European Union formally adopts new AI Act regulating artificial intelligence

European Union formally adopts new AI Act regulating artificial intelligence
Technology · News Network
Share

European Union formally adopts new AI Act regulating artificial intelligence

Brussels – The European Union’s landmark Artificial Intelligence Act, first proposed in 2021, has now been fully adopted and is in force across all 27 member states, marking a watershed moment in global technology regulation. With the completion of a first package of amendments in early July 2026—the so-called “Digital Omnibus” package—the EU has reset key compliance dates and clarified implementation rules ahead of the Act’s main application phase, which begins in August 2026.

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, following publication in the Official Journal on 12 July 2024. But it is only now, two years later, that the regulatory framework is taking its definitive shape, with the core obligations for developers and deployers of artificial intelligence systems about to take effect. The legislation is being rolled out in stages, with most rules for businesses and public bodies starting to bite between 2025 and 2028.

For technology firms, employers, public authorities and product manufacturers across Europe and beyond, the message is clear: the era of voluntary AI governance is over. The EU is now enforcing binding rules that classify AI systems by risk, impose transparency requirements, and ban certain unacceptable uses outright.

What is happening now: mid‑2026 status

The AI Act is already law in all 27 EU member states. Several key application dates have already passed, and the regulatory machinery is fully operational.

On 2 February 2025, the general provisions—including definitions and requirements for AI literacy—and the prohibitions on “unacceptable risk” AI practices became applicable. These banned practices include certain forms of social scoring by governments, manipulative or exploitative uses of AI, and real-time remote biometric identification in public spaces for law enforcement (subject to limited exceptions). These prohibitions are already enforceable, and national authorities have been empowered to investigate and sanction violations.

On 2 August 2025, rules for general-purpose AI (GPAI) models—including foundation models like large language models—entered into application. Member states were required to designate national competent authorities and adopt national penalty regimes. At the EU level, governance structures were established: an AI Board composed of member state representatives, a Scientific Panel of independent experts, and an Advisory Forum for stakeholder input.

As of mid-2026, the EU and member states are in a sprint toward 2 August 2026, when the majority of rules come into force and enforcement begins. This includes transparency rules under Article 50, covering chatbots, deepfakes and AI-generated content. Measures in support of innovation, including regulatory sandboxes, also begin to apply on that date. Each member state must have at least one AI regulatory sandbox in place by then.

Recent change: deadlines for high‑risk AI systems pushed back

In a significant development, the EU has agreed and adopted a “Digital Omnibus” amendments package that delays key obligations for high-risk AI systems.

On 16 June 2026, the European Parliament granted final approval to the amendments. On 2 July 2026, the Council of the European Union gave its final approval, closing what one commentary described as a “legislative scramble” following a collapsed trilogue in late April.

The result is a staggered timeline:

  • Standalone high‑risk AI systems in areas listed in Annex III of the Act—such as education, employment, critical infrastructure, credit scoring, law enforcement, migration and border control—will now apply from 2 December 2027 instead of 2 August 2026.
  • High‑risk AI systems embedded in regulated products covered by Annex I—such as medical devices, toys, radio equipment, and other product-safety regimes—will apply from 2 August 2028 instead of 2 August 2027.
  • This means that while the AI Act is formally adopted and in force, the most onerous obligations for high-risk AI systems have been staggered and delayed, reshaping compliance strategies for technology firms and product manufacturers.

    Why this matters

    The EU AI Act is widely regarded as the world’s first comprehensive legal framework for artificial intelligence. It follows a risk-based approach: AI systems are classified into four categories—minimal risk, limited risk, high risk, and unacceptable risk—with corresponding obligations.

    The Act applies not only to developers and deployers within the EU but also to providers and users outside the bloc whose AI systems affect people in the EU, giving it significant extraterritorial reach. As such, it sets a global benchmark, similar to the role the General Data Protection Regulation (GDPR) played for data privacy.

    The delay for high-risk AI systems is particularly notable. It reflects intense lobbying by industry groups and some member states who argued that the original deadlines were unrealistic given the complexity of compliance. Critics have warned that rushed implementation could stifle innovation and place European businesses at a competitive disadvantage against US and Chinese rivals.

    At the same time, consumer protection and digital rights groups have expressed concern that the delays weaken protections at a time when AI applications are proliferating rapidly in hiring, lending, policing, and other sensitive areas.

    Background and context

    The AI Act was first proposed by the European Commission in April 2021 as part of its digital strategy. The legislative process involved intense negotiations between the European Parliament, the Council of the EU, and the Commission, culminating in a political agreement in December 2023 and final adoption in March 2024.

    The Act’s phased implementation was always intended to give businesses and regulators time to adapt. However, the rapid advancement of generative AI—particularly after the launch of ChatGPT in late 2022—prompted calls for faster action on transparency and risk management. The EU responded by tightening rules on general-purpose AI models in the final text, introducing obligations for foundation model providers to assess and mitigate systemic risks.

    The Digital Omnibus package was introduced to address practical concerns about the original compliance calendar. Industry associations representing sectors from banking to healthcare argued that the high-risk AI rules would require extensive retooling of existing systems and that more time was needed to align with other regulatory frameworks, such as the EU’s Medical Device Regulation and the proposed AI Liability Directive.

    Different perspectives

    Industry viewpoint

    Technology companies and business associations have broadly welcomed the delay for high-risk AI systems, arguing that it allows for a more orderly transition. “The additional time will enable businesses to develop robust compliance frameworks and avoid a last-minute scramble that could harm innovation,” said a spokesperson for the industry group DigitalEurope.

    However, some smaller firms have warned that compliance costs remain a burden regardless of the timeline. The requirement to conduct conformity assessments, maintain technical documentation, and implement human oversight mechanisms is costly, particularly for startups and SMEs.

    Consumer and civil society concerns

    Digital rights groups, including Access Now and the European Consumer Organisation (BEUC), have voiced disappointment at the delay. “The EU has kicked the can down the road on protecting fundamental rights from high-risk AI systems,” said a senior policy adviser at Access Now. “Meanwhile, algorithms are already making decisions about people’s jobs, loans, and access to services without adequate safeguards.”

    These groups argue that the prohibited practices—which are already enforceable—do not go far enough and that the high-risk rules should have taken effect on schedule.

    National regulators

    Member states have been busy designating competent authorities and setting up national enforcement structures. Countries like Germany, France, and Spain have already launched AI oversight bodies. However, coordination remains a challenge. The AI Board is expected to issue guidance on harmonised enforcement, but questions remain about how consistently rules will be applied across the 27 member states.

    Academic and expert views

    Legal scholars and AI ethicists have noted that the Act’s risk-based classification system, while innovative, leaves significant discretion to developers in self-assessing whether their systems are high-risk. The delayed compliance dates give the European Commission time to issue further guidance and delegated acts, but critics argue that the framework remains too reliant on industry self-regulation.

    Impact and implications

    For businesses

    Companies that develop or deploy AI systems in the EU must take immediate steps to comply with the rules that are already in force. The prohibitions on unacceptable risk AI practices are effective now, and violations can lead to significant fines—up to €35 million or 7% of annual global turnover, whichever is higher.

    For GPAI model providers, obligations that took effect in August 2025 include transparency requirements, copyright compliance, and risk management for systemic risks. Open-source models are subject to a somewhat lighter regime, but still must adhere to transparency rules.

    Businesses deploying AI systems in high-risk categories listed in Annex III now have until December 2027 to achieve full compliance. This applies to sectors such as:

  • Employment (AI used for recruitment, performance evaluation, promotion decisions)
  • Education (AI used for student admissions, grading, or monitoring)
  • Credit scoring and insurance pricing
  • Access to essential services (public benefits, healthcare)
  • Law enforcement (predictive policing, risk assessment for reoffending)
  • Migration and border control (AI for document verification, risk assessment)
  • For products where AI is embedded in regulated items like medical devices or toys, the deadline is August 2028. Manufacturers must ensure their AI systems meet the Act’s requirements alongside existing sector-specific regulations.

    For public authorities

    Governments across the EU are preparing to use AI in public services while ensuring compliance. Several member states have launched pilot projects in regulatory sandboxes—controlled environments where innovative AI systems can be tested under regulatory supervision. Each member state must have at least one such sandbox operational by August 2026.

    Public bodies are also required to ensure AI literacy among staff who work with AI systems, as mandated by the general provisions that took effect in February 2025.

    For global technology companies

    The EU AI Act has extraterritorial effect: any company that places AI systems on the EU market or whose AI outputs are used in the EU must comply, regardless of where the company is headquartered. This includes major US firms like Google, Meta, Microsoft, and OpenAI, as well as Chinese companies like Baidu and Tencent.

    These companies have been preparing for the Act for years, but the delayed timelines for high-risk AI offer some breathing room. However, they must already comply with the prohibitions on unacceptable risk practices and the transparency rules for general-purpose AI.

    For international regulatory convergence

    The EU’s approach is being closely watched by other jurisdictions. Canada, Brazil, Japan, and South Korea are developing their own AI laws, while the United States has taken a more sectoral approach with executive orders and voluntary commitments. The UK has favoured a principles-based framework rather than binding legislation.

    The EU hopes that its Act will become a global standard, much like the GDPR became a benchmark for data protection. However, the delay in high-risk rules may be seen by some as a sign of the difficulties in regulating a rapidly evolving technology.

    What happens next

    Immediate steps

  • 2 August 2026: The majority of AI Act rules come into force and enforcement begins. This includes transparency obligations for chatbots and deepfakes, the requirement for regulatory sandboxes in each member state, and the full activation of the AI Board and Scientific Panel.
  • Autumn 2026: The European Commission is expected to issue additional delegated acts and guidance documents, particularly on the classification of high-risk AI systems and the implementation of conformity assessments.
  • Ongoing: National authorities will begin active enforcement. The first fines for violations of the prohibitions could emerge within months.
  • Medium-term milestones

  • 2 December 2027: Obligations for standalone high-risk AI systems (Annex III) become enforceable. This is likely to be the most significant compliance deadline for most businesses.
  • 2 August 2028: Obligations for high-risk AI systems in regulated products (Annex I) become enforceable. This aligns with the EU’s existing product safety regimes.
  • 2028–2030: The European Commission is required to review the AI Act periodically and propose updates. The rapid evolution of generative AI and the emergence of new risks will likely prompt further amendments.
  • Challenges ahead

  • Enforcement capacity: National authorities vary widely in resources and expertise. The AI Board will need to ensure consistent enforcement across the single market to avoid a patchwork of national interpretations.
  • International coordination: The EU is pushing for alignment with other major economies, but divergent approaches could create compliance burdens for global companies.
  • Technological change: The Act was drafted before the generative AI boom. While general-purpose AI rules were added late in the process, some experts argue that the framework is already outdated.
  • Legal challenges: Court challenges to the Act’s provisions, particularly from tech companies arguing that the rules are overly restrictive or vague, are expected in the coming years.
  • The broader picture

    The EU AI Act represents a bold experiment in democratic governance of transformative technology. Whether it succeeds will depend on the ability of regulators to enforce rules without stifling innovation, the willingness of companies to comply in good faith, and the capacity of the framework to adapt to rapid technological change.

    As the August 2026 deadline approaches, the message from Brussels is clear: the rules are in place, the clock is ticking, and compliance is not optional. For the global AI industry, the European Union has become the world’s first digital regulator with teeth.

    Further Reading

    ← Back to News