AI Regulation in the European Union
The European Union has enacted the most comprehensive AI regulatory framework in the world. The EU AI Act — effective August 2024, with enforcement phasing through 2026 and 2027 — introduces risk-based obligations for AI developers and deployers across four tiers: prohibited uses, high-risk systems with strict conformity requirements, limited-risk systems with transparency obligations, and minimal-risk AI with no specific mandates.
Alongside the AI Act, organizations deploying AI in EU markets must navigate a layered stack of intersecting regulations. GDPR governs personal data used to train and operate AI systems. The Digital Operational Resilience Act (DORA) sets requirements for AI in financial services. The Data Act, Digital Services Act, and Cyber Resilience Act each add obligations relevant to specific AI use cases. The EU AI Office, established in 2024, is the central authority responsible for regulating general-purpose AI models with systemic risk.
For compliance teams, the EU's approach means that no single framework is sufficient. A high-risk AI system in healthcare or hiring must satisfy the AI Act's conformity assessment requirements, maintain GDPR-compliant data practices, and meet sector-specific rules simultaneously. Organizations using AI in critical infrastructure, biometrics, or access to essential services face the most demanding compliance burden.
Key themes
- 1.Risk-tiered obligations — prohibited, high-risk, limited risk, minimal risk
- 2.Prohibited AI practices (social scoring, real-time biometrics in public spaces)
- 3.General-purpose AI model governance via the EU AI Office
- 4.Intersection with GDPR, DSA, DORA, and the Data Act
Regulatory frameworks and guidance(16)
European Commission Enforcement Powers for Advanced AI Models under the AI Act
The European Commission can enforce EU AI Act requirements against providers of advanced general-purpose models meeting its capability thresholds. Coverage applies regardless of incorporation location. Powers include information requests, model access for evaluation, required mitigations, and penalties reaching 3 percent of worldwide annual turnover.
EU Action Plan on Cybersecurity and Artificial Intelligence
The European Commission’s Action Plan on Cybersecurity and Artificial Intelligence coordinates EU efforts to secure AI systems. It covers developers and deployers subject to the AI Act, particularly advanced or high-risk systems. The plan creates a secure testing platform and EU-level evaluation capability for advanced models.
Regulation (EU) 2026/1744: AI Act Omnibus Amendment (High-Risk Deadline Deferral)
Regulation (EU) 2026/1744 defers the AI Act’s high-risk compliance deadlines. Stand-alone Annex III systems move from August 2, 2026 to December 2, 2027. Product-embedded high-risk systems have until August 2, 2028. GPAI duties remain applicable from August 2025. Prohibited practices and AI literacy requirements remain applicable from February 2026.
EU AI Act Harmonised Standard prEN 18286, Quality Management Systems for AI
Draft standard prEN 18286 is under public enquiry. It addresses AI quality management systems supporting conformity with the EU AI Act. It targets developers and deployers seeking standardized compliance evidence. Conformity with a harmonized standard creates a presumption of conformity for the corresponding requirements it covers.
EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)
This entry lists February 2, 2026 as the EU AI Act’s first major compliance deadline. It requires AI developers and deployers in the EU to establish workforce literacy measures. It also describes enforceable prohibitions on unacceptable-risk practices. Organizations must cease prohibited practices and demonstrate adequate staff competency by that date.
EU AI Liability Directive
The proposed EU AI Liability Directive would have lowered evidentiary barriers for people seeking compensation for AI harm. It proposed disclosure mechanisms and presumptions of causation. The proposal was withdrawn in early 2025 after political agreement failed.
AI Act Governance and Enforcement Framework
EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.
AI Omnibus Regulation (EU AI Act Extension)
The AI Omnibus entered into force on July 27, 2026, extending AI Office oversight powers. It covers general-purpose AI providers and deployers, plus AI embedded in large online platforms and search engines. Organizations must maintain model governance, conduct provider due diligence, and respond to AI Office evidence requests.
EU Code of Practice on Transparency of AI-Generated Content
The European Commission published this voluntary Code of Practice to support Article 50 compliance under the EU AI Act. It addresses generative AI providers and deployers serving the EU. The Code covers content labeling, provenance controls, and disclosure workflows.
EU Cyber Resilience Act
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.
EU Data Act
The EU Data Act governs access to personal and non-personal data from connected products and related services. Data holders must share covered data with users and third parties. It also sets conditions for public bodies accessing privately held data in exceptional circumstances.
EU Data Governance Act
The EU Data Governance Act regulates data intermediaries, data altruism organizations, and reuse of protected public-sector data. It establishes structures for trusted sharing across sectors and member states as part of the European Data Strategy.
EU Proposal for a Regulation for the Digital Networks Act (DNA)
The European Commission proposed the Digital Networks Act on January 21, 2026. Parliament and Council are reviewing it. It addresses digital infrastructure and aspects of AI governance. Expected duties concern network operators and deployers, including those using AI for network management.
EU Digital Operational Resilience Act
DORA, Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover ICT risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
EU Digital Services Act, AI and Algorithmic Accountability Provisions
The Digital Services Act regulates online intermediaries’ recommender systems, targeted advertising, and systemic risks. Duties cover transparency, accountability, and risk management. Requirements increase with platform size, with the strictest applying to VLOPs and VLOSEs.
EU General-Purpose AI Model Training Data Public Summary Template
The European Commission published a template for general-purpose AI providers’ public training-data summaries. It supports disclosure obligations under the EU AI Act. Providers are expected to follow its structure when preparing those summaries.
