AI Act
Regulation (EU) 2024/1689Regulation laying down harmonised rules on artificial intelligence
In force since August 1, 2024
Who it applies to
- Providers placing AI systems or general-purpose AI models on the EU market, wherever established
- Deployers of AI systems located in the EU
- Providers and deployers outside the EU where the system's output is used in the EU
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — grantedObtain meaningful human involvement in a significant automated decision.
- Non-discrimination — not granted
- Appeal a refusal — grantedHave a denied request reconsidered through a stated appeals process.
- Private right of action — not granted
Obligations
- Consent model
- Mixed
- Universal opt-out signal
- Not required
- Risk assessments
- Required for higher-risk processing
- Data protection officer
- Not required
- Records of processing
- Required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
- Minors
- AI systems exploiting the vulnerabilities of children are a prohibited practice, not a regulated one.
- Automated decisions
- High-risk systems require human oversight, logging, technical documentation and a fundamental rights impact assessment for public bodies and certain private deployers.
Breach notification
- To individuals
- Not a breach-notification statute; the GDPR governs personal data breaches
- To the regulator
- Serious incidents involving high-risk systems must be reported to the market surveillance authority
- What triggers it
- A serious incident or malfunctioning of a high-risk AI system
Penalties
- Headline
- Up to €35 million or 7% of total worldwide annual turnover for prohibited practices
- Private right of action
- No — enforcement is by the regulator only
- Notes
- A higher ceiling than the GDPR. Lower tiers of €15 million or 3% apply to most other obligations, and €7.5 million or 1% to supplying incorrect information to authorities.
Exemptions
Entities
- Systems used exclusively for military, defence or national security purposes
- Free and open-source AI components, except where they are high-risk or general-purpose with systemic risk
- Purely personal non-professional use
Amendment history
February 2, 2025
Prohibited practices apply
Bans on unacceptable-risk systems, including untargeted facial-image scraping and most emotion recognition at work and in education, became applicable.
August 2, 2025
General-purpose AI obligations apply
Transparency, copyright-policy and systemic-risk duties for general-purpose AI model providers became applicable.
August 2, 2026
High-risk system obligations apply
The main high-risk conformity, logging and human-oversight duties become applicable.
Sources
- PrimaryRegulationRegulation (EU) 2024/1689 — AI Act text