European Union AI Act: Risk Tiers, Bans, Compliance Dates

The European Union adopted the AI Act, a binding risk-tiered law with prohibited uses, transparency duties, and phased obligations through 2028.

kindGovernment
foundedNov 1, 1993
Event history

A union of 27 that legislates as one

The European Union is a political and economic union of 27 member states, created when the Maastricht Treaty entered into force on November 1, 1993. Law that applies across all 27 is made through three institutions acting together: the European Parliament, whose members are directly elected; the Council of the European Union, made up of ministers from each member state's government; and the European Commission, which alone can propose new EU legislation and which then enforces what Parliament and Council adopt. A regulation passed this way binds all 27 states directly, without each one separately writing it into national law, which is what makes an EU statute a different kind of instrument than a single country's law. [1]

The AI Act: what it actually requires

The AI Act was adopted by the European Parliament in March 2024 and entered into force that August, the first broad statute anywhere aimed specifically at AI systems. It sorts AI uses into four tiers. Nine practices are banned outright, among them social scoring and untargeted scraping of biometric data to build facial recognition databases. A defined set of high-risk uses, including AI in critical infrastructure, employment decisions and law enforcement, carries obligations for risk assessment, data quality, human oversight and logging. A transparency tier requires that people be told when they are talking to a chatbot and that AI-generated content, including deepfakes, be labelled. Everything else, the large majority of AI systems, faces no AI Act-specific rule at all. [2]

The obligations phase in over several years rather than arriving at once: the bans took effect in February 2025, rules for general-purpose AI models in August 2025, transparency enforcement in August 2026, and the high-risk system rules stretch out to 2027 and 2028. The Act also applies to providers outside the EU whose AI systems are used within it, which is why compliance planning at non-European AI companies has to account for it regardless of where the company is headquartered. [2]

The EU on the timeline

Both events credited directly to the European Union mark the Act's own start: adoption in March 2024 and entry into force that August. The obligations that actually bind companies, the general-purpose AI rules and the transparency enforcement, are credited to the European Commission instead, since the Commission's AI Office is the body that administers them. Reading the two organizations' pages together traces the Act from statute to enforcement. [2]

Sources

  1. History of the European Union - 1990-99

    European Union

  2. AI Act

    European Commission · Sep 9, 2026