Artificial intelligence is now regulated in the European Union. The EU AI Act is the first comprehensive AI law, with eight categories of AI systems already banned since February 2025. It applies to organisations that build, deploy, import, or distribute AI systems reaching EU users, regardless of physical presence in the European Union. This guide explains the four risk tiers, the fines, the deadlines, and what compliance actually involves.
€35M
Maximum fine for banned AI practices or 7% global turnover, whichever is higher
4
Risk tiers governing all AI systems operating in or reaching the EU market
Aug 2026
Applicability of transparency obligations for providers and deployers of generative AI systems
1. What is the EU AI Act? What is its Scope in 2026?
EU AI Act Summary
The EU AI Act is the world’s first regulation governing the development and use of artificial intelligence in the European Union. It is also called the Artificial Intelligence Act. It establishes a risk-based AI classification system, applying different rules to AI systems according to the 4 types of risk they pose. The act bans certain unacceptable risk AI use cases and implements strict governance, risk management and transparency requirements for others. The regulation has extraterritorial reach. Any non-EU company is in scope if its AI systems or outputs involve EU users.
Who does the EU AI Act apply to?
- Providers: Organizations or people developing or placing an AI system or general-purpose AI (GPAI) models on the EU market, irrespective of where they are located
- Deployers: Organizations or people using AI systems in the EU in a professional capacity
- Importers of AI systems
- Distributors of AI systems
Key Exemptions: The regulation does not apply to AI systems used and developed for:
JAGGAER AI
JAI is a secure AI built for Source-to-Pay and procurement
JAI is a Source-to-Pay AI which combines ISO 42001-certified governance with GDPR-aligned EU data residency.
2. The 4 Risk Categories
These are 4 defined risk categories for AI systems under the act as per EU Artificial Intelligence Act. Not sure which tier your system falls into? Our complete guide to EU AI Act risk levels walks through each one with real examples. Each tier determines the compliance obligations that apply.
Compliance Obligations
High-risk AI systems have the most detailed compliance obligations under the act. Organizations deploying high-risk AI systems must comply with the following obligations:
3. Fines and Penalties
The EU AI Act fines and penalties for various violations as per EU Artificial Intelligence Act are listed below. Want to know if you are exposed? Run through our EU AI Act compliance and fines checklist.
| Violation | Who it applies to | Maximum fine |
|---|---|---|
| Prohibited AI practices (Article 5) | Companies / operators | €35M or 7% of global annual turnover, whichever is higher |
| Other obligation breaches (providers, deployers, importers, distributors, authorised reps, notified bodies, transparency) | Companies / operators | €15M or 3% of global annual turnover, whichever is higher |
| Incorrect, incomplete, or misleading information to authorities | Companies / operators | €7.5M or 1% of global annual turnover, whichever is higher |
| Any breach (Article 5 or other) | SMEs and startups | The lower of the percentage or fixed amount |
| GPAI model provider violations (Article 101) | General-purpose AI model providers | €15M or 3% of global annual turnover, whichever is higher |
| Prohibited AI practices (Article 5) | EU institutions, bodies, agencies | €1.5M |
| Other breaches | EU institutions, bodies, agencies | €750,000 |
4. EU AI Act Timeline: Key Dates Through 2026 and Beyond
Deadlines are arriving fast. The EU AI Act effective date was 1 August 2024, with obligations rolling out in phases through 2027 as per European Commission AI Act. Map your obligations against the full compliance timeline so nothing catches you off guard.
The EU AI Act came into force.
- Prohibitions on certain AI systems and regulatory requirements came into effect
- Rules for general-purpose AI (GPAI) models, governance, confidentiality and penalties came into effect
EU AI Act obligations for general-purpose AI models
- Remaining rules under the act including high-risk AI system obligations and transparency rules will come into effect
- Member States should have established at least one AI regulatory sandbox at national level
- Rules for AI systems that are products or safety components of products regulated under Article 6(1) of act will apply
- Providers of GPAI models that were placed on the market before 2 August 2025 must comply with rules for GPAI models by this date
This regulatory timeline will be updated with any new key dates announced by official European Union bodies.
JAGGAER AI
When the deadlines hit, your procurement AI must hold up: JAI is built to.
JAGGAER’s AI is embedded across sourcing, contracts, and supplier management in one Source-to-Pay platform.
5. EU AI Act vs. GDPR: How They Interact?
GDPR and the EU AI Act are complementary, not competing. Both take a risk-based approach, but they are built on different objectives.
Where they overlap?
| Theme | GDPR | EU AI Act |
|---|---|---|
| Fundamental Rights & Data Protection Impact assessment | A data protection impact assessment for high-risk processing (Article 35) | A fundamental rights impact assessment before the first deployment (Article 27) |
| Transparency to people | Informing data subjects about collection and use of personal data and automated decision making (Article 13, 14, 15(1)(h)) | Deployers should inform people using high risk AI systems (Article 26(11)) |
| Human oversight | Data subjects have the right not to be subject to automated decisions (Article 22) | High-risk systems designed and developed for human oversight (Article 14) |
| Traceability | Controllers and Processors required to maintain records of processing activities (Article 30) | Providers of high-risk AI systems to maintain technical documentation and automatic logging (Article 11,12, 26(6)) |
| Security | Controllers and Processors to take technical and organizational measures to ensure security (Article 32) | Providers must ensure robustness, accuracy, and cybersecurity of high-risk AI systems (Article 15(5)) |
| Special-category data | Processing personal data is prohibited unless an exception applies (Article 9) | Processing personal data permitted only where strictly necessary for bias monitoring, detection and correction in high-risk AI (Art. 10(5)) |
6. What do US Companies Need to Know in 2026?
The act has extraterritorial reach. U.S. companies providing AI systems to users in the European Union are in the scope of the act. The physical presence of the US company does not matter. See how the act affects US companies in practice. Non-compliance can trigger fines up to €35 million or 7% of global annual turnover.
For US companies, the main ways the EU AI Act would apply to them is if they:
01
Provide AI systems or General-Purpose AI models in the EU, irrespective of a physical presence in EU
02
Deploy AI systems from a location within the EU
03
Import or distribute AI systems within the EU
JAGGAER
How agentic AI works in procurement once it’s compliant
A JAGGAER guide on how agentic AI operates across procurement workflows
7. Frequently Asked Questions
The EU AI Act is the world’s first law regulating development and use of artificial intelligence. It governs AI systems used in the European Union according to four risk tiers.
The EU AI Act entered into force on 1 August 2024. Its rules apply in phases, and most obligations will take effect on 2 August 2026.
The EU AI Act applies to providers, deployers, importers, and distributors of AI systems, including companies based outside the EU when their AI system’s output is used within the Union.
Yes. The EU AI Act applies to US companies that place AI systems on the EU market, or whose AI outputs are used in the EU.
The EU AI Act bans AI posing unacceptable risk, including social scoring, manipulative techniques, untargeted facial-image scraping, emotion recognition in workplaces and schools, and most real-time public biometric identification.
EU AI Act high risk AI systems are those used in sensitive areas like employment, education, essential services, law enforcement, migration, and critical infrastructure.
The EU AI Act imposes fines up to 35 million euros or 7% of global turnover for banned practices, and up to 15 million euros or 3% for other violations.
GDPR governs personal data and privacy, while the EU AI Act regulates AI systems by risk level.
A general-purpose AI model under the EU AI Act is an AI model capable of performing many distinct tasks and being integrated into multiple downstream systems.
Yes, ChatGPT and models like GPT-5 are general-purpose AI models under the EU AI Act. The most capable models are classed as GPAI with systemic risk, triggering extra obligations.
Next Steps
This guide covers the EU AI Act end to end. The five articles below go deeper on the topics that matter most to your situation. Whether you are assessing applicability, mapping risk, calculating exposure, or preparing for a specific deadline, each of the areas have a dedicated guide with the detail this overview cannot fit.
Applicability
Does the EU AI Act Apply to Your Company? A Guide for Non-EU Businesses
Find out whether the act applies to your company, what triggers compliance obligations, and what you need to do next.
Read More
Risk Classification
EU AI Act Risk Categories: The 4 Tiers Explained
Learn what each risk tier means and which obligations apply to each level.
Read More
Fines & Penalties
EU AI Act Fines and Penalties: What Non-Compliance Will Cost You
Learn which violations trigger which penalties and how enforcement works.
Read More
GPAI Models
EU AI Act Rules for General-Purpose AI: What GPAI Providers Need to Know
Learn what qualifies as a GPAI model, which obligations apply, and what systemic risk means for your organisation.
Deadlines
EU AI Act Compliance Deadlines: Key Dates and Obligations
The EU AI Act applies in phases. This guide covers every key compliance deadline with dates and what each means.
Read More
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



