EdLaw int/eu/ai-act/README.md

language: en · status: in-force · last checked: 2026-09-05

Artificial Intelligence Act (Regulation (EU) 2024/1689)

The EU's horizontal AI regulation, published in the Official Journal on 12 July 2024 (OJ L, 2024/1689) and in force since 1 August 2024 (the twentieth day after publication, Art. 113), applying in phases through 2028 (see APPLICATION-TIMELINE.md). It takes a risk-based approach: prohibited practices, high-risk systems with conformity requirements, transparency duties for certain systems, and a separate regime for general-purpose AI models. It applies to providers placing AI systems on the Union market wherever established, to deployers in the Union, and extraterritorially where a system's output is used in the Union (Art. 2(1)). Enforced by national market surveillance authorities; the Commission's AI Office supervises general-purpose AI models.

Amended. This folder reproduces the consolidated text CELEX 02024R1689-20260727: the Regulation as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI", 8 July 2026). The amendment materially changed the parts EdTech cares about — it postponed the application of the high-risk regime for Annex III systems to 2 December 2027 (Annex I systems: 2 August 2028) (Art. 113(c)), added prohibitions on AI generation of non-consensual intimate imagery and child sexual abuse material (points (ba)/(bb), applying from 2 December 2026), softened the Art. 4 AI-literacy duty, and inserted Art. 4a permitting special-category processing for bias detection. Secondary commentary describing the pre-amendment timeline (high-risk from August 2026) is now wrong.

Applicability to EdTech

Contents

Document Covers
GENERAL-PROVISIONS.md Arts. 1–4a — subject matter, scope, definitions, AI literacy, bias-detection processing
PROHIBITED-PRACTICES.md Art. 5 — prohibited practices (incl. education emotion inference)
HIGH-RISK-CLASSIFICATION.md Arts. 6, 7; Annex III — what counts as high-risk
HIGH-RISK-REQUIREMENTS.md Arts. 8–15 — requirements for high-risk systems
OPERATOR-OBLIGATIONS.md Arts. 16, 25–27 — provider/deployer obligations, value chain, FRIA
TRANSPARENCY.md Art. 50 — disclosure and synthetic-content marking
GPAI.md Arts. 51, 53, 55 — general-purpose AI models
REMEDIES-AND-PENALTIES.md Arts. 85, 86, 99, 101 — complaints, explanation right, fines
APPLICATION-TIMELINE.md Arts. 111, 113 — application dates (as amended) and transitional rules

Scope note: the conformity-assessment machinery (Arts. 28–49), governance chapters and the remaining annexes can be added with the same tooling when needed.

Key obligations at a glance

Enforcement

National market surveillance authorities (Chapter IX); the AI Office enforces the GPAI chapter with Omnibus-added powers (Arts. 75a–75d, not reproduced here). Fine ceilings: EUR 35m / 7% of worldwide turnover for prohibited practices (Art. 99(3)); EUR 15m / 3% for most operator obligations (Art. 99(4)); EUR 7.5m / 1% for misleading information (Art. 99(5)); GPAI providers up to 3% / EUR 15m (Art. 101(1)). Affected persons may complain to a market surveillance authority (Art. 85) and obtain explanations of individual decisions based on Annex III systems (Art. 86).

Sources

Meta

Built and re-verified mechanically — see tools/eur-lex: build_eu_ai_act.py extracts from the Cellar API copy of the consolidated text; build_eu_ai_act.py verify confirms every source paragraph appears verbatim. Do not hand-edit article text. The consolidated CELEX id is pinned in the script — on the next amendment, adopt the new consolidation id deliberately. Consolidation markers (▼M1/▼B) are stripped as apparatus. Known source quirk: the consolidated text renders Article 1's title as Subject matter' (stray trailing apostrophe) — present in both the Cellar XHTML and the EUR-Lex HTML view, reproduced here verbatim; do not "fix" it.