01Risk-based approach: four tiers
The regulation governs AI systems according to their risk. Practices posing an unacceptable risk are prohibited under Art. 5 – including social scoring, deliberately manipulative techniques, emotion recognition in the workplace and certain real-time remote biometric identification for law enforcement purposes. High-risk systems (Art. 6 in conjunction with Annexes I and III) – for example in critical infrastructure, education, employment or law enforcement – are subject to comprehensive requirements covering risk management, data quality, technical documentation, human oversight and conformity assessment. Certain systems such as chatbots and generative AI are subject to transparency obligations under Art. 50, which we cover in detail on a dedicated knowledge page. The vast majority of AI systems in use fall into the minimal-risk category and remain free of specific obligations.
02Timeline: staggered application since 2025
The prohibitions of Art. 5 and the AI literacy obligation (Art. 4) have applied since 2 February 2025; the rules for general-purpose AI models (GPAI) as well as the governance and penalty provisions since 2 August 2025. From 2 August 2026, the remainder of the regulation applies, including the transparency obligations under Art. 50. The obligations for high-risk systems were postponed by the Digital Omnibus: standalone systems under Annex III must meet the requirements only from 2 December 2027, and systems embedded in regulated products under Annex I only from 2 August 2028 (originally 2 August 2026 and 2027 respectively). GPAI models placed on the market before 2 August 2025 have until 2 August 2027 under Art. 111(3).
03Digital Omnibus: Regulation (EU) 2026/1744
The amendments proposed by the Commission at the end of 2025 are now law in force: amending Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”) was adopted by Parliament on 16 June 2026 and by the Council on 29 June 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It moves the high-risk deadlines to fixed dates – the mechanism originally under discussion, which would have tied applicability to the availability of harmonised standards, was dropped. Generative systems placed on the market before 2 August 2026 receive a transition period until 2 December 2026 for the machine-readable marking under Art. 50(2). Newly added to Art. 5 is a prohibition, applicable from 2 December 2026, on AI systems that generate non-consensual intimate imagery or child sexual abuse material; the deadline for national AI regulatory sandboxes was pushed back to 2 August 2027, and SMEs and start-ups benefit from simplifications, for instance in documentation and quality management.
04Roles and obligations: providers and deployers
The regulation distinguishes in particular between providers, who develop an AI system or place it on the market under their own name, and deployers, who use a system professionally under their own responsibility. Providers of high-risk systems bear the main burden (Art. 16 et seq.): risk management, technical documentation, quality management system, conformity assessment and CE marking. Under Art. 26, deployers must, among other things, use the systems as intended, ensure competent human oversight, monitor operation and report incidents; anyone who substantially modifies a high-risk system or offers it under their own name may themselves assume the provider role. The scope is also extraterritorial (Art. 2): providers from third countries are covered as well where the output of their systems is used in the EU.
05Penalties: up to €35 million or 7%
Art. 99 provides for three tiers of fines. Infringements of the prohibitions in Art. 5 can be punished with fines of up to €35 million or 7% of worldwide annual turnover – whichever is higher. Infringements of most other obligations, including the provider, deployer and transparency obligations under Art. 16, 26 and 50, cost up to €15 million or 3%; supplying incorrect or misleading information to authorities, up to €7.5 million or 1%. For SMEs and start-ups, the lower of the two amounts applies in each case. Enforcement lies with the national market surveillance authorities; for GPAI models, the Commission's AI Office is responsible, and its enforcement powers take full effect from 2 August 2026.
06ISO/IEC 42001 and harmonised standards
ISO/IEC 42001:2023 defines a certifiable management system for AI (AIMS) and is a suitable framework for structurally anchoring AI governance – especially in combination with an existing ISMS based on ISO/IEC 27001. However, an ISO 42001 certification does not establish a presumption of conformity under Art. 40 of the AI Act: that arises only from harmonised European standards whose references have been published in the Official Journal of the EU. These standards are still being developed by CEN/CENELEC JTC 21; for quality management under Art. 17, EN 18286 is being created as a dedicated European standard rather than a direct adoption of ISO 42001 – it is in its final vote, while further documents exist only as prEN drafts. As of July 2026, no harmonised standard for the AI Act has yet been cited in the Official Journal; in practice, a combined approach therefore proves effective: ISO/IEC 42001 for the organisation and the emerging standards for the individual high-risk system.