Introduction
The European Union has responded to the recent AI developments with what is arguably the most comprehensive regulatory framework for AI anywhere in the world. The EU AI Act, formally adopted in 2024, establishes a set of obligations for all organizations involved in the AI value chain – from developers and importers to deploying companies. It applies to EU organizations and also globally to non-EU organizations that address the European market. Together with the General Data Protection Regulation (GDPR), the NIS2 Directive, the EU’s various digital strategy acts, and emerging sector-specific rules, organizations have to navigate through a number of laws governing their use of AI.
Background: The EU AI Act and GDPR
The EU AI Act’s stated purpose is to “improve the functioning of the internal market by establishing a uniform legal framework… for the development, placing on the market, putting into service and use of AI systems in the Union,” while ensuring a high level of protection of health, safety, and fundamental rights. The regulation sits alongside the GDPR, which continues to apply in full wherever AI systems process personal data – during development (training data), deployment (cloud usage data), and at runtime (input and output of personal data). Both regimes apply in parallel, with recognizable parallels in their territorial scope (marketplace principle), requirements for EU representatives, transparency obligations, and sanction structures. Additional intersections exist with the NIS2 Directive (cybersecurity incident reporting and risk management), the EU Product Liability Directive, and copyright law. The EU’s Digital Omnibus proposal further aims to consolidate and reduce duplication across these instruments.
Overview of the EU AI Act and timeline
The AI Act pursues a risk-based approach, classifying AI systems into four categories with escalating obligations. For more information, visit the European Commission’s website.
- Prohibited AI practices. (Art. 5) AI systems posing unacceptable risk – for example, those involving subliminal manipulation, social scoring, and certain real-time biometric identification – are banned outright.
- High-risk AI systems. (Arts. 6–49) Systems listed in Annexes II and III (covering areas such as biometrics, critical infrastructure, education, employment, law enforcement, and migration) must comply with extensive requirements, including risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity.
- Limited-risk AI systems. (Art. 50) Systems interacting directly with persons, generating synthetic content, or performing emotion recognition must meet specific transparency and labeling obligations.
- Low and minimal-risk AI systems. Subject only to voluntary codes of conduct.
General-Purpose AI (GPAI) models are separately regulated under Chapter V, with additional obligations for “systemic risk” models.
Timeline (as amended by the AI Omnibus, in force July 27, 2026):
|
Milestone |
Date |
|---|---|
|
AI Act enters into force |
August 1, 2024 |
|
Chapters I–II apply (definitions, AI literacy, prohibited practices) |
February 2, 2025 |
|
GPAI provisions, sanctions, notifying authorities |
August 2, 2025 |
|
Transparency rules (Art. 50) and enforcement begins |
August 2, 2026 |
|
Machine-readable marking deadline (Art. 50(2)) for existing systems; new deepfake/CSAM prohibitions |
December 2, 2026 |
|
High-risk AI obligations under Annex III (stand-alone systems) |
December 2, 2027 |
|
High-risk AI embedded in regulated products (Annex I) |
August 2, 2028 |
For non-compliance, supervisory authorities can impose fines ranging from 3% of global annual turnover or €15 million (whichever is higher) to 7% of global turnover or €35 million (Art. 99 AI Act).
Most important obligations for providers (developers)
The AI Act places the heaviest compliance burden on “providers” – defined as natural or legal persons that develop or have developed an AI system or GPAI model and place it on the market or put it into service under their own name or trademark, whether for payment or free of charge (Art. 3 No. 3 AI Act). For high-risk AI systems, providers must fulfill the following key duties:
- Risk management system. Establishing, implementing, documenting, and maintaining a continuous risk management system throughout the AI system’s lifecycle (Art. 9).
- Data governance. Ensuring that training, validation, and testing datasets meet quality criteria – including relevance, representativeness, accuracy, and completeness – and are subject to appropriate data governance practices (Art. 10).
- Technical documentation. Drawing up and maintaining detailed technical documentation demonstrating compliance with the AI Act’s requirements, prior to placing the system on the market (Art. 11, Annex IV).
- Record-keeping (logging). Designing the AI system to automatically record events (logs) during operation to enable traceability and monitoring of the system’s functioning (Art. 12).
- Transparency and instructions for use. Providing deployers with sufficiently clear, complete, and understandable information – including the system’s capabilities, limitations, intended purpose, and foreseeable risks – to enable correct use and human oversight (Art. 13).
- Human oversight by design. Designing and developing high-risk AI systems so that they can be effectively overseen by natural persons during use, including through appropriate human-machine interfaces (Art. 14).
- Accuracy, robustness, and cybersecurity. Ensuring that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity, and perform consistently throughout their lifecycle (Art. 15).
- Conformity assessment. Undergoing the applicable conformity assessment procedure before placing a high-risk AI system on the market, and obtaining CE marking (Art. 16, 43).
- Quality management system. Implementing and documenting a quality management system ensuring compliance with the AI Act (Art. 17).
- Registration. Registering the AI system in the EU database for high-risk AI systems before placing it on the market (Art. 49).
- Post-market monitoring. Establishing and documenting a post-market monitoring system proportionate to the nature and risks of the AI system (Art. 72).
- Serious incident reporting. Reporting serious incidents and malfunctions to the competent authority immediately, and no later than 15 days after becoming aware of them (Art. 73).
- Document retention. Keeping documentation available to competent authorities for 10 years from the date of placing on the market (Art. 18); event logs must be retained for at least six months (Art. 20).
- EU representative. Appointing an authorized representative within the EU for providers not established in the EU (Art. 22).
- Supply chain cooperation. Making compliance documentation and information available to downstream actors (importers, distributors, deployers) in the supply chain.
For GPAI models, providers face additional obligations under Chapter V (Art. 53 et seq. AI Act): preparing detailed technical documentation (including on training data, computing resources, and energy consumption), making documentation available to downstream AI system providers, publishing a sufficiently detailed summary of training content, and complying with EU copyright law. Providers of GPAI models with systemic risk must additionally carry out state-of-the-art model evaluations, assess and mitigate systemic risks, report serious incidents, and ensure an appropriate level of cybersecurity (Art. 55).
Most important obligations for deployers
The AI Act distributes obligations along the supply and value chain. “Deployers” (i.e., organizations using AI systems under their own responsibility, Art. 3 (4) AI Act) face the following key duties:
- Prohibition compliance. Ensuring no AI system is used for purposes prohibited under Art. 5.
- Use in accordance with instructions. Operating high-risk AI systems in line with the provider’s instructions for use (Art. 26).
- Human oversight. Assigning competent, trained natural persons to oversee the operation of high-risk AI systems (Art. 14/26).
- Input data quality. Ensuring that input data is relevant and sufficiently representative for the intended purpose (Art. 26).
- Monitoring and logging. Monitoring operation of high-risk AI systems and retaining automatically generated logs for at least six months (Art. 26)Fundamental Rights Impact Assessment (FRIA). Conducting a FRIA before putting the system into operation for deployers of high-risk AI in essential services (banks, schools, hospitals) (Art. 27).
- Fundamental Rights Impact Assessment (FRIA). Conducting a FRIA before putting the system into operation for deployers of high-risk AI in essential services (banks, schools, hospitals) (Art. 27).
- Data Protection Impact Assessment (DPIA). Using provider documentation to prepare a DPIA under Art. 35 GDPR where required (Art. 26(9)).
- Transparency toward end users. Informing natural persons that they are interacting with an AI system (Art. 50(1)); disclosing deepfakes and AI-generated content of public interest (Art. 50(4)); informing individuals exposed to emotion recognition or biometric categorization systems (Art. 50(3)).
- Incident reporting. Reporting serious incidents to competent authorities.
- AI literacy. Taking measures to ensure sufficient AI literacy among staff involved in the operation of AI systems (Art. 4).
What organizations are focusing on now
In practice, organizations are currently concentrating their AI Act readiness efforts on several workstreams:
AI governance. Establishing interdisciplinary AI governance teams – typically including compliance, legal, IT, IT security, data protection, and HR – to oversee the setup, integration, operation, and monitoring of AI throughout its lifecycle. While appointing a dedicated “AI officer” is not mandatory, it is widely recommended.
AI inventory (mapping). Conducting AI mapping to identify all AI systems and AI functionalities used across the organization and maintain a respective AI inventory. This includes documenting model overviews, intended use cases, data flows, training data summaries, configuration options, and deactivation possibilities – particularly for AI features hidden or default-activated in non-AI solutions.
Risk classification. Assessing whether deployed AI systems fall within the prohibited practices (Art. 5), qualify as high-risk under Annexes II/III, or benefit from the Art. 6(3) exception for systems not posing significant risk. This self-assessment entails considerable legal risk, as supervisory authorities may subsequently reach a different conclusion.
AI literacy and training. Implementing staff training programs on AI regulations and responsible use of AI, as required by Art. 4. This extends to the AI governance team, management, and all employees interacting with AI systems.
Transparency and end-user obligations. Preparing disclosure mechanisms for Art. 50 obligations – including labeling AI-generated content, disclosing chatbot interactions, and notifying individuals of emotion recognition systems. Organizations are addressing complex questions around AI agents, hybrid services, and multi-step content distribution chains where deployer obligations must reach the final end user.
Status of supervisory authorities in EU Member States
Member States were required to designate market surveillance and notifying authorities by August 2, 2025. However, implementation has been uneven. As of mid-2026, only approximately 33% of Member States (nine out of 27) have fully designated both their market surveillance and notifying authorities. Around 44% (12 Member States) have achieved only partial clarity – through pending legislative proposals, announcements, or appointment of one authority – while roughly 22% (six Member States) have yet to designate or establish any competent authority. All Member States have, however, designated their fundamental rights authorities.
AI and automated decision-making in other EU legislation
Beyond the AI Act, AI and automated decision-making are already regulated under several other EU instruments:
The GDPR addresses algorithmic decision-making primarily through Article 22, which grants individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects – a provision that directly intersects with the AI Act’s human oversight requirements for high-risk systems (Art. 14). However, this GDPR requirement and the AI Act requirements do not run in parallel and require separate and individual assessments.
The Digital Services Act (DSA, Regulation (EU) 2022/2065) regulates AI as part of its holistic approach to online platforms: it creates transparency requirements for algorithmic recommender systems, mandates independent audits of very large platforms’ AI-driven content moderation, and requires platforms to offer users an alternative recommendation option not based on profiling.
The Digital Markets Act (DMA, Regulation (EU) 2022/1925) targets AI deployments by “gatekeepers” (platforms) – barring self-preferencing in AI-driven rankings and enabling Commission inspections of gatekeepers’ data and AI systems.
Together with the AI Act, these instruments create an integrated but overlapping legal framework, requiring organizations to coordinate compliance across product safety (AI Act), data protection (GDPR), platform governance (DSA), and competition (DMA) simultaneously.
Looking ahead
The EU AI Act represents a landmark piece of legislation for the EU. However, it is complex, and many rules leave room for wide interpretation. The EU is lagging behind in providing guidance and, as we see from the Digital Omnibus legislation, the EU AI Act was already outdated before it even fully applied. Organizations operating in the EU must nonetheless press ahead with governance structures, AI inventories, and risk classifications despite these interpretive gaps. Whether the AI Act will be a similar “blockbuster” to the GDPR is highly doubtful, and the EU will have to watch closely to avoid negative impacts on business and innovation in the EU caused by the Act.