

Open-source GPAI models are exempt from the Annex XI and XII documentation duties but must still comply with the copyright policy and training-summary obligations, and lose the exemption if they pose systemic risk (Art 53(2)).

Systemic risk: the 10^25 FLOPs threshold (Article 51)

A GPAI model is classified as posing systemic risk where it has high-impact capabilities. This is presumed when the cumulative amount of computation used in training exceeds 1025 floating-point operations (FLOPs). Additional criteria under Annex XIII include the number of parameters, training data-set size, modalities, benchmark performance, and a reach presumption of at least 10,000 registered EU business users. The Commission may also designate a model on the Annex XIII criteria by decision. Providers must notify the AI Office within two weeks of meeting (or expecting to meet) the systemic-risk threshold (Article 52).

Systemic-risk duties (Article 55)

  • Model evaluation: conduct evaluations of the model including adversarial testing and red-teaming, before and after placing on the market.
  • Systemic-risk assessment and mitigation: assess and mitigate risks at Union or global level that could arise from training, capabilities, deployment or misuse of the model.
  • Serious incident reporting: report relevant information about serious incidents and possible corrective measures to the AI Office without undue delay.
  • Cybersecurity: ensure an adequate level of cybersecurity protection for the model, its training infrastructure and physical infrastructure.
Codes of practice (Article 56)

The primary compliance tool for GPAI obligations is a set of codes of practice developed jointly by the AI Office and GPAI model providers, downstream deployers and other stakeholders. Adherence to a code of practice creates a presumption of compliance with the corresponding AI Act obligations. The codes were to be ready by 2 May 2025, and GPAI rules became applicable on 2 August 2025. Providers not adhering to a code may demonstrate compliance through alternative means. Signatories include OpenAI, Anthropic, Google DeepMind, Mistral, Meta and Microsoft.


Transparency obligations

Article 50, Chapter IV: disclosure duties applicable regardless of risk tier

Chatbot disclosure (Art 50(1))

Providers of AI systems intended to interact directly with natural persons must ensure those persons are informed that they are interacting with an AI system, unless this is obvious from the context or the system is used to detect, prevent, investigate or prosecute criminal offences. The disclosure must be given at the latest at the time of the first interaction.

Machine-readable marking of synthetic content (Art 50(2))

Providers of AI systems that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format as artificially generated or manipulated, using technical solutions such as watermarking. This obligation supports downstream detection and disclosure by deployers and platforms. The Commission is responsible for specifying technical standards. The watermarking deadline was subject to a short extension under the 2025/0359 Digital Omnibus.

Emotion recognition and biometric categorisation notice (Art 50(3))

Deployers of AI systems that operate on the basis of emotion recognition or biometric categorisation must inform natural persons exposed to those systems of the operation of the system. This disclosure obligation applies even where the system is otherwise outside the high-risk tier, and regardless of where the person is located relative to the deployer.

Deepfake labelling (Art 50(4))

Deployers using AI systems to generate or manipulate image, audio or video content that constitutes a deepfake must disclose that the content has been artificially generated or manipulated. A lighter rule applies to evidently artistic, creative, satirical or fictional works, where disclosure may be limited to avoiding deception about authenticity. AI-generated text published in the public interest must also be disclosed unless the content has been subject to human review under editorial responsibility.


Governance and enforcement

Chapters VII and IX: the five-body Union architecture plus national authorities

Union-level bodies
  • AI Office (within the Commission, established 24 January 2024): develops Union expertise in AI; supervises GPAI models; monitors market developments; coordinates enforcement; issues guidelines and codes of practice; manages the EU database.
  • European Artificial Intelligence Board (Member State representatives): ensures consistent application of the Regulation; advises the Commission; facilitates cross-border cooperation; contributes to the development of standards and guidance.
  • Advisory forum: stakeholder advisory body including CEN, CENELEC, ETSI, ENISA, the Fundamental Rights Agency, industry, civil society and academia.
  • Scientific panel: independent experts who can issue qualified alerts to the AI Board about potential systemic risks in GPAI models and advise on technical matters.
National and sectoral authorities
  • Each Member State must designate at least one notifying authority and at least one market surveillance authority (one of which acts as single point of contact).
  • The European Data Protection Supervisor (EDPS) acts as the market surveillance authority for Union institutions, bodies and agencies when they deploy AI systems.
  • For AI systems used by regulated financial institutions (banks, insurers, investment firms), the relevant financial-services supervisors act as market surveillance authorities, consistent with the CRR, CRD, Solvency II and insurance-distribution frameworks (recital 158).
  • Supervision of GPAI models is centralised at Union level: the AI Office is the lead authority, with national authorities supporting cross-border enforcement.
AI regulatory sandboxes (Article 57)

Each Member State must establish at least one AI regulatory sandbox, operational by 2 August 2026, to facilitate the development, testing and validation of innovative AI systems in a controlled environment before their placing on the market. Sandboxes must provide priority and simplified access conditions for SMEs and start-ups. The Regulation also provides for real-world testing of AI systems outside sandboxes under conditions ensuring adequate protection (Articles 58 to 60). EPRS research (April 2026) identified design, fragmentation and timing challenges in Member State sandbox implementation.


Penalties

Articles 99 to 101: a three-tier fine structure based on severity and actor type

Violation category Legal basis Maximum fine Notes
Prohibited practices (Article 5) Art 99(3) EUR 35,000,000 or 7% of worldwide annual turnover Whichever is higher. The highest penalty tier reflects the gravity of the prohibited conduct.
Other obligations (providers, deployers, importers, distributors, notified bodies, transparency duties) Art 99(4) EUR 15,000,000 or 3% of worldwide annual turnover Applies to the full range of high-risk AI requirements and GPAI obligations other than Art 5.
Incorrect, incomplete or misleading information provided to notified bodies or national competent authorities Art 99(5) EUR 7,500,000 or 1% of worldwide annual turnover Covers false declarations, false documentation and obstruction of supervisory activities.
SMEs and start-ups Art 99(6) Lower of percentage or fixed amount Proportionality: for each tier, SMEs and start-ups pay whichever is smaller of the percentage of turnover or the fixed ceiling.
GPAI model providers Art 101 EUR 15,000,000 or 3% of worldwide annual turnover Commission may fine GPAI providers directly. Applicable from 2 August 2025.
Union institutions, bodies and agencies Art 100 EUR 1,500,000 (Art 5) or EUR 750,000 (other) Imposed by the EDPS. Turnover-based calculation does not apply to Union bodies.

General calculation rules

In all cases, the applicable penalty is the higher of the fixed ceiling and the percentage-of-turnover figure, except for SMEs and start-ups (where it is the lower). Competent authorities must take into account the nature, gravity, duration and effects of the infringement; the degree of responsibility of the person concerned; and mitigating or aggravating circumstances. Repeated breaches within five years raise the upper limit. The European Data Protection Board may also impose fines through the GDPR where AI processing implicates personal data.


The staggered application timeline

Article 113 and recital 179: a phased rollout from entry into force to full application

1 August 2024
Regulation (EU) 2024/1689 enters into force (20th day after publication in OJ L, 2024/1689, 12.7.2024). No substantive obligations apply yet; the clock for all subsequent phase-in dates begins running from this date.
2 February 2025 (6 months)
Chapters I (general provisions) and II (prohibited practices, Article 5) begin to apply, along with the AI literacy duty. The eight prohibited uses of AI are enforceable from this date. National competent authorities must also be designated by this point (Art 70(1)).
2 May 2025
Codes of practice for GPAI models to be ready (Article 56(9)). The AI Office facilitates the drafting process through taskforce sessions with signatories (third GPAI Signatory Taskforce meeting on safety and security held 27 April 2026).
2 August 2025 (12 months)
Chapter III Section 4 (notifying authorities and notified bodies), Chapter V (GPAI models), Chapter VII (governance), Chapter XII (penalties) and Article 78 (confidentiality) begin to apply. GPAI providers are subject to all Article 53 duties, systemic-risk obligations (Art 55), and the AI Office may impose GPAI fines. Member States must designate national AI authorities. The general prohibition on Article 101 fines does not yet apply.
2 August 2026 (24 months)
General date of application. The bulk of the Regulation applies, including the Annex III high-risk system obligations, transparency duties (Art 50), sandboxes (Art 57), conformity assessments, CE marking, EU database registration and fundamental-rights impact assessments. AI regulatory sandboxes must be operational in each Member State.
2 August 2027 (36 months)
Article 6(1) and the corresponding obligations for Annex I product-related high-risk AI systems begin to apply. GPAI models placed on the market before 2 August 2025 must be brought into compliance by this date (Art 111(3)).
2 August 2030 / 31 December 2030
Compliance deadlines for legacy public-authority high-risk AI systems (Art 111) and certain large-scale IT systems listed in Annex X (including Eurodac, VIS, SIS II, EES and ETIAS) that were already in operation before the general application date.

Note on the Digital Omnibus (2025/0359)

Update (16 June 2026): the European Parliament adopted the AI Act simplification omnibus (2025/0359(COD)) at first reading on 16 June 2026 by 423 votes to 57, with 174 abstentions, following the provisional inter-institutional agreement of 7 May 2026 (Coreper cleared the deal on 13 May 2026). The adopted text makes the revised dates binding: a new Article 5 ban on AI systems creating non-consensual intimate imagery and child sexual abuse material (compliance by 2 December 2026); watermarking of AI-generated content from 2 December 2026; standalone high-risk AI (Annex III) from 2 December 2027; and high-risk AI embedded in regulated products from 2 August 2028. Most other AI Act provisions continue to apply from 2 August 2026. Only the Council's formal adoption now remains; the existing text of Regulation (EU) 2024/1689 remains in force until the amending act is published in the Official Journal. Joint EP rapporteurs (IMCO and LIBE): Arba Kokalari (EPP, Sweden) and Michael McNamara (Renew, Ireland). Source: EP press release 20260611IPR45207.


Key definitions

Essential terms from Article 3 of Regulation (EU) 2024/1689

AI system
A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from input how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments (Article 3(1)). The key distinguishing feature is the capability to infer (recital 12), setting AI apart from traditional rule-based software.
Provider
A natural or legal person, public authority, agency or other body that develops an AI system or has an AI system developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Article 3(3)). Providers bear the primary obligations under Chapter III (high-risk) and Chapter V (GPAI).
Deployer
A natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of personal non-professional activity (Article 3(4)). Deployers must follow provider instructions, carry out fundamental-rights impact assessments where required, and disclose AI interaction to users.
High-risk AI system
An AI system classified as high-risk under Article 6: either a safety component of a product covered by Union harmonisation legislation in Annex I that requires third-party conformity assessment (Art 6(1)), or an AI system falling in one of the eight use-case areas listed in Annex III (Art 6(2)). Subject to the full Chapter III requirements.
General-purpose AI model
An AI model trained with large amounts of data using self-supervision at scale, displaying significant generality and competently performing a wide range of distinct tasks (recital 97). Large language models and large multimodal models are the paradigm cases (recital 99). Subject to Chapter V obligations. If it poses systemic risk, additional duties under Article 55 apply.
Systemic risk
The risk that a GPAI model poses a high-impact capability that could cause significant negative effects at Union or global level, including on public health, safety, public security or fundamental rights, or through misuse for serious crimes. Presumed when cumulative training compute exceeds 1025 FLOPs or where the Annex XIII reach criteria are met (Article 51).
Prohibited practice
One of the eight AI uses listed in Article 5 that are banned outright from 2 February 2025: subliminal or manipulative techniques, exploitation of vulnerabilities, social scoring, predictive policing by profiling, untargeted facial scraping, emotion recognition at work and school, biometric categorisation by sensitive attributes, and (with limited exceptions) real-time RBI by law enforcement in public spaces.

Glossary

Key abbreviations and bodies referenced in Regulation (EU) 2024/1689

AI Act
Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence. The world's first comprehensive horizontal AI regulation. Entry into force 1 August 2024; general application 2 August 2026.
AI Office
The body within the European Commission responsible for Union-level expertise in AI and the supervision of GPAI models. Established by Commission Decision of 24 January 2024 ahead of the Regulation's entry into force. Manages the EU database and codes of practice.
GPAI
General-purpose AI: an AI model trained at scale capable of performing a wide range of tasks. Covered by Chapter V of the AI Act. Systemic-risk GPAI models face additional obligations under Article 55, including adversarial testing (red-teaming) and incident reporting.
CE marking
The conformity marking that high-risk AI systems must bear before being placed on the EU market (Articles 47 to 48). It signifies that the system meets all applicable AI Act requirements and, where relevant, the requirements of the Union harmonisation legislation in Annex I.
RBI
Remote biometric identification: the automated recognition of individuals at a distance using biometric data. Real-time RBI in public spaces for law enforcement is prohibited under Article 5(1)(h), with three narrow exceptions requiring prior judicial or independent administrative authorisation.
Conformity assessment
The procedure by which providers verify that their high-risk AI system satisfies the Chapter III requirements. For most systems this is a provider self-assessment; biometric systems may require notified-body (third-party) assessment (recital 125). Results are documented in the technical documentation and a Declaration of Conformity (Article 47).
DG CNECT
Directorate-General for Communications Networks, Content and Technology: the Commission DG responsible for preparing and implementing the AI Act. DG CNECT coordinates with the AI Office and other DGs and national authorities on implementation, guidelines and delegated acts.
EDPS
European Data Protection Supervisor: acts as market surveillance authority for Union institutions, bodies and agencies deploying AI systems (Article 100), and may impose fines up to EUR 1,500,000 (Art 5 breaches) or EUR 750,000 (other obligations). Also the supervisory authority for AI processing involving personal data by Union bodies.
Deepfake
AI-generated or manipulated image, video or audio content that depicts an identifiable real person, place, object or event in a way that falsely appears authentic or truthful. Deployers must label deepfake content as artificially generated under Article 50(4), with a lighter rule for artistic and satirical works.

Official sources

Primary documentation for Regulation (EU) 2024/1689



Explore the AI Act with Brubru

Six tools to analyse, track and work with EU artificial-intelligence regulation

Brubru Chat
Ask any question about the AI Act: whether your system is high-risk, how to structure a fundamental-rights impact assessment, what the GPAI documentation duties require, or how the Article 5 prohibitions interact with your use case. Answers grounded in official EUR-Lex sources.
Open Chat
Amendator
Load the AI Act into the Amendator and draft amendment language directly against the official EUR-Lex text. Useful for policy professionals working on Commission implementing acts, delegated acts and the GPAI codes of practice.
Open Amendator
My EU Bubble
Track AI Act implementing acts and delegated acts, follow AI Board opinions, monitor AI Office guidance updates, receive alerts when new high-risk AI systems are registered in the EU database, and follow the GPAI codes of practice drafting process.
Open My EU Bubble
EU Law Comply
Run a compliance gap analysis for your organisation against AI Act obligations: classify your AI systems by risk tier, check conformity-assessment requirements, audit data governance practices against Article 10, and verify your GPAI documentation against Annexes XI and XII.
Open EU Law Comply
Tenderator
Find EU procurement opportunities related to AI regulatory sandboxes, AI Office infrastructure, notified-body accreditation support, fundamental-rights impact assessment tooling and high-risk AI system testing and evaluation services across the EU.
Open Tenderator
Brubru API
Programmatic access to EU legislation data, procedure tracking and institutional calendar events. Build AI Act compliance monitoring workflows, track Annex III classification changes and GPAI model registrations, and automate regulatory-intelligence pipelines on Brubru's REST API.
View API Docs

Get the full Brubru platform

14-day free trial. No card needed.

Start free trial