Overview
Regulation (EU) 2024/1689, the AI Act, entered into force on August 1, 2024 and applies in stages. Prohibited practices and the AI literacy duty have applied since February 2, 2025. Rules for general-purpose AI (GPAI) models, governance, and penalties followed on August 2, 2025, and most other provisions, including the Article 50 transparency duties, from August 2, 2026. Some dates have since moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744 of July 8, 2026, is adopted law, in force since July 27, 2026. It moved the high-risk rules to December 2, 2027 for Annex III systems, such as those used in biometrics, employment, education, and migration, and to August 2, 2028 for AI in products covered by Annex I. It also recast Article 4 as a duty to take measures that support AI literacy, added prohibitions on AI-generated non-consensual intimate content from December 2, 2026, and gave providers of generative systems already on the market before August 2, 2026 until December 2, 2026 to meet the Article 50(2) marking duty. A separate Digital Omnibus proposal on data and privacy (COM(2025) 837) remains a proposal.
Reach is extraterritorial. Article 2 covers providers that place AI systems or GPAI models on the EU market, wherever they are established, and providers and deployers outside the EU when the system's output is used in the EU. A Canadian provider of a high-risk system must appoint an authorized representative in the EU by written mandate before making it available there (Article 22), and GPAI model providers have a similar duty (Article 54). Fines reach €35 million or 7% of worldwide annual turnover for prohibited practices.
Article 15 requires high-risk systems to achieve appropriate accuracy, robustness, and cybersecurity throughout their life cycle. Systems must resist attempts by unauthorized third parties to alter their use, outputs, or performance by exploiting vulnerabilities. Measures should address data poisoning, model poisoning, adversarial examples, confidentiality attacks, and model flaws. Most Annex III systems use internal control for conformity assessment. Some need outside review. Notified bodies take part for some biometric systems and for products that already need third-party assessment under EU product law, and their certificates last up to 4 or 5 years.
Who it applies to in Canada
Providers that place AI systems or general-purpose AI models on the EU market, deployers in the EU, and providers and deployers outside the EU whose AI output is used in the EU.
Canadian AI developers selling into the EU, or whose system output is used there, are covered wherever they are established. Non-EU providers of high-risk systems and general-purpose AI models must appoint an authorized representative in the EU.
Controls at a glance
The AI Act sorts AI by risk, with bans, high-risk requirements, transparency duties, and separate rules for general-purpose AI models.
Prohibited practices (Article 5)
- Manipulative or deceptive techniques causing significant harm
- Exploiting vulnerabilities linked to age, disability, or social situation
- Social scoring leading to unjustified detrimental treatment
- Predicting criminal risk based solely on profiling
- Untargeted scraping of facial images to build databases
- Emotion recognition in workplaces and schools, with narrow exceptions
- Biometric categorization to infer sensitive traits
- Real-time remote biometric identification by police, narrow exceptions
- AI-generated non-consensual intimate content, from December 2, 2026
AI literacy (Article 4, as amended)
- Providers and deployers take measures supporting staff AI literacy
- Covers others operating AI systems on their behalf
- Consider knowledge, experience, training, and context of use
- Commission and member states support these efforts
High-risk system requirements (Articles 9 to 15)
- Risk management system across the life cycle
- Data governance for training, validation, and testing data
- Technical documentation
- Automatic logging of events
- Transparency and instructions for deployers
- Human oversight measures
- Accuracy, robustness, and cybersecurity
Cybersecurity of high-risk AI (Article 15)
- Declare accuracy levels and metrics in instructions for use
- Resilience to errors, faults, and inconsistencies
- Technical redundancy, backup, or fail-safe plans
- Limit biased feedback loops in systems that keep learning
- Resist unauthorized attempts to alter use or performance
- Prevent and respond to data and model poisoning
- Counter adversarial examples and model evasion
- Address confidentiality attacks and model flaws
Provider obligations for high-risk AI
- Quality management system (Article 17)
- Conformity assessment before placing on the market (Article 43)
- EU declaration of conformity and CE marking
- Registration in the EU database (Article 49)
- Post-market monitoring (Article 72)
- Report serious incidents to authorities (Article 73)
- Non-EU providers appoint an EU authorized representative (Article 22)
Deployer obligations (Articles 26 and 27)
- Use systems according to instructions
- Assign competent people to human oversight
- Monitor operation and keep logs
- Inform workers before workplace use
- Fundamental rights impact assessment for public bodies and some others
Transparency (Article 50)
- Tell people when they interact with an AI system
- Mark synthetic audio, image, video, and text machine-readably
- Disclose deepfakes
- Inform people exposed to emotion recognition or biometric categorization
- Disclose AI-generated text published on matters of public interest
General-purpose AI models (Articles 53 to 55)
- Technical documentation for the AI Office and downstream providers
- Copyright compliance policy
- Public summary of training content
- Systemic-risk models undergo evaluation and adversarial testing
- Systemic-risk models report serious incidents
- Systemic-risk models need adequate cybersecurity protection
- Codes of practice can be used to show compliance
Certification and assessment
Providers of high-risk systems complete a conformity assessment, draw up an EU declaration of conformity, affix the CE marking, and register the system before placing it on the market. Where a notified body is involved, it reviews the quality management system and technical documentation and issues a certificate. GPAI providers show compliance to the AI Office, often through a code of practice.
Dates to know
- 2024-08-01
- AI Act enters into force
- 2025-02-02
- Prohibited practices and AI literacy provisions apply
- 2025-08-02
- GPAI model obligations, governance, and penalties apply
- 2025-11-19
- Commission proposes the Digital Omnibus on AI
- 2026-07-27
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) enters into force
- 2026-08-02
- Most remaining provisions apply, including Article 50 transparency duties
- 2026-12-02
- New prohibitions on non-consensual intimate content apply, and Article 50(2) marking deadline for generative systems already on the market
- 2027-12-02
- High-risk rules apply to Annex III systems
- 2028-08-02
- High-risk rules apply to AI systems in Annex I products
Resources
Official texts and free tools for EU AI Act. Links open the publisher’s site.
- Regulation (EU) 2024/1689 (AI Act), official text, EUR-Lex, Publications Office of the European Union
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union
- AI Act: regulatory framework for AI, European Commission
- European AI Office, European Commission
- AI Act Service Desk, European Commissionguidance
- General-Purpose AI Code of Practice, European Commissionguidance
Need help? Browse the directory or read the guides.
References
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex, Publications Office of the European Union
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union
- AI Act: regulatory framework for AI, European Commission
- Procedure file 2025/0360(COD), Digital Omnibus, European Parliament Legislative Observatory
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.