Skip to content
In this article

Rules and standards

The EU AI Act

What Europe's AI law asks for, and who it reaches

Published 9 September 20263 min read

In one paragraph

The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by the risk they carry, bans a short list of practices outright, and puts the heaviest duties on systems used in areas such as hiring, credit, education, essential services and law enforcement. It reaches further than the EU's borders: any organisation that places an AI system on the EU market, or whose AI output is used there, falls within it, wherever that organisation is based. The rules are being phased in over several years rather than arriving all at once.

Who it applies to

Any organisation, wherever it is headquartered, that places an AI system on the EU market or whose AI output is used within the EU. It reaches providers and users of AI systems, and it applies alongside existing sector rules rather than replacing them. Enforcement sits with the EU AI Office at the European level, national market surveillance authorities in each member state, and, for high-risk systems, independent notified bodies that carry out conformity assessment.

What it asks for

  • A defined set of unacceptable practices is banned outright, in force since 2 February 2025, with two further prohibitions due to phase in on 2 December 2026.
  • Transparency duties under Article 50, covering matters such as chatbots and AI-generated content, have applied since 2 August 2026.
  • General-purpose AI models have carried their own obligations since 2 August 2025.
  • Systems classed as high-risk under Annex III, covering areas such as hiring, credit, education, essential services and law enforcement, must meet the full set of obligations from 2 December 2027.
  • AI embedded in products already regulated under Annex I, such as machinery and medical devices, has until 2 August 2028 to comply.
  • High-risk systems need a risk management process, data governance, technical documentation, logging, human oversight, a defined level of accuracy and cybersecurity, a conformity assessment, and registration in an EU database.

What it looks like in practice

A tool has been helping screen job applications for a while now, and it arrived without much ceremony. Nobody set out to build a high-risk system, but screening candidates is exactly the kind of use the Act treats as high-risk. Working that out is the first job: what the system does, whether it falls under Annex III, and what evidence would need to exist before the relevant deadline. In most cases the answer changes nothing about whether the tool is kept, only about the documentation, oversight and testing that has to sit around it.

Where it stands now

Regulation (EU) 2024/1689 was amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published 24 July 2026 and in force from 27 July 2026. Prohibited practices have applied since 2 February 2025, with two further prohibitions due on 2 December 2026. General-purpose AI model obligations have applied since 2 August 2025. Transparency duties under Article 50 have applied since 2 August 2026. High-risk obligations for Annex III uses are due 2 December 2027. High-risk obligations for AI embedded in Annex I regulated products are due 2 August 2028. Dates change; the official text linked below is the authority.

How this connects to our work

Working out which of your systems this reaches, and what each deadline actually requires of it, is part of the policy and record-keeping that comes with a private AI setup. The same inventory and classification work applies whichever deadline ends up mattering to you.

Read the original

Every link goes to the publisher. Dates and status change; the text linked below is the authority.