Reference · content version 2026-08-06
A current reference to Regulation (EU) 2024/1689 as amended: what applies today, what is still coming, which tier a system falls into, and what Article 50 actually requires. The dates below are the post-Omnibus ones — a great deal of material still on the internet is not.
Every application date in the Act, with what the Digital Omnibus changed. Two rows carry most of the practical consequence: transparency is live, and high-risk is not.
| Obligation | Article | Applies from | Status | Max penalty | What the Omnibus changed |
|---|---|---|---|---|---|
| Prohibited AI practices bannedSocial scoring, real-time remote biometric identification in public spaces, manipulation of vulnerable groups, emotion inference at work and in education. | Art. 5 | 2 Feb 2025 | In force | €35M / 7% | Nothing. |
| General-purpose AI model obligationsApplies to providers of GPAI models, not to organisations merely deploying systems built on them. | Ch. V | 2 Aug 2025 | In force | — | Nothing. |
| AI literacyOrganisation-level, regardless of tier, wherever staff operate or are affected by AI systems. Evidence should be role-specific and logged against the individual learner. | Art. 4 | 2 Aug 2026 | In force | €7.5M / 1% | Softened from “ensure a sufficient level” of AI literacy to “support its development” — an obligation of effort, not of result. |
| Transparency obligationsTell people they are talking to an AI; inform people exposed to emotion recognition or biometric categorisation; label AI-generated published content and deepfakes. | Art. 50(1), 50(3), 50(4) | 2 Aug 2026 | In force | €15M / 3% | Not deferred. Only Art. 50(2) machine-readable marking moved — see the next row. |
| Machine-readable marking of generative outputProvider-side duty: outputs of generative systems must be marked in a machine-readable format as artificially generated or manipulated. | Art. 50(2) | 2 Dec 2026 | Upcoming | €15M / 3% | Deferred from 2 Aug 2026 to 2 Dec 2026. |
| High-risk obligations — standalone Annex III systemsConformity assessment, risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and robustness, EU database registration. Deployers: Art. 26 duties and, where applicable, an Art. 27 fundamental rights impact assessment. | Ch. III + Annex III | 2 Dec 2027 | Upcoming | €15M / 3% | Deferred from 2 Aug 2026 by 16 months. This is the row most published guidance still gets wrong. |
| High-risk obligations — AI embedded in regulated productsAI systems that are safety components of products already covered by Annex I Union harmonisation legislation. | Art. 6(1) + Annex I | 2 Aug 2028 | Upcoming | €15M / 3% | Deferred by 12 months. |
Penalty figures are stated as the maximum of a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher. The Act’s penalty regime is in Article 99; national market surveillance authorities set the actual amount.
Article 50 is the provision that matters commercially right now. It is live, it was not deferred, it carries a penalty tier three times Article 4’s, and it catches a far wider population than high-risk ever will — because almost every organisation now has something that talks to a person or produces published text.
Any system interacting directly with natural persons must inform them that they are interacting with an AI system, unless that is obvious from the context. Falls on both providers and deployers. Live since 2 August 2026.
A provider-side duty: the outputs of generative systems must be marked in a machine-readable format as artificially generated or manipulated. This is the only part of Article 50 the Omnibus moved — to 2 December 2026.
Where emotion recognition or biometric categorisation is in use, the persons exposed to it must be informed of its operation. A deployer duty. Live since 2 August 2026.
Deployers publishing AI-generated text on matters of public interest, or deepfake content, must disclose it. A deployer duty. Live since 2 August 2026.
The obligations diverge sharply, and most organisations assume “deployer” for everything and are wrong about at least one system. Establish the role per system, not once for the organisation.
Article 50 is not limited to organisations established in the Union. Providers are in scope where they place a system on the EU market or where the system’s output is used in the EU; deployers likewise where the output is used in the EU. A company with no EU entity, no EU office and an EU-facing chatbot or an EU readership for its AI-written articles is inside the scope of the Regulation.
The Act is risk-tiered: obligations attach to what a system does and where it is used, not to the technology. A capability operating in an Annex III domain escalates above its base tier — which is why the same chatbot can be limited risk in marketing and high risk in recruitment.
Eight domains. A system operating in one of them is high risk regardless of how modest the technology looks. These are facts about where a system is used, so they have to be captured in discovery, not inferred from a product description.
Remote biometric identification, biometric categorisation by sensitive attributes.
Safety components in the management of road traffic, water, gas, heating, electricity, and critical digital infrastructure.
Admission, evaluation of learning outcomes, proctoring, steering the learning process.
Recruitment and selection, targeted job advertising, decisions on promotion or termination, task allocation, monitoring and evaluation of workers. This is why HR-tool AI features are the canonical conditional case: any AI touching recruitment, employee assessment or workforce management is explicitly high risk.
Credit scoring, risk assessment and pricing in life and health insurance, emergency call dispatching, eligibility for public benefits.
Risk-of-offending assessments, evidence reliability evaluation, profiling in criminal investigations.
Visa and asylum application examination, risk assessments of persons entering the EU.
Assisting judicial authorities in researching and applying the law, influencing election outcomes.
Banned outright since 2 February 2025, and carrying the Act’s highest penalty tier at up to €35 million or 7% of worldwide turnover. If a system matches one of these, the answer is not mitigation — it is discontinuation.
Subliminal or purposefully manipulative techniques; exploitation of vulnerabilities due to age, disability, or social or economic situation.
Evaluation or classification of persons based on social behaviour or personal characteristics leading to detrimental treatment.
Risk assessments of persons to predict the commission of a criminal offence based solely on profiling or personality traits.
Creating or expanding facial recognition databases through untargeted scraping of the internet or CCTV footage.
Emotion recognition systems in the areas of the workplace and education institutions, except for medical or safety reasons.
Categorisation of persons based on biometric data to deduce race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation.
Banned for law enforcement purposes, with narrow exceptions.
Three bands. Each is expressed as a fixed maximum or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher.
| Band | Maximum | Attaches to |
|---|---|---|
| Highest | €35M / 7% | Prohibited practices under Article 5. |
| Standard | €15M / 3% | Transparency obligations under Article 50, and the high-risk obligations once they apply (2 Dec 2027 / 2 Aug 2028). |
| Lower | €7.5M / 1% | AI literacy under Article 4. |
The penalty regime is set out in Article 99; enforcement and the actual amount are matters for national market surveillance authorities. The figures above are the maxima encoded in this app’s methodology data — they are not a prediction of what any given authority will impose.
Primary legislation and Commission guidance first. Where a law-firm analysis is cited it is because it dates and summarises the Omnibus changes precisely — but the Regulation and the Commission’s own material are the references to rely on.
EU AI Act Navigator applies exactly this methodology to your organisation: a guided discovery interview to find the AI, an honest classification per system, obligations mapped to the timeline above, and the registry and action plan exported as documents. It runs entirely on your iPhone — no account, no server, nothing leaves the device.
See what the app does