AI Regulation in the European Union
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. Bans on prohibited practices and the AI literacy duty have applied since 2 February 2025. Duties for providers of general-purpose AI models have applied since 2 August 2025, and the Commission's power to fine those providers applies from 2 August 2026.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed back the high-risk deadlines. Stand-alone high-risk systems in Annex III now have until 2 December 2027, and AI built into regulated products under Annex I has until 2 August 2028. The amendment also added two new bans from 2 December 2026.
The AI Act sits alongside other EU law that applies to AI. GDPR governs personal data used to train and run AI systems. The Data Act has applied since 12 September 2025, and the Digital Services Act covers recommender systems on online platforms. EN 18286, the first European standard supporting the AI Act, was published in July 2026. The proposed AI Liability Directive was withdrawn in 2025.
Key themes
- 1.Risk-based duties: prohibited, high-risk, transparency, and minimal-risk AI
- 2.High-risk deadlines moved to December 2027 and August 2028 by the 2026 Omnibus
- 3.General-purpose AI model duties, supervised by the European AI Office
- 4.Overlap with GDPR, the Data Act, the Digital Services Act, and DORA
Regulatory frameworks and guidance(16)
European Commission Enforcement Powers for Advanced AI Models under the AI Act
The European Commission enforces the EU AI Act's obligations for all general-purpose AI model providers, wherever they are based. Its fining powers apply from 2 August 2026. It can request information, evaluate models, require measures, and fine up to 3 percent of worldwide turnover or EUR 15 million.
EU Action Plan on Cybersecurity and Artificial Intelligence
The European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence on 7 July 2026. It aims to promote safe use of advanced AI, strengthen EU cybersecurity, and build European AI capabilities for cybersecurity. It creates no new obligations and relies on existing laws such as NIS2, DORA, and the Cyber Resilience Act.
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
Regulation (EU) 2026/1744: Digital Omnibus on AI (EU AI Act Amendment)
Regulation (EU) 2026/1744 defers the AI Act’s high-risk compliance deadlines. Stand-alone Annex III systems move from August 2, 2026 to December 2, 2027. Product-embedded high-risk systems have until August 2, 2028. General-purpose AI (GPAI) duties remain applicable from August 2025. Prohibited practices and AI literacy requirements have applied since February 2025. The amendment adds two bans from December 2026 and softens the literacy duty.
EN 18286:2026, Quality Management System for EU AI Act Regulatory Purposes
EN 18286:2026 sets quality management system requirements for AI providers under the EU AI Act. CEN and CENELEC published it in July 2026, the first European standard supporting the Act. It gives a presumption of conformity only once cited in the Official Journal.
EU AI Liability Directive (withdrawn proposal)
The proposed EU AI Liability Directive would have lowered evidentiary barriers for people seeking compensation for AI harm. It proposed disclosure mechanisms and presumptions of causation. The Commission approved its withdrawal on 16 July 2025, and the notice was published on 6 October 2025.
AI Act Governance and Enforcement Framework
EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.
EU Code of Practice on Transparency of AI-Generated Content
The European Commission published this voluntary Code of Practice to support Article 50 compliance under the EU AI Act. It addresses generative AI providers and deployers serving the EU. The Code covers content labeling, controls that record where content came from, and disclosure workflows.
EU Cyber Resilience Act
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.
EU Data Act
The EU Data Act governs access to personal and non-personal data from connected products and related services. Data holders must share covered data with users and third parties. It also sets conditions for public bodies accessing privately held data in exceptional circumstances.
EU Data Governance Act
The EU Data Governance Act regulates data intermediaries, data altruism organizations, and reuse of protected public-sector data. It establishes structures for trusted sharing across sectors and member states as part of the European Data Strategy.
EU Proposal for a Regulation for the Digital Networks Act (DNA)
The European Commission proposed the Digital Networks Act (COM(2026) 16) on 21 January 2026. It would replace the European Electronic Communications Code with a single regulation for telecoms networks. It aims to enable AI and cloud adoption but sets no AI-specific governance duties.
EU Digital Operational Resilience Act
DORA (the Digital Operational Resilience Act), Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover technology risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
EU Digital Services Act, AI and Algorithmic Accountability Provisions
The Digital Services Act regulates online intermediaries’ recommender systems, targeted advertising, and systemic risks. Duties cover transparency, accountability, and risk management. Requirements increase with platform size, with the strictest applying to very large online platforms and search engines (VLOPs and VLOSEs).
EU General-Purpose AI Model Training Data Public Summary Template
The European Commission published a template for general-purpose AI providers’ public training-data summaries. It supports disclosure obligations under the EU AI Act. Providers are expected to follow its structure when preparing those summaries.
General Data Protection Regulation (GDPR)
The GDPR is the EU's data protection law. It applies whenever an AI system uses personal data about people in the EU, from training a model to making decisions about individuals. Organizations need a lawful basis for each use, must tell people how their data is used, and must respect their rights. It also limits decisions made solely by automated means that significantly affect people.
