What Is the EU AI Act?

The EU AI Act is the world\'s first comprehensive legal framework for artificial intelligence. Adopted in 2024 and entering force in stages through 2028, it establishes binding rules for any AI system used in the European Union — regardless of where the company that built it is located.

The Act classifies AI systems into four risk tiers and imposes requirements proportional to each tier\'s potential for harm. It is the most significant piece of AI regulation in history, and its effects will be felt globally as companies adjust their products to comply.

The EU AI Act is not just European regulation. It is the global standard that every AI company will have to meet.

The Four Risk Tiers

1. Unacceptable Risk (Banned)

AI systems that pose an unacceptable risk to fundamental rights are completely banned. This includes:

2. High Risk (Strict Requirements)

AI systems used in critical areas face the most stringent requirements:

High-risk AI must meet requirements including risk management, data governance, technical documentation, transparency, human oversight, accuracy, and cybersecurity.

3. Limited Risk (Transparency Requirements)

AI systems that interact with humans or generate content must disclose that they are AI:

4. Minimal Risk (No Requirements)

AI systems with minimal risk — such as spam filters, AI-enabled video games, or inventory management systems — face no specific requirements under the Act. Most AI systems fall into this category.

What Changed with the Digital Omnibus

In July 2026, the European Commission introduced the Digital Omnibus on AI, which modified several aspects of the original AI Act:

Timeline Shifts

The high-risk AI requirements, originally scheduled for August 2026, were delayed to December 2027. This gives companies more time to comply but also signals the difficulty of implementing comprehensive AI regulation in a rapidly evolving field.

Nudification Ban

The Omnibus added a specific prohibition under Article 5: AI systems that generate, distribute, or facilitate non-consensual intimate imagery (commonly called "nudification" or "deepfake pornography") are now explicitly banned. This was not explicitly addressed in the original Act and was added in response to the growing problem of AI-generated non-consensual intimate imagery.

Enforcement Centralization

The Omnibus established a centralized EU AI Office to coordinate enforcement across member states. Previously, enforcement was left to national authorities, creating inconsistency. The EU AI Office now has the power to investigate, fine, and order the withdrawal of non-compliant AI systems.

Standardization Support

The Omnibus accelerated the development of harmonized standards by mandating that European standardization organizations produce technical standards for high-risk AI systems within 12 months. These standards will define how companies can demonstrate compliance with the Act\'s requirements.

When Does Everything Apply?

Date Requirement
February 2025 Prohibited AI practices take effect (social scoring, manipulation, etc.)
August 2025 Transparency requirements for limited-risk AI (chatbots, deepfakes)
December 2027 High-risk AI requirements take effect (delayed from August 2026)
2028 Full enforcement, including fines up to 7% of global annual turnover

How It Affects Companies Outside the EU

The EU AI Act has extraterritorial reach — it applies to any company that places an AI system on the EU market or whose AI system\'s output is used in the EU. This means:

The practical effect is that many companies are adopting EU-compliant practices globally, because maintaining separate compliance regimes for different regions is more expensive than meeting the strictest standard everywhere.

Enforcement and Penalties

The EU AI Act has significant enforcement teeth:

For context, a 7% fine on a company with €100 billion in revenue would be €7 billion — a potentially existential penalty. The severity of these fines is designed to ensure that companies take compliance seriously.

EU vs. US Approach

The EU and US have taken fundamentally different approaches to AI regulation:

EU: Comprehensive, Risk-Based

The EU AI Act applies to all AI systems, classifies them by risk, and imposes requirements proportional to that risk. It is prescriptive, detailed, and applies to the technology itself.

US: Sector-Specific, Voluntary

The US has no comprehensive federal AI law. Instead, AI is regulated through existing sector-specific laws (healthcare, finance, employment) and voluntary frameworks. The AI Executive Order (2023) established guidelines but did not create binding requirements. State-level laws (like California\'s AI transparency requirements) are emerging but remain fragmented.

Implications

For companies, the EU approach creates clarity but also complexity. The US approach creates flexibility but also uncertainty. Most companies are choosing to comply with the EU standard as a de facto global baseline, because the penalties for non-compliance are too severe to ignore.

The Nudification Ban in Detail

The AI nudification ban is worth examining separately because it addresses a specific, growing harm. AI tools that generate non-consensual intimate imagery — often called "deepfake pornography" — have become increasingly sophisticated and accessible. The ban prohibits:

This ban is notable because it targets a specific use case rather than a category of technology. It represents a new approach to AI regulation: addressing specific harms as they emerge rather than waiting for comprehensive frameworks to catch up.

What Can You Do

Sources