EU AI Act: Regulation (EU) 2024/1689
Issuer: European Parliament & Council
Date: 1 AUG 2024
Status: IN FORCE in European Union, as of 29 JUL 2026
World's first horizontal AI law; four-tier risk pyramid; extraterritorial (Art. 2).
One single rulebook for all 27 member states. It regulates what AI is used for, not the technology itself: prohibited practices are banned outright, high-risk uses carry the full conformity stack, limited-risk systems owe transparency, and ~85% of AI (minimal risk) faces no new duties. Applies to any provider or deployer whose AI output is used in the EU.
What it actually requires (5 provisions)
- Art. 5 prohibitions: social scoring, manipulation, workplace/school emotion recognition, most police real-time facial recognition (in force 2 Feb 2025)
- Annex III high-risk: recruitment, credit scoring, education, essential services, law enforcement, biometrics
- Art. 50 transparency: chatbot disclosure, machine-readable synthetic-content marking, deepfake labels
- Ch. V GPAI: documentation, copyright policy, training-data summary, systemic-risk tier >10²⁵ FLOPs
- Art. 99 to 101 penalties: up to €35M / 7% of worldwide turnover for prohibited practices
How its status moved
- PUBLISHEDOJ L, 12 Jul 2024
- IN FORCE1 Aug 2024
- CURRENTPhased application: prohibitions live, high-risk duties 2 Dec 2027 / 2 Aug 2028
Sources (2)
Reg. 2024/1689: EU Artificial Intelligence Act
The world's first comprehensive horizontal AI law: one rulebook for all 27 member states, in force 1 Aug 2024.
Prohibited-practice violations: fines up to €35M or 7% of total worldwide annual turnover, bigger than GDPR's €20M/4%.
The rest of the European Union stack
5 more instruments in this jurisdiction, each with its own status, provisions and sources.
- Digital Omnibus on AI: Regulation (EU) 2026/1744IN FORCEDefers high-risk application to 2 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I); adds nudifier/NCII + AI-CSAM bans (2 Dec 2026); SME simplifications; substance of high-risk duties unchanged.
- GPAI rules (Chapter V) + Code of PracticeIN FORCEDocumentation, copyright policy, training-data summary; systemic-risk tier >10²⁵ FLOPs; open-source carve-out; Meta declined to sign; enforcement powers activate 2 Aug 2026 (Implementing Reg. 2026/1755).
- European AI OfficeIN FORCEEU-level GPAI regulator: evaluate models, demand access, sanction; expanded remit under the Omnibus.
- Art. 50 transparency dutiesUPCOMINGChatbot disclosure; machine-readable synthetic-content marking; visible deepfake labels.
- GDPR Art. 22IN FORCERight not to be subject to purely automated decisions: the ancestor of the rights-based approach.
Where this sits in the wider picture
- The European Union regime dossier gives the doctrine this instrument belongs to, next to the other two jurisdictions.
- The Framework Explorer, filtered to EU lists every instrument in this jurisdiction in one filterable index.
- The governance simulator shows what these rules do to a real AI system, next to what the other two jurisdictions do to the same one.
- The timeline places this date beside what the other capitals were doing that month.
- This sits inside Regulation (EU) 2024/1689. Read the article text itself, with its cross references, in the free EU AI Act Explorer.
Knowing the instrument is step one. Complying with it is the job.
The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.
VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.