AI Act

Regulation (EU) 2024/1689

Regulation laying down harmonised rules on artificial intelligence

In force since August 1, 2024

Who it applies to

  • Providers placing AI systems or general-purpose AI models on the EU market, wherever established
  • Deployers of AI systems located in the EU
  • Providers and deployers outside the EU where the system's output is used in the EU

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — grantedObtain meaningful human involvement in a significant automated decision.
  • Non-discrimination — not granted
  • Appeal a refusal — grantedHave a denied request reconsidered through a stated appeals process.
  • Private right of action — not granted

Obligations

Consent model
Mixed
Universal opt-out signal
Not required
Risk assessments
Required for higher-risk processing
Data protection officer
Not required
Records of processing
Required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required
Minors
AI systems exploiting the vulnerabilities of children are a prohibited practice, not a regulated one.
Automated decisions
High-risk systems require human oversight, logging, technical documentation and a fundamental rights impact assessment for public bodies and certain private deployers.

Breach notification

To individuals
Not a breach-notification statute; the GDPR governs personal data breaches
To the regulator
Serious incidents involving high-risk systems must be reported to the market surveillance authority
What triggers it
A serious incident or malfunctioning of a high-risk AI system

Penalties

Headline
Up to €35 million or 7% of total worldwide annual turnover for prohibited practices
Private right of action
No — enforcement is by the regulator only
Notes
A higher ceiling than the GDPR. Lower tiers of €15 million or 3% apply to most other obligations, and €7.5 million or 1% to supplying incorrect information to authorities.

Exemptions

Entities

  • Systems used exclusively for military, defence or national security purposes
  • Free and open-source AI components, except where they are high-risk or general-purpose with systemic risk
  • Purely personal non-professional use

Amendment history

  1. February 2, 2025

    Prohibited practices apply

    Bans on unacceptable-risk systems, including untargeted facial-image scraping and most emotion recognition at work and in education, became applicable.

  2. August 2, 2025

    General-purpose AI obligations apply

    Transparency, copyright-policy and systemic-risk duties for general-purpose AI model providers became applicable.

  3. August 2, 2026

    High-risk system obligations apply

    The main high-risk conformity, logging and human-oversight duties become applicable.

Sources

Timeline

todayAI Act in forceAugust 1, 2024Prohibited practices applyFebruary 2, 2025General-purpose AI obligations applyAugust 2, 2025High-risk system obligations applyAugust 2, 2026