Blog

    What Is the EU AI Act? Key Provisions Explained

    2026 Update AI Compliance EU AI Act
    What Is the EU AI Act? Key Provisions Explained

    The EU AI Act is the world’s first binding legal framework governing artificial intelligence end to end. It sets out which AI systems are permitted in the EU, which are banned outright, and what obligations apply to everything in between. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases, with some obligations already being enforced.

    It applies regardless of where a company is based. If your AI systems are used in the EU, by customers, employees, or partners, your company is within scope. That includes US businesses with no EU office, no EU employees, and no formal EU presence. The operative question is not where you are incorporated. It is whether your AI outputs reach EU users.

    This EU AI Act summary explains what the regulation is, who it applies to, the four risk tiers, the key provisions already in force, and the compliance timeline through 2028. For the full regulatory picture, see our complete guide to the EU AI Act.

    What Is the EU AI Act?

    Regulation (EU) 2024/1689 is the first regulation anywhere in the world to establish a binding legal framework specifically for artificial intelligence, covering development, deployment, and use. Formally titled the Artificial Intelligence Act, it was adopted by the European Parliament on 13 March 2024 and published in the Official Journal of the European Union on 12 July 2024.

    Its legislative purpose, set out in Article 1, is to promote the development of trustworthy AI while protecting health, safety, fundamental rights, democracy, and the rule of law. It also creates the legal foundation for a functioning EU internal market for AI: one set of rules, applied uniformly across all 27 member states, without variation or national transposition.

    The mechanism matters. The Act is a regulation, not a directive. A directive requires each member state to pass its own implementing legislation, which takes time and produces variation. A regulation applies directly and identically, the moment it enters into force.

    The Act does not replace GDPR. Both apply independently. An AI system that processes personal data must comply with both regimes. Existing GDPR compliance gives no credit under the AI Act. The obligations are separate and additive.

    This section of the EU AI Act summary covers its legal foundation; each subsequent section addresses a different layer of the regulation.

    27

    EU member states bound

    The AI Act is directly binding across all 27 EU member states. No national transposition required. No country-by-country variation in the core rules.

    Who Does the EU AI Act Apply To?

    The regulation recognises four categories of entity, each with different obligations. Which one applies to you determines what you are required to do and when.

    EU AI Act: Entity Roles at a Glance

    To be explicit: a US company has no safe harbour here. Article 2(1)(c) covers providers and deployers in third countries whose AI outputs are used in the EU. No EU office. No EU employees. No EU sales team. None of that exempts you if your AI reaches EU users.

    Open-source AI is not automatically excluded. The exception does not apply if the system is high-risk, prohibited under Article 5, or subject to Article 50 transparency obligations.

    JAGGAER

    Map which AI systems in your source-to-pay stack fall within EU AI Act scope before your compliance team asks.

    What Does the EU AI Act Regulate?

    The Act regulates the development, deployment, and use of AI systems in the EU. It covers how AI systems are built, who can place them on the market, what safety and transparency standards they must meet, and what happens when they cause harm. The scope is broad by design.

    The Act’s scope turns on the definition in Article 3(1): a machine-based system that infers outputs — predictions, recommendations, or decisions — from inputs, and may adapt over time. Fixed-rule software does not qualify; systems that generate outputs from training data do.

    Three categories are fully excluded:

    One clarification that catches companies out: the research exclusion does not cover real-world testing. Pre-market pilots and beta deployments with actual users, even pre-launch, can bring a system within scope. If real people are interacting with it in the EU, assume it is regulated until you have confirmed otherwise.

    The Four Risk Tiers

    Every AI system regulated by the Act falls into one of four tiers. Which tier it lands in determines everything: whether it is banned, what compliance obligations apply, and what the penalty exposure looks like. Most AI systems fall into the minimal risk tier and face no mandatory requirements. A much smaller proportion are classified as high risk, and those face the full weight of the Act.

    EU AI Act: Four Risk Tiers
    Unacceptable Risk

    Banned outright. Clear threats to safety, livelihoods, and fundamental rights.

    Subliminal manipulation, Social scoring, Workplace emotion recognition, Real-time biometric ID

    In force Feb 2025
    High Risk

    Six mandatory pre-market requirements before any deployment.

    Employment AI (hiring, ranking, evaluation), Biometric systems, Critical infrastructure, Education, Migration

    Dec 2027
    Limited Risk

    Must disclose AI nature to users. Transparency obligations only.

    Chatbots, Synthetic content tools, Deepfake generators, Emotion recognition

    Aug 2026
    Minimal Risk

    No mandatory requirements. The vast majority of AI applications.

    Spam filters, AI in video games, Inventory management tools, Content recommendation

    Unregulated

    The prohibitions in the unacceptable risk tier have been enforced since 2 February 2025. Any company operating a prohibited system has been in breach for over a year.

    For US companies, the highest-exposure high-risk category for most US businesses is employment AI. Any system used to filter job applications, rank candidates, or evaluate employee performance in an EU context falls under Annex III, Category 4. Full obligations apply from December 2027, but the conformity assessment and documentation process takes time. Starting in late 2027 is too late.

    For a full breakdown of how to determine which tier your AI systems fall into, see our EU AI Act risk categories explained.

    JAGGAER

    Know which AI tools are active in your procurement stack before EU AI Act compliance obligations land.

    Key Provisions at a Glance

    The five provisions below form the operative core of this EU AI Act summary — they determine what is banned, what requires compliance preparation, and what the penalty exposure looks like.

    Prohibited Practices (Article 5)

    Eight categories of AI are banned outright as clear threats to safety, fundamental rights, and human dignity. They include subliminal manipulation, social scoring, emotion recognition in workplaces and schools, untargeted facial recognition database scraping, and real-time biometric identification in public spaces. These prohibitions have been in force since 2 February 2025. Violations carry the highest penalty tier: €35M or 7% of worldwide annual turnover, whichever is higher. See our EU AI Act fines and penalties.

    High-Risk Obligations (Articles 8 to 15)

    Before a high-risk AI system can be placed on the EU market, its provider must satisfy six requirements. These are: a risk management system, data governance documentation, technical documentation, logging and record-keeping, human oversight measures, and accuracy and cybersecurity standards. A conformity assessment follows, then EU database registration, a declaration of conformity, and CE marking. These obligations apply from December 2027 for most Annex III systems. SMEs and small mid-cap companies qualify for simplified documentation under the AI Omnibus.

    Transparency for Limited-Risk Systems (Article 50)

    Systems in the limited risk tier must be honest with users. Chatbots must disclose they are AI. Synthetic content must carry machine-readable markings. Deepfakes must be labelled as artificially generated. These obligations apply from 2 August 2026. Violations attract up to €15M or 3% of worldwide annual turnover. The Commission published practical compliance guidance in June 2026.

    General-Purpose AI Model Rules (Articles 51 to 55)

    GPAI providers (foundation models used as the basis for downstream applications) have four baseline obligations. They must produce technical documentation, provide information to downstream providers, maintain a copyright compliance policy, and publish a training data summary. Providers above the 10²&sup5; FLOPs systemic risk threshold face four additional obligations: adversarial testing, ongoing risk assessment, incident reporting, and cybersecurity measures. In force since August 2025, enforced by the European AI Office rather than national authorities. See our EU AI Act rules for general-purpose AI models.

    Fine Structure (Articles 99 and 101)

    EU AI Act: Maximum Fines

    Operative from 2 August 2025. Whichever figure is higher applies.

    Prohibited practices
    (Art. 5)

    €35M or 7%


    Whichever is higher

    High-risk & other violations
    (Art. 99)

    €15M or 3%


    Whichever is higher

    Misleading information
    (Art. 99)

    €7.5M or 1%


    Whichever is higher

    GPAI providers
    (Art. 101)

    €15M or 3%


    Whichever is higher

    The penalty framework has been operational since 2 August 2025. For large US companies, the percentage ceiling, not the euro cap, is the binding constraint. A company generating $10 billion in global revenue faces a potential €700M fine for a prohibited practices violation.

    JAGGAER

    See the penalty tiers mapped to each AI system classification in your stack

    When Does the EU AI Act Apply?

    Two sets of obligations are already being enforced. A third arrives in two months. The rest phase in through 2028. The timeline is not academic. Two of the six milestones are already past.

    EU AI Act: Application Timeline
    In force Upcoming Future
    Aug 2024
    Act enters
    into force
    Law
    Feb 2025
    Prohibitions
    (Art. 5)
    Enforced
    Aug 2025
    GPAI rules
    + penalties
    In force
    Aug 2026
    Art. 50
    Transparency
    2 months
    Dec 2027
    High-risk
    Annex III
    Omnibus
    Aug 2028
    High-risk
    products
    Omnibus
    AI Omnibus (7 May 2026): Revised the original Aug 2026 high-risk deadline to Dec 2027 for Annex III systems, and Aug 2028 for product-embedded AI. Nodes marked “Omnibus” reflect the updated dates.

    The brief’s stated August 2026 high-risk date reflects the original regulation text. The AI Omnibus, agreed in May 2026, revised that deadline. High-risk systems in Annex III categories (employment AI, biometrics, critical infrastructure) now face December 2027. High-risk AI embedded in regulated products such as medical devices and machinery has until August 2028.

    August 2026 is the next live deadline. Article 50 transparency obligations take effect then for chatbot providers, synthetic content platforms, and deepfake systems. If your product falls into any of those categories, that deadline is now.

    For US businesses using this EU AI Act summary as a planning reference, the August 2026 and December 2027 deadlines carry the most immediate operational weight.

    For the full milestone map, see our EU AI Act compliance deadlines 2025–2027.

    The Commission has moved quickly from legislation to implementation. July 2025 brought three GPAI compliance instruments — the general-purpose AI Code of Practice, the GPAI model registration guidance, and the systemic risk classification guidelines. The AI content marking Code of Practice was published on 10 June 2026, ahead of the August 2026 Article 50 deadline. The Commission will publish full Article 50 transparency guidelines before the end of 2026.

    Frequently Asked Questions

    The EU AI Act, Regulation (EU) 2024/1689, is the world’s first binding legal framework governing artificial intelligence end to end. It governs which AI systems are permitted in the EU, which are banned, and what obligations apply to providers and deployers based on the risk their systems pose.

    The EU AI Act entered into force on 1 August 2024, following its publication in the Official Journal of the European Union on 12 July 2024. It does not apply all at once. Obligations phase in across multiple dates, with the first set of rules already enforced from 2 February 2025.

    The Act applies to providers, deployers, importers, and distributors of AI systems used in the EU, regardless of where those entities are based. The critical test is not incorporation. It is whether the AI system is placed on the EU market or its outputs reach EU users.

    Yes, on two legal grounds. Article 2(1)(a) covers any provider placing an AI system on the EU market, regardless of where the company is based. Article 2(1)(c) covers companies in third countries whose AI outputs are used in the EU. Incorporation in the US does not exclude a company from scope.

    The Act regulates the development, deployment, and use of AI systems in the EU. It covers which systems are permitted, which are banned, and what safety, transparency, and accountability obligations apply across four risk tiers. It does not regulate AI research for purely scientific purposes, military or national security systems, or personal non-professional use.

    The primary goal, set out in Article 1, is to promote the development of trustworthy and human-centric AI while protecting health, safety, fundamental rights, democracy, and the rule of law. It also aims to create a single, uniform set of rules for AI across the EU internal market, replacing the fragmented national approaches that existed before.

    Unacceptable risk (banned outright), high risk (six mandatory pre-market obligations), limited risk (transparency requirements), and minimal risk (no mandatory requirements). Classification determines both the obligations that apply and the penalty exposure for non-compliance.

    Eight practices are banned outright under Article 5. They include subliminal manipulation, social scoring, emotion recognition in workplaces and educational institutions, untargeted facial recognition database scraping, and real-time public biometric identification. These prohibitions have been in force since 2 February 2025.

    They are separate legal instruments that apply independently. GDPR governs the processing of personal data; the AI Act governs AI system risk. An AI system that processes personal data must comply with both. GDPR compliance does not satisfy AI Act obligations.

    Under Article 3(1), an AI system is a machine-based system that infers outputs: predictions, content, recommendations, or decisions, from inputs it receives. It operates with varying autonomy and may adapt after deployment. The key distinction from conventional software is inference: the system generates outputs from data rather than executing fixed pre-programmed rules.

    Next Steps

    This article covers the foundations. Each of the areas below has its own dedicated guide with the detail this EU AI Act overview cannot fit.

    If you are not yet certain which risk tier your AI systems fall into, start with the risk categories guide, as that is the most consequential question for most businesses. If you are tracking compliance deadlines and building a preparation roadmap, the timeline guide maps every milestone and what it requires. If you are assessing penalty exposure or need to brief a board or legal team, the fines guide covers the full enforcement framework.

    Continue Reading

    Risk Tiers

    EU AI Act risk categories explained

    Deadlines

    EU AI Act compliance deadlines 2025–2027

    Penalties

    EU AI Act fines and penalties

    JAGGAER

    See which AI systems in your procurement stack require compliance action, and when.

    Talk to a procurement expert.

    Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.

    • Direct or indirect?
      We handle both — on one platform.
    • Already have an ERP?
      JAGGAER Link connects to 1,000+ systems, no rip-and-replace.
    • Need to show ROI fast?
      We define outcomes and KPIs before you sign.
    • Vertical-specific?
      Manufacturing, higher ed, public sector — configured, not customized.

    Related Articles

    Copyright © 2026 JAGGAER – All Rights Reserved

    JAGGAER and the JAGGAER logo are registered trademarks of JAGGAER, LLC. All other registered trademarks, trademarks, and service marks are the property of their respective owners.