Source basis
Official source basis
Last reviewed on 2026-06-08.
This profile is grounded in official laws, policy documents, regulator guidance, standards, and public-sector source materials listed below.
Executive summary
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases. Chapters I and II, including the AI system definition, AI literacy, and prohibited practices, have applied since 2 February 2025. Governance rules, GPAI obligations, and penalties have applied since 2 August 2025. The regulation generally applies from 2 August 2026, while Article 6(1) product-safety high-risk obligations had an original statutory application date of 2 August 2027 under the base regulation. The AI Act uses a four-level risk logic in Commission-facing communications: unacceptable risk, high risk, transparency risk, and minimal or no risk. In legal terms, the binding structure is anchored in prohibited practices under Article 5, high-risk systems under Article 6 and Annex III plus product-safety legislation in Annex I, transparency obligations under Article 50, and model-level obligations for general-purpose AI under Chapter V. The EU governance architecture is hybrid. The AI Office, established within the Commission, supports implementation across the Union and directly supervises GPAI obligations. National market surveillance authorities supervise and enforce most system-level rules. The AI Board, Scientific Panel, and Advisory Forum provide coordination and expert or stakeholder input. The Commission appointed the Scientific Panel and Advisory Forum in June 2026, strengthening the institutional layer behind enforcement. At EU level, the AI Office is the core implementation node. It was established within the Commission and is tasked with supporting coherent application of the AI Act, preparing guidance and implementing tools, investigating possible infringements, and supervising the most powerful general-purpose AI models. The governance page and the AI Office page also identify the European AI Board, Scientific Panel, and Advisory Forum as the main advisory bodies surrounding the system. At member-state level, national competent authorities include market surveillance authorities and notifying authorities. Market surveillance authorities supervise and enforce compliance for AI systems, including prohibited and high-risk rules, while notifying authorities designate and supervise notified bodies that carry out relevant third-party conformity assessment. The Commission stated that these authorities had to be designated and empowered by 2 August 2025. For GPAI, the legal architecture is more centralized than for other AI categories. Article 88 gives the Commission exclusive powers to supervise and enforce Chapter V, and the Commission entrusts those tasks to the AI Office. That centralization is one of the EU model’s most consequential structural choices.
Governance architecture
At EU level, the AI Office is the core implementation node. It was established within the Commission and is tasked with supporting coherent application of the AI Act, preparing guidance and implementing tools, investigating possible infringements, and supervising the most powerful general-purpose AI models. The governance page and the AI Office page also identify the European AI Board, Scientific Panel, and Advisory Forum as the main advisory bodies surrounding the system. At member-state level, national competent authorities include market surveillance authorities and notifying authorities. Market surveillance authorities supervise and enforce compliance for AI systems, including prohibited and high-risk rules, while notifying authorities designate and supervise notified bodies that carry out relevant third-party conformity assessment. The Commission stated that these authorities had to be designated and empowered by 2 August 2025. For GPAI, the legal architecture is more centralized than for other AI categories. Article 88 gives the Commission exclusive powers to supervise and enforce Chapter V, and the Commission entrusts those tasks to the AI Office. That centralization is one of the EU model’s most consequential structural choices.
Major policies and frameworks
| Policy | Issuer | Year | Status | Summary |
|---|---|---|---|---|
| EU AI Act | European Union | 2024 | Regulation - Binding law | Core EU legal framework for prohibited AI practices, high-risk AI systems, transparency obligations, general-purpose AI obligations, governance, remedies, and penalties. |
| AI Act implementation framework | European Commission | 2024 | Commission policy page - Institutional explainer / implementation signal | Official Commission implementation page consolidating the AI Act risk model, phased implementation path, support tools, and current timeline framing. Use with care where it reflects later political agreements or implementation updates. |
| European AI Office governance framework | European Commission | 2024 | Commission decision / institutional framework - Official institutional act | Establishes the European AI Office within the European Commission and anchors the EU AI Act's institutional governance architecture, especially for general-purpose AI supervision. |
| Guidelines on prohibited AI practices | European Commission | 2025 | Commission guidelines - Official guidance, non-binding | Interprets Article 5 prohibited AI practices and provides practical examples. Non-binding guidance; the Court of Justice of the European Union remains authoritative. |
| Guidelines on AI system definition | European Commission | 2025 | Commission guidelines - Official guidance, non-binding | Clarifies whether software falls within the AI Act's definition of an AI system. Important for determining whether a system is in scope. |
| General-Purpose AI Code of Practice and GPAI provider guidance | European Commission | 2025 | Code of practice / Commission guidance - Voluntary code plus non-binding official guidance | Provides implementation guidance for general-purpose AI model providers, including scope, provider status, exemptions, obligations, and enforcement expectations. The related GPAI Code of Practice offers a voluntary compliance pathway on transparency, copyright, and safety and security. |
| Draft high-risk AI and transparency guidelines | European Commission | 2025 | Draft guidance / consultation - Draft guidance | Draft and consultation-stage guidance intended to clarify high-risk AI classification and AI Act transparency obligations. Do not present as final guidance. |
| AI Act standardisation, AI literacy, and implementation support | European Commission | 2025 | Implementation support framework - Official implementation support | Explains the AI Act standardisation pipeline, the role of harmonised standards, presumption of conformity, AI literacy, and broader implementation support. Standards and practice repositories should be treated as support tools, not standalone legal obligations. |
Policy timeline
2024-08-01
AI Act entered into force
The EU AI Act entered into force, starting the phased implementation clock.
2025-02-02
Chapters I and II apply
AI system definition, AI literacy obligations, and prohibited AI practices start applying.
2025-02-04 to 2025-02-06
First implementation guidance issued
The Commission published guidance on prohibited AI practices and the AI system definition. Label this guidance as non-binding.
2025-08-02
Governance rules and GPAI obligations apply
AI governance bodies and Chapter V general-purpose AI obligations become applicable. The penalties framework also applies.
2026-08-02
General application date
Most remaining AI Act obligations apply, including Article 50 transparency obligations. Commission enforcement powers for general-purpose AI begin operating from this date.
2027-08-02
Legacy GPAI compliance deadline
General-purpose AI models placed on the market before 2025-08-02 must comply by this date.
2027-12-02
Certain Annex III high-risk rules
The Commission implementation page states that rules for certain high-risk areas will apply from this date following the AI omnibus political agreement. Only with caveat and verify the final amending act before treating this as settled law.
2028-08-02
Product-integrated high-risk rules
The Commission implementation page states that product-integrated high-risk rules will apply from this date following the AI omnibus political agreement. Only with caveat and verify the final amending act before treating this as settled law.
Enterprise implications
For providers, the EU regime requires disciplined product governance. The immediate tasks are role-mapping, AI-system inventory, prohibited-practice screening, high-risk classification, documentation architecture, vendor-chain allocation, incident-handling pathways, and literacy measures. For high-risk systems, providers should assume that conformity assessment, declaration of conformity, CE marking, registration, post-market monitoring, and evidence retention are core control functions rather than legal back-office items. For deployers, the main enterprise risk lies in use-context governance. Deployers cannot outsource all responsibility to vendors. They must ensure use consistent with instructions, assign competent human oversight, manage controlled input data, monitor operations, report serious incidents, satisfy notice duties in relevant cases, and—where applicable—carry out fundamental-rights impact assessments. Employers using AI in workforce contexts should pay particular attention to high-risk triggers in employment and worker-management use cases, as well as the workforce-facing implications of Article 4 literacy duties. For GPAI providers and downstream integrators, the EU’s most distinctive burden is value-chain transparency. Documentation must flow downstream, copyright and training-content summary obligations must be operationalized, and systemic-risk providers must be prepared for Commission-facing engagement, including notification, evaluations, incident reporting, and cybersecurity expectations. Penalty exposure is material. Member-state penalties can reach up to EUR 35 million or 7% of worldwide turnover for prohibited-practice violations, and up to EUR 15 million or 3% of worldwide turnover for a broad set of operator, deployer, notified-body, and Article 50 obligations. GPAI providers face Commission-level fines up to 3% of worldwide turnover or EUR 15 million.
Observatory interpretation
Observatory interpretation: The EU model is best understood as a layered governance stack rather than a single compliance rulebook. The statute sets the legal architecture, but actual enterprise burden is distributed across guidance, standards, conformity processes, national authorities, and role-specific controls. This is especially true for high-risk and GPAI governance. Observatory interpretation: The EU’s most globally influential design choice is the split between centralized supervision for GPAI and decentralized supervision for most AI systems. That makes the EU simultaneously a market-regulation regime and a frontier-model governance regime. Observatory interpretation: As of mid-2026, the EU profile is strongest on legal architecture and weaker on settled operational certainty in some areas, because key implementation materials remain draft or are still moving through standardisation and post-political-agreement channels. That does not reduce the law’s significance; it increases the importance of documented governance judgments and publication control.
Official resources
| Resource | Source | Type | Date | Legal force | Why it matters |
|---|---|---|---|---|---|
| Regulation (EU) 2024/1689 AI Act on EUR-Lex | EUR-Lex | Law | 2024 | Binding | Use as the authoritative source for obligations, definitions, timelines, enforcement, remedies, and penalties. |
| AI Act implementation page | European Commission | Guidance | 2024 | Guidance | Use with care where it reflects later political agreements or implementation updates. |
| Governance and enforcement of the AI Act | European Commission | Guidance | 2025 | Guidance | Useful for mapping institutional responsibilities. |
| European AI Office | European Commission | Guidance | 2024 | Not applicable | Use for governance architecture and institutional capacity analysis. |
| Commission Decision establishing the European AI Office | European Commission | Public-sector rule | 2024 | Guidance | Use as the institutional origin source for the AI Office. |
| First rules of the Artificial Intelligence Act are now applicable | European Commission | Report | 2025 | Guidance | Useful for explaining early applicability of AI literacy, AI system definition, and prohibited practices. |
| Guidelines on prohibited AI practices | European Commission | Guidance | 2025 | Guidance | Non-binding guidance; CJEU interpretation remains authoritative. |
| Guidelines on AI system definition | European Commission | Guidance | 2025 | Guidance | Useful for scope and threshold questions. |
| EU rules on governance start to apply | European Commission | Report | 2025 | Guidance | Useful for tracking implementation capacity and institutional readiness. |
| Guidelines for providers of general-purpose AI models | European Commission | Guidance | 2025 | Guidance | Non-binding but enforcement-relevant. |
| General-Purpose AI Code of Practice now available | European Commission | Guidance | 2025 | Voluntary | Use for the status and timing of the voluntary GPAI code. |
| Questions and answers on the General-Purpose AI Code of Practice | European Commission | Guidance | 2025 | Voluntary | Useful for explaining how the voluntary code interacts with legal obligations. |
| Questions and answers on GPAI provider guidelines | European Commission | Guidance | 2025 | Guidance | Use as implementation support alongside the main GPAI provider guidelines. |
| Template for public summary of training content for general-purpose AI models | European Commission | Guidance | 2025 | Not applicable | Supports Article 53(1)(d) operationalization. |
| Consultation on draft transparency guidelines under the AI Act | European Commission | Guidance | 2025 | Draft | Use as a watchlist item only. Do not present as final guidance. |
| Guidelines for providers and deployers of high-risk AI systems | European Commission | Guidance | 2026 | Draft | Use as a high-risk classification watchlist item only. |
| Understanding the standardisation of the AI Act | European Commission | Standard | 2025 | Guidance | Useful for understanding presumption of conformity and compliance infrastructure. |
| Standardisation of the AI Act | European Commission | Standard | 2025 | Guidance | Use for high-risk AI compliance infrastructure and standards development tracking. |
| AI talent, skills and literacy | European Commission | Guidance | 2025 | Guidance | Useful for Article 4 interpretation and workforce implications. |
| Repository of AI literacy practices | European Commission | Guidance | 2025 | Not applicable | The repository does not create a presumption of compliance. |
| AI Pact marks one year of progress | European Commission | Report | 2025 | Voluntary | Use as an early compliance and implementation signal. |
| Over a hundred companies sign EU AI Pact pledges | European Commission | Guidance | 2024 | Voluntary | Use for early compliance framing, not as a legal obligation source. |
| AI Pact pledgers’ achievements | European Commission | Report | 2025 | Voluntary | Use as supplemental implementation signal only. |
| AI Act enforcement gets independent expert support | European Commission | Enforcement case | 2026 | Guidance | Useful for tracking enforcement architecture development. |
| Supporting the implementation of the AI Act with clear guidelines | European Commission | Guidance | 2026 | Guidance | Useful for tracking upcoming guidance and implementation capacity. |
| Draft Commission guidelines on classification of high-risk AI systems | European Commission | Guidance | 2026 | Draft | Watchlist use only. Do not present as final guidance. |
| Digital Omnibus on AI proposal | EUR-Lex | Law | 2025 | Proposed | Caveated watchlist source only until final amending legislation is verified. |
Update log
2026-06-08: Initial test profile shell created for V1 system validation.
