Jurisdictions · European Union · reviewed 2026-09-21

🇪🇺 AI regulation in European Union

The EU AI Act (Regulation (EU) 2024/1689) applies to providers and deployers of AI systems in the EU, and to providers and deployers elsewhere when their systems or outputs are used in the EU. It works by risk: a short list of prohibited practices, heavy duties for high-risk systems, transparency duties for AI that talks to people or generates content, and an AI-literacy duty for everyone who provides or deploys AI.

The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) deferred the high-risk obligations to 2 December 2027 and 2 August 2028 and softened the literacy duty. It did not defer Article 50, which has applied since 2 August 2026.

Next date: Machine-readable marking of generative AI output, 2 Dec 2026 (in 71 days, upcoming).

European Union: obligations

DateObligationStatusWhoWhat and evidence
2 February 2025
597 days ago
AI literacy duty, Article 4
EU · EU AI Act (Reg. 2024/1689)
In force Providers and deployers of AI systems Take measures, to your best extent, so that staff and others operating AI on your behalf have sufficient AI literacy. The Digital Omnibus (July 2026) clarified that no specific level must be guaranteed. The duty itself was kept.
Evidence: Training register, training programme, validation of learning outcomes, written AI usage rules.
2 August 2025
416 days ago
General-purpose AI model obligations
EU · EU AI Act (Reg. 2024/1689)
In force Providers of general-purpose AI models only Technical documentation, copyright policy and a training-data summary for model providers, with extra duties for models with systemic risk. Companies that only use AI tools are not in scope.
Evidence: Not applicable to deployers.
2 August 2026
51 days ago
Transparency obligations, Article 50
EU · EU AI Act (Reg. 2024/1689)
In force Providers of AI that talks to people or generates content; deployers of emotion recognition, biometric categorisation, deepfakes and AI-written public-interest text Chatbots must disclose they are AI unless obvious. Generated audio, image, video and text must be marked as artificial in a machine-readable way. Deepfakes and AI-generated public-interest text must be disclosed. Disclosure must be clear and given at the latest at first interaction. Not deferred by the Omnibus.
Evidence: Disclosure texts in place, marking mechanism documented, transparency checklist completed per system.
2 December 2026
in 71 days
Machine-readable marking of generative AI output
EU · EU AI Act as amended by Reg. 2026/1744
Upcoming Providers of generative AI systems and, in practice, companies publishing generated content New obligation introduced by the Digital Omnibus: generated output must carry machine-readable marking. The same package bans generating non-consensual intimate imagery and child sexual abuse material, with penalties up to €35M or 7% of global turnover.
Evidence: Marking mechanism in place for every generative system in the inventory.
2 December 2027
in 436 days
High-risk obligations for stand-alone systems (Annex III)
EU · EU AI Act as amended by Reg. 2026/1744
Deferred Providers and deployers of high-risk AI in employment, education, credit, essential services, law enforcement, migration and justice Risk management, data governance, technical documentation, logging, human oversight, conformity assessment and registration. Deferred from 2 August 2026 by the Digital Omnibus.
Evidence: Risk classification record, impact assessment, vendor documentation, oversight design.
2 August 2028
in 680 days
High-risk obligations for AI in regulated products (Annex I)
EU · EU AI Act as amended by Reg. 2026/1744
Deferred AI embedded in products under EU product law (machinery, medical devices, vehicles and similar) Deferred from 2 August 2027 by the Digital Omnibus.
Evidence: Product conformity files updated for AI components.

What to do first

  1. List every AI system you use with the free inventory template.
  2. Check which rows above apply with the readiness scan.
  3. Put the disclosures in place with the disclosure generator.
  4. Hold the evidence. In the Compliance Kit the documents that matter most here are:
    • 02 Acceptable use policy: Article 4 written rules
    • 03 AI inventory: the starting point for every duty
    • 04 Risk classification: prohibited, high-risk, Article 50 or minimal
    • 05 Transparency checklist: Article 50 texts and checks
    • 06 AI literacy programme: Article 4 evidence

Terms you will meet

AI inventory (AI register) · AI literacy · AI system · Annex I (AI in regulated products) · Article 50 (transparency obligations) · Biometric categorisation system · Deep fake · Deployer · Digital Omnibus on AI · Distributor · Emotion recognition system · Fine tiers and the SME rule · General-purpose AI model · High-risk AI system (Annex III) · Impact assessment · Importer · ISO/IEC 42001 · Machine-readable marking · NIS2 · Prohibited practices · Provider · Serious incident · Statement of Applicability · Substantial modification

Vendors based in the EU

24 verified listings from the directory, each checked against the company's own website. Listing is free; paid placements are labelled.

2021.AI

PlatformDenmarkEnterprise

GRACE AI platform whose governance module registers AI systems, runs risk assessments, maps controls to the EU AI Act and ISO 42001, and monitors compliance.

EU AI ActISO/IEC 42001GDPR

Advisera

TemplatesCroatiaSME and enterprise

Zagreb provider of ISO documentation toolkits, online courses and compliance software, including ISO 42001 toolkits, courses and employee training academies.

ISO/IEC 42001GDPR

aiacto

PlatformFranceSME and enterprise

EU AI Act compliance software that classifies AI system risk and generates Annex IV technical documentation and Article 26 deployer registers.

EU AI Act

Algorithm Audit

AuditorNetherlandsUnknown

Dutch nonprofit conducting algorithm audits and bias analyses, supporting AI Act and GDPR implementation, and publishing open-source bias detection tools.

EU AI ActGDPR

appliedAI Initiative

ConsultancyGermanySME and enterprise

Munich AI initiative offering AI strategy consulting, implementation, enablement programs and EU AI Act compliance support, including an accelerator for SMEs.

EU AI Act

AY Prime

TrainingPolandSME and enterprise

Polish training and HR company delivering KFS-subsidised courses in AI and automation, digital skills and management for companies with 10 to 5,000+ employees.

ComplianceHive

PlatformNetherlandsSME

SMB compliance tool for GDPR and NIS2 with an AI system register for documenting AI tools, risk classification and measures under the EU AI Act.

EU AI ActGDPR

Considerati

ConsultancyNetherlandsUnknown

Amsterdam legal and compliance consultancy providing AI compliance and governance, privacy, DPO-as-a-service, risk assessments and training.

EU AI ActGDPR

Cortina Consult

PlatformGermanySME and enterprise

Modular KI-Governance software for EU AI Act compliance covering AI system inventory, risk classification, fundamental rights assessment, documentation and model monitoring.

EU AI ActGDPR

DCMR Legal

Law firmPolandSME and enterprise

Wrocław law firm selling a ready-to-implement internal AI policy template aligned with RODO/GDPR and the AI Act, delivered as a PDF.

EU AI ActGDPR

Delbion

TrainingSpainSME and enterprise

Barcelona firm providing FUNDAE-subsidised AI training including EU AI Act literacy, plus cybersecurity consulting and enterprise AI agents.

EU AI ActGDPR

Flutteris

ConsultancyBelgiumSME and enterprise

Belgian consultancy offering AI governance advisory and implementation alongside Flutter application development and software architecture services.

EU AI Act

See all 24 in the directory →