European UnionIn effect

EU AI Act: what applies now, and what starts on 2 August 2026

In force since August 1, 2024AI Law Tracker Editorial Team
EU AI Act: what applies now, and what starts on 2 August 2026 — In effect, European Union

The EU AI Act sorts AI into four risk tiers and phases its duties in over four years. Prohibitions have applied since 2 February 2025 and general-purpose AI rules since 2 August 2025; the main enforcement phase begins on 2 August 2026, with the two high-risk deadlines in December 2027 and August 2028.

At a glance
Jurisdiction
European Union
Status
In effect
Effective date
Aug 1, 2024
Reported
July 23, 2026

Regulation (EU) 2024/1689 — the AI Act — is the European Union's horizontal law for artificial intelligence. It does not regulate the technology as such; it sorts AI systems into four tiers by the risk they pose and attaches duties to each. The European Commission describes the tiers as unacceptable risk, high risk, transparency risk, and minimal or no risk, and notes that the great majority of AI systems used in the EU today fall into that last group and carry no specific obligations.

At the top, the Act bans nine practices outright as "a clear threat to the safety, livelihoods and rights of people", including harmful manipulation, social scoring, untargeted scraping of facial images, emotion recognition in workplaces and schools, and real-time remote biometric identification for law enforcement.

The high-risk tier is where most of the compliance work sits. It covers AI used in critical infrastructure, education scoring, employment decisions, access to essential services, biometrics, law enforcement and migration. Providers of those systems must carry out risk assessment and mitigation, use high-quality datasets to limit discriminatory outcomes, log activity for traceability, keep detailed technical documentation, give deployers clear information, build in human oversight, and meet a high level of robustness, cybersecurity and accuracy. A separate transparency tier is lighter: it exists so people know when they are dealing with a machine, requiring disclosure when a user interacts with a chatbot and identification of AI-generated content.

The timeline is staged and is the part most often misread. The Act entered into force on 1 August 2024. The prohibitions and the AI-literacy duty became applicable on 2 February 2025, and the governance rules together with the general-purpose AI obligations on 2 August 2025 — all of these already bind. The main enforcement phase opens on 2 August 2026. The two heaviest high-risk deadlines come later still: systems in the sensitive areas listed in Annex III must comply by 2 December 2027, and AI embedded in products already regulated under Annex I by 2 August 2028.

The Commission's own overview page does not state the penalty levels, so the figures often quoted alongside the Act are not repeated here.

#AILaw #EUAIAct #FacialRecognition #AISurveillance #AIRegulation #AICompliance
Primary sourcedigital-strategy.ec.europa.euOfficial government page this story is reported from
Receipts

Sources & citations

  1. Four risk tiers, the nine prohibited practices, the high-risk provider obligations, the transparency duties, and every application date cited above. digital-strategy.ec.europa.eu

See the full AI law picture for European Union

Statuses, deadlines, penalties, and primary sources — kept current on AI Law Tracker.

← All AI law news

How this was made. This story is drafted by an automated pipeline from the primary sources cited above, then checked against those sources before it is published. Nothing is published as raw machine output, and no claim here is stronger than the source it links to. Full methodology · our own data & AI practices.