Live with itExplainer

The EU AI Act in plain English: what does the law say?

Europe's AI law now applies to the chatbots, hiring tools and credit checks you meet every day. Here is what it bans, what it demands, and what it lets you do.

A page of rules with a yellow seal, next to a pink shield marked with a tick.
AI-generated illustration
Short answer

The EU AI Act sorts AI by how much harm it could do. A few uses, such as social scoring, are banned outright; risky uses such as CV screening or credit scoring face strict rules from December 2027; and chatbots and deepfakes must be disclosed. Anyone can complain to a national authority if they think the law has been broken.

What is the AI Act, in one breath?

The AI Act is the European Union's law on artificial intelligence, officially Regulation (EU) 2024/1689. The European Commission calls it the first comprehensive legal framework on AI anywhere in the world.

It entered into force on 1 August 2024, but it switches on in stages. Most of it has applied since 2 August 2026, which is when national and EU enforcement began, according to the Commission's AI Act Service Desk.

Its duties fall on the organisations that build AI systems or use them in their work. As an ordinary user, you are the person it protects rather than the person it regulates.

How does the "risk-based" approach work?

Think of it like food safety. Nobody inspects your kitchen, but a restaurant gets checked, and some ingredients are simply not allowed. The AI Act sorts AI uses into four levels, as the Commission describes them:

  • Unacceptable risk: banned. Uses that threaten people's safety, livelihoods or rights.
  • High risk: strict rules. Uses that could seriously affect your health, safety or basic rights, such as software that sorts job applications or scores your creditworthiness.
  • Transparency risk: you must be told. Chatbots and AI-generated content such as deepfakes.
  • Minimal risk: no specific rules. The Commission says this covers most AI in use today, such as spam filters and AI in video games.

The law looks at what a system is used for, not how clever it is. The same model could be minimal risk in a photo app and high risk in a hiring tool.

What does the law ban?

Eight practices have been banned since 2 February 2025. The Commission lists them as follows, and the plain examples in brackets are ours:

  1. Harmful manipulation and deception (an app built to push vulnerable users into decisions that hurt them).
  2. Exploiting people's vulnerabilities, such as age or disability (a toy that talks children into risky behaviour).
  3. Social scoring (ranking citizens by their behaviour and cutting their access to services as a result).
  4. Predicting that a person will commit a crime based only on profiling or personality traits.
  5. Scraping faces from the internet or CCTV, without a target, to build facial recognition databases.
  6. Emotion recognition at work and in schools (a webcam that grades whether employees look engaged).
  7. Biometric categorisation that infers sensitive traits, such as sorting people by face into religion or sexual orientation.
  8. Real-time remote facial recognition by police in public spaces, except in a few narrowly defined cases.

A ninth ban was added this year. From 2 December 2026, AI systems that generate non-consensual sexual images or child sexual abuse material, such as "nudification" apps, are prohibited, according to the Commission and the AI Act Service Desk.

Breaking a ban is the most serious offence in the Act. Article 99 sets fines of up to €35 million or 7% of a company's worldwide annual turnover, whichever is higher. For small firms and start-ups, the lower of the two figures applies.

Which high-risk uses could affect me?

The high-risk list reads like a tour of moments when a decision about you really matters. The Commission's examples include:

  • Work: CV-sorting software for recruitment and tools used to manage workers. Our guide to AI at work covers this in more detail.
  • Money: credit scoring that decides whether you get a loan.
  • Education: AI that affects who gets into a course, or that scores exams.
  • Public and essential services: systems that decide access to benefits and other services.
  • Policing, migration, border control and justice.

Companies that build these systems will have to manage risks, use good-quality training data (to reduce bias), keep logs, write documentation and make sure a human can oversee the system, according to the Commission.

Here is the catch. These rules were due to apply on 2 August 2026, but they have been postponed. For most of the uses listed above, they now start on 2 December 2027. For AI built into products that already have EU safety rules, such as medical devices or machinery, they start on 2 August 2028.

Why were the high-risk rules delayed?

In November 2025 the Commission proposed a package of simplifications, known as the "digital omnibus" (an omnibus is a single law that amends several others at once). EU governments and the European Parliament reached a political deal in spring 2026.

The AI part became law as Regulation (EU) 2026/1744. According to White & Case, it was published in the EU's Official Journal on 24 July 2026 and entered into force on 27 July 2026. The Commission's AI Act page confirms the same entry-into-force date.

The law firm Jones Walker describes the delay as "a reprieve rather than a repeal": the high-risk duties are still coming. Beyond the new dates, the omnibus also added the nudification ban, gave the EU's AI Office stronger powers over AI built on large general-purpose models, and eased some paperwork for smaller companies. It also softened the duty on firms to train their staff in AI: they must now "take measures to support" a sufficient level of AI literacy, rather than ensure it, according to White & Case.

What do chatbots and deepfakes have to tell me?

The transparency rules in Article 50 did apply from 2 August 2026, and the omnibus left them largely in place. According to the Commission and Jones Walker:

  • Chatbots must say they are AI. When you talk to an AI system, you must be told, unless it is already obvious.
  • AI-generated content must be detectable. Companies that make generative AI tools must mark what they produce in a machine-readable way, "to the extent technically feasible". Tools already on the market before August get until 2 December 2026 to do this.
  • Deepfakes must be labelled. Anyone who publishes AI-made or AI-altered images, audio or video that look real must disclose it. Clearly artistic, satirical or fictional work gets lighter treatment.
  • Some AI-written text must be labelled too, when it is published to inform the public on matters of public interest, unless a human has reviewed it and an editor takes responsibility.
  • Emotion recognition and biometric categorisation: where these are still allowed, people exposed to them must be told.

You must get this information no later than your first interaction with the system. Breaking these rules can cost up to €15 million or 3% of worldwide turnover, under Article 99.

Labels will not catch everything, so the old habits still help. Our guide to spotting AI-generated content explains what to look for.

What are my rights?

You can complain. Under Article 85, anyone who has grounds to think the Act has been broken can file a complaint with the relevant national market surveillance authority, the body that polices products on the market. This does not take away any other legal route, such as going to court or to your data protection authority.

You can ask for an explanation of some decisions. Article 86 gives a right to "clear and meaningful explanations" when a decision about you is based on a high-risk AI system from the law's main list (hiring, credit, education and so on), and that decision has legal effects or similarly significant effects that you consider harmful to your health, safety or fundamental rights. You can ask the organisation that used the system to explain the AI's role and "the main elements of the decision taken". The right does not apply where other EU law already provides it.

In practice this right is tied to the high-risk rules, which now start in December 2027.

Your privacy rights, including over decisions made by an algorithm, come mainly from separate data protection law. Our guide to your data and AI chatbots covers the privacy side.

Who enforces it?

Enforcement is split. Each EU country names national authorities to supervise AI on its territory and handle complaints. The EU's AI Office, part of the Commission, has direct powers over the providers of general-purpose AI models, the large systems behind popular chatbots. The Commission says the AI Office can request documentation, evaluate models, order fixes and issue fines.

In Italy, Law No. 132/2025, which entered into force on 10 October 2025, names two agencies, according to the law firm Cleary Gottlieb. The Agency for Digital Italy (AgID) handles the bodies that check whether high-risk AI meets the rules. The National Cybersecurity Agency (ACN) supervises AI systems, with powers to inspect and sanction, and acts as the market surveillance authority, the body Italians would normally complain to. The Bank of Italy, Consob and IVASS keep their roles for AI in banking, investments and insurance.

Italy's law also adds a new crime: spreading AI-faked or altered images, video or audio without consent, in a way that misleads people and causes them unjust harm, can bring one to five years in prison.

If you live elsewhere in the EU, your country's authority will differ.

Key dates at a glance

Date What applies
1 August 2024 The AI Act enters into force
2 February 2025 First eight bans; AI literacy duty for firms
2 August 2025 Rules for general-purpose AI models; countries name their authorities
27 July 2026 Digital omnibus amendments enter into force
2 August 2026 Most of the Act applies; transparency rules; enforcement begins
2 December 2026 Ban on nudification and child abuse imagery apps; watermarking deadline for older tools
2 August 2027 Each EU country must have at least one AI "regulatory sandbox" (a supervised test space for firms)
2 December 2027 High-risk rules for hiring, credit, education, public services and similar uses
2 August 2028 High-risk rules for AI built into regulated products

Sources: European Commission and AI Act Service Desk.

How this was made

This explainer was drafted with AI assistance from the official text of the AI Act, the European Commission's AI Act pages and Service Desk timeline, and legal analysis of the 2026 amendments, then checked and edited by a human. It is general information, not legal advice.

Sources

  1. EUR-Lex: Regulation (EU) 2024/1689 (Artificial Intelligence Act)
  2. European Commission: AI Act, regulatory framework for AI
  3. AI Act Service Desk (European Commission): Timeline for the implementation of the EU AI Act
  4. AI Act Explorer (Future of Life Institute): Digital Omnibus on AI
  5. AI Act Explorer: Article 85, Right to lodge a complaint
  6. AI Act Explorer: Article 86, Right to explanation of individual decision-making
  7. AI Act Explorer: Article 99, Penalties
  8. White & Case: EU AI Omnibus enters into force, amending the AI Act
  9. Gibson Dunn: EU AI Act Omnibus agreement, postponed high-risk deadlines and other key changes
  10. Jones Walker: Yes, August 2 still matters, the EU approved a high-risk AI delay but most transparency obligations remain
  11. Cleary Gottlieb: Italy adopts the first national AI law in Europe complementing the EU AI Act