
The EU AI Act, Explained
The EU AI Act is the world's first comprehensive law on artificial intelligence. It sorts AI systems into four risk tiers, bans a short list of practices outright, imposes strict obligations on high-risk systems, adds dedicated rules for general-purpose AI (GPAI), and backs all of it with fines of up to €35 million or 7% of global annual turnover.
This dossier explains the Act in plain terms: what it is, how the risk categories work, when each obligation applies, who is caught by its extraterritorial reach, and what it means for businesses. Every figure is sourced and dated. It is a core entry in our AI governance coverage and connects to the enterprise AI guide.
What is the EU AI Act
The EU AI Act is the European Union's regulation establishing harmonised rules for artificial intelligence across the single market. Formally Regulation (EU) 2024/1689, it was published in the EU's Official Journal on 12 July 2024 and entered into force on 1 August 2024, twenty days later (European Commission, 2024). It is widely described as the world's first comprehensive AI law.
Its core idea is a risk-based approach: the obligations placed on an AI system scale with the risk it poses to health, safety and fundamental rights. A spam filter and a CV-screening tool are not regulated the same way. The Act assigns every system to one of four tiers and attaches a different rulebook to each (European Commission, AI Act high-level summary, 2024).
The Act sits at the heart of the EU's wider AI Act framework and its broader push for responsible AI. Enforcement is shared between national market surveillance authorities and a new central body, the European AI Office, established within the European Commission to supervise and coordinate implementation, with special responsibility for general-purpose AI models (European Commission, AI Office, 2024).
AI Act risk categories
The Act defines four risk categories. The tier determines what a provider or deployer must do before and after putting an AI system on the EU market. The table below summarises the tiers, with examples and headline obligations.
| Risk tier | Examples | Core obligations |
|---|---|---|
| Unacceptable (prohibited) | Social scoring by public authorities; subliminal manipulation causing harm; untargeted facial-image scraping; emotion recognition at work or school; real-time remote biometric ID in public for law enforcement (narrow exceptions) | Banned outright. Prohibited since 2 Feb 2025 under Article 5 |
| High-risk | AI in biometrics, critical infrastructure, education, employment and HR, essential services and credit scoring, law enforcement, migration and border control, justice (Annex III); safety components of regulated products | Risk-management system, data governance, technical documentation, logging, human oversight, accuracy & cybersecurity; conformity assessment, CE marking and EU database registration |
| Limited | Chatbots, AI-generated content and deepfakes, emotion-recognition systems (outside banned contexts) | Transparency only: users must be told they are interacting with AI; AI-generated content must be labelled |
| Minimal | Spam filters, AI in video games, inventory-management tools — the large majority of AI in use today | No mandatory obligations; voluntary codes of conduct encouraged |
Unacceptable-risk practices are listed in Article 5 and have been banned since 2 February 2025. They include eight categories — among them social scoring, manipulative or exploitative AI, untargeted scraping of facial images, emotion recognition in workplaces and schools, and certain biometric categorisation and real-time biometric identification (European Commission, 2024–2025).
High-risk is where most of the Act's text sits. A system is high-risk if it is a safety component of a product already covered by EU product-safety law, or if it falls within one of the use cases listed in Annex III — biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration, and the administration of justice (EU AI Act, Annex III). These systems carry the full compliance load and are central to debates around AI governance.
Limited-risk systems face only transparency duties, and minimal-risk systems — the bulk of AI on the market — face no new obligations at all.
Timeline of application
The Act does not apply all at once. After entry into force on 1 August 2024, its provisions switch on in staggered phases over three years, giving organisations time to prepare. The key dates are below.
| Date | Milestone |
|---|---|
| 1 Aug 2024 | Regulation (EU) 2024/1689 enters into force |
| 2 Feb 2025 | Prohibitions on unacceptable-risk AI (Article 5) apply; AI-literacy obligations begin |
| 2 Aug 2025 | Rules for general-purpose AI (GPAI) models apply; governance provisions and the AI Office's remit take effect; penalty provisions become applicable |
| 2 Aug 2026 | The bulk of the Act applies, including obligations for Annex III high-risk systems (e.g. employment, credit, essential services) |
| 2 Aug 2027 | Obligations for high-risk AI that are safety components of regulated products (e.g. medical devices, civil aviation) apply; full roll-out complete |
These dates come directly from the European Commission's official implementation timeline and the AI Act Service Desk (European Commission, 2024–2026). Note that GPAI providers whose models were already on the market before 2 August 2025 have until 2 August 2027 to bring them into full compliance.
One caveat for 2026: in 2026 the Commission proposed a "Digital Omnibus" package that would defer some high-risk (Annex III) obligations beyond August 2026. As of June 2026 this is a legislative proposal, not adopted law — the dates above reflect the binding text of Regulation (EU) 2024/1689, and businesses should track the Omnibus negotiations rather than assume any delay (European Commission Digital Omnibus proposal, 2026). For the canonical, continuously updated calendar, see the EU AI Act implementation timeline.
Rules for general-purpose AI (GPAI)
General-purpose AI (GPAI) models — the foundation models that can be adapted to many tasks and now underpin much of the AI ecosystem — get their own chapter in the Act. Obligations for GPAI providers began to apply on 2 August 2025 (European Commission, GPAI guidelines, 2025).
All GPAI providers must meet baseline transparency and copyright duties: maintain up-to-date technical documentation, provide information to downstream developers who build on the model, publish a summary of the training data, and put in place a policy to comply with EU copyright law.
A smaller set of the most capable models is classed as carrying systemic risk. Under the Act, a model is presumed to have high-impact capabilities — and therefore systemic risk — when the cumulative compute used for training exceeds 10^25 floating-point operations (FLOPs) (EU AI Act, Article 51; artificialintelligenceact.eu). These providers face extra obligations:
To help providers show compliance, the Commission and the AI Office published the General-Purpose AI Code of Practice in July 2025 — a voluntary instrument drawn up by independent experts, structured around three chapters: Transparency, Copyright, and Safety & Security (European Commission, GPAI Code of Practice, 2025). The Safety & Security chapter applies only to systemic-risk models, currently a small group of frontier-model developers. Many of these labs sit among Europe's leading AI companies and the broader field of foundation-model providers.
Who is affected
The Act applies across the AI value chain and, crucially, reaches beyond the EU's borders. Article 2 sets out its scope. It applies to:
That third limb is the one most non-EU firms miss: if your system produces a score, decision, recommendation or piece of content that is used inside the EU, the Act can apply regardless of where your servers or staff sit (EU AI Act, Article 2; William Fry, 2025). The Act does not apply to AI used for purely personal, non-professional activity, to systems used solely for military, defence or national-security purposes, or to research and development before a system is placed on the market.
The split between providers (who design and build) and deployers (who put systems to use) matters: providers carry the conformity-assessment and documentation burden, while deployers are responsible for proper use, human oversight and monitoring. Governance leaders working through these roles — such as practitioners featured among our speakers, including Alia Zafar and Laura Gilbert — increasingly treat the provider/deployer line as the first question in any compliance review.
Penalties
The Act backs its rules with a tiered fines regime under Article 99. Penalties are calculated as a fixed amount or a percentage of worldwide annual turnover — whichever is higher (whichever is lower for SMEs and start-ups). The three tiers are:
These figures are set out in Article 99 of Regulation (EU) 2024/1689 (EU AI Act, Article 99). Member States designate the penalties, which must be "effective, proportionate and dissuasive," while the European AI Office enforces fines specifically against GPAI-model providers. Penalty provisions became applicable on 2 August 2025.
What it means for businesses
For most companies, the Act is less about foundation models and more about knowing which tier your AI falls into and acting accordingly. A practical sequence:
The cost of getting this wrong is set by Article 99 above; the cost of getting it right is a governance programme that many firms are now standing up regardless of jurisdiction, because the Act is becoming a de facto global reference for responsible AI. For a structured starting point, see our enterprise AI guide, and for the policy debate in person, the AI Summit Europe programme convenes regulators, providers and deployers each year.
The EU AI Act is now the reference point for AI regulation worldwide: four risk tiers, a three-year roll-out to 2027, dedicated rules for general-purpose AI, and fines reaching 7% of global turnover. For any team building or deploying AI in Europe, the first task is simple — find your tier, fix your role, and document everything. That work, and the people doing it, increasingly gather in Barcelona.
Follow AI regulation where it is decided
The EU AI Act is reshaping how AI is built and deployed across Europe. AI Summit Barcelona 2026 brings together the regulators, providers and enterprise teams working through it in practice.
Get your tickets →Sources
Frequently asked questions
What is the EU AI Act in simple terms?
The EU AI Act is the European Union's law on artificial intelligence, the first comprehensive AI regulation in the world. It groups AI systems by risk: it bans a few dangerous uses, puts strict rules on high-risk uses like hiring and credit scoring, asks for transparency on chatbots and deepfakes, and leaves most everyday AI untouched. It entered into force on 1 August 2024 and applies in stages through 2027.
When does the AI Act apply?
The Act entered into force on 1 August 2024 and applies in phases. Bans on unacceptable-risk AI started on 2 February 2025; rules for general-purpose AI on 2 August 2025; most high-risk obligations on 2 August 2026; and obligations for high-risk AI in regulated products on 2 August 2027. A 2026 Digital Omnibus proposal could shift some high-risk dates, but it is not yet adopted law.
What are the penalties under the AI Act?
Fines are tiered under Article 99. Breaching the bans on unacceptable-risk AI can cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Most other breaches reach 15 million euros or 3%, and supplying misleading information up to 7.5 million euros or 1%. For SMEs and start-ups, the lower of the two figures applies.
Does the AI Act apply to my company if we are outside the EU?
It can. The Act has extraterritorial reach: it applies to non-EU providers who place AI on the EU market, and to non-EU providers and deployers whenever the output of their AI system is used in the EU. If your AI produces a result that is used inside the EU, you may be in scope regardless of where you are based.
What counts as high-risk AI under the Act?
An AI system is high-risk if it is a safety component of a regulated product, or if it is used in one of the areas listed in Annex III: biometrics, critical infrastructure, education, employment and HR, essential public and private services and credit scoring, law enforcement, migration and border control, and the administration of justice. High-risk systems must meet requirements on risk management, data, documentation, human oversight and conformity assessment.
What are the rules for general-purpose AI (GPAI)?
Since 2 August 2025, all GPAI providers must meet transparency and copyright duties, including documentation, downstream information and a training-data summary. The most capable models, above 10^25 FLOPs of training compute, are classed as systemic risk and face extra duties: model evaluation, adversarial testing, risk mitigation, incident reporting and cybersecurity. A voluntary Code of Practice helps providers demonstrate compliance.
Reviewed by the AI Summit Barcelona editorial team: Guillaume Rostand, Tanguy Wincker, Adam Hruska.
More from Resources

AESIA: Spain's AI Supervisory Agency, Explained
AESIA, Spain's AI Supervisory Agency, explained: Europe's first dedicated AI regulator, based in A Coruña, its powers, the Spanish AI law, penalties and its role under the EU AI Act.

AI in Spain
AI in Spain explained: €3.3B raised since 2020, a multi-city strategy across Barcelona, Madrid, La Coruña, San Sebastián and Valencia, plus ENIA and AESIA — Europe's first AI regulator. Sourced 2026 data.

ALIA & Salamandra: Spain's Open Language Models
ALIA is Spain's public, open and multilingual AI programme led by the Barcelona Supercomputing Center: a guide to ALIA-40B, Salamandra and sovereign European LLMs.

Why Barcelona Is Becoming Europe's AI Hub
Why Barcelona is becoming Europe's AI hub: MareNostrum 5, the public ALIA models, a fast-growing startup scene, five universities and MWC — with sourced data.