>
AI Concept

AI Regulation — EU AI Act and Global Landscape

The EU AI Act is the first comprehensive AI law and applies extraterritorially. Understanding which tier your use falls into determines what you must actually do.

AI Concept

The Risk-Based Structure

The EU AI Act classifies AI systems by risk and imposes obligations proportionally.

Prohibited — social scoring by public authorities, untargeted facial image scraping, emotion recognition in workplaces and schools, and certain manipulative systems. Banned outright.

High risk — AI used in employment decisions, credit scoring, education access, essential services, law enforcement, migration and critical infrastructure. Permitted subject to substantial obligations: risk management, data governance, documentation, human oversight, accuracy and conformity assessment.

Limited risk — chatbots and systems interacting with people, and generated content. Transparency obligations: people must know they are dealing with AI, and synthetic content must be marked.

Minimal risk — everything else. No specific obligations.

Obligations Depend on Your Role

The Act distinguishes providers who develop systems, deployers who use them, importers and distributors.

Most organisations are deployers, and the obligations are lighter but real — particularly for high-risk uses, where human oversight, monitoring and record-keeping are required.

Note that deploying a general-purpose model for a high-risk purpose brings you within the high-risk obligations even though you did not build the model.

General-Purpose AI Models

The Act includes specific rules for general-purpose models: technical documentation, information for downstream providers, a copyright policy, and a summary of training content.

Models judged to present systemic risk face additional requirements around evaluation, adversarial testing, incident reporting and cybersecurity.

Extraterritorial Reach

The Act applies to providers placing systems on the EU market and to deployers established in the EU, and also where output is used in the EU regardless of where the provider sits.

An organisation outside Europe serving European users is in scope. This mirrors GDPR's reach and has the same practical consequence: it sets the effective global floor for many companies.

The Wider Landscape

Approaches differ markedly. The EU regulates comprehensively and prescriptively. The UK has favoured sector regulators applying existing powers. The US has moved through executive action and state-level law rather than comprehensive federal legislation, producing a patchwork. China regulates specific applications with a focus on content and algorithmic recommendation.

This is a fast-moving area and any summary dates quickly. Verify the current position for your jurisdiction and use case rather than relying on a general description — including this one.

The Timeline Moved in 2026, and Only Part of It

The EU AI Act's high-risk deadline was widely expected in August 2026 and did not arrive. Anyone working from a plan written before mid-2026 is working from the wrong dates.

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was adopted by Parliament on 16 June 2026, approved by Council on 29 June, published in the Official Journal on 24 July and entered into force on 27 July 2026, six days before the original deadline.

ObligationPosition
Prohibited practices, AI literacyIn force since 2 February 2025. Not deferred
GPAI model obligationsIn force since 2 August 2025. Not deferred. Models on the market before that date must comply by 2 August 2027
Article 50 transparencyApplied 2 August 2026 as scheduled. Catches chatbots and synthetic content
High-risk, Annex III standaloneDeferred to 2 December 2027 — hiring, credit scoring, education, critical infrastructure
High-risk, Annex I embeddedDeferred to 2 August 2028 — medical devices, machinery, toys
National regulatory sandboxesDeferred to 2 August 2027

Neither high-risk date is conditional on further decisions — the earlier mechanism tying them to the publication of standards was dropped from the final text. Penalties reach €35 million or 7% of global turnover.

Working Out Which Role You Are In

The Act allocates obligations by role, and the same organisation can hold several. Establishing which you are in is the first compliance task and the one most often skipped.

Provider — you develop an AI system or model and place it on the market under your name. The heaviest obligations.

Deployer — you use an AI system in a professional capacity. Lighter, and not nothing: human oversight, using it as intended, and in several cases informing the people affected.

The trap: a deployer can become a provider by putting their own name on a system, substantially modifying it, or using it for a purpose the original provider did not intend. A company fine-tuning a model and shipping it as a feature has probably crossed that line.

Extraterritorial reach is wide. The Act applies where the output is used in the Union, regardless of where you are established — so an Indian company serving European users is in scope, and a plan that treats this as a European problem is mistaken.

Two practical notes. Free and open-source GPAI models are exempt from most transparency and documentation duties but must still comply with copyright rules and publish a training-data summary — and if a model crosses the systemic-risk threshold of 1025 FLOPs, all obligations apply regardless of licence. And high-risk documentation describes design decisions being taken now: reconstructing it in 2027 from systems already in production costs several times more than recording it as you go, which is the argument for not treating the deferral as a reason to stop.

Sources

What each claim on this page rests on. Entries are typed so you can see which are primary.

  1. officialRegulation (EU) 2024/1689 (AI Act) and Regulation (EU) 2026/1744 (Digital Omnibus on AI) — the risk tiers, the deferred high-risk dates, the Article 50 transparency duties, the GPAI systemic-risk threshold and the penalty ceiling. The Omnibus was adopted by Parliament on 16 June 2026, approved by Council on 29 June, published in the Official Journal on 24 July and entered into force on 27 July 2026 eur-lex.europa.eu
  2. officialEuropean Commission — Navigating the AI Act — the Commission's own account of why the high-risk timeline moved and what was not deferred digital-strategy.ec.europa.eu

Ask an AI about this page

Opens your assistant with this page as the source, and a question rather than a summary. It will ask what you are building before it answers.

ChatGPTClaudeGeminiPerplexityGrok

Nothing is sent from here. The link carries only this page’s title and address.