Law enters into force
1 August 2024
The EU AI Act enters into force on 1 August 2024, 20 days after its publication in the Official Journal of the
EU. Entering into force is an administrative milestone which does not create any immediate legal obligations for
providers or deployers of AI systems. The first legal obligations under the Act will come into effect on 2
February 2025 (6 months from entering into force) – the effect of this will be to ban AI systems with an
unacceptable risk.
For more information on who the EU AI Act applies to, see our article here.
For assistance with AI system risk categorisation, or to discuss our approach to
compliance, download our guide or reach out to a member of the team.
Ban on AI systems with unacceptable risk. Rules on AI Literacy come into effect
2 February 2025
AI Literacy Rules
Providers and deployers of AI systems must now implement measures to ensure that personnel and other persons
dealing with the operation and use of AI systems possess adequate AI literacy in order to do so in an informed
way. The threshold for AI literacy should take into account the context the AI systems are to be used in and the
groups of people on whom the systems are to be used.
Unacceptable Risk Ban
The Act enforces a prohibition on AI systems identified as posing an "unacceptable risk" in accordance with
Article 5. The Act prohibits systems which have the consequence of undermining fundamental human rights. AI
systems prohibited since 2 February 2025 include those which have the following functions or characteristics:
- Engage in deception, manipulation, or use subliminal techniques;
- Use social scoring for public or private purposes;
- Exploit biometric data in real-time or for categorisation purposes (i.e. to deduce or infer race, political
opinions, trade union membership, religious or philosophical beliefs or sexual orientation);
- Scrape internet or CCTV for facial images to build-up or expand databases;
- Recognise emotions in the workplace and education institutions;
- Conduct certain types of predictive risk profiling; and
- Exploit vulnerable persons;
The maximum penalty for breaches in respect of prohibited AI systems is the higher of: (a) EUR 35 million, or
(b) up to 7% of worldwide annual turnover.
While the provisions in relation to these prohibitions came into effect on 2 February 2025,
the penalties will not apply until 2 August 2025. The EU Commission conducted a consultation on
prohibitions and AI system definitions under the Act in late 2024 and early 2025, and published draft Guidelines
on 4 February 2025 (which are approved by the EU Commission but not yet adopted).
AI Office Codes of Practice required to be ready
2 May 2025
The final draft of the General-Purpose AI Code of Practice (the Code) was due to be presented for approval on 2
May 2025. The Code, which has undergone an iterative drafting process involving nearly 1000 stakeholders and
three previous drafts, is intended to facilitate the proper application of the EU AI Act's rules for
general-purpose AI models, including transparency and copyright-related rules, risk assessment, and mitigation
measures. The final version
was, in the end, presented for approval in July 2025.
Details of the Code
The Code will be an important tool for General-Purpose AI providers to demonstrate their compliance with the AI
Act (whilst not providing a presumption of conformity). However, not all GPAI providers are prepared to confirm
that they will sign the Code.
Given the evolving state of AI, the drafting of the Code aims to strike a balance between clear commitments and
the flexibility to adapt as AI technology evolves, but its passage to date has been controversial. Article 56 EU
AI Act outlines the key issues addressed in the Code. These include:
- the means to ensure that information is kept up to date in light of market and technological developments
(transparency);
- the adequate level of detail for the summary about the content used for training (copyright);
- the identification or the type and nature of the systemic risks, including, where appropriate, their sources
(risk assessment); and
- the measures, procedures and modalities for the assessment and management of the systemic risks identified
above (mitigation measures).
We have analysed the final version of the Code here.
General Purpose AI (GPAI) models must comply (subject to grandfathering provisions). Rules on penalties,
governance and notification come into force
2 August 2025
From 2 August 2025, a number of provisions in the EU AI Act begin to apply. In particular, providers of General
Purpose AI (GPAI) models put on the market in the EU on or after that date must comply with certain rules and
obligations. For GPAI models placed on the EU market before 2 August 2025, however, the deadline for compliance
is 2 August 2027. Supervision and enforcement by the AI Office for compliance with the rules for GPAI
models (including issuing of penalties) will start as of 2 August 2026. However, other penalties can now be
imposed by the Office.
Rules on GPAI models
These include:
- Technical documentation: Providers of GPAI models must prepare detailed technical
documentation and other information about their model which must be kept up-to-date and demonstrate compliance
with the Act.
- Copyright compliance: Providers of GPAI models must implement policies for compliance with
EU copyright law, in particularly identifying and respecting reservations of rights expressed by rights
holders. Summaries of the content used for training GPAI models must be made publicly available.
- Risk assessment for GPAI models with systemic risk: For GPAI models with systemic risk,
providers must perform model evaluation; assess and mitigate possible systemic risks at the EU level; document
and report any serious incidents to the AI Office and national authorities; and ensure an adequate level of
cybersecurity protection.
- Appointment of authorised EU representative: Providers of GPAI models established outside
of the EU must appoint an 'authorised representative' within the EU before placing the model on the market.
This representative shall cooperate with local authorities and is responsible for verifying technical
documentation has been drawn up and made available.
Materials have been published to assist GPAI model providers in compliance with their obligations including:
- A voluntary Code of Practice which will not provide a presumption of conformity but will provide
'increased legal certainty' – discussed in our article here. The Commission has confirmed providers who sign the
Code will benefit in effect from a grace period to demonstrate 'good faith' adherence.
-
Guidelines on the scope of obligations for GPAI model providers –
discussed in our article here.
-
Mandatory Template for disclosing summaries of training data –
discussed in our article here.
Penalties and enforcement
The AI Act's tiered approach to penalties also applies from 2 August 2025 - non-compliance with the Act's
provisions could potentially result in substantial fines, for example up to €35 million or 7% of global annual
turnover, whichever is higher in respect of prohibited AI practices.
However, fines against providers of GPAI models (which are a maximum of €15 million or 3% of global annual
turnover, whichever is higher) will not start to apply until 2 August 2026.
Other provisions
This date will also see the establishment of the respective national competent authorities (Chapter VII,
Article 70), who will be responsible for supervising the application of the Act on a national level.
Majority of AI Act rules come into force and enforcement starts for applicable rules
2 August 2026
Extension of compliance deadlines for Annex III High Risk Systems
2 August 2026 is a key compliance milestone for the EU AI Act. However, compliance deadlines in relation to high-risk systems have been extended under the Digital AI Omnibus, as follows:
- 2 December 2027: implementation of provisions relating to standalone high-risk AI systems listed in Annex III of the Act (for example, those used in employment, education, biometrics, critical infrastructure, and migration and border contexts).
- 2 August 2028: implementation of provisions relating to high-risk AI systems embedded in products covered by EU product-safety regimes listed in Annex I.
Guidelines on the classification of high-risk systems under the Act remain to be finalised. Although the Omnibus delays the high-risk obligations, it does not remove the need to prepare effectively and the additional time provided will likely raise the bar for what regulators consider acceptable preparedness.
Our article on the AI Omnibus discusses the implications of the extensions to the compliance deadlines for high-risk systems and also other changes that will be introduced. The other key compliance deadlines that will apply under the AI Omnibus include:
- 2 December 2026:
- New prohibition on AI systems used to generate non-consensual intimate imagery and child sex abuse material
- Marking and detection obligation on providers of AI systems (re AI-generated content) will apply for AI systems placed on the EU market before 2 August 2026 (see further below re transparency obligations)
Transparency obligations on providers and deployers
On 2 August 2026, key obligations come into effect on providers and deployers of AI systems in relation to transparency requirements (pursuant to Article 50 EU AI Act), as set out below. Fines for breaches of the transparency obligations can be up to 15 million Euros or 3% of annual worldwide turnover.
Providers of AI systems (including those that have an AI system developed and placed on the EU market under their own name or trade mark)
- Interactive AI systems: providers of AI systems that interact directly with natural persons, such as chatbots, AI agents and avatars, must ensure that those persons are informed they are interacting with AI from the start of the first interaction in a clear and distinguishable manner, and complying with accessibility requirements.
There are four cumulative criteria that clarify when the obligation will apply:
- The system is an AI system
- It is designed for a genuine two-way exchange with people
- The interaction is direct (i.e., the AI itself communicates with the person, not through a human intermediary)
- The interaction is with natural persons, such as consumers and also professionals
The obligation will not apply when it is obvious to the person that they are interacting with an AI system (to be assessed by reference to an average person who is reasonably well-informed, circumspect, and observant).
- Marking and detection of AI-generated content: providers must ensure that outputs from their generative AI systems are marked with effective, reliable, robust and interoperable machine-readable marking to enable outputs to be detected as generated or manipulated by AI systems (subject to the limited extension until 2 December 2026 in respect of AI systems placed on the EU market before 2 August 2026).
There are certain exceptions in terms of the outputs in scope, standard editing functionality, and a narrow exception in relation to certain B2B contexts.
Deployers of AI systems
- Emotion recognition and biometric systems: deployers must inform people when they are exposed to emotion recognition and biometric systems.
- Labelling of deepfakes and AI-generated/manipulated text on matters of public interest: deployers must clearly label deepfakes upon first exposure by a natural person, and AI-generated or manipulated text on matters of public interest without human review or editorial content.
There are three cumulative criteria for assessing whether something is a 'deepfake':
- Resemblance: high level of similarity between the deepfake and the simulated subject
- Existing: simulated persons, objects, places, entities or events must resemble someone or something that exists, can plausibly exist or could have plausibly existed
- False appearance as authentic or truthful: capacity to potentially deceive or mislead a person regarding the authenticity or truthfulness of the content. On this point, deployers can take into account certain factors which may mean that the intended audience doe not expect the content to be authentic or truthful (e.g., background scenes, special effects etc).
Whilst content generated before 2 August 2026 does not need to be labelled retroactively, the Commission has encouraged relevant deployers to do so, where possible.
Where deepfakes form part of evidently artistic, creative, satirical, fictional or analogous works or programmes, the transparency obligation is limited to disclosing the deepfake content in an appropriate manner that doesn't hamper the display or enjoyment of the work.
Materials relating to transparency obligations
The following materials have been published to assist providers and deployers comply with their transparency obligations:
- Code of Practice on Transparency of AI-generated Content: the Code is a voluntary tool setting out practical steps for providers and deployers to demonstrate compliance with their obligations in relation to detection and marking, and labelling of AI-generated content. Signing the Code will assist providers and deployers to demonstrate compliance with their transparency obligations, and give them the benefit of a streamlined compliance pathway. If a provider or deployer does not sign the Code, however, they will need to demonstrate compliance with their transparency obligations through other means.
- Guidelines on Transparency Obligations for Providers and Deployers of Certain AI Systems: the Guidelines address the full scope of Article 50, including additionally: Article 50(1) (re interactive AI systems) and Article 50(3) (re emotion recognition and biometric categorisation systems). Providers and deployers subject to these obligations must look to the Guidelines, not the Code, for practical guidance.
Enforcement
Enforcement of the AI Act begins at national and EU-level in relation to general-purpose AI (GPAI) models, prohibitions, transparency rules and AI literacy.
New prohibitions against AI systems generating non-consensual sexual deepfakes and child sexual abuse material; and transitional deadline for certain transparency obligations
2 December 2026
Rules for high-risk AI systems in Annex III apply
2 December 2027
Rules for high-risk AI embedded in regulated products covered by Annex I apply
2 August 2028