Skip to content
recaplica

    One moment: security check

    Cloudflare wants to make sure you're not a robot. Tick the box below and your search will continue on its own.

    IT
    recaplica The EU AI Act: how Europe's artificial intelligence law works
    © 2026 Recaplica · recaplica.com — All rights reserved
    Home › Technology

    The EU AI Act: how Europe's artificial intelligence law works

    By Recaplica Newsroom · Updated on September 5, 2026

    What to print

    Page numbers appear when printing with default margins.

    Slides

    Choose a cut

    Flash10 slidesThe essential thread, to present in classFull17 slidesEvery chapter and the deeper detail

    Both come with speaker notes.

    Telegram channel
    recaplica Clear in 30 seconds, yours in 10 minutes.
    In 30 seconds Key points Figures Deep dive Slides Myths Mind map Quiz Flashcards FAQ

    In 30 seconds quick read

    The AI Act is Regulation (EU) 2024/1689, the law with which the European Union governs artificial intelligence: approved by the European Parliament and the Council on 13 June 2024, it entered into force on 1 August 2024. It sorts AI systems into four risk tiers — unacceptable, high, limited, minimal — and bans the most dangerous practices, such as government social scoring. The most serious violations can cost up to 35 million euros or 7% of a company's worldwide turnover, whichever is higher. The rules phase in on a staggered schedule spread over several years, already amended once in 2026 to push back some deadlines for high-risk systems.

    Key Points

    • Official name: Regulation (EU) 2024/1689, approved on 13 June 2024, published on 12 July 2024, in force since 1 August 2024.
    • Four risk tiers: unacceptable (banned), high (strict requirements), limited (transparency duties), minimal (unrestricted use).
    • General-purpose AI (GPAI) models must guarantee transparency about their training data and comply with copyright law from 2 August 2025.
    • Fines of up to 35 million euros or 7% of worldwide turnover for banned practices; for SMEs, including start-ups, the lower amount always applies.
    • The "Digital Omnibus on AI", in force since 27 July 2026, pushed some high-risk system deadlines back to 2 December 2027 and 2 August 2028.
    • It also applies to providers based outside the EU whenever their system or its output reaches the European market.

    Key figures

    • 35 million euros the maximum fine for violating the bans on unacceptable-risk practices, or 7% of the company's annual worldwide turnover if that figure is higher Source: Regulation (EU) 2024/1689, Article 99
    • 2 August 2026 the date the regulation starts applying generally, under the staggered schedule set out in Article 113 Source: Regulation (EU) 2024/1689, Article 113
    • 10^25 FLOPs the training-compute threshold above which a GPAI model is classified as carrying "systemic risk" and faces extra obligations Source: Regulation (EU) 2024/1689

    Deep Dive

    A law meant to steer AI, not stop it

    The AI Act is the name everyone uses for Regulation (EU) 2024/1689, approved by the European Parliament and the Council on 13 June 2024 and published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, but, as often happens with EU rules of this scale, it didn’t switch on all at once: the underlying logic is that risk, not the technology itself, decides how many obligations apply to an AI system.

    The idea is to tell apart a chatbot that suggests recipes from a system that decides who gets hired or who qualifies for a mortgage: the first carries no obligations, the second must meet safety requirements and human oversight before it can reach the market.

    Four risk tiers

    The regulation sorts AI systems into four categories, with obligations that grow heavier as the risk to people’s safety, rights or livelihood increases.

    Risk tierExamplesWhat it means
    UnacceptableGovernment social scoring, subliminal manipulationBanned
    HighSystems in critical infrastructure, law enforcementStrict requirements (risk management, documentation, human oversight)
    LimitedChatbots, AI-generated or altered contentTransparency duties toward the user
    MinimalVideo games, spam filtersNo specific obligations

    The unacceptable-risk practices are listed one by one in Article 5: manipulative techniques that distort behavior and undermine informed choices, exploitation of vulnerabilities tied to age or disability, unauthorized biometric categorization based on sensitive traits, criminal risk assessment based solely on profiling a person, indiscriminate scraping of photos from the web or CCTV footage to build facial recognition databases, emotion inference in schools and workplaces (except for medical or safety reasons), and “real-time” biometric identification in public spaces for law enforcement purposes, narrowly limited to missing persons or serious threats. As of 2 December 2026, a ban on generating non-consensual intimate images and child sexual abuse material was added to this list.

    High-risk systems aren’t banned, but they are closely watched: they need a risk management system running through their whole life cycle, training data checked for quality and representativeness, technical documentation, logging capabilities, a human oversight mechanism, and a conformity marking before reaching the market. It’s the same principle that has long governed medical devices or toys: before you sell it, you prove the product is safe.

    Practical example: software that screens job applications is high-risk: it must show that the data it was trained on doesn’t systematically discriminate against a group of candidates, and a human must be able to review its decisions. A filter that just sorts emails by date, on the other hand, is minimal-risk: no obligations, no oversight.

    General-purpose AI (GPAI) models

    A separate part of the regulation deals with general-purpose AI models (GPAI): the large models capable of writing text, generating images or answering questions on almost any topic, the same family of systems behind generative AI. From 2 August 2025, whoever provides them must prepare technical documentation, share information with downstream providers, comply with copyright obligations and publish a sufficiently detailed summary of the content used for training. Open-source or free models are exempt from most of these duties, unless they cross a precise line: above 10^25 FLOPs of training compute, a model is classified as carrying “systemic risk”, and its providers are also asked to run adversarial testing, assess systemic risks and report serious incidents to the AI Office.

    Behind any of these models, generative or not, sits the same underlying method: learning from enormous amounts of data instead of following hand-written rules, as covered in the article on machine learning, often built with many-layered neural networks.

    The fines: up to 7% of worldwide turnover

    Article 99 sets three tiers of fines, scaled to the severity of the violation. For banned unacceptable-risk practices, fines reach 35 million euros or 7% of the company’s annual worldwide turnover, whichever is higher. For other obligations in the regulation, such as the requirements for high-risk systems, the cap drops to 15 million euros or 3% of turnover. For incomplete, incorrect or misleading information supplied to authorities, it goes up to 7.5 million euros or 1% of turnover. There’s a clause built to avoid crushing smaller businesses, though: for SMEs, including start-ups, the lower amount between percentage and fixed figure always applies, while large companies face the reverse rule and always pay the higher amount.

    A staggered timeline, already amended once

    The regulation doesn’t switch on all at once: Article 113 sets out a phased application, with obligations that grow tougher as each reference date passes.

    DateWhat applies
    2 February 2025General provisions and bans on prohibited practices
    2 August 2025Governance, GPAI model obligations, penalty framework
    27 July 2026Amendments to other EU harmonization rules
    2 August 2026General application of the regulation
    2 December 2026Ban on non-consensual intimate deepfakes; end of the grace period for transparency on AI-generated content
    2 December 2027Obligations for “stand-alone” high-risk systems
    2 August 2028Obligations for high-risk systems embedded in already-regulated products

    The last two dates weren’t the original ones: in July 2026 the Digital Omnibus on AI arrived (Regulation (EU) 2026/1744, approved on 8 July 2026 and in force since 27 July 2026), pushing the obligations for “stand-alone” high-risk systems from 2 August 2026 to 2 December 2027, and those for high-risk systems embedded in products already covered by safety rules (such as machinery or aircraft equipment) from 2 August 2027 to 2 August 2028. The text explicitly states it isn’t introducing a new legal regime, but simplifying the implementation of the existing one and cutting administrative burden.

    Who oversees it, and who the obligations fall on

    From 2 August 2025, the European Commission’s AI Office oversees providers of GPAI models, with powers to request documentation, assess systems and order corrections; the power to fine GPAI providers (Article 101) only applies from 2 August 2026, alongside the regulation’s general application. An AI Board, a Scientific Panel of independent experts and a technical Advisory Forum provide guidance and advice. Day-to-day market surveillance, that is, checking that a product sold in a single member state meets the requirements, stays with national authorities.

    The regulation distinguishes two roles: providers, who develop or commission the development of a system to place it on the market, and deployers, meaning whoever uses it professionally (companies, public administrations, other organizations). Its scope doesn’t stop at the Union’s borders: it also applies to providers from third countries, whenever they place a high-risk system on the EU market or its output is used within the Union anyway: an extraterritorial principle that follows the same logic as other EU digital rules, and one that intersects with the broader rules governing any algorithm tasked with making decisions on sensitive data.

    Slide deck

    Slides ready to download and make your own in PowerPoint or Google Slides, with speaker notes. Pick the Flash cut or the Full one.

    Slide 1 of the presentation on The EU AI Act: The EU AI ActSlide 2 of the presentation on The EU AI Act: Who decides how many obligations an AI system faces?Slide 3 of the presentation on The EU AI Act: What we will coverSlide 4 of the presentation on The EU AI Act: Chapter 01: A law that measures riskSlide 5 of the presentation on The EU AI Act: Where the obligations grow: Unacceptable, High, LimitedSlide 6 of the presentation on The EU AI Act: High risk against minimal riskSlide 7 of the presentation on The EU AI Act: Chapter 02: General-purpose AI modelsSlide 8 of the presentation on The EU AI Act: What GPAI providers must doSlide 9 of the presentation on The EU AI Act: What changes above the threshold?Slide 10 of the presentation on The EU AI Act: Chapter 03: Fines and timelineSlide 11 of the presentation on The EU AI Act: Banned practices · High risk · InformationSlide 12 of the presentation on The EU AI Act: A staggered timeline, already amended onceSlide 13 of the presentation on The EU AI Act: Chapter 04: Who oversees, and who compliesSlide 14 of the presentation on The EU AI Act: The watchdogs: AI Office, AI Board, Member statesSlide 15 of the presentation on The EU AI Act: Where the company sits does not matter.Slide 16 of the presentation on The EU AI Act: When does the regulation start applying generally?Slide 17 of the presentation on The EU AI Act: And now, the review
    Flash10 slidesThe essential thread, to present in classFull17 slidesEvery chapter and the deeper detail

    Common myths

    • ✗ Myth The AI Act bans artificial intelligence.

      ✓ Reality It only bans a handful of specific practices classified as unacceptable risk, like government social scoring or subliminal manipulation of people. Most AI systems — spam filters, video games, everyday voice assistants — remain minimal risk and free of obligations; even high-risk systems aren't banned, they simply have to meet strict requirements.

    • ✗ Myth The regulation only concerns companies based in Europe.

      ✓ Reality It also applies to providers from third countries, whenever they place a high-risk AI system on the EU market or whenever the system's output is used within the Union anyway. What matters is where the AI affects people, not where the company that built it is headquartered.

    • ✗ Myth The regulation's deadlines have been fixed since 2024 and never change.

      ✓ Reality The Digital Omnibus on AI, in force since 27 July 2026, already pushed the high-risk system obligations back to 2 December 2027 and 2 August 2028: the amending regulation states it isn't introducing a new legal regime, but cutting administrative burden and simplifying the implementation of the existing rules.

    Mind map

    Drag the background to move around and the nodes to reposition them; use − and + to collapse and expand branches.

    Customize
    Mind map: The EU AI Act: how Europe's artificial intelligence law works
    • The AI Act
      • The regulation
        • Approved on 13 June 2024 European Parliament and Council.
        • In force since 1 August 2024
      • The four risk tiers
        • Unacceptable risk Banned practices, such as social scoring.
        • High risk Strict requirements, not a ban.
        • Limited risk Transparency duties, as for chatbots.
        • Minimal risk Unrestricted use, as for spam filters.
      • GPAI models
        • Transparency about training data
        • Systemic risk threshold Above 10^25 FLOPs of training compute.
      • The fines
        • Up to 7% of worldwide turnover For unacceptable-risk practices.
        • The SME clause Small businesses get the lower amount.
      • The timeline
        • 2 February 2025 Bans on prohibited practices.
        • 2 August 2025 Governance and GPAI obligations.
        • 2 December 2027 and 2 August 2028 High-risk obligations, pushed back by the Digital Omnibus.
      • Who oversees it
        • European Commission's AI Office
        • National authorities Market surveillance in member states.

    Quiz: test yourself

    Answer the questions to check what you have learned: you get instant feedback and a short explanation.

    Grade 0/10 0/5
    1 What does the AI Act ban under "unacceptable risk"?

    Article 5 lists specific practices treated as unacceptable — from social scoring to subliminal manipulation, from unauthorized biometric categorization to the indiscriminate scraping of photos for facial recognition. Everything else isn't banned: it's regulated according to the risk it carries.

    2 When does the regulation start applying generally?

    The AI Act entered into force on 1 August 2024, but its general application only starts on 2 August 2026: in between sits a staggered timeline, with the bans already effective from 2 February 2025 and the high-risk obligations pushed even further out.

    3 What is the maximum fine for violating the bans on unacceptable-risk practices?

    It's the highest penalty in the regulation, reserved for the most serious violations (Article 5). Less critical obligations, like those for high-risk systems, carry lower caps of 15 million euros or 3% of turnover.

    4 True or false: for small and medium enterprises, including start-ups, AI Act fines are always calculated using the lower amount between the percentage and the fixed figure.

    It's a clause built specifically to avoid crushing smaller businesses: large companies face the higher amount between percentage and fixed figure, while SMEs get the opposite — always the lower one.

    5 What did the "Digital Omnibus on AI", approved in July 2026, change?

    The amending regulation explicitly states it doesn't introduce a new legal regime: it moves the high-risk deadlines forward (to 2 December 2027 and 2 August 2028) to give businesses more time, and adds a new ban on non-consensual intimate deepfakes.

    Answers: 1-A · 2-A · 3-A · 4-A · 5-A

    Flashcards

    Tap the card to flip it and check whether you remember the answer, then move to the next one.

    1 / 8

    Explain it in your own words

    The ultimate test: if you can explain it in simple words, you've truly understood it. Write your explanation, then compare it with the Recap.

    Your explanation is saved only on this device.

    The AI Act is Regulation (EU) 2024/1689, the law with which the European Union governs artificial intelligence: approved by the European Parliament and the Council on 13 June 2024, it entered into force on 1 August 2024. It sorts AI systems into four risk tiers — unacceptable, high, limited, minimal — and bans the most dangerous practices, such as government social scoring. The most serious violations can cost up to 35 million euros or 7% of a company's worldwide turnover, whichever is higher. The rules phase in on a staggered schedule spread over several years, already amended once in 2026 to push back some deadlines for high-risk systems.

    Frequently asked questions

    What is the EU AI Act, in short?

    It's Regulation (EU) 2024/1689, the law with which the European Union governs artificial intelligence according to the risk its uses carry: some practices are banned, the most sensitive systems must meet strict requirements, others only carry transparency duties, and the most harmless ones remain unrestricted.

    When does the AI Act apply from?

    Not from a single date: the bans on unacceptable-risk practices have applied since 2 February 2025, the governance and GPAI-model obligations since 2 August 2025, general application starts on 2 August 2026, while the high-risk system obligations arrive in 2027 and 2028 after being pushed back by the Digital Omnibus on AI.

    What can a company be fined for violating the AI Act?

    Administrative fines of up to 35 million euros or 7% of annual worldwide turnover for the most serious violations (banned practices), up to 15 million euros or 3% for other obligations, up to 7.5 million euros or 1% for supplying incorrect information to authorities: the higher amount always applies, except for SMEs.

    Does the AI Act apply to companies without a base in the EU?

    Yes: it applies to providers from third countries whenever they place high-risk AI systems on the European market, or whenever their system's output is used within the Union, regardless of where the company is established.

    Who checks that companies comply with the AI Act?

    The European Commission's AI Office oversees general-purpose AI models from 2 August 2025, with powers to request documentation, run assessments and order corrections; the power to fine GPAI providers (Article 101) only applies from 2 August 2026. National authorities in each member state handle market surveillance within their own territory.

    Sources

    • EUR-Lex — Regulation (EU) 2024/1689 (consolidated text)
    • European Commission — Shaping Europe's digital future, "AI Act"
    • EU Artificial Intelligence Act — high-level summary
    • EUR-Lex — Regulation (EU) 2026/1744, "Digital Omnibus on AI"

    Every Recap goes through an independent review before publication.

    Every evening, the day's new Recaps on our Telegram channel. Join the channel →

    Keep learning

    • Technology AI Pop Culture: When Synthetic Content Rewrites History According to Lead Stories, a World War Two photo held by the Imperial War Museums circulated in 2026 in an AI-colorized version that a detector rated 99% likely to be artificially generated, even though the original shot was genuine. Cases like this also touch pop culture and current events: text, image and video models produce content that looks historical or iconic without actually being so, or alter real content in details that are hard to spot at a glance. Some tools leave technical clues, such as digital watermarks or video length limits, but no single clue covers every generator on the market. The Reuters Institute reports that in 2026 trust in AI chatbot answers about the news stays low, at 20% against 37% for news overall. Checking whether an image or video is authentic still means comparing it against the original archive that holds it. Read the Recap →
    • Technology Echo Chamber: How Recommendation Algorithms Shape What You See An echo chamber is an environment, online or offline, where a person mostly encounters opinions that confirm their own. Recommendation algorithms can build a narrower version of this, often called a filter bubble, by quietly deciding what to show someone based on what they've clicked and watched before. The two ideas get mixed up constantly, but they aren't the same phenomenon, and the strongest research available paints a more mixed picture than the popular narrative: algorithms have a measurable but modest effect, and people's own choices matter more. Whether algorithms actually drive political polarization is not something the most rigorous experiments have settled. Read the Recap →
    • Technology Virtual influencers: the AI-made creators behind the profiles Virtual influencers are digital characters built by an agency or studio, complete with a face, a voice and a biography, who post on social media the way a real creator would. The phenomenon predates the generative-AI boom: Lil Miquela's account has been live since April 23, 2016, and Shudu Gram first appeared on April 22, 2017. Some of these profiles work with major brands: Miquela has partnered with Calvin Klein and Prada, while the Spanish agency The Clueless built Aitana López after finding human models and influencers too unreliable to manage. In the United States, the Federal Trade Commission updated its advertising rules in 2023 to explicitly cover virtual influencers among the content that must be disclosed as sponsored. Read the Recap →

    recaplica

    Clear in 30 seconds, yours in 10 minutes.

    Recaps Mind maps Request a Recap Telegram channel Mind map maker Our method About Privacy & cookies Legal notes & terms of use

    © 2026 Recaplica · A project by Curi S.r.l. — VAT IT05472000750

    Statistics, only if you say so

    To learn which Recaps help most we would use Google Analytics, with aggregate, anonymous data. It starts only with your OK, and you can change your mind anytime. Privacy policy