The EU AI Act, summarised in plain English
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's law regulating artificial intelligence, and the first comprehensive AI law from a major jurisdiction. It entered into force on 1 August 2024 and applies in stages: bans on the worst AI practices since 2 February 2025, rules for general-purpose AI models since 2 August 2025, transparency duties for chatbots and AI-generated content since 2 August 2026, and the high-risk regime from 2 December 2027 (2028 for AI embedded in regulated products). It sorts AI uses into four risk tiers — prohibited, high-risk, limited-risk, and minimal-risk — and attaches obligations in proportion to the risk, with fines reaching €35 million or 7% of worldwide annual turnover. It applies to companies outside the EU whenever their AI system, or its output, is used inside the EU.
That is the law in one paragraph. The rest of this page unpacks it, tier by tier and date by date, in about 1,500 words. Every claim below can be checked against the official text on EUR-Lex, read together with Regulation (EU) 2026/1744, the July 2026 amendment that set the revised high-risk dates used in the timeline below.
What the AI Act is
The AI Act was adopted in June 2024, published in the EU's Official Journal on 12 July 2024, and entered into force twenty days later, on 1 August 2024. Entry into force did not mean everything applied at once: the Act switches on in stages, and the last stages now run into 2028.
It is best understood as product-safety law, not privacy law. Where the GDPR asks what you do with people's data, the AI Act asks what your AI system is and what it is used for, then assigns it to a risk tier. Almost everything the Act demands of you follows from which tier you land in.
Who it covers — including companies outside the EU
The Act splits duties between providers, who develop an AI system or model and place it on the market, and deployers, who use one under their own authority. A SaaS company that builds a chatbot is a provider; the online shop that runs that chatbot on its website is a deployer. Both carry obligations, and they are not the same obligations.
Its reach is deliberately extraterritorial. Article 2 applies the Act to providers placing AI systems on the EU market "irrespective of whether those providers are established… within the Union or in a third country," and — the clause that surprises people — to providers and deployers in third countries "where the output produced by the AI system is used in the Union." A US or UK company whose chatbot talks to EU visitors, or whose AI-generated content reaches EU readers, is in scope. There is no general small-business exemption: SMEs get support measures and a gentler fine calculation, not a pass.
The risk pyramid: four tiers
- Prohibited (Article 5). Practices the EU considers unacceptable. Banned outright since 2 February 2025.
- High-risk (Article 6, Annexes I and III). AI in domains where failure harms health, safety, or fundamental rights. Heavily regulated, with certification-style duties.
- Limited risk — transparency (Article 50). AI that people interact with or whose output they consume. These uses remain legal — but they must be disclosed. This is the tier that touches ordinary websites, and it applies now.
- Minimal risk. Everything else — spam filters, recommendation logic, AI in games. No new obligations.
Tier 1 — prohibited practices
Since 2 February 2025, Article 5 bans, among others: manipulative or deceptive techniques that materially distort behaviour and cause significant harm; exploiting vulnerabilities of age, disability, or a specific social or economic situation; social scoring that leads to unjustified detrimental treatment; predicting criminality from profiling alone; building facial-recognition databases by untargeted scraping of the internet or CCTV; inferring emotions in workplaces and schools (outside medical and safety uses); biometric categorisation to deduce race, political opinions, religion, or sexual orientation; and real-time remote biometric identification in public spaces for law enforcement, save for narrowly defined exceptions. If your business does none of these things — and most don't — this tier asks nothing of you.
Tier 2 — high-risk systems
High-risk covers AI used as a safety component of regulated products (Annex I — medical devices, machinery, vehicles) and AI in sensitive standalone domains (Annex III — biometrics, critical infrastructure, education, employment and hiring, access to essential services such as credit and insurance, law enforcement, migration, justice, and elections). Providers of these systems owe the Act's full weight: a risk-management system, data-governance rules, technical documentation, logging, human oversight, accuracy and cybersecurity requirements, a conformity assessment, CE marking, and registration in an EU database. Deployers owe oversight and monitoring duties of their own.
These deadlines moved. The Digital Omnibus package — provisionally agreed on 7 May 2026 and given final approval by the Council on 29 June 2026 — pushed the Annex III high-risk regime to 2 December 2027 and Annex I embedded systems to 2 August 2028. Many headlines compressed that into "the AI Act is delayed." The transparency tier below was not delayed, and that misreading is now the most common compliance error we see.
Tier 3 — transparency: Article 50
Article 50 is the tier most businesses meet first, because it covers things nearly every modern website does: run a chatbot, publish AI-generated images or text. It has applied — and been enforceable — since 2 August 2026. Four duties:
| Duty | Who it binds | What it requires | Applies from |
|---|---|---|---|
| 50(1) Chatbot disclosure | Provider | People interacting with an AI system must be informed they are dealing with AI, no later than the first interaction, unless it is obvious to a reasonably well-informed person. | 2 Aug 2026 |
| 50(2) Machine-readable marking | Provider | AI-generated or AI-manipulated audio, image, video, and text must be marked in a machine-readable format so it is detectable as artificially generated (for example C2PA Content Credentials). | 2 Aug 2026 — deferred to 2 Dec 2026 only for generative systems already on the market before 2 Aug 2026. Details |
| 50(3) Emotion recognition & biometric categorisation notice | Deployer | People exposed to an emotion-recognition or biometric-categorisation system must be informed it is in operation. | 2 Aug 2026 |
| 50(4) Deepfake & AI-text labels | Deployer | Deepfakes must be visibly disclosed as artificially generated or manipulated. AI-generated text published to inform the public on matters of public interest must be disclosed too, unless a human exercised editorial control and someone holds editorial responsibility. | 2 Aug 2026 |
In every case the information must arrive clearly, and at the latest at the first interaction or exposure. The European Commission has published official guidance on these obligations and a Code of Practice with an official set of EU labels and icons. For the duty-by-duty depth — who counts as a provider, what the exceptions actually say, how enforcement works — see our full guide to Article 50, explained.
Tier 4 — minimal risk
Everything that is neither banned, high-risk, nor caught by Article 50 carries no new obligations. The Act encourages voluntary codes of conduct for this tier, and stops there.
General-purpose AI models
Alongside the pyramid, the Act regulates general-purpose AI models — the large models underneath products like ChatGPT — separately, since 2 August 2025. Their providers must keep technical documentation, publish a summary of training content, and adopt a copyright policy; models posing "systemic risk" carry extra evaluation and incident-reporting duties. Models already on the market before 2 August 2025 have until 2 August 2027 to comply. If you merely build on such a model through an API, these duties sit with the model's provider, not with you — but Article 50 may still sit with you.
The timeline, date by date
- 1 August 2024 — the Act enters into force.
- 2 February 2025 — prohibited practices banned; AI-literacy duty applies.
- 2 August 2025 — general-purpose AI model rules; governance and penalties provisions.
- 2 August 2026 — the general application date, including all of Article 50. Already passed.
- 2 December 2026 — machine-readable marking (50(2)) catches up for generative systems that predate 2 August 2026.
- 2 August 2027 — compliance date for general-purpose models placed on the market before August 2025.
- 2 December 2027 — Annex III high-risk regime applies (moved from 2026 by the Digital Omnibus).
- 2 August 2028 — Annex I embedded high-risk systems (moved from 2027).
The penalties
Article 99 sets three fine ceilings, each "whichever is higher" of a fixed sum or a share of total worldwide annual turnover: €35 million or 7% for prohibited practices, €15 million or 3% for most other breaches — including every Article 50 duty — and €7.5 million or 1% for supplying false or misleading information to authorities. For SMEs and start-ups, each cap is read as whichever is lower. Enforcement sits with national market-surveillance authorities, and for the transparency duties it has been available since 2 August 2026 — there is no separate grace period for enforcement.
What most website owners actually need to do
Strip away the tiers that don't apply to an ordinary business website, and what remains is Article 50. In practice that means three questions:
- If a visitor opens your chat, is it explicit — before or in the very first exchange — that they are talking to AI?
- If you publish AI-generated images, audio, or video, does the marking embedded by your generator actually survive your publishing pipeline — and are deepfakes visibly labelled?
- If AI writes or drafts public-facing text on matters of public interest, is it either labelled or under documented human editorial control?
Then keep dated evidence of the answers, because the burden of showing a disclosure was present falls on you, and a regulator or complainant can check your site in minutes. That is the part DisclosureProof automates: it visits your site in a real browser the way a first-time visitor would, records what it finds against each Article 50 duty as detected, not detected, or unverified, and seals the screenshots and findings into a hash-verified evidence record. No scan of a website — ours included — can declare you "compliant," and we deliberately never use the word. What a scan can do is show you, and later show others, exactly what your site disclosed on a given date.
Common questions
Is the EU AI Act already in force?
Yes. It entered into force on 1 August 2024 and has applied in stages since: prohibited practices since 2 February 2025, general-purpose AI model rules since 2 August 2025, and the Article 50 transparency duties — the tier that touches ordinary websites — since 2 August 2026, with enforcement available from the same day. The high-risk regime follows on 2 December 2027 (Annex III) and 2 August 2028 (Annex I), after the Digital Omnibus moved those dates.
Does the EU AI Act apply to UK and US companies?
It can. Article 2 applies the Act to providers placing AI systems on the EU market regardless of where they are established, and to providers and deployers in third countries where the output produced by the AI system is used in the Union. A UK or US company whose chatbot serves EU visitors, or whose AI-generated content reaches EU readers, is in scope. Brexit did not take UK companies out of that reach — the test is where the output is used, not where the company sits.
What are the fines under the EU AI Act?
Article 99 sets three ceilings, each the higher of a fixed sum or a share of total worldwide annual turnover: €35 million or 7% for prohibited practices, €15 million or 3% for most other breaches — including every Article 50 transparency duty — and €7.5 million or 1% for supplying false or misleading information to authorities. For SMEs and start-ups, each cap is read as whichever is lower. National market-surveillance authorities enforce.
What does the EU AI Act mean for an ordinary website?
Usually just Article 50, which has applied since 2 August 2026. A chatbot must make clear it is AI no later than the first interaction. AI-generated audio, images, video, and text must carry machine-readable marking — a duty on the generative system's provider, though marking often breaks quietly in publishing pipelines. Deepfakes, and AI-written text published to inform the public on matters of public interest, need visible disclosure unless a human exercised editorial control. Most websites are not high-risk systems, and minimal-risk AI carries no new duties.
Sources and further reading
- Regulation (EU) 2024/1689 — the official text (EUR-Lex)
- Article 50, Article 99 (penalties), and Article 113 (timeline) in the AI Act Explorer
- European Commission: transparency obligations under Article 50
- Article 50, explained in full — the four duties, the exceptions, and enforcement
- The free printable Article 50 checklist
- What the 2 December 2026 date does and doesn't cover
- Country-by-country guides — how national authorities enforce Article 50, member state by member state
This page summarises the Regulation for orientation. It is not legal advice; the statute linked above is the authority. Where your situation is non-obvious, involve qualified counsel.