EU AI Act
Regulating Artificial Intelligence in the European Union
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689), or the AI Act, creates a common framework for the development, supply and use of artificial intelligence in the European Union.
The Act entered into force on 1 August 2024 and applies in stages. It was amended in July 2026 by Regulation (EU) 2026/1744, known as the Digital Omnibus on AI. The amendments clarify the high-risk regime, introduce new prohibited practices and modify certain compliance and supervisory rules.
The applicable requirements depend mainly on: the purpose and use of the AI system; the organisation's role; and the risks created for people, safety and fundamental rights.
Who Is Covered and How Risk Is Classified
Operator Roles
The AI Act assigns different responsibilities to different operators. A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority in a professional context, for example for recruitment, fraud detection or customer management. An importer brings an AI system from a non-EU provider onto the EU market, and a distributor makes an AI system available within the EU supply chain.
These roles can change. An organisation may become a provider if it substantially modifies a system, changes its intended purpose or markets it under its own name. The Act may also apply to organisations outside the EU, including where the output of their AI system is used in the EU.
Risk-Based Framework
For general understanding, the AI Act can be divided into four broad areas: prohibited AI practices; high-risk AI systems; systems and content subject to transparency requirements; and other AI systems. This is a simplified explanation, not a formal four-tier classification in the Act. Separate rules also apply to providers of general-purpose AI models.
Classification is based on the system's intended purpose and context of use, not simply on the underlying technology.
Prohibited Practices and High-Risk AI Systems
Prohibited AI Practices (Article 5)
Article 5 prohibits defined AI practices considered incompatible with safety, fundamental rights or European values. These include certain forms of harmful manipulation, exploitation of vulnerabilities, social scoring and biometric categorisation. The prohibitions also cover untargeted scraping of facial images and emotion recognition in workplaces and educational institutions.
Real-time remote biometric identification in public spaces for law-enforcement purposes is generally prohibited, subject to limited exceptions and safeguards.
From 2 December 2026, additional prohibitions apply to specified practices involving: realistic AI-generated or manipulated intimate or sexually explicit material depicting an identifiable person without explicit consent; and AI-generated or manipulated child sexual abuse material. These new rules include detailed conditions and exclusions. For providers, the system's intended purpose, foreseeable misuse and technical safeguards are relevant. For deployers, the prohibition applies to deliberate use for the prohibited purpose.
When Is an AI System High-Risk?
An AI system is not high-risk simply because it is powerful, complex or used by a large organisation. Classification is a legal assessment under Article 6 and the relevant annexes. There are two main routes to high-risk status:
- AI used as a product, or as a safety component of a product, covered by specified EU product legislation and requiring third-party conformity assessment;
- Uses listed in Annex III, including certain systems that can materially affect employment, education, essential services, critical infrastructure, law enforcement, migration or access to justice.
The system's actual purpose is decisive. For example, software used only to improve the wording of a job advertisement is not equivalent to a system that filters applicants or influences recruitment decisions. Similar technology can therefore receive different legal treatment in different contexts.
The Digital Omnibus also clarifies the meaning of a safety component. AI used only for convenience, efficiency, automation, quality control or performance optimisation does not normally qualify. However, it may qualify where it is intended to prevent or reduce safety risks, or where its failure would endanger people or property.
What Does High-Risk Status Mean?
High-risk AI systems are permitted, but subject to stricter controls throughout their lifecycle.
Providers must be able to demonstrate that risks have been assessed and controlled, the system has been appropriately tested and documented, and its performance can be monitored. Requirements cover matters such as data governance, logging, human oversight, accuracy, cybersecurity, conformity assessment and post-market monitoring.
Deployers must use the system according to its instructions, ensure suitable human oversight and monitor its operation in their environment. Certain deployers must also conduct a fundamental rights impact assessment. Relevant parts of an existing GDPR data-protection impact assessment may be reused or cross-referenced where they address the same issues.
The Digital Omnibus introduces proportionate arrangements for SMEs, start-ups and small mid-cap enterprises, including simplified technical documentation and quality-management measures. These arrangements reduce administrative burdens but do not remove the underlying obligations.
Transparency and Synthetic Content
Some AI systems are subject to transparency requirements even when they are not high-risk. Depending on the circumstances, people may need to be informed that they are interacting with AI or are exposed to emotion-recognition or biometric-categorisation technology. Deep-fake content may need to be disclosed as artificially generated or manipulated.
Providers of systems generating synthetic audio, images, video or text may also need to mark their outputs in a machine-readable and detectable format. For relevant systems placed on the market before 2 August 2026, the deadline for compliance with the content-marking obligation is 2 December 2026.
General-Purpose AI, AI Literacy and Penalties
General-Purpose AI
General-purpose AI models can perform a broad range of tasks and can be integrated into many downstream systems. Their providers are subject to separate requirements concerning technical documentation, information for downstream providers, copyright compliance and publication of information about training content. Additional requirements apply to models presenting systemic risk.
Using a general-purpose model does not automatically make an organisation its provider. However, responsibilities may change if the organisation substantially modifies the model or places a resulting system on the market under its own name.
AI Literacy
Providers and deployers must take measures to support the AI literacy of employees and other people who operate or use AI systems on their behalf. The measures should reflect the people involved, their knowledge and experience, the context of use and the possible effects on others. The Act does not require every individual to reach a prescribed level of expertise. AI literacy is therefore a proportionate governance obligation, not a requirement to provide identical training to all personnel.
Monitoring and Serious Incidents
Providers of high-risk AI systems must monitor their systems after they are placed on the market. Serious incidents must generally be reported within 15 days after the provider becomes aware of them. Shorter deadlines apply: 10 days where an incident results in a person's death, and two days for certain widespread infringements or serious and irreversible disruption of critical infrastructure. The applicable deadline and reporting authority must be assessed for each incident.
Supervision and Penalties
National authorities supervise most AI systems. Following the Digital Omnibus, the European AI Office has exclusive competence over certain systems based on general-purpose AI models and systems integrated into designated very large online platforms or search engines.
Maximum fines include:
Infringement Maximum fine Prohibited AI practices €35 million or 7% of worldwide annual turnover Other specified infringements €15 million or 3% of worldwide annual turnover Incorrect, incomplete or misleading information €7.5 million or 1% of worldwide annual turnover Different maximum-fine rules apply to SMEs, start-ups and small mid-cap enterprises. The actual penalty depends on the circumstances of the infringement.
Application Timetable and the Luxembourg Context
Application Timetable
The AI Act applies progressively:
Date Main provisions 2 February 2025 General provisions, original prohibited practices and AI literacy 2 August 2025 Governance and general-purpose AI model obligations 27 July 2026 Certain governance and mutual-assistance provisions 2 December 2026 New prohibited practices and transitional content-marking deadline 2 December 2027 High-risk rules for systems classified under Article 6(2) and Annex III 2 August 2028 High-risk rules for regulated products under Article 6(1) and Annex I 2 August 2030 Compliance deadline for specified high-risk systems used by public authorities Transitional provisions may apply to systems already lawfully placed on the market. A significant design change may bring an existing system within the full compliance regime.
The Luxembourg Context
Luxembourg's national framework for implementing the AI Act is set out in Bill of Law 8476.
As of September 2026, the Bill has not yet been voted on by the Luxembourg Parliament. The proposed allocation of national supervisory and enforcement responsibilities is therefore not yet final and may change during the legislative process.
This does not suspend the AI Act or its applicable deadlines. As an EU regulation, the AI Act is directly applicable. However, until the national legislation is adopted, organisations should follow the progress of Bill 8476 and any guidance from the relevant Luxembourg authorities.
Legislative Framework Reference
Level Legislation (or equivalent) Comments 1 AI Act (Regulation (EU) 2024/1689) EU Law which entered into force on 1 August 2024. Applies in stages; see application timetable. 1 Digital Omnibus on AI (Regulation (EU) 2026/1744) Amends the AI Act: clarifies the high-risk regime, introduces new prohibited practices and modifies compliance and supervisory rules. 1 Bill of Law 8476 (Luxembourg) National implementing law, pending as of September 2026