The EU AI Act is the European Union law that sets rules for AI systems based on the risk they pose, rather than the specific technology behind them. A model that writes marketing copy and a model that screens job applicants can be built the same way but face very different obligations, because the Act cares about what the system is used for. This is general information, not legal advice — consult qualified counsel before making compliance decisions.
What changed in 2026
- Staggered obligations continued rolling out. The Act did not take effect all at once; prohibited-practice bans and AI literacy duties applied earliest, with high-risk system requirements phasing in on a longer schedule set by the regulation.
- General-purpose AI model rules matured. Providers of large foundation models faced clearer documentation and transparency duties, applied regardless of how downstream developers use the model.
- Standardization work advanced. Technical standards bodies continued producing the detailed conformity-assessment standards that high-risk system providers need to demonstrate compliance, since the Act itself sets requirements at a high level.
- National enforcement bodies stood up operations. Member states designated the market surveillance authorities responsible for enforcement within their borders, working alongside the EU-level AI Office.
The risk tiers, explained
| Tier |
What it covers |
Obligation level |
| Unacceptable risk |
Social scoring, manipulative or exploitative systems, certain biometric uses |
Banned outright |
| High risk |
Systems used in hiring, credit, education, medical devices, law enforcement |
Conformity assessment, risk management, human oversight, documentation |
| Limited risk |
Chatbots, emotion recognition, deepfake generation |
Transparency — users must be told they are interacting with AI or AI-generated content |
| Minimal risk |
Spam filters, AI-enabled games, inventory tools |
No AI Act-specific obligations |
How general-purpose AI models are treated separately
Because a single foundation model can power thousands of different downstream applications, the AI Act layers a separate set of rules on top of the risk tiers specifically for general-purpose AI models. Providers of these models — regardless of what any particular downstream developer builds with them — face documentation and transparency obligations, with additional requirements for models deemed to carry systemic risk based on the scale of compute used to train them. Downstream developers building a specific product still classify that product under the standard risk tiers separately.
Who actually has to comply
Classification determines obligations, and classification depends on use case, not company size or location alone. A small startup building a high-risk hiring tool faces the same core obligations as a large enterprise doing the same thing, though the Act does include some allowances for smaller companies on cost-sensitive requirements like conformity assessment fees. Non-EU companies are in scope if their system is used in the EU or its output has effect there — for the fuller picture of how this fits with the rest of EU law, see AI regulation in the EU.
What compliance actually looks like day to day
For a high-risk system, this means maintaining a risk management process across the system's lifecycle, keeping technical documentation current, ensuring meaningful human oversight rather than rubber-stamp review, and monitoring performance after deployment rather than treating compliance as a one-time gate. For limited-risk systems like most consumer chatbots, the bar is lower but not zero — clear disclosure that a user is talking to AI is required. None of this replaces a company-wide AI usage policy that tells employees which systems require which level of scrutiny before deployment.
FAQ
Does the EU AI Act ban AI systems outright?
Only a narrow set of practices deemed unacceptable risk, such as certain social scoring and manipulative systems. Most AI use cases fall into lower tiers with obligations rather than prohibitions.
What counts as a high-risk AI system under the Act?
Systems used in specified sensitive contexts — employment, credit, education, medical devices, law enforcement, among others — as defined in the Act's annexes. Verify current classification against the official text, since interpretive guidance continues to evolve.
Do foundation model providers have different obligations than app developers?
Yes. General-purpose AI model providers face documentation and transparency duties independent of use case, while developers building specific applications on top of those models are classified under the standard risk tiers.
What happens if a company does not comply?
Penalties use a turnover-based structure similar to GDPR fines, with amounts scaling by violation severity. Check the current official penalty figures directly, as amounts can be subject to revision.
Where to go next