The EU AI Act is the world’s first binding legal framework governing artificial intelligence end to end. It sets out which AI systems are permitted in the EU, which are banned outright, and what obligations apply to everything in between. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases, with some obligations already being enforced.
It applies regardless of where a company is based. If your AI systems are used in the EU, by customers, employees, or partners, your company is within scope. That includes US businesses with no EU office, no EU employees, and no formal EU presence. The operative question is not where you are incorporated. It is whether your AI outputs reach EU users.
This EU AI Act summary explains what the regulation is, who it applies to, the four risk tiers, the key provisions already in force, and the compliance timeline through 2028. For the full regulatory picture, see our complete guide to the EU AI Act.
What Is the EU AI Act?
Regulation (EU) 2024/1689 is the first regulation anywhere in the world to establish a binding legal framework specifically for artificial intelligence, covering development, deployment, and use. Formally titled the Artificial Intelligence Act, it was adopted by the European Parliament on 13 March 2024 and published in the Official Journal of the European Union on 12 July 2024.
Its legislative purpose, set out in Article 1, is to promote the development of trustworthy AI while protecting health, safety, fundamental rights, democracy, and the rule of law. It also creates the legal foundation for a functioning EU internal market for AI: one set of rules, applied uniformly across all 27 member states, without variation or national transposition.
The mechanism matters. The Act is a regulation, not a directive. A directive requires each member state to pass its own implementing legislation, which takes time and produces variation. A regulation applies directly and identically, the moment it enters into force.
The Act does not replace GDPR. Both apply independently. An AI system that processes personal data must comply with both regimes. Existing GDPR compliance gives no credit under the AI Act. The obligations are separate and additive.
This section of the EU AI Act summary covers its legal foundation; each subsequent section addresses a different layer of the regulation.
27
EU member states bound
The AI Act is directly binding across all 27 EU member states. No national transposition required. No country-by-country variation in the core rules.
Who Does the EU AI Act Apply To?
The regulation recognises four categories of entity, each with different obligations. Which one applies to you determines what you are required to do and when.
EU AI Act: Entity Roles at a Glance
Heaviest obligations
Provider
Develops an AI system and places it on the EU market or puts it into service, whether for payment or free of charge.
US example: A company selling or deploying an AI product for EU use. The deploying entity is the provider — not the underlying developer.
Moderate obligations
Deployer
Uses an AI system in a professional or commercial context. Carries lighter obligations than providers but is not exempt.
US example: A company using an AI hiring tool to screen EU-based candidates. Human oversight and Article 50 disclosure requirements apply.
Lighter obligations
Importer
An EU-established entity that places a third-country AI system onto the EU market.
Scope note: EU entity only. US companies placing AI on the EU market directly are covered under the provider definition, not importer.
Lighter obligations
Distributor
An entity in the supply chain that makes an AI system available in the EU without modifying it.
Scope note: Modification changes your status. Altering the system — even partially — can reclassify a distributor as a provider.
To be explicit: a US company has no safe harbour here. Article 2(1)(c) covers providers and deployers in third countries whose AI outputs are used in the EU. No EU office. No EU employees. No EU sales team. None of that exempts you if your AI reaches EU users.
Open-source AI is not automatically excluded. The exception does not apply if the system is high-risk, prohibited under Article 5, or subject to Article 50 transparency obligations.
JAGGAER
See how Jaggaer tracks AI system usage across procurement and sourcing workflows
Map which AI systems in your source-to-pay stack fall within EU AI Act scope before your compliance team asks.
What Does the EU AI Act Regulate?
The Act regulates the development, deployment, and use of AI systems in the EU. It covers how AI systems are built, who can place them on the market, what safety and transparency standards they must meet, and what happens when they cause harm. The scope is broad by design.
The Act’s scope turns on the definition in Article 3(1): a machine-based system that infers outputs — predictions, recommendations, or decisions — from inputs, and may adapt over time. Fixed-rule software does not qualify; systems that generate outputs from training data do.
Three categories are fully excluded:
- Military, defence, and national security systems (Article 2(3))
- Pure scientific research and development (Article 2(6))
- Personal, non-professional use (Article 2(10))
One clarification that catches companies out: the research exclusion does not cover real-world testing. Pre-market pilots and beta deployments with actual users, even pre-launch, can bring a system within scope. If real people are interacting with it in the EU, assume it is regulated until you have confirmed otherwise.
The Four Risk Tiers
Every AI system regulated by the Act falls into one of four tiers. Which tier it lands in determines everything: whether it is banned, what compliance obligations apply, and what the penalty exposure looks like. Most AI systems fall into the minimal risk tier and face no mandatory requirements. A much smaller proportion are classified as high risk, and those face the full weight of the Act.
Banned outright. Clear threats to safety, livelihoods, and fundamental rights.
Subliminal manipulation, Social scoring, Workplace emotion recognition, Real-time biometric ID
Six mandatory pre-market requirements before any deployment.
Employment AI (hiring, ranking, evaluation), Biometric systems, Critical infrastructure, Education, Migration
Must disclose AI nature to users. Transparency obligations only.
Chatbots, Synthetic content tools, Deepfake generators, Emotion recognition
No mandatory requirements. The vast majority of AI applications.
Spam filters, AI in video games, Inventory management tools, Content recommendation
The prohibitions in the unacceptable risk tier have been enforced since 2 February 2025. Any company operating a prohibited system has been in breach for over a year.
For US companies, the highest-exposure high-risk category for most US businesses is employment AI. Any system used to filter job applications, rank candidates, or evaluate employee performance in an EU context falls under Annex III, Category 4. Full obligations apply from December 2027, but the conformity assessment and documentation process takes time. Starting in late 2027 is too late.
For a full breakdown of how to determine which tier your AI systems fall into, see our EU AI Act risk categories explained.
JAGGAER
See how Jaggaer maps AI system usage across source-to-pay workflows
Know which AI tools are active in your procurement stack before EU AI Act compliance obligations land.
Key Provisions at a Glance
The five provisions below form the operative core of this EU AI Act summary — they determine what is banned, what requires compliance preparation, and what the penalty exposure looks like.
Prohibited Practices (Article 5)
Eight categories of AI are banned outright as clear threats to safety, fundamental rights, and human dignity. They include subliminal manipulation, social scoring, emotion recognition in workplaces and schools, untargeted facial recognition database scraping, and real-time biometric identification in public spaces. These prohibitions have been in force since 2 February 2025. Violations carry the highest penalty tier: €35M or 7% of worldwide annual turnover, whichever is higher. See our EU AI Act fines and penalties.
High-Risk Obligations (Articles 8 to 15)
Before a high-risk AI system can be placed on the EU market, its provider must satisfy six requirements. These are: a risk management system, data governance documentation, technical documentation, logging and record-keeping, human oversight measures, and accuracy and cybersecurity standards. A conformity assessment follows, then EU database registration, a declaration of conformity, and CE marking. These obligations apply from December 2027 for most Annex III systems. SMEs and small mid-cap companies qualify for simplified documentation under the AI Omnibus.
Transparency for Limited-Risk Systems (Article 50)
Systems in the limited risk tier must be honest with users. Chatbots must disclose they are AI. Synthetic content must carry machine-readable markings. Deepfakes must be labelled as artificially generated. These obligations apply from 2 August 2026. Violations attract up to €15M or 3% of worldwide annual turnover. The Commission published practical compliance guidance in June 2026.
General-Purpose AI Model Rules (Articles 51 to 55)
GPAI providers (foundation models used as the basis for downstream applications) have four baseline obligations. They must produce technical documentation, provide information to downstream providers, maintain a copyright compliance policy, and publish a training data summary. Providers above the 10²&sup5; FLOPs systemic risk threshold face four additional obligations: adversarial testing, ongoing risk assessment, incident reporting, and cybersecurity measures. In force since August 2025, enforced by the European AI Office rather than national authorities. See our EU AI Act rules for general-purpose AI models.
Fine Structure (Articles 99 and 101)
EU AI Act: Maximum Fines
Operative from 2 August 2025. Whichever figure is higher applies.
The penalty framework has been operational since 2 August 2025. For large US companies, the percentage ceiling, not the euro cap, is the binding constraint. A company generating $10 billion in global revenue faces a potential €700M fine for a prohibited practices violation.
JAGGAER
See how Jaggaer audits AI system usage across source-to-pay workflows
See the penalty tiers mapped to each AI system classification in your stack
When Does the EU AI Act Apply?
Two sets of obligations are already being enforced. A third arrives in two months. The rest phase in through 2028. The timeline is not academic. Two of the six milestones are already past.
into force
(Art. 5)
+ penalties
Transparency
Annex III
products
The brief’s stated August 2026 high-risk date reflects the original regulation text. The AI Omnibus, agreed in May 2026, revised that deadline. High-risk systems in Annex III categories (employment AI, biometrics, critical infrastructure) now face December 2027. High-risk AI embedded in regulated products such as medical devices and machinery has until August 2028.
August 2026 is the next live deadline. Article 50 transparency obligations take effect then for chatbot providers, synthetic content platforms, and deepfake systems. If your product falls into any of those categories, that deadline is now.
For US businesses using this EU AI Act summary as a planning reference, the August 2026 and December 2027 deadlines carry the most immediate operational weight.
For the full milestone map, see our EU AI Act compliance deadlines 2025–2027.
Frequently Asked Questions
The EU AI Act, Regulation (EU) 2024/1689, is the world’s first binding legal framework governing artificial intelligence end to end. It governs which AI systems are permitted in the EU, which are banned, and what obligations apply to providers and deployers based on the risk their systems pose.
The EU AI Act entered into force on 1 August 2024, following its publication in the Official Journal of the European Union on 12 July 2024. It does not apply all at once. Obligations phase in across multiple dates, with the first set of rules already enforced from 2 February 2025.
The Act applies to providers, deployers, importers, and distributors of AI systems used in the EU, regardless of where those entities are based. The critical test is not incorporation. It is whether the AI system is placed on the EU market or its outputs reach EU users.
Yes, on two legal grounds. Article 2(1)(a) covers any provider placing an AI system on the EU market, regardless of where the company is based. Article 2(1)(c) covers companies in third countries whose AI outputs are used in the EU. Incorporation in the US does not exclude a company from scope.
The Act regulates the development, deployment, and use of AI systems in the EU. It covers which systems are permitted, which are banned, and what safety, transparency, and accountability obligations apply across four risk tiers. It does not regulate AI research for purely scientific purposes, military or national security systems, or personal non-professional use.
The primary goal, set out in Article 1, is to promote the development of trustworthy and human-centric AI while protecting health, safety, fundamental rights, democracy, and the rule of law. It also aims to create a single, uniform set of rules for AI across the EU internal market, replacing the fragmented national approaches that existed before.
Unacceptable risk (banned outright), high risk (six mandatory pre-market obligations), limited risk (transparency requirements), and minimal risk (no mandatory requirements). Classification determines both the obligations that apply and the penalty exposure for non-compliance.
Eight practices are banned outright under Article 5. They include subliminal manipulation, social scoring, emotion recognition in workplaces and educational institutions, untargeted facial recognition database scraping, and real-time public biometric identification. These prohibitions have been in force since 2 February 2025.
They are separate legal instruments that apply independently. GDPR governs the processing of personal data; the AI Act governs AI system risk. An AI system that processes personal data must comply with both. GDPR compliance does not satisfy AI Act obligations.
Under Article 3(1), an AI system is a machine-based system that infers outputs: predictions, content, recommendations, or decisions, from inputs it receives. It operates with varying autonomy and may adapt after deployment. The key distinction from conventional software is inference: the system generates outputs from data rather than executing fixed pre-programmed rules.
Next Steps
This article covers the foundations. Each of the areas below has its own dedicated guide with the detail this EU AI Act overview cannot fit.
If you are not yet certain which risk tier your AI systems fall into, start with the risk categories guide, as that is the most consequential question for most businesses. If you are tracking compliance deadlines and building a preparation roadmap, the timeline guide maps every milestone and what it requires. If you are assessing penalty exposure or need to brief a board or legal team, the fines guide covers the full enforcement framework.
Continue Reading
Full Picture
Risk Tiers
EU AI Act risk categories explained
Deadlines
EU AI Act compliance deadlines 2025–2027
Penalties
EU AI Act fines and penalties
GPAI Models
JAGGAER
See Which AI Systems in Your Source-to-Pay Stack Fall Within EU AI Act Scope
See which AI systems in your procurement stack require compliance action, and when.
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



