EU AI Act
Artificial Intelligence Act, Regulation (EU) 2024/1689
Risk-based AI regulation with obligations assigned by role: prohibited practices, high-risk requirements, transparency duties and rules for general-purpose models.
The law in brief
The EU AI Act is the first comprehensive law on artificial intelligence. It sorts AI by risk: some practices are banned outright, high-risk systems must meet detailed requirements before and after they reach the market, some systems carry transparency duties, and general-purpose AI models have their own rules.
Most duties fall on providers, who develop a system or put it on the market, but deployers, the organizations that use AI in their work, carry real obligations too.
Who it applies to
- Providers placing AI systems or general-purpose AI models on the EU market or putting them into service, wherever they are established.
- Deployers using AI systems in the EU in a professional capacity.
- Providers and deployers outside the EU where the system's output is used in the EU.
- Importers, distributors and authorized representatives.
- It does not apply to AI used only for military, defense or national security purposes, to pure scientific research and development, or to purely personal use.
What it requires
Banned practices
Do not place on the market or use AI for practices the Act prohibits, including manipulative techniques that cause harm, social scoring, untargeted scraping to build facial recognition databases, emotion recognition at work or in education, and most real-time remote biometric identification in public spaces for law enforcement.
AI literacy
Take measures to ensure a sufficient level of AI literacy among staff and others operating or using AI systems on your behalf.
Requirements for high-risk systems
Providers must run a risk management system, govern training data, keep technical documentation and logs, design for human oversight, meet accuracy, robustness and cybersecurity levels, operate a quality management system, and complete conformity assessment before placing the system on the market.
Deployer duties for high-risk systems
Use the system according to its instructions, assign competent human oversight, monitor its operation, keep automatically generated logs for at least six months, and inform workers before using it at work. Public bodies and some others must also assess the impact on fundamental rights.
Transparency for certain systems
Tell people when they are interacting with an AI system, mark synthetic content in a machine-readable way, and disclose deep fakes and AI-generated text published to inform the public.
General-purpose AI models
Providers of general-purpose AI models keep technical documentation, give information to downstream providers, respect EU copyright law and publish a summary of training content; models with systemic risk carry additional evaluation, incident and cybersecurity duties.
People's rights
People affected by AI have specific protections: the right to an explanation of certain decisions taken on the basis of a high-risk system's output (Art. 86), the right to be told when they are interacting with an AI system or seeing AI-generated or manipulated content (Art. 50), and the right to complain to a market surveillance authority (Art. 85).
Enforcement and penalties
Three tiers of fines (Art. 99): up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices; up to €15 million or 3% for most other obligations; up to €7.5 million or 1% for supplying incorrect information to authorities. For smaller businesses and start-ups the lower of the two amounts applies. Fines for general-purpose AI model providers are set by the Commission (Art. 101).
The highest fines, for prohibited practices
Up to €35 million or 7% of worldwide annual turnover, whichever is higher.
What's changing
Dates moved by Regulation (EU) 2026/1744. High-risk obligations for systems listed in Annex III now apply from 2 December 2027, and for AI in products under Annex I from 2 August 2028. The prohibitions have applied since 2 February 2025, general-purpose AI model rules since 2 August 2025, and the Article 50 transparency duties since 2 August 2026. Regulatory Watch reports guidance and implementing acts as they arrive.
What to do first
- Inventory the AI you build, buy and use, and record your role for each: provider, deployer, importer or distributor.
- Screen every use against the prohibited practices in Article 5 and stop anything that falls inside.
- Classify each system: prohibited, high-risk, transparency-only or minimal.
- Give staff AI literacy training proportionate to their role (Art. 4).
- For high-risk systems, plan the provider requirements or, as a deployer, human oversight, log retention and monitoring.
- Label AI interactions and AI-generated content where Article 50 applies.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI
The meeting signals EU progress on AI governance, linking AI Act enforcement with a new cybersecurity‑AI action plan. On 17 September 2026 the EU AI Board met under the Irish Presidency to review priorities for EU AI policy and AI Act enforcement. The meeting included an update on the Commission’s Action Plan on cybersecurity and AI and on transparency rules that became applicable on 2 August 2026. Observers from Moldova attended for the first time.
Effective: 2 August 2026.
Source: European Commission digital strategy news. EU AI Act in the regulations library.
-
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore. On July 20, 2026, Singapore’s Personal Data Protection Commission released its finalized Advisory Guidelines on the Use of Personal Data in Generative AI. The guidance clarifies the Publicly Available Exception for web‑scraping and requires AI‑specific notifications when seeking consent to train AI models. It is part of broader APAC regulator efforts to address agentic AI and biometric data challenges.
Source: Future of Privacy Forum. EU AI Act in the regulations library.
-
Future of Privacy Forum releases updated AI risk assessment framework and best practices for hiring
The updated best practices give organizations concrete guidance to responsibly deploy AI in hiring, mitigating legal and ethical risks. Future of Privacy Forum and leading HR software firms released Updated Best Practices for AI and Workplace Assessment Technologies, addressing generative and agentic AI in employment. The guidance outlines a risk assessment framework and assigns responsibilities to developers and deployers for governance, non‑discrimination, transparency, data security, privacy, and human oversight. A webinar on September 28 will present the framework to policymakers and practitioners.
Source: Future of Privacy Forum. EU AI Act in the regulations library.
-
EU Commission begins enforcing AI Act and new transparency rules on 2 August 2026
The enforcement introduces mandatory disclosure obligations for AI systems to curb deception and give users clearer information. From 2 August 2026 the European Commission’s AI Office and national authorities will start enforcing the AI Act. New transparency rules require chatbots to disclose they are AI and AI‑generated content such as deepfakes to be labelled with machine‑readable marks. The Commission also published a list of over 180 organisations that have signed the Code of Practice on transparency of AI‑generated content.
Effective: 2 August 2026.
Source: European Commission digital strategy news. EU AI Act in the regulations library.
Sources
- Regulation (EU) 2024/1689 EUR-Lex · Official text or regulator