The EU AI Act is the world's first comprehensive law for artificial intelligence, and it is already reshaping how AI gets built and sold. Officially Regulation (EU) 2024/1689, it entered into force on 1 August 2024. But "in force" did not mean "in effect": the law phases in over several years, with different obligations switching on at different dates. As of October 2026, a confusing mix is true at once. The bans are live. The transparency rules are live. The toughest obligations, for high-risk systems, were pushed back by a 2026 simplification package. This is a plain-English map of where things stand. It is explanatory only, not legal advice.

The four risk tiers

The Act's core idea is simple: regulate the use case, not the technology. Every AI system falls into one of four risk levels, and the obligations scale with the level.

Prohibited (unacceptable risk). Banned outright. This covers social scoring systems, AI that manipulates people by exploiting vulnerabilities related to age or disability, untargeted scraping of facial images from the internet, emotion recognition in workplaces and schools, and real-time remote biometric identification by law enforcement, subject to narrow exceptions. In December 2026, AI tools that generate non-consensual intimate imagery or child sexual abuse material, including so-called nudification apps, join the banned list.

High-risk. Systems where failure could seriously harm health, safety, or fundamental rights: hiring and worker-management tools, credit scoring, medical devices, education admissions, and certain law enforcement and migration tools, listed in Annex III. These face the heaviest duties: risk management, data governance, technical documentation, human oversight, accuracy and robustness testing, and incident reporting, plus a conformity assessment before deployment.

Limited risk (transparency). Chatbots, voice agents, and generative tools. The main duty is disclosure: people must be told they are interacting with AI, and synthetic content must be labeled (Article 50).

Minimal risk. Spam filters, video game AI, and most everyday uses. No extra obligations beyond existing law.

The EU wrote the strictest AI rules in the world, then gave industry years to prepare for the hardest parts: the bans are live, the high-risk audits are not.

What is in force right now (October 2026)

Enjoying this story?

Get the five most important stories in tech, every morning. Free.

Several tracks are already binding. Prohibited practices and the AI literacy duty, which requires providers and deployers to ensure staff sufficiently understand the AI they operate, have applied since 2 February 2025, with no transition period. Obligations for general-purpose AI models, covering the foundation models behind today's chatbots, have applied since 2 August 2025: transparency about training, compliance with EU copyright rules, and, for the most capable models with systemic risk, ongoing safety evaluations. The penalty regime in Article 99 has applied since August 2025 as well.

Since 2 August 2026, the Article 50 transparency obligations apply: chatbots and voice agents must disclose that they are AI, and providers of generative systems must mark synthetic content, including deepfakes, as artificially generated. Enforcement teeth grew on the same date, with fining powers over general-purpose AI providers now active. The fines are what companies actually feel, because they scale with revenue: up to EUR 35 million or 7% of global annual turnover for prohibited practices, up to EUR 15 million or 3% for other breaches, and up to EUR 7.5 million or 1% for supplying incorrect information. And the Act reaches beyond Europe: it binds any provider or deployer whose AI output is used inside the EU.

What the Digital Omnibus changed

The EU AI Act by the numbers

Verified figures, 2026.

Risk tiers
4
Max fine, prohibited practices (% of turnover)
7
Max fine, other breaches (% of turnover)
3
Max fine, supplying wrong info (% of turnover)
1
Months from entry into force to Annex III deadline
40

In 2026 the EU passed a simplification package known as the Digital Omnibus on AI. Published as Regulation (EU) 2026/1744 in the Official Journal on 24 July 2026 and effective from 27 July 2026, it reshuffled the calendar rather than rewriting the substance.

The headline change is the high-risk delay. Obligations for standalone high-risk systems under Annex III, originally due in August 2026, now apply from 2 December 2027, a 16-month extension. High-risk obligations for AI embedded in regulated products (Annex I) were pushed to 2 August 2028. The deadline for each member state to set up at least one AI regulatory sandbox moved from August 2026 to August 2027. On the business-friendly side, relief measures designed for small and medium enterprises were extended to "small mid-caps," and registration was simplified for systems claiming an exemption.

The Omnibus was not only about delays. It added the new prohibition on AI-generated non-consensual intimate imagery and CSAM, effective 2 December 2026, the same date the grace period ends for machine-readable marking on generative AI systems that were already on the market before August 2026. Legal analysts generally advise companies to keep preparing for the high-risk duties rather than treating the extension as a pause.

What it means for builders and users

EU AI Act: the numbers that matter

Max fine, prohibited practices
EUR 35M or 7%

Share of global annual turnover, whichever is higher (Article 99)

Max fine, other breaches
EUR 15M or 3%

Applies to provider and deployer obligation breaches

Prohibited practices in force since
2 Feb 2025

No transition period; full fining authority active since August 2026

High-risk (Annex III) deadline
2 Dec 2027

Deferred 16 months by the July 2026 Digital Omnibus

New ban: AI nudification apps
2 Dec 2026

Added by the Digital Omnibus; covers non-consensual intimate imagery

For builders of foundation models, the message is that the core duties already apply: transparency documentation, copyright compliance for training data, and systemic-risk evaluations for the most capable models, with the GPAI Code of Practice published in July 2025 as the practical guide. For companies building or deploying high-risk systems such as hiring tools, the December 2027 date is runway, not a reprieve: data lineage, documentation, and human-oversight processes take time to build, and the architecture has to support them.

For deployers, meaning any organization using AI, two duties already bite. The AI literacy requirement means you should be able to show that staff understand the tools they use. And if you operate chatbots or publish AI-generated content in the EU, disclosure and labeling duties are live now. For users, the practical effects are the right to know when you are talking to a machine, labels on synthetic media, and bans on the most manipulative and intrusive uses. The strictest AI law on the planet is no longer a future event. Its sharpest edges are still being honed, but the shape of enforcement is already visible.

References

Regulation (EU) 2024/1689 (Official Journal of the European Union); European Commission regulatory framework for AI; Digital Omnibus on AI, Regulation (EU) 2026/1744; Volkov Law AI Act timeline analysis; Iris.ai enterprise AI Act briefing; euaiact.com compliance deadlines; artificialintelligenceact.eu implementation timeline.