Frameworks

EU AI Act

The EU AI Act is the first comprehensive AI law, and its general obligations have applied since 2 August 2026. It regulates AI by risk tier rather than by technology. Prohibited practices are already banned, transparency duties now bind every chatbot and every piece of synthetic content, and the heaviest high-risk obligations run to December 2027.

What the EU AI Act regulates

The Act classifies AI systems by the risk they present, not by the technique used to build them. The same model can fall into different tiers depending on how it is deployed. It applies extraterritorially: a provider outside the EU is in scope where the system output is used inside the EU.

The four risk tiers

Unacceptable risk systems are banned outright. These include social scoring by public authorities and certain biometric categorization practices. The ban took effect in February 2025.

High risk covers systems in areas such as critical infrastructure, employment, education, and law enforcement. This tier carries the heaviest obligations: risk management, data governance, technical documentation, logging, human oversight, and conformity assessment.

Limited risk triggers transparency duties under Article 50. Users must be told when they are interacting with an AI system, and synthetic content must be marked as such.

Minimal risk covers everything else and carries no specific obligations.

The compliance timeline

The Act entered into force on 1 August 2024. Prohibitions on unacceptable-risk systems applied from February 2025. Transparency obligations for general-purpose AI models applied from August 2025. 2 August 2026 was the date of general application, which also switched on Article 50 transparency duties and the enforcement powers covering GPAI providers.

What the Digital Omnibus changed

Regulation (EU) 2026/1744, known as the Digital Omnibus, came into force on 27 July 2026 and moved the high-risk deadlines. Stand-alone high-risk systems listed in Annex III now apply from 2 December 2027. AI embedded in regulated products under Annex I applies from 2 August 2028. General-purpose AI models already on the market retain a transition window until 2 August 2027, during which providers must still show they are working toward conformity, guided by the Commission Code of Practice. The postponement buys time. It does not remove the obligation.

Penalties

Fines are tiered to the breach. Prohibited practices carry up to €35 million or 7 percent of global annual turnover, whichever is higher. Breaches of GPAI provider rules carry up to €15 million or 3 percent of global turnover. Penalties scale to company size, so the cap is a ceiling rather than a forecast.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies extraterritorially. A provider or deployer established outside the EU is in scope where the output of the AI system is used within the EU, regardless of where the system was built or hosted. Having no EU entity does not put a company outside the Act.

When do the high-risk obligations actually start?

Stand-alone high-risk systems in Annex III apply from 2 December 2027. AI embedded in regulated products under Annex I applies from 2 August 2028. Both dates were set by the Digital Omnibus, Regulation (EU) 2026/1744, which postponed the original deadlines.

What are the maximum penalties under the EU AI Act?

Up to €35 million or 7 percent of global annual turnover, whichever is higher, for engaging in prohibited practices. Breaches of the general-purpose AI provider rules carry up to €15 million or 3 percent of global turnover. Fines scale to company size, so these figures are ceilings.

Does ISO/IEC 42001 certification prove EU AI Act compliance?

No. Certification against ISO/IEC 42001 is useful evidence of diligence and produces much of the documentation the Act expects, but it does not by itself demonstrate conformity. Conformity assessment under the Act is a separate process with its own requirements.

Is a customer service chatbot covered by the EU AI Act?

Almost certainly as limited risk, which triggers Article 50 transparency duties: users must be told they are interacting with an AI system. Those duties have applied since 2 August 2026. A chatbot used for something like screening job applicants would instead fall into the high-risk tier and carry the full obligations.

How the EU AI Act relates to the other frameworks

The EU AI Act is law. The others are not. That is the distinction that matters most. NIST AI RMF is a voluntary risk process that maps well onto the Act’s risk management requirements. ISO/IEC 42001 provides a certifiable management system, and certification is useful evidence of diligence even though it does not by itself demonstrate conformity. MITRE ATLAS and OWASP AI address the security engineering the Act assumes you are already doing. See the full AI security framework comparison.

Turning these obligations into a register of AI systems, named owners and evidence an assessor will accept is the practical work. See AI Governance, or AISGRC for a free scorecard and artifact toolkit.

© 2026 AI Security Central. All rights reserved.