The EU AI Act explained in plain English
The EU AI Act (Regulation (EU) 2024/1689) is the first broad, binding law for artificial intelligence. It entered into force on 1 August 2024 and applies in stages. If you build or use AI and have any link to the EU market, it matters even if your company is based somewhere else.
Who it applies to
The Act reaches beyond Europe. It covers providers that place AI systems on the EU market, deployers (organisations that use AI) located in the EU, and in some cases providers and deployers outside the EU whose AI output is used in the EU. A startup in the US or Kenya selling to EU customers can be in scope.
The four risk tiers
- Unacceptable risk: banned outright, for example certain manipulative uses and social scoring. These bans have applied since 2 February 2025.
- High risk: allowed, but with strict duties. This covers AI used in areas such as hiring, education, credit scoring, essential services, law enforcement and critical infrastructure.
- Transparency risk: systems such as chatbots and AI-generated content must be disclosed as AI.
- Minimal risk: most other AI, with no specific obligations beyond existing law.
Separate rules apply to general-purpose AI models, and those obligations have applied since 2 August 2025.
What changed in 2026
The EU adopted the AI Omnibus (Regulation (EU) 2026/1744), which entered into force on 27 July 2026. Its biggest effect is that the date for stand-alone high-risk systems listed in Annex III moved from 2 August 2026 to 2 December 2027. The Omnibus also added new bans, including on certain AI tools that generate realistic intimate imagery or child sexual abuse material, and it widened some relief for smaller companies.
Some transparency-related timelines were adjusted as well, so check the exact date for your use case instead of assuming everything was delayed.
Deferred does not mean cancelled. Providers of high-risk systems still need risk management, data governance, logging, human oversight and technical documentation in place.
What high-risk providers must prepare
- A risk management system that covers the whole lifecycle
- Data governance and data quality controls
- Technical documentation (its required content is set out in Annex IV)
- Automatic logging of events
- Instructions for deployers and human oversight measures
- Accuracy, robustness and cybersecurity measures
- A conformity assessment and registration before going to market
Penalties
Under the original text, fines can reach 35 million euros or 7% of worldwide annual turnover for banned practices, with lower tiers for other breaches. Check whether the 2026 changes affect the figures that apply to you.
What to do now
- List every AI system you build or use.
- Work out which risk tier each one falls into.
- Start keeping records and documentation now. It is far cheaper than rebuilding it later.
Good starting points are the official text on EUR-Lex and the European Commission pages on the AI Act.
This article is general information, not legal advice. Rules change often, so check official sources before you rely on it.