Regulation (EU) 2024/1689 sets harmonised rules for placing AI systems on the Union market and using them, together with a separate regime for general-purpose AI models. It entered into force on 1 August 2024 and was amended on 27 July 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which rescheduled several obligations and added others.
The Act regulates by risk and by role rather than by technology. Article 5 bans a defined set of practices outright. Article 6, read with Annexes I and III, identifies high-risk systems that carry the full compliance regime. Article 50 imposes transparency duties on certain systems regardless of risk class. Everything outside those categories is largely unregulated, which makes classification the decisive step rather than a formality.
Obligations attach to the role an organisation holds, and Article 3 defines six: provider, deployer, importer, distributor, authorised representative, and product manufacturer. The boundary is easier to cross than most organisations expect. Under Article 25, putting your own name or trademark on a high-risk system, modifying it substantially, or changing its intended purpose so that it becomes high-risk transfers the full set of provider obligations to you.
The penalty structure follows the same hierarchy. Breaching an Article 5 prohibition reaches EUR 35 million or 7% of total worldwide annual turnover, whichever is higher; other obligations reach EUR 15 million or 3%; supplying incorrect information reaches EUR 7.5 million or 1%. The Omnibus added capped tiers for smaller companies and room for non-monetary measures.