Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
EUDEEP coverage2 enforcement actions

EU Artificial Intelligence Act: AI Compliance Requirements

Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, critical infrastructure, law enforcement), limited-risk (transparency obligations for chatbots and deepfakes), minimal-risk (most AI tools). Providers AND deployers have obligations. Extraterritorial: applies when the AI system's output is used in the EU regardless of provider location. TIMELINE UPDATE (Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026): the Annex III stand-alone high-risk obligations are deferred from 2 Aug 2026 to 2 Dec 2027 and the Annex I product-embedded high-risk obligations from 2 Aug 2027 to 2 Aug 2028; the already-live prohibited-practice (Feb 2025) and GPAI (Aug 2025) obligations were unchanged, and the Art. 50 transparency obligations took effect as scheduled on 2 Aug 2026 (the Art. 50(2) marking duty for AI systems placed on the market before 2 Aug 2026 has a grace period to 2 Dec 2026).

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

August 1, 2024

Enforcement Begins

August 2, 2026

Maximum Penalty

€35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities

What Your Business Must Do

10 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

AI Risk Classification

Critical

Classify each AI system you use or deploy as Minimal, Limited, High, or Unacceptable risk under EU AI Act Annex III. High-risk categories: biometric systems, critical infrastructure, education/vocational training, employment/HR, essential services (credit, insurance), law enforcement, migration/asylum, administration of justice. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).

Deadline: December 2, 2027

Art. 6, Annex III

Conformity Assessment (High-Risk)

Critical

Providers of Annex III high-risk AI systems must conduct conformity assessment before placing on market. Most systems: self-assessment via internal checks. Biometric and critical infrastructure: third-party assessment required. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).

Deadline: December 2, 2027

Art. 43, Annex VI

Prohibited: Non-Consensual Intimate Imagery & CSAM-Generation AI

Critical

Digital Omnibus amendment (Regulation (EU) 2026/1744) added two new Art. 5(1) prohibited practices, effective 2 Dec 2026: (ba) placing on market, putting into service, or using AI systems that generate or manipulate realistic depictions of an identifiable person's intimate body parts or sexually explicit activity without that person's freely-given, specific, informed, unambiguous, and explicit consent (targets "nudifier" apps); (bb) AI systems designed to generate child sexual abuse material, subject to narrow law-enforcement/crime-prevention/compliance-red-teaming exceptions. Providers are banned if generation/manipulation is the intended purpose OR a reasonably foreseeable outcome absent adequate technical safeguards (data cleaning, refusal training, content filtering, abuse detection); deployers are banned only for actual use to generate prohibited material.

Deadline: December 2, 2026

Art. 5(1)(ba), Art. 5(1)(bb) (inserted by Regulation (EU) 2026/1744)

Transparency Disclosures

High Priority

Inform users when they are interacting with AI (chatbots, generated content, AI-assisted decisions). Deepfake content must be labeled. AI chatbots must identify themselves. Cannot deploy AI that impersonates humans without disclosure.

Deadline: August 2, 2026

Art. 50

AI Acceptable Use Policy

High Priority

Document how employees may and may not use AI tools within your organization. Required for deployers of high-risk systems. Must include authorized uses, restrictions, human oversight requirements, and escalation procedures.

Deadline: December 2, 2027

Art. 4, Art. 26

Employee AI Monitoring Notice

High Priority

Notify employees if AI systems are used to monitor their work performance or productivity. Covers AI-assisted performance management, productivity scoring, and automated scheduling. Must be clear, written notice before deployment. Art. 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers. As an Art. 26 high-risk deployer obligation this follows the Digital Omnibus deferral to 2 Dec 2027.

Deadline: December 2, 2027

Art. 26(7)

Technical Documentation (Annex IV)

High Priority

Providers of high-risk AI systems must maintain Annex IV technical documentation: system description, development methodology, training data summary, testing procedures, accuracy metrics, post-market monitoring plan.

Deadline: December 2, 2027

Art. 11, Annex IV

Record Keeping & Logging

High Priority

Deployers of high-risk AI must keep logs for minimum 6 months. Providers must keep technical documentation for 10 years. Logs must enable reconstruction of circumstances leading to any incident.

Deadline: December 2, 2027

Art. 12, Art. 18, Art. 19, Art. 26(6)

Human Oversight Procedures

Medium Priority

Implement procedures ensuring human review of high-risk AI decisions. Must document how humans can intervene, override, or halt the AI system. Human oversight must be technically possible and operationally implemented — a nominal checkbox does not suffice.

Deadline: December 2, 2027

Art. 14, Art. 26(1)-(2)

GPAI Model Obligations

Medium Priority

General Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policy, and train providers who use their models. Systemic risk GPAI (>10^25 FLOPs training compute) have additional obligations: adversarial testing, serious incident reporting, cybersecurity measures.

Deadline: August 2, 2025

Art. 51-56

Who Does This Apply To?

Applies to: (1) providers placing AI systems on EU market or putting into service, (2) deployers using AI systems within EU, (3) providers/deployers in third countries when output used in EU, (4) importers and distributors of AI systems. Exemptions: AI for military/national security, AI used solely for scientific research, open-source models (partial). SMB deployers using third-party AI tools (e.g., ChatGPT, Copilot) are "deployers" — must comply with Annex III obligations when using AI for HR decisions, credit assessments, or customer profiling.

Recent Enforcement Actions

French CNIL (GDPR — see caseCitations for the full, corrected framing)2022-10-17€20,000,000 (+ €5,200,000 periodic penalty)Source verified· as of 2026-08-22

Against: Clearview AI

CNIL fined Clearview AI €20,000,000 under GDPR (not the EU AI Act, which had no applicable prohibition provisions in force until Feb 2025) for unlawful biometric scraping and disregard of data-subject rights, plus a €5,200,000 periodic penalty (2023-04-13) for non-compliance with the deletion order. No EU AI Office action and no formal "EU market ban" exist on the public record — see the caseCitations entry below for the full corrected history (R133).

Source
EU AI Office (GPAI Code of Practice)2025-07-18Source verified· as of 2026-08-22

Against: Meta

Meta publicly declined to sign the GPAI Code of Practice (Joel Kaplan statement), meaning Meta's LLaMA models get no rebuttable-compliance presumption under Art. 51-56 and are assessed directly against the statute. ~24 organizations (Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, among others) had signed by June 2026.

Source

Recent Regulatory Guidance

guidance2025-09-16

EU AI Office GPAI Code of Practice (Final)

AI Office published the final GPAI Code of Practice covering transparency, copyright, and safety for general-purpose AI providers. Participation voluntary but creates safe harbor for Art. 51-56 compliance. Key requirement: model cards with capability disclosures, capability thresholds for enhanced red-teaming.

Source
guidance2026-01-20

Commission Guidance: Deployer Obligations for Third-Party AI Tools

Commission clarified that companies using ChatGPT Enterprise, Microsoft Copilot, or similar third-party AI tools for employment decisions are "deployers" under Art. 22(1) and must conduct their own fundamental rights impact assessment. Vendor contracts providing AI access do not transfer deployer liability to the provider.

Source
opinion2024-12-17

EDPB Opinion 28/2024 — Personal Data in AI Models (legal basis for training)

EDPB Opinion 28/2024 (adopted 17 Dec 2024, at the Irish DPC's request) addresses processing personal data when developing/deploying AI models: an AI model trained on personal data is not automatically "anonymous" (case-by-case test), and a controller may rely on legitimate interest for AI-model development/deployment only after the full three-part balancing test — it does not apply automatically. Note: the Opinion expressly excluded automated decision-making/Art. 22, profiling and DPIAs from its scope.

Source
guidance2026-04-01

EU AI Office: Q&A on Annex III Scope for HR AI Tools

AI Office Q&A confirmed that AI tools used for candidate screening, employee scheduling optimization, and performance monitoring meet the Annex III high-risk threshold. "Substantially assisting" a consequential HR decision — even with human final sign-off — qualifies as high-risk AI.

Source

Key Case Law & Precedent

CNIL v. Clearview AI

French CNIL (Commission Nationale de l'Informatique et des Libertés) · 2022

A GDPR action, NOT an EU AI Act action (Art. 5 biometric-surveillance prohibitions became applicable Feb 2025 and have no enforcement on record as of this entry). The CNIL found Clearview's scraping of facial images and biometric processing had no legal basis (GDPR Art. 6) and disregarded data-subject rights (Arts. 12, 15, 17), and ordered deletion of French residents' data. Establishes that scraping facial images to build a recognition database is unlawful biometric processing under EU data-protection law — a relevant precedent for any biometric-AI deployer, but under the GDPR, not the AI Act.

Outcome: IMPOSED: €20,000,000 GDPR fine (17 Oct 2022) plus a €5,200,000 periodic penalty (13 Apr 2023) for failure to comply with the deletion order. No EU AI Act penalty and no "EU market ban" exist — those framings were corrected as fabricated (Round 133).

Case reference

Loomis v. Wisconsin (Referenced in EU guidance)

Wisconsin Supreme Court → EU guidance context · 2016

US case (COMPAS recidivism AI) cited in EU AI Office guidance as example of high-risk AI in justice sector requiring human oversight under Art. 14. Established that opaque AI scoring in consequential decisions raises due process concerns even without explicit bias finding.

Outcome: Referenced in EU Art. 14 human oversight guidance

Case reference

Quarterly Enforcement Digest

Q3 2026 update: Commission published deployer guidance clarifying third-party AI tool liability. EDPB Opinion 28/2024 confirmed AI-model training on personal data needs its own GDPR legal basis (legitimate interest is not automatic). Cycle 8 (2026-08-22) correction: removed two uncorroborated "EU AI Office formal inquiry" claims against OpenAI and Meta that had no independent source and were procedurally impossible as dated (GPAI enforcement powers only became legally active 2026-08-02); the real, verified fact is that Meta declined to sign the GPAI Code of Practice (2025-07-18) while ~24 other organizations signed. The Clearview AI enforcementActions entry was also corrected to match this entry's own already-corrected caseCitations record — it is a 2022 CNIL GDPR fine, not an EU AI Act/AI Office action, and no "EU market ban" exists on the public record.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering EU Artificial Intelligence Act

These industry playbooks include jurisdiction-specific checklist items and guidance for EU Artificial Intelligence Act.

Frequently Asked Questions

Does EU Artificial Intelligence Act apply to my business?

Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, critical infrastructure, law enforcement),… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under EU Artificial Intelligence Act is: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with EU Artificial Intelligence Act?

The 10 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan