The EU AI Act explained
The EU AI Act is the first comprehensive law regulating AI itself, not just the data it uses. Its risk-based structure, who it applies to, and where things stand.
This guide is general information, not legal advice, and it is a summary of a long and evolving law. The EU AI Act is being amended as it is implemented, and dates and details change. For anything that carries legal or financial weight, read the official sources and consult a qualified professional. Official references: the European Commission’s AI Act pages and the EU AI Act explorer.
What you’ll learn
What the EU AI Act sets out to do, how its risk-based structure works, who it actually applies to, and roughly where its obligations stand as of mid-2026. This is the first in a planned series on AI regulation by jurisdiction; the EU is the furthest along with comprehensive rules, so it is where we start.
Why this is different from data protection
Data protection law, like the GDPR, governs how you handle personal data. The EU AI Act is a different kind of law: it regulates AI systems themselves, based on what they are used for, whether or not personal data is involved. This is the shift worth grasping. There is now a growing body of rules aimed at AI as a technology, separate from the data rules that came before, and running a model on your own hardware does not place it outside them.
Who it applies to
The Act has deliberately broad reach. It applies not only to organisations in the EU but, in many cases, to providers and deployers outside the EU whose AI systems are placed on the EU market, or whose output is used within the EU. An organisation elsewhere serving EU users can fall within its scope. It also distinguishes roles: a provider develops or places an AI system on the market, while a deployer uses one. Their obligations differ, a distinction that matters a great deal for local and open models, covered in the next guide.
The risk tiers
The Act sorts AI into four levels of risk, with heavier obligations as risk rises.
Unacceptable risk (prohibited). A short list of banned practices, such as social scoring by public authorities, certain manipulative or exploitative systems, and some uses of biometric identification. These bans have been in force since February 2025. Amendments in 2026 added further prohibitions, including AI that generates child sexual abuse material or non-consensual intimate imagery.
High risk. AI used in sensitive areas, such as employment, education, essential services, law enforcement, and safety components of regulated products. These systems carry the heaviest obligations: risk management, data governance, documentation, human oversight, accuracy and robustness, and conformity assessment. This is the tier whose deadlines moved most in 2026 (see below).
Limited risk (transparency). Where the main concern is that people know they are dealing with AI. Chatbots must make clear you are talking to a machine, and AI-generated or manipulated content, including deepfakes, must be labelled as such.
Minimal risk. The vast majority of AI, from spam filters to game logic. No specific obligations.
General-purpose AI models
Separately from the risk tiers, the Act places obligations on providers of general-purpose AI (GPAI) models, the large models that underpin many applications. These include transparency, technical documentation, a policy to comply with EU copyright law, and a public summary of the training data. The most capable models, judged to carry systemic risk, face additional requirements. A voluntary GPAI Code of Practice offers a route to demonstrate compliance. Because this is the part most relevant to open and local models, it has its own guide.
Where the timeline stands, as of mid-2026
The Act entered into force in 2024 and applies in phases. As of mid-2026:
- In force: the prohibited-practice bans (since February 2025) and the GPAI model obligations (since August 2025). Enforcement powers and penalties for GPAI apply from August 2026.
- Delayed: in 2026 a package of amendments, known as the Digital Omnibus, deferred the main high-risk obligations. The use-case-based high-risk rules, originally due in August 2026, moved to December 2027, and product-related high-risk rules moved to 2028. These changes were finalised in mid-2026 and were very recent at the time of writing, so confirm the current position against the official sources before relying on a specific date.
The direction of travel is clear even as dates shift: the prohibitions and the general-purpose model rules are live, while the heaviest high-risk obligations have been given more time.
Penalties
The Act’s penalties are significant, and scale with the seriousness of the breach. Prohibited practices carry the highest fines, up to tens of millions of euros or a percentage of global annual turnover, whichever is greater. Other obligations, including for general-purpose models, carry lower but still substantial maximums. These are ceilings rather than typical outcomes, but they signal that the Act is meant to have teeth.
What can go wrong
- Assuming local means out of scope. The Act regulates use, not location. Running a model yourself does not remove it from the rules.
- Relying on a date that has moved. The 2026 amendments shifted several deadlines. Always check the current position rather than an older summary, this one included.
- Confusing this with data protection. The GDPR and the AI Act are separate, and you may need to satisfy both.
Next steps
For what the Act means specifically if you run open models on your own hardware, including the provider-versus-deployer question and the exemptions for open-source models, continue to the EU AI Act and local and open models.