home / frameworks / eu-ai-act

// Foreign laws with Canadian reach

EU Artificial Intelligence Act, Regulation (EU) 2024/1689

The EU's risk-based law on artificial intelligence, applying in stages since February 2, 2025. It bans some practices, regulates high-risk systems and general-purpose AI models, and reaches Canadian providers whose AI is used in the EU.

European Union

Overview

Regulation (EU) 2024/1689, the AI Act, entered into force on August 1, 2024 and applies in stages. Prohibited practices and the AI literacy duty have applied since February 2, 2025. Rules for general-purpose AI (GPAI) models, governance, and penalties followed on August 2, 2025, and most other provisions, including the Article 50 transparency duties, from August 2, 2026. Some dates have since moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744 of July 8, 2026, is adopted law, in force since July 27, 2026. It moved the high-risk rules to December 2, 2027 for Annex III systems, such as those used in biometrics, employment, education, and migration, and to August 2, 2028 for AI in products covered by Annex I. It also recast Article 4 as a duty to take measures that support AI literacy, added prohibitions on AI-generated non-consensual intimate content from December 2, 2026, and gave providers of generative systems already on the market before August 2, 2026 until December 2, 2026 to meet the Article 50(2) marking duty. A separate Digital Omnibus proposal on data and privacy (COM(2025) 837) remains a proposal.

Reach is extraterritorial. Article 2 covers providers that place AI systems or GPAI models on the EU market, wherever they are established, and providers and deployers outside the EU when the system's output is used in the EU. A Canadian provider of a high-risk system must appoint an authorized representative in the EU by written mandate before making it available there (Article 22), and GPAI model providers have a similar duty (Article 54). Fines reach €35 million or 7% of worldwide annual turnover for prohibited practices.

Article 15 requires high-risk systems to achieve appropriate accuracy, robustness, and cybersecurity throughout their life cycle. Systems must resist attempts by unauthorized third parties to alter their use, outputs, or performance by exploiting vulnerabilities. Measures should address data poisoning, model poisoning, adversarial examples, confidentiality attacks, and model flaws. Most Annex III systems use internal control for conformity assessment. Some need outside review. Notified bodies take part for some biometric systems and for products that already need third-party assessment under EU product law, and their certificates last up to 4 or 5 years.

Who it applies to in Canada

Providers that place AI systems or general-purpose AI models on the EU market, deployers in the EU, and providers and deployers outside the EU whose AI output is used in the EU.

Canadian AI developers selling into the EU, or whose system output is used there, are covered wherever they are established. Non-EU providers of high-risk systems and general-purpose AI models must appoint an authorized representative in the EU.

Controls at a glance

The AI Act sorts AI by risk, with bans, high-risk requirements, transparency duties, and separate rules for general-purpose AI models.

Prohibited practices (Article 5)

  • Manipulative or deceptive techniques causing significant harm
  • Exploiting vulnerabilities linked to age, disability, or social situation
  • Social scoring leading to unjustified detrimental treatment
  • Predicting criminal risk based solely on profiling
  • Untargeted scraping of facial images to build databases
  • Emotion recognition in workplaces and schools, with narrow exceptions
  • Biometric categorization to infer sensitive traits
  • Real-time remote biometric identification by police, narrow exceptions
  • AI-generated non-consensual intimate content, from December 2, 2026

AI literacy (Article 4, as amended)

  • Providers and deployers take measures supporting staff AI literacy
  • Covers others operating AI systems on their behalf
  • Consider knowledge, experience, training, and context of use
  • Commission and member states support these efforts

High-risk system requirements (Articles 9 to 15)

  • Risk management system across the life cycle
  • Data governance for training, validation, and testing data
  • Technical documentation
  • Automatic logging of events
  • Transparency and instructions for deployers
  • Human oversight measures
  • Accuracy, robustness, and cybersecurity

Cybersecurity of high-risk AI (Article 15)

  • Declare accuracy levels and metrics in instructions for use
  • Resilience to errors, faults, and inconsistencies
  • Technical redundancy, backup, or fail-safe plans
  • Limit biased feedback loops in systems that keep learning
  • Resist unauthorized attempts to alter use or performance
  • Prevent and respond to data and model poisoning
  • Counter adversarial examples and model evasion
  • Address confidentiality attacks and model flaws

Provider obligations for high-risk AI

  • Quality management system (Article 17)
  • Conformity assessment before placing on the market (Article 43)
  • EU declaration of conformity and CE marking
  • Registration in the EU database (Article 49)
  • Post-market monitoring (Article 72)
  • Report serious incidents to authorities (Article 73)
  • Non-EU providers appoint an EU authorized representative (Article 22)

Deployer obligations (Articles 26 and 27)

  • Use systems according to instructions
  • Assign competent people to human oversight
  • Monitor operation and keep logs
  • Inform workers before workplace use
  • Fundamental rights impact assessment for public bodies and some others

Transparency (Article 50)

  • Tell people when they interact with an AI system
  • Mark synthetic audio, image, video, and text machine-readably
  • Disclose deepfakes
  • Inform people exposed to emotion recognition or biometric categorization
  • Disclose AI-generated text published on matters of public interest

General-purpose AI models (Articles 53 to 55)

  • Technical documentation for the AI Office and downstream providers
  • Copyright compliance policy
  • Public summary of training content
  • Systemic-risk models undergo evaluation and adversarial testing
  • Systemic-risk models report serious incidents
  • Systemic-risk models need adequate cybersecurity protection
  • Codes of practice can be used to show compliance

Certification and assessment

Providers of high-risk systems complete a conformity assessment, draw up an EU declaration of conformity, affix the CE marking, and register the system before placing it on the market. Where a notified body is involved, it reviews the quality management system and technical documentation and issues a certificate. GPAI providers show compliance to the AI Office, often through a code of practice.

Dates to know

2024-08-01
AI Act enters into force
2025-02-02
Prohibited practices and AI literacy provisions apply
2025-08-02
GPAI model obligations, governance, and penalties apply
2025-11-19
Commission proposes the Digital Omnibus on AI
2026-07-27
Regulation (EU) 2026/1744 (Digital Omnibus on AI) enters into force
2026-08-02
Most remaining provisions apply, including Article 50 transparency duties
2026-12-02
New prohibitions on non-consensual intimate content apply, and Article 50(2) marking deadline for generative systems already on the market
2027-12-02
High-risk rules apply to Annex III systems
2028-08-02
High-risk rules apply to AI systems in Annex I products

Resources

Official texts and free tools for EU AI Act. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex, Publications Office of the European Union
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union
  3. AI Act: regulatory framework for AI, European Commission
  4. Procedure file 2025/0360(COD), Digital Omnibus, European Parliament Legislative Observatory