Regulation (EU) 2024/1689 is the world's first comprehensive, horizontal legal framework for artificial intelligence. It bans a small set of unacceptable practices, subjects high-risk AI systems to mandatory requirements and conformity assessment, and creates a dedicated regime for general-purpose AI models including the largest foundation models.
The world's first comprehensive legal framework for artificial intelligence
Artificial intelligence presents major economic and societal opportunities but also risks to health, safety and fundamental rights. Without a harmonised EU framework, diverging national rules threatened to fragment the internal market and reduce legal certainty for developers and deployers operating across Member States. The AI Act fills that gap with a single horizontal regulation, built on Article 114 TFEU (internal market approximation) and Article 16 TFEU for the biometric law-enforcement provisions (recitals 3 and 38).
The organising principle is a risk-based approach: rather than regulating all AI uniformly, the Regulation sorts AI systems into four tiers and calibrates obligations to the potential for harm. It is technology-neutral, applying to any AI system regardless of its architecture, training method or deployment modality. Its stated objectives are to promote the development and uptake of human-centric and trustworthy AI while protecting health, safety, fundamental rights, democracy, the rule of law and the environment, and supporting innovation.
The Commission published its proposal as COM(2021) 206 on 21 April 2021, following the 2018 AI strategy and the 2021 Coordinated Plan on AI. The Council adopted a general approach on 6 December 2022. The European Parliament's IMCO and LIBE committees led the Parliament's work in a joint procedure, with co-rapporteurs Brando Benifei (S&D, Italy) and Dragos Tudorache (Renew, Romania). A trilogue political agreement was reached on 8 December 2023; the Parliament formally adopted the text on 13 March 2024 (523 in favour, 46 against, 49 abstentions). The Council formally adopted it on 21 May 2024. The Regulation was published in the Official Journal on 12 July 2024 (OJ L, 2024/1689) and entered into force on 1 August 2024. Lead DG at the Commission: DG CNECT; central enforcement body: the AI Office (established by Commission Decision of 24 January 2024).
The Regulation covers providers placing AI systems on the EU market or putting them into service in the EU, and deployers of AI systems located in the EU. Key exclusions (Article 2): military, defence and national-security uses (recital 24, Art 2(3)); AI developed solely for scientific research and development (recital 25, Art 2(6)); pure research and development prior to placing on the market (Art 2(8)); purely personal non-professional use (Art 2(10)); and free and open-source AI systems, unless they are high-risk, prohibited, or subject to the Article 50 transparency obligations (Art 2(12)).
The AI Act contains 113 articles arranged in 13 Chapters, plus 180 recitals and 13 Annexes. The Annexes carry most of the technical and operational detail: Annex I lists the Union harmonisation legislation that triggers the Annex I high-risk route; Annex II provides the list of Annex II legislation; Annex III lists the eight Annex III high-risk use-case areas; Annex IV specifies the mandatory content of technical documentation; Annexes XI and XII set out documentation requirements for GPAI models; and Annex XIII sets out the criteria for designating systemic risk in GPAI models. The Regulation also amends nine existing instruments (regulations and directives in the product-safety and transport-safety acquis), listed in Articles 102 to 110.
Four tiers, calibrated obligations: recital 26 and Article 5 onwards
Article 5: AI uses that are banned outright from 2 February 2025
Chapter II of the Regulation, which contains Article 5, began applying on 2 February 2025, six months after entry into force. Breaching any of the eight prohibitions carries the highest penalty tier: up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher. SMEs and start-ups pay the lower of the percentage or the fixed amount.
AI systems that deploy subliminal, deceptive or manipulative techniques operating below the threshold of a person's awareness, or that exploit psychological weaknesses, with the effect of materially distorting a person's behaviour in a manner likely to cause significant harm to that person or another person.
AI systems that exploit specific vulnerabilities of a person or group due to their age, disability or a specific social or economic situation, to materially distort their behaviour in a manner likely to cause significant harm to that person or another person.
AI systems for social scoring of natural persons by public or private actors that evaluate or classify individuals based on their social behaviour or personal characteristics, resulting in detrimental or disproportionate treatment that is unrelated to the original data context or that is unjustified.
AI systems used by law enforcement that assess the risk of a natural person committing a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics, without a factual basis. This prohibition does not cover risk assessments based on objective facts about the specific person concerned.
AI systems that create or expand facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. This prohibition targets the mass, indiscriminate collection of biometric data without a specific subject or investigative purpose.
AI systems that infer emotions of natural persons in the workplace and educational institutions. An exception applies for AI systems used for medical or safety reasons (for example detecting driver fatigue in a vehicle).
AI systems that categorise natural persons individually based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. This is distinct from the prohibition on real-time RBI: it targets categorisation, not identification.
The use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement is prohibited, save three exhaustively listed exceptions: targeted search for victims of abduction, trafficking or sexual exploitation and missing persons; prevention of a specific, substantial and imminent terrorist attack or threat to life; and identification or localisation of a suspect of an Annex II offence punishable by at least four years' imprisonment. All three exceptions require prior authorisation by a judicial or independent administrative authority (within 24 hours in urgent cases), a fundamental-rights impact assessment and registration in the EU database.
Articles 6 to 49, Annexes I and III: two classification routes, six mandatory requirements
An AI system is high-risk under this route if it is a safety component of a product covered by Union harmonisation legislation listed in Annex I, and that product undergoes third-party conformity assessment. Annex I Section A covers New Legislative Framework legislation including machinery, toys, recreational craft, lifts, ATEX equipment, radio equipment, pressure equipment, personal protective equipment, gas appliances, medical devices and in-vitro diagnostic medical devices. Section B covers civil aviation security, two- and three-wheel vehicles, agricultural and forestry vehicles, marine equipment, rail interoperability, motor vehicles and EASA aviation. Application of this route is deferred to 2 August 2027.
A derogation (Art 6(3)) lets an Annex III system escape high-risk status where it does not perform profiling of natural persons and poses no significant risk. The Commission must publish guidelines with practical examples by 2 February 2026 (Art 6(5)).
Providers of high-risk AI systems must ensure their systems meet six requirements, applied throughout the entire lifecycle:
In addition, Article 15 requires accuracy, robustness and cybersecurity at an appropriate level, with resilience against unauthorised third-party alteration.
High-risk AI systems bear the CE marking (recital 129, Articles 47 to 48), signifying conformity with the Regulation. Most high-risk systems must also be registered in a public EU database (Article 49, recital 131) before deployment. The EU database is operated by the Commission. Entry includes the provider's identity, the system name and version, a description of its intended purpose, the conformity-assessment procedure used, and information about the post-market monitoring plan.
Deployers that are public bodies, providers of public services, and banking or insurance deployers of Annex III high-risk AI systems must carry out a fundamental rights impact assessment before deployment (Art 27, recital 96). The assessment must identify the rights at risk, the expected harm, the measures to mitigate harm and, where residual risk is identified, consult affected persons or their representatives where feasible. The results must be registered in the EU database (for systems covered by that obligation).
Chapter V, Articles 51 to 56: horizontal rules for foundation models, with extra obligations for systemic-risk providers
A general-purpose AI model is defined by its generality and capability to perform a wide range of distinct tasks competently (recital 97). Large generative models are the paradigm example (recital 99). The chapter applies to providers of GPAI models, not to deployers or integrators who incorporate those models into their own products, unless they themselves modify a GPAI model and place a new version on the market.
Every provider of a GPAI model, regardless of size, must:
Open-source GPAI models are exempt from the Annex XI and XII documentation duties but must still comply with the copyright policy and training-summary obligations, and lose the exemption if they pose systemic risk (Art 53(2)).
A GPAI model is classified as posing systemic risk where it has high-impact capabilities. This is presumed when the cumulative amount of computation used in training exceeds 1025 floating-point operations (FLOPs). Additional criteria under Annex XIII include the number of parameters, training data-set size, modalities, benchmark performance, and a reach presumption of at least 10,000 registered EU business users. The Commission may also designate a model on the Annex XIII criteria by decision. Providers must notify the AI Office within two weeks of meeting (or expecting to meet) the systemic-risk threshold (Article 52).
The primary compliance tool for GPAI obligations is a set of codes of practice developed jointly by the AI Office and GPAI model providers, downstream deployers and other stakeholders. Adherence to a code of practice creates a presumption of compliance with the corresponding AI Act obligations. The codes were to be ready by 2 May 2025, and GPAI rules became applicable on 2 August 2025. Providers not adhering to a code may demonstrate compliance through alternative means. Signatories include OpenAI, Anthropic, Google DeepMind, Mistral, Meta and Microsoft.
Article 50, Chapter IV: disclosure duties applicable regardless of risk tier
Providers of AI systems intended to interact directly with natural persons must ensure those persons are informed that they are interacting with an AI system, unless this is obvious from the context or the system is used to detect, prevent, investigate or prosecute criminal offences. The disclosure must be given at the latest at the time of the first interaction.
Providers of AI systems that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format as artificially generated or manipulated, using technical solutions such as watermarking. This obligation supports downstream detection and disclosure by deployers and platforms. The Commission is responsible for specifying technical standards. The watermarking deadline was subject to a short extension under the 2025/0359 Digital Omnibus.
Deployers of AI systems that operate on the basis of emotion recognition or biometric categorisation must inform natural persons exposed to those systems of the operation of the system. This disclosure obligation applies even where the system is otherwise outside the high-risk tier, and regardless of where the person is located relative to the deployer.
Deployers using AI systems to generate or manipulate image, audio or video content that constitutes a deepfake must disclose that the content has been artificially generated or manipulated. A lighter rule applies to evidently artistic, creative, satirical or fictional works, where disclosure may be limited to avoiding deception about authenticity. AI-generated text published in the public interest must also be disclosed unless the content has been subject to human review under editorial responsibility.
Chapters VII and IX: the five-body Union architecture plus national authorities
Each Member State must establish at least one AI regulatory sandbox, operational by 2 August 2026, to facilitate the development, testing and validation of innovative AI systems in a controlled environment before their placing on the market. Sandboxes must provide priority and simplified access conditions for SMEs and start-ups. The Regulation also provides for real-world testing of AI systems outside sandboxes under conditions ensuring adequate protection (Articles 58 to 60). EPRS research (April 2026) identified design, fragmentation and timing challenges in Member State sandbox implementation.
Articles 99 to 101: a three-tier fine structure based on severity and actor type
| Violation category | Legal basis | Maximum fine | Notes |
|---|---|---|---|
| Prohibited practices (Article 5) | Art 99(3) | EUR 35,000,000 or 7% of worldwide annual turnover | Whichever is higher. The highest penalty tier reflects the gravity of the prohibited conduct. |
| Other obligations (providers, deployers, importers, distributors, notified bodies, transparency duties) | Art 99(4) | EUR 15,000,000 or 3% of worldwide annual turnover | Applies to the full range of high-risk AI requirements and GPAI obligations other than Art 5. |
| Incorrect, incomplete or misleading information provided to notified bodies or national competent authorities | Art 99(5) | EUR 7,500,000 or 1% of worldwide annual turnover | Covers false declarations, false documentation and obstruction of supervisory activities. |
| SMEs and start-ups | Art 99(6) | Lower of percentage or fixed amount | Proportionality: for each tier, SMEs and start-ups pay whichever is smaller of the percentage of turnover or the fixed ceiling. |
| GPAI model providers | Art 101 | EUR 15,000,000 or 3% of worldwide annual turnover | Commission may fine GPAI providers directly. Applicable from 2 August 2025. |
| Union institutions, bodies and agencies | Art 100 | EUR 1,500,000 (Art 5) or EUR 750,000 (other) | Imposed by the EDPS. Turnover-based calculation does not apply to Union bodies. |
In all cases, the applicable penalty is the higher of the fixed ceiling and the percentage-of-turnover figure, except for SMEs and start-ups (where it is the lower). Competent authorities must take into account the nature, gravity, duration and effects of the infringement; the degree of responsibility of the person concerned; and mitigating or aggravating circumstances. Repeated breaches within five years raise the upper limit. The European Data Protection Board may also impose fines through the GDPR where AI processing implicates personal data.
Article 113 and recital 179: a phased rollout from entry into force to full application
Update (16 June 2026): the European Parliament adopted the AI Act simplification omnibus (2025/0359(COD)) at first reading on 16 June 2026 by 423 votes to 57, with 174 abstentions, following the provisional inter-institutional agreement of 7 May 2026 (Coreper cleared the deal on 13 May 2026). The adopted text makes the revised dates binding: a new Article 5 ban on AI systems creating non-consensual intimate imagery and child sexual abuse material (compliance by 2 December 2026); watermarking of AI-generated content from 2 December 2026; standalone high-risk AI (Annex III) from 2 December 2027; and high-risk AI embedded in regulated products from 2 August 2028. Most other AI Act provisions continue to apply from 2 August 2026. Only the Council's formal adoption now remains; the existing text of Regulation (EU) 2024/1689 remains in force until the amending act is published in the Official Journal. Joint EP rapporteurs (IMCO and LIBE): Arba Kokalari (EPP, Sweden) and Michael McNamara (Renew, Ireland). Source: EP press release 20260611IPR45207.
Essential terms from Article 3 of Regulation (EU) 2024/1689
Key abbreviations and bodies referenced in Regulation (EU) 2024/1689
Primary documentation for Regulation (EU) 2024/1689
Six tools to analyse, track and work with EU artificial-intelligence regulation