Digital & AI
Regulation (EU) 2024/1689
AI Act
Artificial Intelligence Act
The EU sorts AI by how much harm it could do — banning a few uses, tightly watching high-risk ones, and asking chatbots to be honest about being machines.
Does this hit me?
You should see labels on AI chat and on realistic fake images or video. A bank, hospital, or employer using high-risk AI has to be able to explain the system and keep a human responsible. You are not personally fined — companies are.
Check in the wizardPick a country in the header to see who enforces this at home. Union text is not the last word for directives.
Next switch-on: in 11 months · 2 Aug 2027 — AI Act — remaining product-related high-risk rules
How it rolls in
Aug 2024
Law entered into force.
Feb 2025
Bans and AI-literacy duties started to apply.
Aug 2025
Rules for general-purpose AI models apply.
Aug 2026
Most high-risk system rules apply.
Aug 2027
Remaining product-related high-risk rules apply.
Why it exists
Lawmakers wanted people to know when they are talking to AI, and to stop systems that score people, scrape faces from the street, or make life-changing decisions without a human in the loop.
What actually changes
- Some uses are banned: social scoring, untargeted scraping of faces for databases, and emotion-reading at work or school in most cases.
- High-risk AI (hiring, credit, policing, medical devices) needs documentation, testing, and human oversight before it can be sold.
- General-purpose models like large chatbots have extra duties: summarize training data, label synthetic media, and publish safety information.
- If you interact with AI, you should be told. Deepfakes should be marked.
How it hits you
You should see labels on AI chat and on realistic fake images or video. A bank, hospital, or employer using high-risk AI has to be able to explain the system and keep a human responsible. You are not personally fined — companies are.
For citizens
What this does to everyday life
Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.
You should know when it is a machine
Chatbots and realistic fake images or video should be labelled. If a public service or a bank uses high-risk AI on you, a human still has to be responsible.
Hiring, credit, school, benefits
These uses are treated as high-risk. The organisation must test the system, keep logs, and avoid dumping the decision on a black box.
Banned uses
Social scoring like a credit score for your whole life, untargeted scraping of faces off the street into a database, and most emotion-reading at work or school are not allowed.
Rights you actually get
- Transparency when you interact with AI in many settings.
- Explanation and human oversight when high-risk AI affects you.
- Complaints to market-surveillance authorities as the system matures.
Costs and trade-offs
- Some cheap tools may disappear or get more disclaimers.
- Public services may slow down slightly while they document systems — that is the point.
What you can do
- Ask an employer or bank whether AI is used on your file and who oversees it.
- Treat unmarked deepfakes as a red flag; platforms also have DSA duties on illegal content.
What you can ignore
- You are not licensed as an AI provider for using a chatbot at home.
- The Act does not ban you from criticising AI or from using it for homework help.
If something goes wrong
The organisation that deployed the system first (employer, bank, hospital). Then the national market-surveillance / consumer body. Data-protection authorities still cover personal data inside the AI.
More citizen notes across files: For people
Heard this? Not quite.
Claim: The EU banned ChatGPT.
No. General chatbots can operate, but providers must be transparent and meet model-level duties. A few uses (not the products themselves) are banned.
Claim: Hobby projects are illegal.
Research, open-source, and personal non-professional use sit in lighter lanes. The heavy rules target placing systems on the market or using them on people at scale.
Latest official statements
All EU NewsNo tagged Commission, Parliament or Council statement in the current feeds.
Board one-pager
Board one-pager
Who this is for: EU digital, product and data teams. Regulation (EU) 2024/1689. in 11 months · 2 Aug 2027.
Scope
- You develop, import, or brand an AI system used in the EU.
- You deploy AI that affects hiring, workers, credit, access to services, education, or essential public services.
- You provide a general-purpose model.
First 90 days
- Week 1: Inventory every AI system, including embedded vendor tools.
- Week 2: Classify: prohibited / high-risk / GPAI / transparency-only.
- Week 3: Kill or redesign anything that looks like social scoring, untargeted face scraping, or workplace emotion recognition.
- Month 2: For high-risk: risk-management file, data governance, logging, human oversight, and instructions for use.
Penalties: Up to €35 million or 7% of worldwide annual turnover for prohibited practices; lower caps for other breaches. National market-surveillance authorities enforce.
For companies
How to stay on the right side of this file
Practical order of work, not a substitute for counsel. Providers placing AI on the EU market, and deployers using it in the EU — especially high-risk and general-purpose models.
You are probably
A deployer if you use a vendor tool on staff or customers; a provider if you put a system on the Union market under your name.
Effort
Inventory and class: days for a small shop, weeks for a bank. High-risk conformity: a real programme.
Budget
Most SMEs: vendor due diligence only. High-risk providers: documentation, testing, possible notified-body costs.
Roles in this file
The same company can wear more than one hat. Classify before you buy a tool.
Provider
You develop or put the system on the market under your name (including a substantial modification).
Classify (prohibited / GPAI / high-risk / limited). Technical file, quality system, instructions for deployers.
Deployer
You use the system at work or on the public (employer, bank, hospital, authority).
Use it as intended, human oversight, logs, staff literacy. High-risk: FRIA if you are a public body or an Annex III private deployer in scope.
Distributor / importer
You land a third-country system in the Union without being the provider.
Check CE / documentation, keep the provider’s name on the system, do not hide the class.
Are you in scope?
This year's work- You develop, import, or brand an AI system used in the EU.
- You deploy AI that affects hiring, workers, credit, access to services, education, or essential public services.
- You provide a general-purpose model.
Usually not, if
- Personal, non-professional tinkering.
- Many purely internal, low-risk tools — still check prohibited uses.
First moves
- Week 1Inventory every AI system, including embedded vendor tools.CTO + compliance
- Week 2Classify: prohibited / high-risk / GPAI / transparency-only.Legal + product
- Week 3Kill or redesign anything that looks like social scoring, untargeted face scraping, or workplace emotion recognition.Product
- Month 2For high-risk: risk-management file, data governance, logging, human oversight, and instructions for use.Quality / risk
- Prefer vendors who already treat their product as high-risk or GPAI and will share the file.
- If you only wrap a third-party API for copywriting, stay in the light lane — do not quietly turn it into a hiring bot.
- Write who is allowed to use which tool. That is AI literacy in practice.
If you skip this
- A hiring tool you ‘just use’ is still a deployer file in 2026.
- Calling everything ‘GPAI’ does not escape Annex III if the intended purpose is credit or work.
- Fines scale to worldwide turnover for prohibited and high-risk breaches.
Done looks like
- A register of AI systems with a written class and an owner.
- Vendor files that state Annex III yes/no and where the technical documentation lives.
- Human-oversight design for anything that ranks people.
- A literacy note for staff who use the tools — not a one-hour video for the whole company.
Keep this evidence
- AI inventory with role (provider vs deployer).
- Risk classification memo.
- Technical documentation and quality-management traces for high-risk systems.
- GPAI transparency artefacts if you provide models.
Ask vendors
- How is this system classified under the AI Act, and who is the provider?
- Will you give us the instructions for use, logging, and oversight design?
- Is biometric or emotion inference on by default?
Where programmes usually break
- Assuming 'we only use ChatGPT' means you have no duties as a deployer.
- HR tools that score candidates without a high-risk file.
- Deepfakes or chatbots without user-facing labels.
Call counsel when
- Biometrics, emotion inference, social scoring, or scraping faces.
- You substantially modify a vendor model and might become the provider.
- A public contract that requires an FRIA you have not scoped.
Enforcement
Up to €35 million or 7% of worldwide annual turnover for prohibited practices; lower caps for other breaches. National market-surveillance authorities enforce.
National market surveillance authorities; AI Office for general-purpose models at EU level.
Need a stack, not one file? Open the company desk
Professional briefing
Legal architecture and duties
For counsel, compliance, and policy teams. Not advice. The Official Journal still wins.
- Instrument
- Regulation
- Legal basis
- Art 114 TFEU · Regulation (EU) 2024/1689
- Application
- Entered into force 1 August 2024. Prohibitions and AI literacy: 2 February 2025. GPAI: 2 August 2025. Most high-risk (Annex III): 2 August 2026. Embedded-product high-risk: 2 August 2027.
A product-safety-style regulation that classifies AI systems by risk and assigns duties to providers and deployers. It is extra-territorial for systems placed on the Union market or whose output is used in the Union. The operational core for most corporates is inventory, classification (banned / high-risk / limited-risk / GPAI), and vendor file requests — not a general licence to operate AI. GDPR still governs personal data inside the model.
How the file is built
Risk pyramid
Unacceptable (Art 5 bans), high-risk (Annex I product legislation and Annex III use-cases), limited-risk transparency (Art 50), and residual. GPAI models have a parallel chapter (Arts 51–56) including systemic-risk models.
Provider vs deployer
The provider places the system on the market or puts it into service under its name. A deployer who substantially modifies a system, or puts a general tool to a high-risk use with its own name, can become a provider. That recharacterisation is the main M&A and procurement trap.
Governance
EU AI Office (GPAI), market-surveillance authorities for high-risk, notifying bodies for conformity assessment. National sandboxes are optional; they do not waive placing-on-the-market duties.
Operators
| Role | Who | Core duties |
|---|---|---|
| Provider | Develops or brands the system. | QMS, data governance, technical documentation, logging, human oversight design, CE marking / declaration, post-market monitoring. |
| Deployer | Uses the system under its authority. | Use as instructed, human oversight, logging, worker information, FRIA for public bodies and some private high-risk uses. |
| GPAI provider | Places a general-purpose model on the market. | Technical documentation, copyright policy, training-data summary; extra evaluation and incident reporting if systemic risk. |
Scope
Providers established in the Union; providers outside the Union placing systems on the market or putting them into service here; deployers established in the Union; providers and deployers where the output is used in the Union.
In
- AI system as defined in Art 3(1) — machine-based, infers how to generate outputs that influence environments.
- High-risk uses in Annex III: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.
- GPAI models, including those integrated into downstream systems.
Out, or narrower than assumed
- Military, defence, national-security uses.
- Scientific research and development, and personal non-professional activity — read the recitals, not marketing slides.
- Systems released under free licences may get a lighter GPAI lane unless they are placed on the market against payment or as a service with systemic risk.
Operative provisions
| Anchor | Rule | What it does in practice |
|---|---|---|
| Art 5 | Bans social scoring, untargeted facial scraping into databases, emotion recognition at work/school (narrow exceptions), some biometric categorisation, and certain manipulative techniques. | Procurement of ‘emotion AI’ for HR is usually a stop, not a DPIA exercise. |
| Arts 8–27 | High-risk requirements: risk management, data sets, technical file, logging, transparency to deployers, human oversight, accuracy/cybersecurity. | If you cannot get the technical file from a vendor, you cannot lawfully be the provider of that high-risk system. |
| Art 50 | People must know they interact with AI; synthetic audio/image/video must be marked. | Chat widgets and marketing deepfakes are a labelling problem now, not in 2027. |
| Art 99 | Fines up to €35m or 7% (bans), 3% (other operator duties), 1% (incorrect information). | Group turnover; product-safety authorities may also pull systems. |
Secondary law and guidance
- GPAI Code of Practice (Commission / AI Office).
- Harmonised standards via CEN-CENELEC — delayed standards are the practical bottleneck for CE marking.
- Commission guidelines on the definition of AI system and on prohibited practices.
National layer. Market-surveillance authorities and notifying bodies are national. Public-sector FRIA practice will diverge. Labour law still limits workplace monitoring even where the AI Act does not ban the tool.
How it sits with other files
Lawful basis, DPIA, and automated-decision rights remain. Art 22 GDPR and high-risk AI overlap in credit, hiring, and benefits.
AI products with digital elements carry CRA security-update duties in addition to AI Act logging and robustness.
Recommender systems and deepfake labelling interact; VLOPs have systemic-risk duties that catch AI-amplified content.
Enforcement and private rights
Who
National market surveillance for most systems; Commission AI Office for GPAI. Notified bodies for some conformity assessments.
Tools
Corrective actions, withdrawal, fines. High-risk systems without conformity cannot be placed on the market.
Private rights
No full private damages chapter equivalent to GDPR Art 82. Product-liability reform and national tort law will fill the gap — watch the AI liability file separately.
Risk register
| Risk | Signal | Control |
|---|---|---|
| Mis-classification as minimal risk | Hiring or credit scoring treated as ‘productivity AI’ | Use-case inventory mapped to Annex III, signed off by legal + risk. |
| Vendor file gap | API vendor refuses technical documentation | Contractual audit rights now; do not go live as de facto provider. |
| Banned workplace use | Emotion or attention analytics in call centres | Kill-list of Art 5 practices in procurement. |
Open issues
- Whether a given enterprise tool is an ‘AI system’ at all — Commission guidance is helpful but not a court.
- When a deployer of a customised GPAI becomes a provider.
- Availability of harmonised standards before August 2026 high-risk application.
- Overlap of FRIA, DPIA, and existing fundamental-rights assessments in the public sector.
Primary sources
The Act does not tax ‘using ChatGPT’. It taxes putting AI on people at scale — especially hiring, credit, biometric ID, and general-purpose models.
You feel it now
Bans and AI-literacy duties already apply. GPAI provider rules from August 2025.
Next
Most high-risk duties: August 2026. Product-safety high-risk overlap: 2027.
Where it lands
| Channel | People | Companies |
|---|---|---|
| Everyday use | You should see that a chatbot is a machine, and that a realistic fake is synthetic. You are not fined for prompting. | GPAI and chatbot vendors carry transparency and (for systemic models) safety duties. A widget is not automatically high-risk. |
| Life decisions | Hiring, credit, benefits, policing: a human has to stay responsible. You can demand an explanation from the deployer, not from the model card. | Annex III high-risk means data governance, logs, human oversight, and a technical file before placing on the market or deploying in the Union. |
| Work and school | Emotion recognition at work or school is largely banned. Unwanted biometric scraping for databases is banned. | HR-tech vendors and employers share the file: provider if you place the tool, deployer if you use it on staff. |
| Procurement | Public services using high-risk AI owe a fundamental-rights impact assessment. | Buyers will ask for the technical file and the Annex III class. ‘Our model is transformative’ is not a class. |
Who gains
People facing automated life decisions; SMEs buying documented off-the-shelf tools.
Who pays
Providers who cannot classify the system; deployers who bolted AI onto hiring with no oversight.
Files this pulls with it
- GDPR — Personal data in the model or the logs is still a GDPR file.
- Product Liability Directive — Software and AI in a defective product get an easier evidence path from 2026.
- Cyber Resilience Act — Connected products with AI still need CRA security updates.
Who pays
Providers and deployers of AI systems, especially high-risk and general-purpose models.
Who benefits
People facing automated decisions; smaller firms buying safer off-the-shelf tools.
Read the official text