Guide

What Is the EU AI Act (and What's Actually in Force Now)

The EU's risk-based AI law, which obligations apply today versus which are still phasing in, and the penalties for getting it wrong.

8 min read

The EU AI Act is the world's first comprehensive law regulating artificial intelligence. It takes a risk-based approach: the higher the risk an AI system poses, the more the Act requires, up to banning a small set of uses outright. It phases in over several years, so the single most useful thing to know is which parts apply now and which are still ahead. Treat the dates below as current guidance to re-verify, since this timeline has already been adjusted once.

How the Act Classifies AI

  • Prohibited practices: a narrow set of uses banned entirely, such as social scoring and certain manipulative or biometric practices.
  • High-risk systems: AI used in sensitive contexts (for example employment, credit, or critical infrastructure), which carries the heaviest obligations.
  • Limited-risk systems: AI that mainly triggers transparency duties, such as telling people they are talking to a chatbot or labeling AI-generated content.
  • General-purpose AI (GPAI): foundation and general-purpose models, which carry their own provider obligations.

What Is in Force Now

As of 2026, several parts already apply:

  • The ban on prohibited practices took effect first, in early 2025.
  • General-purpose AI provider obligations have applied since August 2025.
  • Transparency obligations (labeling AI interactions and synthetic or deepfake content) apply from August 2026, with a short grace period into December 2026 for some pre-existing systems.

What Is Still Ahead

The heaviest obligations, for high-risk systems, were deferred and now phase in on a split timeline: late 2027 for stand-alone high-risk systems, and 2028 for AI embedded in products already regulated under other EU rules. This deferral is settled law, not a proposal, so plan around the later dates while treating the earlier, in-force obligations as live today.

Penalties

The Act's fines are steep and tiered. The top tier, for prohibited practices, reaches up to EUR 35 million or 7 percent of global annual turnover, whichever is higher, with lower tiers (in the millions or low single-digit percentages) for other violations. Smaller companies are generally capped at the lower of the figure or the percentage.

How Concord Fits

The EU AI Act is regulatory context, not something Concord certifies you against. What Concord Trust provides is the operational groundwork the Act assumes: an AI governance control family, framework mappings for ISO/IEC 42001 and the NIST AI RMF, and the industry-first AI Policy Generator to produce the AI use policy and disclosures the transparency obligations call for. You build the program; the Act is the reason to.

Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.