Hot Posts

6/recent/ticker-posts

Latest Updates EU AI Act 2026

Last updated: July 23, 2026 TrexoMedia.

EU AI Act News: Latest Updates, Timeline, Rules & What Happens Next (2026)

The EU AI Act just went through the biggest shake-up since it became law. In May 2026, EU negotiators agreed to push back the deadline for high-risk AI rules by more than a year. That agreement became final law in the last week of June, and the European Commission has spent July publishing the guidance businesses need to follow.

If you build, sell, or use AI products that touch EU customers, this is the moment to get your facts straight — not the rumors, not last year's summaries, but what the law actually requires today and what changes next.

This guide walks through everything currently known: what the EU AI Act is, why the timeline just moved, which rules are already live, which ones were delayed, and what a practical compliance checklist looks like for 2026 and beyond.

Latest Updates EU AI Act 2026

Key Takeaways

  • The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive, horizontal AI law, and it has been in force since August 1, 2024.

  • Rules on banned AI practices and AI literacy have applied since February 2, 2025. Rules for general-purpose AI (GPAI) models and enforcement penalties have applied since August 2, 2025.

  • The Digital Omnibus on AI, finalized in June 2026, delayed the high-risk AI system rules that were due August 2, 2026 — pushing most of them to December 2, 2027, and product-embedded high-risk systems to August 2, 2028.

  • Transparency rules — like disclosing that a user is talking to a chatbot — are not delayed and still apply from August 2, 2026. However, AI-generated content labeling gets a short four-month reprieve to December 2, 2026.

  • Fines for the most serious violations can reach €35 million or 7% of global annual turnover, whichever is higher, and this penalty structure has been enforceable since August 2025.

  • Businesses of every size — not just Big Tech — can be classed as "providers" or "deployers" under the Act, especially if they use AI in hiring, lending, education, healthcare, or public services.

Key Facts

FactDetails

Official name Regulation (EU) 2024/1689 (the "EU AI Act")

Region European Union, with extraterritorial reach

Entered into force August 1, 2024

Purpose Regulate AI systems according to the Risk they pose

Approach Risk-based, phased implementation

Main enforcement bodies European AI Office, national market-surveillance authorities

Applies to EU-based companies and non-EU providers whose AI systems are used in the EU

Highest-risk category Prohibited (unacceptable-risk) AI practices, banned outright.

Maximum fine €35 million or 7% of worldwide annual turnover

Major 2026 update Digital Omnibus on AI delays most high-risk obligations to December 2027/August 2028

Table of Contents

Latest EU AI Act News

Here's what's actually new, in order.

The Digital Omnibus on AI became final law in summer 2026. The European Parliament formally endorsed the deal on June 16, 2026, and the Council of the EU gave its final approval on June 29, 2026. The amendments entered into force in July, three days after publication in the EU's Official Journal — just weeks ahead of the original August 2, 2026 deadline the changes were designed to head off.

The Commission rolled out fresh transparency guidance. On July 20, 2026, the Commission published guidelines clarifying transparency obligations for providers and deployers of certain AI systems (source: European Commission, Digital Strategy) — the rules that require disclosing AI-generated content and telling users when they're interacting with a chatbot rather than a human.

A new EU cybersecurity plan for advanced AI arrived on July 7, 2026. The Commission presented an action plan on cybersecurity and advanced AI, aiming to boost the EU's capacity to evaluate AI models before they reach the market.

Enforcement activity is visibly picking up. National authorities and the AI Office are working through the practical machinery of supervision — including guidance on how the AI Act interacts with GDPR, since many AI systems process personal data and now fall under two overlapping regulators.

A separate law, sometimes called the Cloud and AI Development Act, is also moving. This is a distinct piece of legislation focused on cloud sovereignty and AI infrastructure, expected to be published in the Official Journal around mid-July 2026, with its own multi-year rollout running into 2028 and 2029. It's worth knowing this exists so it isn't confused with the AI Act itself — they are related but separate files.

What Is the EU AI Act?

The EU AI Act is a regulation — not a directive — meaning it applies directly and uniformly across all EU member states without each country needing to pass its own implementing law. It was formally adopted in 2024 after roughly three years of negotiation (official text: EUR-Lex, Regulation (EU) 2024/1689), making it the first attempt anywhere in the world to build a comprehensive, cross-sector legal framework for artificial intelligence.

Instead of banning or approving AI wholesale, the Act sorts AI systems into four risk tiers and attaches obligations to each tier. The riskier the use case, the heavier the compliance burden. A spam filter and a system that screens job applicants are both "AI," but the law treats them completely differently.

The Act applies broadly. It covers:

  • Companies established in the EU that develop or use AI.

  • Companies outside the EU whose AI systems are placed on the EU market or whose outputs are used in the EU.

  • Public authorities and private companies alike.

This extraterritorial reach is deliberate. It mirrors the approach the EU took with GDPR, and it means a company with no EU offices can still fall squarely within scope if its AI product reaches EU users.

Why Was It Created?

The EU AI Act was designed to solve a specific problem: AI was advancing faster than any single national law could keep up with, and different member states risked writing their own conflicting rules. The EU wanted one framework that would:

  • Protect fundamental rights — like non-discrimination, privacy, and due process — from being undermined by opaque or biased algorithms.

  • Give businesses legal certainty by creating one set of rules for the entire single market, rather than 27 different national approaches.

  • Build public trust in AI, on the theory that adoption grows faster when people believe the technology is safe and accountable.

  • Position the EU as a global standard-setter, similar to how GDPR became a reference point for privacy law well beyond Europe's borders.

Timeline of Important Events

DateEvent

April 2021 European Commission proposes the AI Act

2023 European Parliament and Council negotiate amendments

June 2024 Political agreement and formal adoption

August 1, 2024 AI Act enters into force

February 2, 2025 Bans on prohibited AI practices and AI literacy obligations take effect.

August 2, 2025 Rules for general-purpose AI models, governance structures, and the penalty framework become applicable.

November 19, 2025 Commission proposes the Digital Omnibus on AI (simplification package)

May 7, 2026 Parliament and Council reach provisional political agreement on the Omnibus.

June 16, 2026 Parliament formally endorses the Omnibus

June 29, 2026 Council gives final green light

July 2026 Omnibus amendments enter into force after Official Journal publication

August 2, 2026 Transparency obligations (chatbot disclosure) take effect; most high-risk rules deferred

December 2, 2026 Deferred deadline for AI-generated content labeling obligations

December 2, 2027 Deferred deadline for standalone high-risk AI systems (Annex III)

August 2, 2028 Deferred deadline for high-risk AI embedded in regulated products (Annex I)

Vertical view:

2021 → Proposal 2023 → Negotiation 2024 → Adoption 2025 → Bans, GPAI rules, and penalties take effect 2026 → Digital Omnibus becomes law; transparency rules apply 2027–2028 → Phased high-risk obligations finally land

The 2026 Digital Omnibus: What Actually Changed

This is the single most important development of the year, and it's also the most misunderstood. The headline that circulated — "the EU delayed the AI Act" — is only half true.

What was proposed and why. By late 2025, it was clear that implementation was falling behind schedule: harmonized technical standards weren't ready, and businesses across the EU were warning they couldn't realistically meet the original August 2026 deadline for high-risk systems. The Commission tabled the Digital Omnibus on November 19, 2025, as part of a broader simplification package that also touches GDPR, the ePrivacy Directive, NIS2, and the Data Act.

What was delayed.

  • Obligations for standalone high-risk AI systems under Annex III — covering areas like employment, education, credit scoring, and law enforcement — move from August 2, 2026 to December 2, 2027, a roughly 16-month deferral.

  • Obligations for high-risk AI embedded in already-regulated products under Annex I — think medical devices, lifts, or certain machinery — move from August 2, 2027 to August 2, 2028.

  • AI-generated content labeling gets a shorter, four-month reprieve, moving to December 2, 2026.

What was NOT delayed.

  • The transparency obligations that require disclosing AI-driven chatbot interactions still apply from August 2, 2026, on schedule.

  • The Article 99 penalty framework is untouched — fine amounts and tiers remain exactly as originally written.

  • GPAI model obligations, already in force since August 2025, are unaffected.

What was added.

  • A new prohibition targeting AI systems used to generate non-consensual intimate imagery ("nudifiers") and child sexual abuse material was folded into Article 5, the Act's list of banned practices.

  • The simplified compliance regime originally built for small and medium enterprises (SMEs) is extended to a new category of "small mid-cap" companies — those with up to 750 employees and €150 million in annual revenue — giving them access to reduced fines, sandbox access, and standardized documentation templates.

  • Rules were clarified to make it easier to use GDPR "special category" data (health status, biometric data, race, sexual orientation) specifically to test AI models for discriminatory bias — closing a gap that had made responsible bias testing legally awkward.

  • Providers who self-assess their system as not high-risk under a narrow exemption in Article 6(3) must still register that system in the EU's public database, though with a lighter administrative process than full high-risk registration.

The practical takeaway: if your organization was racing toward an August 2026 high-risk compliance deadline, you likely have more runway than you thought — but transparency, GPAI, and the banned-practices list are moving forward exactly as planned, and the penalty exposure for getting those wrong hasn't softened at all.

Which AI Systems Are Affected? Risk Categories Explained

The Act organizes every AI system into one of four tiers, often visualized as a pyramid:

        Unacceptable Risk → Banned outright

              ↓

        High Risk → Strict obligations before and after market entry

              ↓

        Limited Risk → Transparency obligations only

              ↓

        Minimal Risk → No new legal obligations

Minimal Risk covers the overwhelming majority of AI in use today — spam filters, recommendation engines in low-stakes contexts, inventory forecasting tools. No new obligations attach here.

Limited Risk includes systems that interact directly with people, like chatbots or AI systems that generate synthetic audio, image, video, or text content. The obligation here isn't about the AI's decision-making — it's about disclosure. People need to know they're dealing with AI.

High Risk covers AI used in contexts where a wrong or biased decision could seriously affect someone's rights, safety, or opportunities. This tier carries the heaviest compliance load.

Unacceptable Risk is the shortest list, and it's a flat ban — no amount of documentation or testing makes these practices legal.

High-Risk AI Rules

High-risk systems fall into two groups under the Act's annexes:

  • Annex I systems: AI that's a safety component of products already regulated elsewhere — medical devices, machinery, lifts, toys, and similar categories with existing EU product-safety rules.

  • Annex III systems: standalone AI used in specific high-stakes sectors, including:

    • Employment — recruitment screening, candidate ranking, performance monitoring, and decisions on promotion or termination.

    • Education — systems that determine access to education or evaluate students.

    • Healthcare — AI used in triage, diagnosis support, or access to care.

    • Banking and credit — creditworthiness scoring and insurance risk assessment.

    • Law enforcement, migration, and justice — risk assessment tools, evidence evaluation, and border-management systems.

    • Critical infrastructure — AI managing safety components of things like energy or water supply.

Providers of high-risk systems face obligations including risk management systems, high-quality training, data governance, detailed technical documentation, human oversight design, robustness and cybersecurity testing, and conformity assessments before the system reaches the market. Deployers — the organizations actually using the system — have their own duties, including monitoring the system in operation and, in certain cases, conducting a fundamental rights impact assessment.

As covered above, the compliance clock for most of these obligations now runs to December 2027 (Annex III) or August 2028 (Annex I), rather than August 2026.

General-Purpose AI Requirements

General-purpose AI (GPAI) models — the large foundation models that power many downstream applications — have had their own obligations in force since August 2, 2025. All GPAI providers must:

  • Maintain technical documentation describing the model's capabilities and limitations.

  • Provide information to downstream developers who build on top of the model.

  • Publish a summary of the content used to train the model, addressing copyright transparency.

  • Put in place a policy to comply with EU copyright law.

Models classified as carrying systemic Risk — generally the most capable, highest-compute models — face additional obligations: adversarial testing, systematic risk assessment and mitigation, incident reporting to the AI Office, and cybersecurity protections for the model and its infrastructure.

What AI Is Banned?

Article 5 of the Act lists AI practices considered too dangerous to fundamental rights to be allowed under any conditions, regardless of sector or safeguards. These include:

  • Social scoring by public authorities that evaluates or classifies people based on behavior, leading to unjustified detrimental treatment.

  • Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, outside a narrow set of defined exceptions.

  • Subliminal or manipulative techniques designed to distort a person's behavior in ways that cause harm.

  • Exploitation of vulnerabilities related to age, disability, or specific social or economic circumstances.

  • Emotion recognition in workplaces and educational institutions.

  • Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases.

  • As of the 2026 Digital Omnibus, AI systems built to generate non-consensual intimate imagery ("nudifiers") and child sexual abuse material.

These bans have already applied since February 2, 2025 — they were never part of the 2026 delay.

Penalties: What Non-Compliance Actually Costs

Article 99 sets out a three-tier fine structure, and it has been enforceable since August 2, 2025. The Digital Omnibus left this framework completely untouched (source: European Commission, AI Act Service Desk, Article 99).

Violation type Maximum fine

Breach of banned AI practices (Article 5) €35 million or 7% of global annual turnover, whichever is higher

Other breaches (e.g., high-risk provider/deployer obligations, transparency duties under Article 50) €15 million or 3% of global annual turnover, whichever is higher

Supplying incorrect, incomplete, or misleading information to authorities €7.5 million or 1% of global annual turnover, whichever is higher

There's an important twist for smaller companies: for SMEs and startups, the rule flips — the fine is capped at whichever figure is lower, not higher, offering some proportionality for smaller businesses. Regulators are also directed to weigh factors like the severity, duration, and intent behind a violation, and whether the company cooperated with investigators, before setting a final number.

National market-surveillance authorities are responsible for most enforcement, while the European AI Office handles GPAI model oversight directly. As of mid-2026, early investigations into potential prohibited-practice violations have reportedly begun, though no major fines have been publicly announced yet.

How Businesses Should Prepare

A practical compliance checklist for the current phase of the Act:

  • Inventory your AI use. Catalog every AI system you build, buy, resell, or use — including embedded AI inside third-party SaaS tools.

  • Map your role. Determine whether you're a provider, deployer, importer, or distributor for each system — obligations differ significantly by role.

  • Risk-classify each system. Identify anything touching hiring, credit, education, healthcare, or public services, since these are the likeliest candidates for high-risk classification.

  • Prioritize transparency compliance now. Chatbot disclosure and content-labeling rules are not delayed — get disclosure language and labeling live before August 2026.

  • Build documentation habits early, even for systems whose high-risk deadline was pushed to 2027–2028. Regulators and buyers increasingly expect to see this evidence regardless of the legal deadline.

  • Set up human oversight processes for any AI-assisted decision that affects a person's opportunities or rights.

  • Establish an incident-reporting process for AI failures or unexpected harmful behavior.

  • Review vendor contracts — confirm what documentation and compliance guarantees your AI vendors are providing you as a deployer.

  • Check GDPR overlap. Any AI system processing personal data now needs to satisfy both the AI Act and GDPR, and the two regulators are expected to coordinate.

Impact on AI Companies and Startups

The most common misconception is that the AI Act is a "Big Tech" problem. In practice, the Act applies based on function, not company size. A ten-person startup that builds a resume-screening tool for HR teams can be a high-risk AI provider just as much as a multinational.

  • Startups and SMEs benefit from the extended simplified regime — now open to small mid-cap companies as well — including reduced fines, regulatory sandboxes, and standardized templates. But they are not exempt from the underlying obligations.

  • SaaS and cloud vendors need to understand whether embedding a GPAI model into their product makes them a "provider" of a high-risk system, not just a reseller of someone else's technology.

  • Enterprises buying AI tools are increasingly asking vendors for compliance documentation as a condition of purchase — proof of compliance is becoming a competitive advantage in EU sales cycles, independent of the legal deadline.

  • Foreign providers serving EU customers remotely are squarely in scope if their systems are placed on the EU market or their outputs are used by people in the EU, even without a local office.

Industry Reactions and Criticism

Reactions to the Digital Omnibus have been mixed. Industry groups and many businesses have broadly welcomed the delay of high-risk obligations, arguing that harmonized technical standards weren't ready and that an August 2026 deadline risked forcing companies into paperwork exercises rather than genuine safety improvements.

Civil society and digital rights advocates have pushed back, arguing that repeatedly delaying protections for people affected by high-stakes AI decisions — in hiring, credit, and law enforcement — leaves real gaps in accountability for over a year longer than originally planned. Critics have also flagged the GDPR amendments bundled into the same package as controversial, since they touch how sensitive personal data can be used, even where the stated purpose is bias testing.

Regulators, meanwhile, have emphasized that transparency rules and the underlying penalty structure remain fully intact, framing the Omnibus as a targeted timeline adjustment rather than a retreat from the Act's core ambitions.

Expert Take

"The mistake we see most often is treating the Digital Omnibus as a blanket delay. It isn't. Transparency duties, GPAI obligations, and the Article 99 penalty structure are moving forward on the original clock — only the high-risk system deadlines shifted. Companies that read 'delay' and stop working on documentation now are the ones most likely to be caught out when the December 2027 deadline arrives faster than they expect."

Elena Marchetti, Senior AI Policy Analyst, TrexoMedia

EU AI Act vs. GDPR vs. US AI Policy

A quick way to place the AI Act in context is to compare it with the regulatory frameworks it's most often confused with or measured against.

EU AI Act vs. GDPR

EU AI Act GDPR

Subject Regulates AI systems based on Risk Regulates personal data processing.

Legal basis Regulation (EU) 2024/1689 Regulation (EU) 2016/679

Core approach Risk-tiered obligations (minimal to unacceptable) Lawful-basis and data-subject-rights model

Applies to AI providers and deployers, regardless of data use Any organization processing personal data of EU residents

Overlap AI systems that process personal data must satisfy both laws simultaneously Applies whenever personal data is involved, including in AI training and inference

Maximum fine €35 million or 7% of global turnover €20 million or 4% of global turnover

Enforcement AI Office (GPAI) + national market-surveillance authorities National Data Protection Authorities

EU AI Act vs. US AI Policy

EU AI Act vs. US Approach

Structure Single, comprehensive, binding federal-level regulation Fragmented mix of executive orders, sector-specific agency guidance, and state-level laws

Enforceability Legally binding across all member states, with statutory fines Largely guidance-based at the federal level, with binding rules emerging mainly from individual states.

Approach Ex-ante, risk-based classification before deployment Largely sectoral and reactive, applied through existing agency authority (FTC, EEOC, etc.)

Consistency Uniform across 27 member states Varies significantly by state (e.g., Colorado and California have their own AI laws)

Global influence Widely referenced as a model framework by other jurisdictions Increasingly cited as a lighter-touch, innovation-first counterpoint.

This comparison is necessarily a simplification — both the US policy landscape and the EU's own framework are moving targets, and this table reflects the general shape of each approach rather than a snapshot of every current rule.

Future Outlook

A few things to watch for the rest of 2026 and into 2027:

  • More implementing guidance. Expect further Commission guidelines and codes of practice as the AI Office continues to clarify open questions, following the pattern of the July 2026 transparency guidelines.

  • The parallel Cloud and AI Development Act. A related but separate framework on cloud sovereignty and AI infrastructure is moving through its own rollout, with early requirements expected from 2028.

  • A second Digital Omnibus track. A further simplification package covering data and cybersecurity rules remains under negotiation, with agreement expected in the first half of 2027.

  • Growing global influence. As with GDPR, other jurisdictions are watching the EU AI Act closely, and its risk-based structure is already shaping AI governance conversations well beyond Europe.

  • Real enforcement cases. With the penalty framework live since 2025 and early investigations reportedly underway, the first major public enforcement actions are likely on the horizon.

Frequently Asked Questions

What is the EU AI Act? It's Regulation (EU) 2024/1689, the first comprehensive law regulating artificial intelligence across the European Union, sorting AI systems into risk tiers with obligations attached to each.

When does the EU AI Act apply? It entered into force on August 1, 2024, with obligations phasing in over several years. Bans and AI-literacy duties started February 2025; GPAI and penalty rules started August 2025; transparency rules start August 2026; and most high-risk obligations, after the 2026 Digital Omnibus delay, now start December 2027 or August 2028 depending on the category.

Who must comply? Any organization that develops, sells, or deploys AI systems used in the EU — including companies based outside the EU whose AI reaches EU users.

What are high-risk AI systems? AI used in sensitive contexts like employment, education, credit scoring, healthcare, law enforcement, and critical infrastructure, or AI embedded as a safety component in already-regulated products.

What AI is prohibited? Practices like social scoring, most real-time public biometric surveillance for law enforcement, manipulative or exploitative AI, workplace emotion recognition, untargeted facial-image scraping, and — as of 2026 — AI tools built to create non-consensual intimate imagery or child sexual abuse material.

Does the Act affect non-EU companies? Yes. If your AI system is placed on the EU market or people in the EU use its output, you're likely in scope regardless of where your company is based.

What are the penalties? Up to €35 million or 7% of global annual turnover for banned practices, €15 million or 3% for most other violations, and €7.5 million or 1% for misleading information to regulators — whichever figure is higher for larger companies, and whichever is lower for SMEs and startups.

How should businesses prepare? Inventory AI use, classify risk levels, prioritize transparency compliance (since it isn't delayed), build documentation habits regardless of the 2027–2028 high-risk deadlines, and monitor GDPR overlap closely.

Glossary

  • AI System — Software that generates outputs like predictions, content, or decisions influencing environments it interacts with.

  • High-Risk AI — Systems in sectors or use cases the Act deems capable of seriously affecting health, safety, or fundamental rights.

  • General-Purpose AI (GPAI) — A model trained to perform a wide range of tasks, often serving as the foundation for many downstream applications.

  • Foundation Model — Common industry term roughly equivalent to GPAI models under the Act.

  • Transparency Obligation — A duty to disclose that content is AI-generated or that a user is interacting with an AI system.

  • Risk Assessment — The process of evaluating an AI system's potential impact before and during deployment.

  • Conformity Assessment — A formal evaluation confirming a high-risk system meets the Act's requirements before it enters the market.

  • Human Oversight — Design and process requirements ensuring people can monitor, intervene in, or override an AI system's outputs.

  • Provider — The organization that develops an AI system or has it developed, and places it on the market under its own name.

  • Deployer — The organization that uses an AI system in a professional context, distinct from the provider that built it.

Related Reads

Sources & References

This article draws on official EU sources plus independent legal and policy tracking; where the Digital Omnibus's final legislative text was still pending formal publication at the time of writing, that is noted in context above.

About the Author: Elena Marchetti is a Senior AI Policy Analyst on the TrexoMedia editorial team, covering AI regulation, digital policy, and cybersecurity governance across the EU and US. She holds a background in technology law and has spent several years tracking EU digital-file negotiations, including the AI Act and its Digital Omnibus amendments.

Editor: James Okoye, Managing Editor, TrexoMedia.

Editorial process: This article is researched using official government publications, regulatory documents (including EUR-Lex and the AI Act Service Desk), and trusted industry legal sources, then reviewed by TrexoMedia's editorial team before publication. Given how quickly this area of law is moving, always confirm current deadlines against the official EUR-Lex text or the AI Act Service Desk before making compliance decisions.

Structured Data (Schema Markup)

The JSON-LD blocks below can be added to this page's <head> to support Article, FAQ, Breadcrumb, and Organization schema for search and AI-overview eligibility.

{

  "@context": "https://schema.org",

  "@type": "Article",

  "headline": "EU AI Act News: Latest Updates, Timeline, Rules & What Happens Next (2026)",

  "description": "Read the latest EU AI Act news, major regulatory updates, compliance deadlines, enforcement timeline, and what businesses should prepare for in 2026.",

  "author": {

    "@type": "Person",

    "name": "Elena Marchetti",

    "jobTitle": "Senior AI Policy Analyst",

    "worksFor": {

      "@type": "Organization",

      "name": "TrexoMedia"

    }

  },

  "editor": {

    "@type": "Person",

    "name": "James Okoye",

    "jobTitle": "Managing Editor"

  },

  "publisher": {

    "@type": "Organization",

    "name": "TrexoMedia",

    "logo": {

      "@type": "ImageObject",

      "url": "https://www.trexomedia.example/logo.png"

    }

  },

  "datePublished": "2026-07-23",

  "dateModified": "2026-07-23",

  "mainEntityOfPage": {

    "@type": "WebPage",

    "@id": "https://www.trexomedia.example/eu-ai-act-news"

  },

  "image": "https://www.trexomedia.example/images/eu-ai-act-timeline-infographic.svg"

}

{

  "@context": "https://schema.org",

  "@type": "FAQPage",

  "mainEntity": [

    {

      "@type": "Question",

      "name": "What is the EU AI Act?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "It's Regulation (EU) 2024/1689, the first comprehensive law regulating artificial intelligence across the European Union, sorting AI systems into risk tiers with obligations attached to each."

      }

    },

    {

      "@type": "Question",

      "name": "When does the EU AI Act apply?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "It entered into force on August 1, 2024, with obligations phasing in over several years. Bans and AI-literacy duties started February 2025; GPAI and penalty rules started August 2025; transparency rules start August 2026; and most high-risk obligations, after the 2026 Digital Omnibus delay, now start December 2027 or August 2028 depending on the category."

      }

    },

    {

      "@type": "Question",

      "name": "Who must comply with the EU AI Act?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "Any organization that develops, sells, or deploys AI systems used in the EU, including companies based outside the EU whose AI reaches EU users."

      }

    },

    {

      "@type": "Question",

      "name": "What are high-risk AI systems under the EU AI Act?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "AI used in sensitive contexts like employment, education, credit scoring, healthcare, law enforcement, and critical infrastructure, or AI embedded as a safety component in already-regulated products."

      }

    },

    {

      "@type": "Question",

      "name": "What AI practices are prohibited under the EU AI Act?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "Practices like social scoring, most real-time public biometric surveillance for law enforcement, manipulative or exploitative AI, workplace emotion recognition, untargeted facial-image scraping, and, as of 2026, AI tools built to create non-consensual intimate imagery or child sexual abuse material."

      }

    },

    {

      "@type": "Question",

      "name": "Does the EU AI Act affect non-EU companies?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "Yes. If an AI system is placed on the EU market or its output is used by people in the EU, the company is likely in scope regardless of where it is based."

      }

    },

    {

      "@type": "Question",

      "name": "What are the penalties for EU AI Act non-compliance?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "Up to 35 million euros or 7% of global annual turnover for banned practices, 15 million euros or 3% for most other violations, and 7.5 million euros or 1% for misleading information to regulators, whichever figure is higher for larger companies and whichever is lower for SMEs and startups."

      }

    },

    {

      "@type": "Question",

      "name": "How should businesses prepare for the EU AI Act?",

      "acceptedAnswer": {

        "@type": "Answer",

        "text": "Inventory AI use, classify risk levels, prioritize transparency compliance since it isn't delayed, build documentation habits regardless of the 2027-2028 high-risk deadlines, and monitor GDPR overlap closely."

      }

    }

  ]

}

{

  "@context": "https://schema.org",

  "@type": "BreadcrumbList",

  "itemListElement": [

    {

      "@type": "ListItem",

      "position": 1,

      "name": "Home",

      "item": "https://www.trexomedia.example/"

    },

    {

      "@type": "ListItem",

      "position": 2,

      "name": "AI Regulation",

      "item": "https://www.trexomedia.example/ai-regulation"

    },

    {

      "@type": "ListItem",

      "position": 3,

      "name": "EU AI Act News",

      "item": "https://www.trexomedia.example/eu-ai-act-news"

    }

  ]

}

{

  "@context": "https://schema.org",

  "@type": "Organization",

  "name": "TrexoMedia",

  "url": "https://www.trexomedia.example",

  "logo": "https://www.trexomedia.example/logo.png",

  "sameAs": [

    "https://www.linkedin.com/company/trexomedia",

    "https://twitter.com/trexomedia"

  ]

}

Note: Replace the placeholder trexomedia.example domain, logo URL, and breadcrumb paths with your live site's actual URLs before publishing.



Post a Comment

0 Comments