AI Regulation in the European Union.
The EU has an AI-specific law, the AI Act, which is directly binding but takes effect in stages: bans on certain AI practices and AI-literacy duties started on February 2, 2025, general-purpose AI duties on August 2, 2025, and most transparency rules on August 2, 2026. The 2026 Digital Omnibus delayed most high-risk AI requirements to December 2, 2027 for Annex III systems and August 2, 2028 for AI built into regulated products, while the GDPR, Digital Services Act, consumer-protection laws, and NIS2 cybersecurity rules continue to apply.
In force today5 instruments
Get the remaining 3 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.
Already subscribed? Unlock →
- AI Act high-risk rules now apply from December 2, 2027 for Annex III systems and August 2, 2028 for AI embedded in regulated products under Regulation (EU) 2026/1744.
- The Product Liability Directive, Directive (EU) 2024/2853, is adopted and expected to apply from December 9, 2026, expanding exposure for defective AI-enabled products and software.
- Track national AI market-surveillance authorities, European AI Office guidance, Article 50 transparency guidance, and GPAI enforcement practice.
Pending and recent legislation8 measures
Live from the Global AI Policy Radar.
Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?
Yes. The EU AI Act is directly binding and is being phased in, with prohibitions, AI-literacy duties, and general-purpose AI obligations already applying, while other requirements take effect later.
Who are the key regulators for AI?
Enforcement is led by national authorities, the European AI Office, data-protection regulators, and sector regulators. Their roles depend on the AI system, the organization using it, and the regulated sector involved.
Which rules apply to AI systems today?
The AI Act applies according to the system's risk category, with prohibitions, AI-literacy duties, general-purpose AI obligations, governance, penalties, and most transparency rules applying on the stated timetable. GDPR applies when AI processes personal data, the Digital Services Act applies to covered online services, consumer-protection rules apply to AI-enabled marketing and influence, and NIS2 applies to covered entities and services.
What is coming next, and when?
Most transparency rules apply from August 2, 2026. The 2026 Digital Omnibus delayed most high-risk AI obligations to December 2, 2027 for Annex III systems and August 2, 2028 for AI embedded in regulated products.
What are the enforcement and penalty risks?
Companies may face enforcement from national authorities, the European AI Office, data-protection regulators, and sector regulators. Risk areas include AI Act penalties, GDPR requirements and enforcement, DSA duties, consumer-protection violations such as misleading claims or fake reviews, and NIS2 obligations including incident reporting and management accountability.
Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.