# AI rules in European Union

The AI Act is partly in force (bans, AI literacy, GPAI and Article 50 transparency apply), and the July 2026 Digital Omnibus pushed high-risk obligations to Dec 2027/Aug 2028 while adding nudifier and CSAM bans from Dec 2026.

- **Approach:** Comprehensive AI law
- **Key bodies:** European Commission AI Office, European Artificial Intelligence Board, National market surveillance authorities, European Data Protection Supervisor
- **Strategy:** [AI Continent Action Plan](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) (2025)
- **Last reviewed:** 4 Oct 2026

## Rules (10)
- [EU AI Act](https://wheresthe.ai/rule/eu-ai-act-2024-1689/index.md): Partly in force, Regulation, effective 2 Feb 2025. Risk-based EU law that bans certain AI practices, imposes conformity, documentation and oversight duties on high-risk AI systems, transparency duties on chatbots and generative AI, and separate duties on general-purpose AI (GPAI) model providers. It applies to providers, deployers, importers and distributors whose AI systems are placed on the EU market or whose outputs are used in the EU.
- [Digital Omnibus on AI](https://wheresthe.ai/rule/eu-digital-omnibus-ai-2026-1744/index.md): In force, Regulation, effective 27 Jul 2026. Amends the AI Act: postpones high-risk obligations to 2 Dec 2027 (Annex III stand-alone systems) and 2 Aug 2028 (Annex I product-embedded systems), adds bans on AI that generates non-consensual sexual images of identifiable people or child sexual abuse material from 2 Dec 2026, and gives pre-Aug-2026 generative systems until 2 Dec 2026 to watermark outputs. It also softens the AI-literacy duty to 'take measures to support' literacy, allows processing of special-category data for bias detection, simplifies registration, extends SME relief to small mid-caps and moves national sandbox deadline to 2 Aug 2027.
- [GPAI Code of Practice](https://wheresthe.ai/rule/eu-gpai-code-of-practice-2025/index.md): In force, Standard, effective 2 Aug 2025. Voluntary code that GPAI model providers can sign to demonstrate compliance with AI Act Articles 53 and 55: a model documentation form, a copyright policy, and (for systemic-risk models only) safety and security practices. The Commission and AI Board confirmed it as an adequate compliance tool; signatories include Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI, with xAI signing only the Safety and Security chapter.
- [GPAI guidelines and training-data summary template](https://wheresthe.ai/rule/eu-gpai-guidelines-training-data-template-2025/index.md): In force, Guideline, effective 2 Aug 2025. Commission guidelines set technical criteria for when a model is 'general-purpose', when downstream modifiers become providers, and when open-source exemptions apply; a mandatory-format template requires GPAI providers to publish a summary of training data sources (including main datasets and top domain names). Applies to all providers placing GPAI models on the EU market.
- [Prohibited-practices and AI-definition guidelines](https://wheresthe.ai/rule/eu-guidelines-prohibited-practices-ai-definition-2025/index.md): In force, Guideline, effective 2 Feb 2025. Two non-binding Commission guidelines explaining, with examples, the AI practices banned under Article 5 (e.g., harmful manipulation, social scoring, workplace emotion recognition, real-time remote biometric identification) and how to decide whether software is an 'AI system' within the Act's scope. They address providers, deployers and market surveillance authorities.
- [AI content marking and labelling code](https://wheresthe.ai/rule/eu-code-of-practice-transparency-ai-generated-content-2026/index.md): In force, Standard, effective 2 Aug 2026. Voluntary code supporting AI Act Article 50(2), (4) and (5): providers of generative AI systems commit to machine-readable marking and detectability of AI outputs; deployers commit to labelling deepfakes and AI-generated text published on matters of public interest, using an EU icon set. The Commission and AI Board confirmed it as an adequate tool to demonstrate compliance; about 190 organisations had signed by end July 2026.
- [Article 50 transparency guidelines](https://wheresthe.ai/rule/eu-guidelines-article-50-transparency-2026/index.md): In force, Guideline, effective 2 Aug 2026. Explains the scope of Article 50 duties: telling people they are interacting with an AI system, marking synthetic audio/image/video/text, disclosing emotion-recognition and biometric categorisation, and labelling deepfakes and AI-generated public-interest text. Addressed to providers and deployers and to enforcing authorities.
- [High-risk classification guidelines (draft)](https://wheresthe.ai/rule/eu-guidelines-high-risk-classification-draft-2026/index.md): In consultation, Guideline. Draft guidance with practical examples of AI systems that are and are not high-risk under Article 6(1) (safety components of Annex I products) and Article 6(2) (Annex III use cases such as employment, credit scoring, education, biometrics). Published for targeted stakeholder feedback.
- [New Product Liability Directive](https://wheresthe.ai/rule/eu-product-liability-directive-2024-2853/index.md): Enacted, not yet in force, Law, effective 9 Dec 2026. Replaces the 1985 directive with no-fault liability for defective products that expressly covers software, including AI systems, and allows claims for damage including destroyed data; it eases the burden of proof for claimants in complex technical cases. It applies to manufacturers, importers and other economic operators for products placed on the EU market from 9 Dec 2026.
- [Digital Omnibus (data/GDPR)](https://wheresthe.ai/rule/eu-digital-omnibus-data-gdpr-proposal-2025/index.md): Proposed, Bill. Commission proposal (COM(2025) 837) that would, among other changes, confirm that training, testing and validation of AI systems on personal data can rely on legitimate interest under the GDPR and create a narrow exception for special-category data unavoidably present in training data. It would apply to all controllers processing personal data for AI development.

## Upcoming deadlines
- 2 Dec 2026: New bans on non-consensual sexual deepfake ('nudifier') and CSAM-generating AI apply; grace period ends for watermarking by generative AI systems placed on the market before 2 Aug 2026 ([EU AI Act](https://wheresthe.ai/rule/eu-ai-act-2024-1689/index.md))
- 2 Dec 2026: New Article 5 prohibitions (non-consensual intimate deepfakes, CSAM generation) apply; legacy generative AI systems must meet Article 50(2) marking ([Digital Omnibus on AI](https://wheresthe.ai/rule/eu-digital-omnibus-ai-2026-1744/index.md))
- 2 Dec 2026: Deadline for generative AI systems placed on the market before 2 Aug 2026 to comply with Article 50(2) marking ([AI content marking and labelling code](https://wheresthe.ai/rule/eu-code-of-practice-transparency-ai-generated-content-2026/index.md))
- 9 Dec 2026: Member State transposition deadline; new rules apply to products (including software and AI systems) placed on the market from this date ([New Product Liability Directive](https://wheresthe.ai/rule/eu-product-liability-directive-2024-2853/index.md))
- 2 Aug 2027: GPAI models placed on the market before 2 Aug 2025 must comply with AI Act GPAI obligations ([GPAI Code of Practice](https://wheresthe.ai/rule/eu-gpai-code-of-practice-2025/index.md))

## Programmes and facts
- AI Act (Reg. 2024/1689) in force since 1 Aug 2024; amended by Digital Omnibus on AI (Reg. 2026/1744) in force 27 Jul 2026
- GPAI Code of Practice published 10 Jul 2025; signatories include Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, OpenAI
- Code of Practice on Transparency of AI-generated Content: about 190 signatories by end Jul 2026
- Product Liability Directive (EU) 2024/2853 covering software and AI applies from 9 Dec 2026

---
Canonical page: https://wheresthe.ai/j/eu/ · Not legal advice.
