Home › AI Governance Insights › The EU AI Act, Explained: Risk Tiers, Obligations, and the Current Timeline
The EU AI Act, Explained: Risk Tiers, Obligations, and the Current Timeline
By GRC Careers Team, Frameworks & Regulation · August 15, 2026 · 11 min read min read
Key Takeaways
- The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law governing artificial intelligence. It regulates AI by risk, not by technology.
- It sorts AI into four tiers: prohibited practices, high-risk systems, limited-risk systems with transparency duties, and minimal-risk systems with no new obligations.
- The 2025 Digital Omnibus (Regulation (EU) 2026/1744) moved the heaviest high-risk deadlines back, but transparency duties and the prohibitions stayed live and the penalties did not soften.
- It reaches far beyond Europe. Providers placing AI on the EU market and deployers whose AI output is used in the EU are covered, wherever they are based.
- Compliance is built on evidence that accumulates over time: technical documentation, data governance records, logging, and post-market monitoring. It cannot be produced at the last minute.

Listen to this guide
Prefer audio? A conversational, 23-minute walkthrough of the EU AI Act and what it means for how organizations govern AI.
The European Union's Artificial Intelligence Act is the first broad, horizontal law written specifically to govern AI. It entered into force on 1 August 2024 as Regulation (EU) 2024/1689, and its obligations phase in over several years. For anyone building an AI governance program, it is the single most consequential piece of regulation in the field, and its influence extends well past Europe's borders.
This guide explains what the Act does, how its risk tiers work, which obligations fall on whom, when each part applies after the 2025 Digital Omnibus amendments, and how the Act sits alongside the NIST AI Risk Management Framework and ISO/IEC 42001.
A risk-based law, not a technology law
The Act does not try to define or restrict AI by how it is built. It regulates AI by what it is used for and how much harm it could cause. That single design choice explains almost everything about how the law is structured. The same underlying model can sit in a minimal-risk product in one deployment and a high-risk system in another. The obligations follow the use case and its potential impact on people, not the algorithm.
The four risk tiers
- Unacceptable risk (prohibited). A short list of practices banned outright under Article 5, including social scoring by public authorities, certain manipulative or exploitative systems, untargeted scraping of facial images, and most real-time remote biometric identification in public spaces.
- High risk. The core of the Act. Annex III lists stand-alone use cases such as AI used in employment, education, access to credit and essential services, law enforcement, migration, and the administration of justice. Annex I covers AI used as a safety component of products already regulated under EU law. High-risk systems carry the heaviest obligations.
- Limited risk (transparency). Systems such as chatbots, emotion-recognition tools, and generators of synthetic media must tell people they are interacting with AI or that content is AI-generated, under Article 50.
- Minimal risk. Everything else, the large majority of AI, carries no new legal obligations under the Act.
The application timeline after the Digital Omnibus
The Act applies in stages. By late 2025 the original schedule was running ahead of the standards, guidance, and national authorities needed to support it, so the Commission proposed the Digital Omnibus on AI. The resulting instrument, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the heaviest high-risk deadlines back, while leaving the transparency duties and the prohibitions on their original timeline.
| Date | What applies |
|---|---|
| 2 Feb 2025 | Prohibited practices (Article 5) and the AI literacy duty (Article 4). In force, unchanged. |
| 2 Aug 2025 | Obligations for providers of general-purpose AI (GPAI) models. |
| 2 Aug 2026 | General application, including the Article 50 transparency obligations. Not deferred. |
| 2 Dec 2027 | High-risk obligations for stand-alone Annex III systems (employment, credit, essential services, and more). Deferred from 2 Aug 2026. |
| 2 Aug 2028 | High-risk obligations for AI embedded in products regulated under Annex I. Deferred from 2 Aug 2027. |
Do not read the delay as a reprieve. Conformity assessment for high-risk systems depends on technical documentation, data governance records, logging, and post-market monitoring evidence that has to accumulate over time. Evidence cannot be backdated. The extra months are enough to build a defensible program, and not enough to build one from nothing starting in 2027.
Who the Act applies to
The Act reaches organizations far outside the EU, an effect often called the Brussels effect. Its two most important roles are:
- Providers develop an AI system or a GPAI model and place it on the EU market or put it into service under their own name, wherever they are established. Providers of high-risk systems carry the bulk of the obligations: a risk-management system, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, a quality management system, and conformity assessment before the system goes to market.
- Deployers use an AI system in a professional capacity. A deployer outside the EU is still covered where the output of the system is used in the EU. Deployer duties are lighter but real: use the system according to instructions, ensure human oversight, monitor operation, and in some cases run a fundamental-rights impact assessment.
General-purpose AI models
The Act sets a separate track for general-purpose AI, the large foundation models that power many downstream products. All GPAI providers owe transparency and documentation duties. Models judged to carry systemic risk face additional obligations around evaluation, risk mitigation, incident reporting, and cybersecurity. The GPAI Code of Practice gives providers a route to demonstrate compliance.
Penalties
Enforcement has teeth, and the Digital Omnibus did not soften it. Breaching the prohibitions can bring fines up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. Most other breaches carry a lower tier of up to 15 million euros or 3 percent of turnover. Supplying incorrect information to authorities carries its own penalty band.
How the Act fits with NIST and ISO/IEC 42001
The EU AI Act is law: it sets binding obligations tied to role and risk classification. It does not tell you, step by step, how to build the program that produces compliance. That is where the voluntary frameworks come in. The NIST AI Risk Management Framework gives you a risk vocabulary and process. ISO/IEC 42001 gives you a certifiable management system whose controls generate much of the evidence the Act expects. A program anchored in those frameworks will satisfy a large share of what the Act asks for, with the marginal work per obligation becoming documentation, notices, and conformity assessment rather than a rebuild. For the mapping in detail, see how the EU AI Act maps to NIST AI RMF and how ISO/IEC 42001 maps to the law.
Careers Insight
The EU AI Act is why AI governance hiring is accelerating worldwide. Its extraterritorial reach means US and global firms need people who can translate its obligations into an audit-ready program. Browse open EU AI Act roles and AI governance jobs on GRC Careers.
None of the dates or figures above should be treated as legal advice. The Act is complex, guidance continues to evolve, and classification often turns on the specific use case. Confirm your obligations with qualified counsel for the jurisdictions you operate in.
Frequently Asked Questions
What is the EU AI Act?
The EU AI Act, Regulation (EU) 2024/1689, is the first comprehensive law governing artificial intelligence. It regulates AI by risk rather than by technology, setting obligations that scale with a system's potential to cause harm.
What are the EU AI Act risk tiers?
Four: unacceptable risk (prohibited practices), high risk (heavy obligations, including employment, credit, and essential-services uses), limited risk (transparency duties such as disclosing AI interaction), and minimal risk (no new obligations).
When does the EU AI Act take effect?
In stages. Prohibited practices and the AI literacy duty applied from 2 February 2025, GPAI obligations from 2 August 2025, general application and Article 50 transparency from 2 August 2026. After the Digital Omnibus (Regulation (EU) 2026/1744), high-risk obligations for stand-alone Annex III systems apply from 2 December 2027 and for Annex I embedded systems from 2 August 2028.
Does the EU AI Act apply outside the EU?
Frequently yes. It reaches providers who place AI systems on the EU market regardless of where they are established, and deployers outside the EU where the system's output is used in the EU. This extraterritorial reach is why firms worldwide are building AI governance programs.
What are the penalties under the EU AI Act?
Breaching the prohibitions can bring fines up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. Most other breaches carry up to 15 million euros or 3 percent of turnover. The 2025 Digital Omnibus deferred some deadlines but did not soften the penalties.
How does the EU AI Act relate to NIST AI RMF and ISO/IEC 42001?
The Act is binding law; NIST AI RMF and ISO/IEC 42001 are voluntary frameworks. NIST gives a risk process and vocabulary, and ISO/IEC 42001 gives a certifiable management system whose controls generate much of the evidence the Act expects. A program built on those frameworks satisfies a large share of the Act's requirements.
- Founder of ExecSearches and GRC Careers
- Executive search across corporate, higher education, financial services, and nonprofit sectors
- Focus on AI governance and GRC hiring
- More than a decade in risk advisory and internal audit in financial services
- Led SOX and regulatory audits for Citi, Goldman Sachs, Morgan Stanley, and McKesson
- Public Accounting Certification, Cornell University
Who's Hiring AI Governance Professionals?
Explore current openings in:
AI Governance · Responsible AI · AI Risk · AI Compliance · AI Audit · AI Policy