Reference · EU AI Act

The EU AI Act, in one page

What the regulation asks, of whom, and from when — as amended by the Digital Omnibus (Regulation (EU) 2026/1744).

Written for people who build or deploy AI systems and need the structure before the detail. It follows the logic of the text, cites the articles, and says what changed in July 2026.

Last reviewed: 30 September 2026

01 · Logic

A product-safety law for AI

The AI Act is closer to CE marking than to the GDPR. The provider shows conformity before placing a system on the market, then monitors it in use.

Obligations depend on two questions, always in this order:

  1. How risky is the intended use — prohibited, high-risk, transparency, minimal. The purpose counts, not the technology.
  2. What role the organisation plays for that system — provider, deployer, importer, distributor.

A separate chapter regulates general-purpose AI models (GPAI) as models, not as systems.

Anyone who has taken a medical device through ISO 13485 and IEC 62304 knows the discipline: quality management, risk management, technical documentation, conformity assessment, post-market monitoring. The AI Act applies it to AI.

02 · Dates

When each part applies

The Digital Omnibus (Regulation (EU) 2026/1744, OJ L of 24 July 2026) moved the high-risk dates. Prohibitions, AI literacy, GPAI and transparency were not postponed.

  1. Entry into force Art. 113
  2. Prohibited practices Art. 5 and AI literacy Art. 4
  3. General-purpose AI models, governance, notified bodies, penalties
  4. Regulation (EU) 2026/1744 enters into forceOmnibus
  5. Transparency obligations Art. 50 — not postponed
  6. Two new prohibitions Art. 5(1)(ba)–(bb); end of the grace period for marking synthetic content of systems already on the market Art. 50(2)Omnibus
  7. GPAI models placed on the market before 2 August 2025 must comply Art. 111(3); national regulatory sandboxes due
  8. High-risk systems, Annex III (employment, credit, education…) Art. 113Omnibuspreviously 2 August 2026
  9. High-risk systems, Annex I (AI in regulated products: medical devices, toys, lifts…)Omnibuspreviously 2 August 2027
  10. High-risk systems already used by public authorities must comply Art. 111(2)

Postponed does not mean optional: a quality system, risk file and technical documentation take a year or more to build.

03 · Scope and roles

Who it applies to

The regulation follows the market and the output, not the address. A company outside the EU is covered when its system, or its system's output, is used in the EU.

Scope Art. 2

  • Providers placing systems on the EU market or putting them into service in the EU, wherever they are established.
  • Deployers established or located in the EU.
  • Providers and deployers in third countries when the output is used in the EU.
  • Out of scope: defence and national security, pure scientific research, personal non-professional use; partial exemptions for open source.

For Swiss companies: selling into the EU, or producing outputs used there, brings them into scope.

Roles Art. 3

  • Provider — develops a system, or has it developed, and places it under its own name. Carries most obligations.
  • Deployer — uses a system under its authority, professionally. The typical position of an SME.
  • Importer, distributor — supply-chain checks, CE marking, documentation.
  • Authorised representative — mandatory for non-EU providers of high-risk systems Art. 22 and of GPAI models Art. 54.
Role change, Art. 25. A deployer or distributor becomes a provider if it puts its name or trademark on a high-risk system, modifies it substantially, or changes its purpose so that it becomes high-risk. Typical case: taking a general-purpose model and using it to screen CVs.

04 · Risk levels

Four levels, and one that adds up

Classification comes from the intended purpose. Transparency obligations stack on top of the others: a chatbot that screens candidates is high-risk and subject to Art. 50.

LevelWhat it coversConsequenceBasis
ProhibitedPractices with unacceptable riskMay not be placed on the market or usedArt. 5
High-riskSafety components of regulated products (Annex I) or uses in the areas of Annex IIIRequirements of Arts. 8–15, conformity assessment, CE marking, registration, monitoringArt. 6
TransparencyChatbots, synthetic content, deep fakes, emotion recognitionInform people, mark outputsArt. 50
MinimalEverything else: spam filters, recommendations, writing aids…Art. 4 only, voluntary codesArt. 95

05 · Prohibited practices

What may not be done at all

Applicable since 2 February 2025, with the highest fines. The Commission published guidelines on these practices and on the definition of an AI system in February 2025.

  1. Subliminal or manipulative techniques that distort behaviour and cause significant harm.
  2. Exploiting vulnerabilities due to age, disability or socio-economic situation.
  3. Social scoring leading to unjustified or disproportionate treatment.
  4. Predicting the risk of a crime based solely on profiling or personality traits.
  5. Building facial recognition databases by untargeted scraping.
  6. Emotion recognition in the workplace and in education, except for medical or safety reasons.
  7. Biometric categorisation to infer race, political opinions, sexual orientation and similar traits.
  8. Real-time remote biometric identification in public spaces for law enforcement, outside narrow exceptions.

Added by the Omnibus, from 2 December 2026: systems generating child sexual abuse material (bb) or non-consensual intimate content of identifiable people (ba).

06 · High-risk

Two routes into high-risk, one way out

A system is high-risk either because of the product it belongs to, or because of the area it is used in. A documented derogation can take an Annex III system out.

Product route Art. 6(1) · Annex I

The system is a product, or a safety component of a product, covered by EU harmonisation legislation that requires third-party assessment: medical devices and IVDs, toys, lifts, radio equipment, personal protective equipment…

Omnibus: machinery moves from Section A to Section B of Annex I, out of the direct application of the requirements; the Commission may add AI-specific requirements by delegated act.

Area route Art. 6(2) · Annex III

  1. Biometrics
  2. Critical infrastructure
  3. Education and vocational training
  4. Employment and management of workers
  5. Essential services: public benefits, creditworthiness, life and health insurance, emergency calls
  6. Law enforcement
  7. Migration and border control
  8. Justice and democratic processes

The derogation Art. 6(3)

An Annex III system is not high-risk if it poses no significant risk because it performs a narrow procedural task, improves the result of a completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task.

  • Never available if the system profiles natural persons.
  • The provider documents the assessment Art. 6(4) and still registers the system, in simplified form since the Omnibus Art. 49(2).

07 · Obligations

Who does what on high-risk systems

The provider builds conformity into the system. The deployer uses it as instructed, keeps a human in charge, and informs the people affected.

Provider

  • Risk management across the life cycle Art. 9
  • Data and data governance Art. 10
  • Technical documentation, Annex IV Art. 11
  • Automatic logs Art. 12
  • Instructions for use and transparency to deployers Art. 13
  • Design for human oversight Art. 14
  • Accuracy, robustness, cybersecurity Art. 15
  • Quality management system Art. 17
  • Conformity assessment, EU declaration, CE marking Arts. 43, 47, 48
  • Registration in the EU database Art. 49
  • Post-market monitoring, serious incidents Arts. 72, 73

Deployer Art. 26

  • Use the system according to the provider's instructions.
  • Assign human oversight to competent, trained people with authority.
  • Check that input data under its control is relevant and representative.
  • Monitor operation; inform provider and authorities and suspend use if a risk appears.
  • Keep logs for at least six months.
  • Inform workers and their representatives before workplace use.
  • Inform people subject to decisions made with the system.
  • Use the provider's information for the GDPR impact assessment.
  • Fundamental rights impact assessment Art. 27: public bodies, private entities providing public services, credit scoring, life and health insurance pricing.

People affected by decisions based on Annex III systems have a right to an explanation Art. 86.

For everyone, already today — AI literacy, Art. 4. Since the Omnibus, providers and deployers must take measures to support the development of their staff's AI literacy, instead of ensuring a sufficient level.

08 · Transparency

Telling people it is AI

Applicable since 2 August 2026. The duties are split between the provider, who builds the notice or the marking, and the deployer, who discloses in context.

  • 50(1) Provider: people know they are interacting with an AI system, unless it is obvious.
  • 50(2) Provider: synthetic audio, images, video and text are marked in a machine-readable way. Systems already on the market have until 2 December 2026.
  • 50(3) Deployer: inform people exposed to emotion recognition or biometric categorisation.
  • 50(4) Deployer: disclose deep fakes, and AI-generated text published on matters of public interest unless it went through human editorial review.

09 · General-purpose AI

Models, not systems

Chapter V regulates the companies that train large models. Most organisations sit downstream: they use a model through a product and are deployers — or providers, if they build a high-risk system on it.

All GPAI providers Art. 53

  • Technical documentation of the model.
  • Information for providers who integrate the model.
  • A copyright policy that respects rights reservations.
  • A public summary of training content, using the AI Office template.

Open-source models are exempt from the first two, unless they carry systemic risk.

With systemic risk Arts. 51, 55

  • Presumed above 1025 FLOP of training compute.
  • Model evaluation, adversarial testing, risk mitigation.
  • Serious-incident reporting to the AI Office.
  • Adequate cybersecurity.

The General-Purpose AI Code of Practice (July 2025) is the usual way to show compliance.

10 · Digital Omnibus

What Regulation (EU) 2026/1744 changed

Signed on 8 July 2026, published on 24 July, in force since 27 July 2026. It postpones and simplifies; it does not remove the high-risk regime.

  • High-risk postponed: Annex III to 2 December 2027, Annex I to 2 August 2028.
  • Art. 50 not postponed, with a grace period to 2 December 2026 only for marking the content of systems already on the market.
  • Art. 4 lightened: from ensuring AI literacy to supporting its development.
  • Two new prohibitions (child sexual abuse material, non-consensual intimate content), from 2 December 2026.
  • Simplified registration for systems exempted under Art. 6(3).
  • New Art. 4a: processing special categories of personal data to detect and correct bias, extended to all providers and deployers, where strictly necessary.
  • Machinery moved from Section A to Section B of Annex I.
  • Simplifications extended from SMEs to small mid-caps; wider AI Office supervision of systems built on a GPAI model of the same group and on very large platforms; national sandboxes due by 2 August 2027.

11 · GDPR and ISO/IEC 42001

One body of evidence, three frameworks

Much of what the AI Act asks overlaps with the GDPR and with an AI management system under ISO/IEC 42001. Mapping them avoids documenting the same thing three times.

AI ActGDPRISO/IEC 42001
Fundamental rights impact assessment Art. 27Data protection impact assessment Art. 35 — complemented, not replaced Art. 27(4)AI system impact assessment A.5, ISO/IEC 42005
Human oversight Arts. 14, 26Automated decisions Art. 22Responsible use, roles A.9, A.3
Data and bias Art. 10, Art. 4aSpecial categories Art. 9, minimisation Art. 5Data for AI systems A.7
Quality and risk management Arts. 9, 17Accountability, privacy by design Arts. 24, 25Clauses 6 and 8, life cycle A.6
Information to people Arts. 26(11), 50, 86Information and access Arts. 13–15Information for interested parties A.8
Authorised representative Art. 22EU representative Art. 27—

ISO/IEC 42001 is not a harmonised standard under the AI Act and does not give a presumption of conformity. The harmonised standards from CEN-CENELEC JTC 21 are late, one of the reasons for the postponement.

12 · Penalties and authorities

Fines, and who enforces

Fines are set as a fixed amount or a share of worldwide annual turnover, whichever is higher; for SMEs and start-ups, whichever is lower Art. 99(6).

InfringementMaximumBasis
Prohibited practices€35 million or 7%Art. 99(3)
Other obligations (providers, deployers, transparency…)€15 million or 3%Art. 99(4)
Incorrect information to authorities€7.5 million or 1%Art. 99(5)
GPAI providers, imposed by the Commission€15 million or 3%Art. 101
  • EU: the AI Office in the Commission for GPAI models; the European AI Board; national market surveillance authorities for everything else.
  • Italy: Law 132/2025, in force since 10 October 2025, designates AgID as notifying authority and ACN as market surveillance authority, alongside sector supervisors (Banca d'Italia, CONSOB, IVASS) and the data protection authority.
  • Switzerland: no equivalent of the AI Act. On 12 February 2025 the Federal Council chose to ratify the Council of Europe Framework Convention on AI and to adapt Swiss law sector by sector; a consultation draft is expected at the end of 2026.

13 · Test yourself

Seven questions

Short cases that come up in practice. Open each one to see the answer.

A Swiss company uses a third-party tool to screen CVs of candidates in France. Role and risk level?

Deployer: it uses the system under its authority, and the output is used in the EU Art. 2(1)(c). High-risk, Annex III point 4. Art. 26 obligations from 2 December 2027; Art. 4 already today.

The same company retrains the tool and sells it under its own brand. What changes?

It becomes a provider Art. 25: requirements of Arts. 9–15, quality system, conformity assessment, CE marking, registration, and an authorised representative in the EU Art. 22.

A customer-service chatbot on an e-commerce site: what applies today?

Transparency: the provider makes sure users know they are talking to an AI Art. 50(1), applicable since 2 August 2026. The deployer checks the notice is active. Plus Art. 4.

Who must carry out a fundamental rights impact assessment?

Deployers of high-risk systems that are public bodies or private entities providing public services, and deployers of systems for creditworthiness or for pricing life and health insurance Art. 27. Not for critical infrastructure.

Can an Annex III system that only performs a preparatory task avoid high-risk status?

Yes, through the derogation of Art. 6(3), provided it does not profile people. The assessment is documented Art. 6(4) and the system is still registered, in simplified form since the Omnibus.

What is the maximum fine for a prohibited practice, and for an SME?

€35 million or 7% of worldwide annual turnover, whichever is higher. For an SME, whichever is lower Art. 99(6).

What did the Omnibus change for AI literacy?

Art. 4 now asks for measures that support the development of staff AI literacy, rather than ensuring a sufficient level. It has applied since 2 February 2025.

Questions

Working out where your system sits?

Classification and role are where most of the work starts. If you want to talk it through, write to me.

This page is a study reference, not legal advice. Dates and content of the Omnibus checked against the text of Regulation (EU) 2026/1744. Official texts: Regulation (EU) 2024/1689 · Regulation (EU) 2026/1744.