Book an Appointment

EU AI Act: Europe's Rulebook for Artificial Intelligence

Risk classes, deadlines after the Digital Omnibus, roles and penalties: what Regulation (EU) 2024/1689 means for businesses – as of July 2026.

With Regulation (EU) 2024/1689 – the AI Act – the EU has created the first horizontal legal framework for artificial intelligence. The regulation entered into force on 1 August 2024 and has been applying in stages ever since; it follows a risk-based approach ranging from outright prohibition to largely unregulated use. With amending Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”), the EU legislator postponed key deadlines for high-risk systems in the summer of 2026 – the regulation's underlying risk-based approach remains unaffected. For CISOs, IT managers and compliance officers, the question is therefore less whether the AI Act affects them than in which role and from when.

The Essentials at a Glance

01

Risk-based approach: four tiers

The regulation governs AI systems according to their risk. Practices posing an unacceptable risk are prohibited under Art. 5 – including social scoring, deliberately manipulative techniques, emotion recognition in the workplace and certain real-time remote biometric identification for law enforcement purposes. High-risk systems (Art. 6 in conjunction with Annexes I and III) – for example in critical infrastructure, education, employment or law enforcement – are subject to comprehensive requirements covering risk management, data quality, technical documentation, human oversight and conformity assessment. Certain systems such as chatbots and generative AI are subject to transparency obligations under Art. 50, which we cover in detail on a dedicated knowledge page. The vast majority of AI systems in use fall into the minimal-risk category and remain free of specific obligations.

02

Timeline: staggered application since 2025

The prohibitions of Art. 5 and the AI literacy obligation (Art. 4) have applied since 2 February 2025; the rules for general-purpose AI models (GPAI) as well as the governance and penalty provisions since 2 August 2025. From 2 August 2026, the remainder of the regulation applies, including the transparency obligations under Art. 50. The obligations for high-risk systems were postponed by the Digital Omnibus: standalone systems under Annex III must meet the requirements only from 2 December 2027, and systems embedded in regulated products under Annex I only from 2 August 2028 (originally 2 August 2026 and 2027 respectively). GPAI models placed on the market before 2 August 2025 have until 2 August 2027 under Art. 111(3).

03

Digital Omnibus: Regulation (EU) 2026/1744

The amendments proposed by the Commission at the end of 2025 are now law in force: amending Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”) was adopted by Parliament on 16 June 2026 and by the Council on 29 June 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It moves the high-risk deadlines to fixed dates – the mechanism originally under discussion, which would have tied applicability to the availability of harmonised standards, was dropped. Generative systems placed on the market before 2 August 2026 receive a transition period until 2 December 2026 for the machine-readable marking under Art. 50(2). Newly added to Art. 5 is a prohibition, applicable from 2 December 2026, on AI systems that generate non-consensual intimate imagery or child sexual abuse material; the deadline for national AI regulatory sandboxes was pushed back to 2 August 2027, and SMEs and start-ups benefit from simplifications, for instance in documentation and quality management.

04

Roles and obligations: providers and deployers

The regulation distinguishes in particular between providers, who develop an AI system or place it on the market under their own name, and deployers, who use a system professionally under their own responsibility. Providers of high-risk systems bear the main burden (Art. 16 et seq.): risk management, technical documentation, quality management system, conformity assessment and CE marking. Under Art. 26, deployers must, among other things, use the systems as intended, ensure competent human oversight, monitor operation and report incidents; anyone who substantially modifies a high-risk system or offers it under their own name may themselves assume the provider role. The scope is also extraterritorial (Art. 2): providers from third countries are covered as well where the output of their systems is used in the EU.

05

Penalties: up to €35 million or 7%

Art. 99 provides for three tiers of fines. Infringements of the prohibitions in Art. 5 can be punished with fines of up to €35 million or 7% of worldwide annual turnover – whichever is higher. Infringements of most other obligations, including the provider, deployer and transparency obligations under Art. 16, 26 and 50, cost up to €15 million or 3%; supplying incorrect or misleading information to authorities, up to €7.5 million or 1%. For SMEs and start-ups, the lower of the two amounts applies in each case. Enforcement lies with the national market surveillance authorities; for GPAI models, the Commission's AI Office is responsible, and its enforcement powers take full effect from 2 August 2026.

06

ISO/IEC 42001 and harmonised standards

ISO/IEC 42001:2023 defines a certifiable management system for AI (AIMS) and is a suitable framework for structurally anchoring AI governance – especially in combination with an existing ISMS based on ISO/IEC 27001. However, an ISO 42001 certification does not establish a presumption of conformity under Art. 40 of the AI Act: that arises only from harmonised European standards whose references have been published in the Official Journal of the EU. These standards are still being developed by CEN/CENELEC JTC 21; for quality management under Art. 17, EN 18286 is being created as a dedicated European standard rather than a direct adoption of ISO 42001 – it is in its final vote, while further documents exist only as prEN drafts. As of July 2026, no harmonised standard for the AI Act has yet been cited in the Official Journal; in practice, a combined approach therefore proves effective: ISO/IEC 42001 for the organisation and the emerging standards for the individual high-risk system.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/1689 (KI-Verordnung / AI Act)

Base regulation: risk-based approach (Art. 5, 6, 50), provider and deployer obligations (Art. 16, 26), penalties (Art. 99) and application timeline (Art. 113).

Amtsblatt der EU / EUR-Lex · 2026

Verordnung (EU) 2026/1744 („Digital Omnibus on AI“)

Amending regulation (published 24 July 2026, in force since 27 July 2026): new high-risk deadlines, transition period for Art. 50(2) and two new prohibitions in Art. 5.

Europäische Kommission · 2026

AI Act | Shaping Europe's digital future

The Commission's official overview of risk tiers, GPAI obligations and the current application timeline following the Digital Omnibus.

Gibson Dunn · 2026

EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes

Legal analysis of the Omnibus agreement, including the Art. 50 transparency obligation, which continues to apply unchanged from 2 August 2026.

Cloud Security Alliance · 2026

EU AI Act Compliance: prEN 18286 and ISO 42001

Research note on the relationship between ISO/IEC 42001 and the emerging harmonised standard EN 18286 (Art. 17), and on the presumption of conformity under Art. 40.

artificialintelligenceact.eu (Future of Life Institute) · 2024

Implementation Timeline

Overview of the original application timeline, including the transitional rule for existing GPAI models under Art. 111(3) (as it stood before the Digital Omnibus).

Where does your AI compliance stand?

In a no-obligation initial consultation, we map your AI systems to the AI Act's risk classes and show you exactly which deadlines and obligations apply to you.