Contact
Early bird promotion ending soon
MediaGet Involved
AI
SUMMIT BCN
Resources
Get ticketsLog In
Home / Resources / AI Regulation

Share

On this page

  • What is the EU AI Act
  • AI Act risk categories
  • Timeline of application
  • Rules for general-purpose AI (GPAI)
  • Who is affected
  • Penalties
  • What it means for businesses

More from Resources

  • DefinitionsAESIA: Spain's AI Supervisory Agency, Explained
  • GuidesAI in Spain
  • AI EngineeringALIA & Salamandra: Spain's Open Language Models
  • GuidesWhy Barcelona Is Becoming Europe's AI Hub
EU AI Act risk pyramid - four risk tiers from unacceptable to minimal, Regulation EU 2024/1689 explained

Inside European AI

The EU AI Act, Explained

Guillaume Rostand, Tanguy Wincker, Adam Hruska·June 25, 2026·10 min read

The EU AI Act (Regulation (EU) 2024/1689) is the EU's risk-based law for artificial intelligence. It entered into force on 1 August 2024 and applies in stages through 2 August 2027. AI is split into four tiers: unacceptable (banned since February 2025), high-risk (strict obligations), limited (transparency only) and minimal (no rules). Rules for general-purpose AI began on 2 August 2025. Penalties reach €35M or 7% of worldwide turnover, whichever is higher.

The EU AI Act is the world's first comprehensive law on artificial intelligence. It sorts AI systems into four risk tiers, bans a short list of practices outright, imposes strict obligations on high-risk systems, adds dedicated rules for general-purpose AI (GPAI), and backs all of it with fines of up to €35 million or 7% of global annual turnover.

This dossier explains the Act in plain terms: what it is, how the risk categories work, when each obligation applies, who is caught by its extraterritorial reach, and what it means for businesses. Every figure is sourced and dated. It is a core entry in our AI governance coverage and connects to the enterprise AI guide.

On this page

  • What is the EU AI Act
  • Risk categories
  • Timeline of application
  • Rules for GPAI
  • Who is affected
  • Penalties
  • What it means for businesses

What is the EU AI Act

The EU AI Act is the European Union's regulation establishing harmonised rules for artificial intelligence across the single market. Formally Regulation (EU) 2024/1689, it was published in the EU's Official Journal on 12 July 2024 and entered into force on 1 August 2024, twenty days later (European Commission, 2024). It is widely described as the world's first comprehensive AI law.

Its core idea is a risk-based approach: the obligations placed on an AI system scale with the risk it poses to health, safety and fundamental rights. A spam filter and a CV-screening tool are not regulated the same way. The Act assigns every system to one of four tiers and attaches a different rulebook to each (European Commission, AI Act high-level summary, 2024).

The Act sits at the heart of the EU's wider AI Act framework and its broader push for responsible AI. Enforcement is shared between national market surveillance authorities and a new central body, the European AI Office, established within the European Commission to supervise and coordinate implementation, with special responsibility for general-purpose AI models (European Commission, AI Office, 2024).

AI Act risk categories

The Act defines four risk categories. The tier determines what a provider or deployer must do before and after putting an AI system on the EU market. The table below summarises the tiers, with examples and headline obligations.

Risk tierExamplesCore obligations
Unacceptable (prohibited)Social scoring by public authorities; subliminal manipulation causing harm; untargeted facial-image scraping; emotion recognition at work or school; real-time remote biometric ID in public for law enforcement (narrow exceptions)Banned outright. Prohibited since 2 Feb 2025 under Article 5
High-riskAI in biometrics, critical infrastructure, education, employment and HR, essential services and credit scoring, law enforcement, migration and border control, justice (Annex III); safety components of regulated productsRisk-management system, data governance, technical documentation, logging, human oversight, accuracy & cybersecurity; conformity assessment, CE marking and EU database registration
LimitedChatbots, AI-generated content and deepfakes, emotion-recognition systems (outside banned contexts)Transparency only: users must be told they are interacting with AI; AI-generated content must be labelled
MinimalSpam filters, AI in video games, inventory-management tools — the large majority of AI in use todayNo mandatory obligations; voluntary codes of conduct encouraged

Unacceptable-risk practices are listed in Article 5 and have been banned since 2 February 2025. They include eight categories — among them social scoring, manipulative or exploitative AI, untargeted scraping of facial images, emotion recognition in workplaces and schools, and certain biometric categorisation and real-time biometric identification (European Commission, 2024–2025).

High-risk is where most of the Act's text sits. A system is high-risk if it is a safety component of a product already covered by EU product-safety law, or if it falls within one of the use cases listed in Annex III — biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration, and the administration of justice (EU AI Act, Annex III). These systems carry the full compliance load and are central to debates around AI governance.

Limited-risk systems face only transparency duties, and minimal-risk systems — the bulk of AI on the market — face no new obligations at all.

Timeline of application

The Act does not apply all at once. After entry into force on 1 August 2024, its provisions switch on in staggered phases over three years, giving organisations time to prepare. The key dates are below.

DateMilestone
1 Aug 2024Regulation (EU) 2024/1689 enters into force
2 Feb 2025Prohibitions on unacceptable-risk AI (Article 5) apply; AI-literacy obligations begin
2 Aug 2025Rules for general-purpose AI (GPAI) models apply; governance provisions and the AI Office's remit take effect; penalty provisions become applicable
2 Aug 2026The bulk of the Act applies, including obligations for Annex III high-risk systems (e.g. employment, credit, essential services)
2 Aug 2027Obligations for high-risk AI that are safety components of regulated products (e.g. medical devices, civil aviation) apply; full roll-out complete

These dates come directly from the European Commission's official implementation timeline and the AI Act Service Desk (European Commission, 2024–2026). Note that GPAI providers whose models were already on the market before 2 August 2025 have until 2 August 2027 to bring them into full compliance.

One caveat for 2026: in 2026 the Commission proposed a "Digital Omnibus" package that would defer some high-risk (Annex III) obligations beyond August 2026. As of June 2026 this is a legislative proposal, not adopted law — the dates above reflect the binding text of Regulation (EU) 2024/1689, and businesses should track the Omnibus negotiations rather than assume any delay (European Commission Digital Omnibus proposal, 2026). For the canonical, continuously updated calendar, see the EU AI Act implementation timeline.

Rules for general-purpose AI (GPAI)

General-purpose AI (GPAI) models — the foundation models that can be adapted to many tasks and now underpin much of the AI ecosystem — get their own chapter in the Act. Obligations for GPAI providers began to apply on 2 August 2025 (European Commission, GPAI guidelines, 2025).

All GPAI providers must meet baseline transparency and copyright duties: maintain up-to-date technical documentation, provide information to downstream developers who build on the model, publish a summary of the training data, and put in place a policy to comply with EU copyright law.

A smaller set of the most capable models is classed as carrying systemic risk. Under the Act, a model is presumed to have high-impact capabilities — and therefore systemic risk — when the cumulative compute used for training exceeds 10^25 floating-point operations (FLOPs) (EU AI Act, Article 51; artificialintelligenceact.eu). These providers face extra obligations:

  • Model evaluation and adversarial testing (red-teaming) before release
  • Systemic-risk assessment and mitigation across the model's lifecycle
  • Serious-incident reporting to the AI Office and national authorities
  • Cybersecurity protection for the model and its physical infrastructure

To help providers show compliance, the Commission and the AI Office published the General-Purpose AI Code of Practice in July 2025 — a voluntary instrument drawn up by independent experts, structured around three chapters: Transparency, Copyright, and Safety & Security (European Commission, GPAI Code of Practice, 2025). The Safety & Security chapter applies only to systemic-risk models, currently a small group of frontier-model developers. Many of these labs sit among Europe's leading AI companies and the broader field of foundation-model providers.

Who is affected

The Act applies across the AI value chain and, crucially, reaches beyond the EU's borders. Article 2 sets out its scope. It applies to:

  • Providers placing AI systems or GPAI models on the EU market, wherever they are established — including non-EU companies
  • Deployers (professional users of AI systems) located or established in the EU
  • Providers and deployers in third countries where the output of the AI system is used in the EU
  • Importers, distributors and product manufacturers placing AI-enabled products on the EU market

That third limb is the one most non-EU firms miss: if your system produces a score, decision, recommendation or piece of content that is used inside the EU, the Act can apply regardless of where your servers or staff sit (EU AI Act, Article 2; William Fry, 2025). The Act does not apply to AI used for purely personal, non-professional activity, to systems used solely for military, defence or national-security purposes, or to research and development before a system is placed on the market.

The split between providers (who design and build) and deployers (who put systems to use) matters: providers carry the conformity-assessment and documentation burden, while deployers are responsible for proper use, human oversight and monitoring. Governance leaders working through these roles — such as practitioners featured among our speakers, including Alia Zafar and Laura Gilbert — increasingly treat the provider/deployer line as the first question in any compliance review.

Penalties

The Act backs its rules with a tiered fines regime under Article 99. Penalties are calculated as a fixed amount or a percentage of worldwide annual turnover — whichever is higher (whichever is lower for SMEs and start-ups). The three tiers are:

  • Up to €35 million or 7% of total worldwide annual turnover — for breaching the Article 5 prohibitions on unacceptable-risk AI
  • Up to €15 million or 3% of turnover — for breaching most other obligations, including high-risk and GPAI rules
  • Up to €7.5 million or 1% of turnover — for supplying incorrect, incomplete or misleading information to authorities

These figures are set out in Article 99 of Regulation (EU) 2024/1689 (EU AI Act, Article 99). Member States designate the penalties, which must be "effective, proportionate and dissuasive," while the European AI Office enforces fines specifically against GPAI-model providers. Penalty provisions became applicable on 2 August 2025.

What it means for businesses

For most companies, the Act is less about foundation models and more about knowing which tier your AI falls into and acting accordingly. A practical sequence:

  • Inventory your AI. Map every system you build, buy or embed, and check it against the Article 5 prohibitions and the Annex III high-risk list.
  • Classify by tier. Most business AI is minimal or limited risk — but HR screening, credit decisions, biometric tools and essential-services systems can be high-risk and carry the full obligation set.
  • Fix your role. Decide whether you are a provider or a deployer for each system; the duties differ sharply.
  • Build AI literacy. Since 2 February 2025, organisations must ensure staff dealing with AI have a sufficient level of AI literacy.
  • Document and govern. High-risk systems need a risk-management system, data governance, human oversight and a conformity assessment before going to market.

The cost of getting this wrong is set by Article 99 above; the cost of getting it right is a governance programme that many firms are now standing up regardless of jurisdiction, because the Act is becoming a de facto global reference for responsible AI. For a structured starting point, see our enterprise AI guide, and for the policy debate in person, the AI Summit Europe programme convenes regulators, providers and deployers each year.

The EU AI Act is now the reference point for AI regulation worldwide: four risk tiers, a three-year roll-out to 2027, dedicated rules for general-purpose AI, and fines reaching 7% of global turnover. For any team building or deploying AI in Europe, the first task is simple — find your tier, fix your role, and document everything. That work, and the people doing it, increasingly gather in Barcelona.

Follow AI regulation where it is decided

The EU AI Act is reshaping how AI is built and deployed across Europe. AI Summit Barcelona 2026 brings together the regulators, providers and enterprise teams working through it in practice.

Get your tickets →

If this interests you

  • Map the framework: the AI Act, AI governance and responsible AI topics.
  • Go deeper: the enterprise AI guide and the AI Summit Europe dossier.
  • See the field: the top AI startups in Europe and Mistral AI.
  • Meet the people: browse the speakers, including Alia Zafar and Laura Gilbert.

Sources

  • European Commission — AI Act / Regulatory framework for AI, Shaping Europe's Digital Future, 2024–2026
  • European Commission — AI Act implementation timeline, AI Act Service Desk, 2024–2026
  • European Commission — European AI Office, 2024
  • European Commission — Guidelines for providers of general-purpose AI models and General-Purpose AI Code of Practice, 2025
  • Regulation (EU) 2024/1689 (EU AI Act) — article-by-article reference: artificialintelligenceact.eu
  • EU AI Act, Article 99 (Penalties)
  • EU AI Act high-level summary, 2024
  • William Fry — A Practical Guide to the Extraterritorial Reach of the AI Act, 2025

Frequently asked questions

What is the EU AI Act in simple terms?+

The EU AI Act is the European Union's law on artificial intelligence, the first comprehensive AI regulation in the world. It groups AI systems by risk: it bans a few dangerous uses, puts strict rules on high-risk uses like hiring and credit scoring, asks for transparency on chatbots and deepfakes, and leaves most everyday AI untouched. It entered into force on 1 August 2024 and applies in stages through 2027.

When does the AI Act apply?+

The Act entered into force on 1 August 2024 and applies in phases. Bans on unacceptable-risk AI started on 2 February 2025; rules for general-purpose AI on 2 August 2025; most high-risk obligations on 2 August 2026; and obligations for high-risk AI in regulated products on 2 August 2027. A 2026 Digital Omnibus proposal could shift some high-risk dates, but it is not yet adopted law.

What are the penalties under the AI Act?+

Fines are tiered under Article 99. Breaching the bans on unacceptable-risk AI can cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Most other breaches reach 15 million euros or 3%, and supplying misleading information up to 7.5 million euros or 1%. For SMEs and start-ups, the lower of the two figures applies.

Does the AI Act apply to my company if we are outside the EU?+

It can. The Act has extraterritorial reach: it applies to non-EU providers who place AI on the EU market, and to non-EU providers and deployers whenever the output of their AI system is used in the EU. If your AI produces a result that is used inside the EU, you may be in scope regardless of where you are based.

What counts as high-risk AI under the Act?+

An AI system is high-risk if it is a safety component of a regulated product, or if it is used in one of the areas listed in Annex III: biometrics, critical infrastructure, education, employment and HR, essential public and private services and credit scoring, law enforcement, migration and border control, and the administration of justice. High-risk systems must meet requirements on risk management, data, documentation, human oversight and conformity assessment.

What are the rules for general-purpose AI (GPAI)?+

Since 2 August 2025, all GPAI providers must meet transparency and copyright duties, including documentation, downstream information and a training-data summary. The most capable models, above 10^25 FLOPs of training compute, are classed as systemic risk and face extra duties: model evaluation, adversarial testing, risk mitigation, incident reporting and cybersecurity. A voluntary Code of Practice helps providers demonstrate compliance.

Reviewed by the AI Summit Barcelona editorial team: Guillaume Rostand, Tanguy Wincker, Adam Hruska.

Back to Resources

More from Resources

AESIA - Spain's AI Supervisory Agency, Europe's first dedicated AI regulator based in A Coruna
Definitions

AESIA: Spain's AI Supervisory Agency, Explained

AESIA, Spain's AI Supervisory Agency, explained: Europe's first dedicated AI regulator, based in A Coruña, its powers, the Spanish AI law, penalties and its role under the EU AI Act.

AI in Spain map - 3.3 billion euros raised since 2020, AI hubs in Barcelona, Madrid, La Coruna, San Sebastian and Valencia
Guides

AI in Spain

AI in Spain explained: €3.3B raised since 2020, a multi-city strategy across Barcelona, Madrid, La Coruña, San Sebastián and Valencia, plus ENIA and AESIA — Europe's first AI regulator. Sourced 2026 data.

ALIA and Salamandra - Spain's open multilingual AI language models developed by the Barcelona Supercomputing Center
AI Engineering

ALIA & Salamandra: Spain's Open Language Models

ALIA is Spain's public, open and multilingual AI programme led by the Barcelona Supercomputing Center: a guide to ALIA-40B, Salamandra and sovereign European LLMs.

Barcelona skyline at the World Trade Center - why Barcelona is becoming Europe's leading artificial intelligence hub in 2026
Guides

Why Barcelona Is Becoming Europe's AI Hub

Why Barcelona is becoming Europe's AI hub: MareNostrum 5, the public ALIA models, a fast-growing startup scene, five universities and MWC — with sourced data.

AI in Europe, weekly

The European AI brief

The companies, leaders and rules shaping AI in Europe — and where it all connects at AI Summit Barcelona. Join the list to be first to know.

Coming soon
AI
SUMMIT BCN

Europe's most experiential AI event. 22-23 September 2026 at WTC Barcelona, during AI Week.

  • info@aisummitnetwork.com
  • Barcelona, Spain

Attend

  • Why Attend
  • Who Attends
  • Plan Your Trip
  • FAQ
  • Relive 2025

Programme

  • Speakers
  • Tracks
  • Schedule
  • Apply to Speak

AI Week

  • AI Week overview
  • Hackathon
  • Side Events
  • Host a Side Event

Sponsors & Partners

  • Sponsors & Partners
  • Community
  • Become a Sponsor

More

  • About
  • Resources
  • Press
  • Tickets
  • Contact

© 2026 AI Summit Barcelona. All rights reserved.

Privacy PolicyTerms of Service