The World's First Comprehensive AI Law
The one-paragraph answer
The EU AI Act is the world's first comprehensive law regulating artificial intelligence. It passed in 2024 and applies in stages through 2027. It bans a short list of AI practices outright, forces heavy documentation on "high-risk" AI, and imposes transparency rules on generative AI. It reaches any company whose AI touches EU users, even from Texas. Fines run up to 35 million euros or 7 percent of global revenue, whichever is higher.
A leadership team in Frisco does not think of themselves as a European company. They serve US customers. Their office is in Texas. Their board is domestic. Then a large enterprise customer in Germany sends over a vendor questionnaire. Question fourteen: "Confirm compliance with EU AI Act Article 26 obligations as a deployer of high-risk AI systems." The room goes quiet.
This is the extraterritorial reach that catches US companies off guard. The EU AI Act does not care where you are headquartered. It cares whether your AI touches people in the European Union. If a French user runs a resume through your AI hiring tool, if your AI credit-scoring product filters a Belgian applicant, if your AI chatbot serves an Irish customer, the EU AI Act applies to you. The pain is that most US executives learn this from a customer contract, an insurance renewal, or a regulatory notice, not from a proactive review. By then the timeline is short and the remediation is expensive.
The EU AI Act is a European Union regulation, formally titled Regulation (EU) 2024/1689. It was adopted in June 2024 and entered into force on August 1, 2024. It is the first horizontal (across all industries) binding AI law in the world. It creates one rulebook for AI providers, deployers, importers, distributors, and product manufacturers whose AI systems are placed on the EU market or whose output is used in the EU.
The regulation uses a risk-based approach. AI systems are sorted into four tiers by the risk they pose to health, safety, and fundamental rights. Each tier gets a different level of obligation. The tiers are: unacceptable risk (banned outright), high risk (heavy compliance), limited risk (transparency), and minimal risk (no obligation).
General-purpose AI models, meaning foundation models and large language models, get their own separate track. Providers of these models have documentation, copyright compliance, and transparency obligations even if they never build an application. Models with "systemic risk" (very large compute or scale) get extra safety-evaluation, incident-reporting, and cybersecurity obligations.
Some AI uses are banned in the EU. This includes AI that manipulates people through subliminal techniques, exploits vulnerabilities of specific groups, does social scoring by public authorities, does predictive policing based solely on profiling, scrapes facial images from the internet, infers emotions in workplaces or schools, and does real-time remote biometric identification in public (with narrow exceptions). These prohibitions took effect February 2, 2025.
An AI system is high-risk if it is a safety component of a regulated product (like medical devices) or if it falls into one of the categories listed in Annex III (employment, education, credit, insurance, law enforcement, migration, essential services, and certain public services). High-risk AI must have a risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy and cybersecurity by design. Providers must complete a conformity assessment and register the system in an EU database.
Deployers are companies that use high-risk AI in their operations. Deployer obligations include using the system according to the provider's instructions, keeping the human oversight running, monitoring performance, keeping logs, and, in many cases, running a fundamental rights impact assessment before deployment. This is the article that catches most US companies. You do not have to build AI to be a deployer; you just have to use it.
Chatbots must disclose that a user is interacting with an AI. Deepfakes and synthetic content must be labeled as artificially generated. Generative AI outputs must be marked in a machine-readable format. This applies whether or not the underlying model is a foundation model or a fine-tuned application.
Providers of general-purpose AI models must publish technical documentation, respect EU copyright law (including opt-outs for text and data mining), and publish a summary of training data. If the model has systemic risk (currently, models trained with more than 10 to the 25th floating point operations), the provider must also run model evaluations, track and report serious incidents, protect against cybersecurity risks, and follow the EU code of practice.
Three obligations, not one, and the distinction has real consequences. High-risk AI systems must achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in all three respects across their lifecycle. Robustness is where adversarial resilience lives. Cybersecurity is where conventional product security lives. They are not the same obligation and they are not discharged by the same evidence.
This matters because of a route that exists in the EU Cyber Resilience Act. CRA Article 12(1) allows a high-risk AI system that is also a product with digital elements to be deemed compliant with Article 15, provided it meets the CRA’s essential requirements and demonstrates the protection level in its EU declaration of conformity. Nearly every summary of that provision stops there, and stopping there is a mistake. The article opens with the words “without prejudice to the requirements relating to accuracy and robustness”. The deeming reaches the cybersecurity limb only. Accuracy and robustness survive intact and must be evidenced independently. A team that stands down its adversarial testing programme on the strength of a CRA declaration has discharged one third of Article 15 and kept the other two thirds without knowing it.
Ask most executives what "high-risk" means under the EU AI Act and they will tell you it means an external audit. For the categories most businesses actually fall into, that is false, and the error runs in both directions: some organisations are budgeting for an assessment they do not need, while others assume a notified body will catch what they missed and no notified body is coming.
Article 43(2) is unambiguous:
“For high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.”
Annex III points 2 through 8 are critical infrastructure, education, employment, essential services including credit scoring, law enforcement, migration, and the administration of justice. That is nearly every high-risk AI system a normal company operates, and the route for all of it is self-assessment.
Two cases, and only two.
Annex III point 1, biometrics. Even here the provider gets a choice: where the harmonised standards have been applied, Annex VI internal control is available; where they have not been applied, or applied only in part, Annex VII with a notified body becomes mandatory.
AI embedded in an Annex I Section A product (machinery, medical devices, lifts, toys, and the rest). Here the AI Act’s requirements are folded into the sectoral conformity assessment that an existing notified body performs on the product anyway. The AI does not get its own separate audit; it gets absorbed into one that was already happening.
One further wrinkle worth knowing: where a high-risk system is intended for use by law enforcement, immigration, or asylum authorities, the market surveillance authority acts as the notified body.
The relief is procedural, not substantive. Annex VI still requires the provider to verify that the quality management system meets Article 17, to examine the technical documentation against every requirement in Chapter III Section 2, and to confirm that the design, development, and post-market monitoring processes are consistent with that documentation. Articles 9 through 15, the risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, robustness and cybersecurity, all still bind in full.
What changes is who checks. Nobody external is coming to catch the gap. The evidence still has to exist, and it has to survive a market surveillance authority arriving after something has already gone wrong, which is a considerably worse moment to discover it is thin.
The self-assessment route is not permanent, and the trigger for changing it is unusually candid. Article 43(6) empowers the Commission to move Annex III points 2 to 8 onto the Annex VII notified-body route by delegated act, taking into account, in the Act’s own words, the effectiveness of internal control and “the availability of adequate capacities and resources among notified bodies.”
Read that twice. Assessor capacity is written into the statute as a condition for tightening the regime. The obligation to self-assess for employment and credit AI today exists partly because the third-party capacity to assess it does not. If that capacity is built, the Commission has a standing power to require its use, and the organisations that treated self-assessment as a reason to build thin evidence will be the ones caught when it is exercised.
Build the evidence base as though a notified body will read it. Whether one ever does is the Commission’s decision, not yours.
Providers of high-risk AI must report serious incidents to the market surveillance authority within 15 days (immediately for widespread infringements). Serious means death, serious harm to health, serious infrastructure disruption, or serious infringement of fundamental rights.
The law came into force August 1, 2024, but obligations phase in through 2028. February 2, 2025 was the deadline for prohibited practices and AI literacy obligations. August 2, 2025 was the deadline for general-purpose AI model obligations and governance provisions. August 2, 2026 is the enforcement date for Article 50 transparency obligations: chatbot disclosure, machine-readable marking of AI-generated content, and clear labeling of deepfakes. AI systems placed on the EU market before August 2, 2026 have until December 2, 2026 to comply with Article 50(2) watermarking.
The Digital Omnibus is now final. The European Parliament endorsed it on June 16, 2026 and the Council gave final approval on June 29, 2026. Stand-alone Annex III high-risk obligations are deferred from August 2, 2026 to December 2, 2027, a sixteen-month reprieve. High-risk AI embedded in regulated Annex I products moves from August 2, 2027 to August 2, 2028. These are no longer proposals; they are the compliance dates.
Two things did not move. Article 50 transparency still applies from August 2, 2026, with only the narrow Article 50(2) watermarking requirement for already-deployed systems getting a grace period to December 2, 2026. And the Act's architecture is untouched: the four risk tiers, the conformity assessment regime, the GPAI track, and the AI Office's oversight role all stand. This is a deferral, not a dismantling.
The Omnibus also adds a prohibited practice. AI-generated non-consensual intimate imagery (so-called nudifiers) and child sexual abuse material are now banned under Article 5, from December 2, 2026, at the maximum penalty tier. Any organisation whose models can synthesise images or audio needs technical and contractual safeguards in place before that date. Member State regulatory sandboxes are pushed to August 2027.
A separate consultation on the European Commission's draft guidelines for Article 6 high-risk classification closes July 23, 2026. The draft interprets "intended purpose" broadly (provider instructions, promotional materials, and technical documentation all count) and treats conformity assessments involving only internal controls as within scope, which is broader than many businesses anticipated. Clients with EU exposure should review the draft and consider submitting comments.
In practice, if your organization touches EU users with AI, you should be operating as if the full EU AI Act is in force today, with Article 50 as the immediate compliance surface.
The EU AI Act matters even if you never plan to sell in Europe, for four reasons.
First, extraterritorial reach. If a European user interacts with your AI, you are in scope. This is the same "long-arm" pattern as GDPR: your web analytics, your hiring tool, your chatbot, your credit product, or your generative-AI feature can all trigger EU jurisdiction without you meaning to.
Second, fines are severe. Prohibited practices carry fines up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. High-risk obligations carry up to 15 million euros or 3 percent. Even a small US company can face material exposure if a violation is proven.
Third, the EU AI Act is becoming the global template. Brazil, Canada, the UK, and multiple US states are drafting laws that mirror its risk-based structure. Building an AI program that aligns to the EU AI Act today is the closest thing to a hedge against the next five years of AI regulation.
Fourth, procurement is already flowing through it. Large European buyers are asking US vendors for EU AI Act compliance statements. If you do not have one, you lose the deal. This is happening in software, professional services, financial services, healthcare, and manufacturing right now.
The academic literature on EU AI Act is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about EU AI Act arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, EU AI Act becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Yes, if you either place an AI system on the EU market, use AI whose output affects people in the EU, or are a deployer of AI in the EU. Location of your company does not matter; location of your users does.
You are a deployer. Deployer obligations still apply. You cannot pass the entire compliance responsibility upstream to the model provider. You are responsible for how you use the model.
If your AI is truly minimal risk (a spam filter, a game NPC), most obligations do not apply. But even minimal-risk AI must comply with prohibited practices and, if it is generative, with Article 50 transparency. Very few businesses have zero EU AI Act obligations.
Alignment to ISO/IEC 42001 is treated as evidence of compliance with many EU AI Act obligations. NIST AI RMF alignment is also useful documentation. Neither substitutes for full EU AI Act compliance, but both dramatically reduce the lift.
In Chapter 8 and in Appendix L (the AI Governance Framework Crosswalk™) of Volume III of The Operating Discipline for AI Library™. Every operating artifact in the Library (the AI Usage Policy, the Accountability Matrix, the risk register, the dossier structure) maps to specific EU AI Act articles. Reaching defensible EU AI Act readiness is the six-step 6-Step Review Process™ that the book codifies.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning EU AI Act that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including EU AI Act, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →