By now most people have heard that the EU passed a sweeping AI law — but a 400-plus page legal text isn't exactly light reading. We've already covered the practical side of this in our piece on AI risks for everyday users; think of this guide as the government's answer to those same problems, written into law.
Strip away the legal jargon and the idea is pretty simple: the EU AI Act sorts AI systems by how much damage they could do, then matches the rules to the danger. The riskier the system, the tighter the leash. Here's what that actually looks like in practice, and what's changed as of mid-2026.
- The EU AI Act sorts AI into four risk tiers and regulates accordingly — the more dangerous the system, the stricter the rules.
- A short list of "unacceptable risk" uses, like government social scoring and manipulative AI, is banned outright.
- High-risk AI in healthcare, law enforcement, and hiring faces strict compliance checks — though the 2026 "Digital Omnibus" pushed several of these deadlines back to December 2027.
- Companies have to tell you when you're talking to an AI or looking at a deepfake.
- Penalties are steep: up to 7% of a company's global revenue for the worst violations.
01The 4-Tier Risk System
At the heart of the Act is a four-tier risk framework. Rather than treating all AI the same, regulators look at what a system actually does and how badly it could hurt someone if it goes wrong or gets misused. You can read the EU's own plain-language breakdown of the tiers on the European Commission's AI Act policy page.
Unacceptable Risk
AI that clearly threatens safety, livelihoods, and rights. These systems are completely banned from the EU market.
BannedHigh Risk
AI used in critical areas like healthcare, policing, or border control. These require strict conformity assessments.
Heavily RegulatedLimited Risk
AI systems with specific transparency obligations, like chatbots or deepfake generators. Users must know they are using AI.
Transparency RulesMinimal Risk
The vast majority of AI tools (like AI in video games or spam filters). No new legal obligations are imposed.
No Regulation02What AI Practices Are Banned?
For "unacceptable risk" AI, the EU didn't bother with a compliance checklist — it just said no. If a system falls into this bucket, it can't be sold or used anywhere in Europe, full stop. The full legal wording for these bans lives in Article 5 of the Act, which you can read on EUR-Lex, the EU's official legislation database.
- Manipulative AI: systems that use subliminal or deceptive techniques to distort behavior in ways that cause psychological or physical harm.
- Exploiting vulnerabilities: AI that specifically targets people based on age, disability, or financial hardship to cause harm.
- Social scoring: governments using AI to rate someone's "trustworthiness" from unrelated personal data.
- Untargeted facial recognition: scraping the internet or CCTV footage to build mass facial recognition databases.
Think of the "unacceptable risk" tier as a hard stop rather than a speed bump. Lawmakers decided a small handful of AI uses are too dangerous to allow in a democratic society, no matter how much money they might make for the companies building them.
03High-Risk AI Rules
Anything used to make consequential decisions about people's lives — medical devices, hiring screens, essential public services, law enforcement tools — lands in the "high-risk" tier. That's where most of the Act's actual weight sits.
Getting a high-risk system compliant means rigorous testing, human oversight built into the process, and technical documentation that regulators can actually inspect. If you're curious how AI developers approach this kind of safety work in practice, our piece on how AI companies make their models safe covers red-teaming and alignment testing in more depth.
One thing worth flagging: the timeline slipped. The European Commission's guidance on how to classify high-risk systems was originally due by February 2026, but it didn't land until a draft was published in May 2026, and a follow-up "Digital Omnibus on AI" package revised the schedule further. Under the updated timeline, obligations for stand-alone high-risk AI systems now apply from December 2, 2027 rather than 2026, as regulators and standards bodies work to catch up. Full details are on the Commission's official regulatory framework page.
04Transparency & General Purpose AI
The "limited risk" tier is really about one thing: your right to know you're dealing with a machine. Talking to a customer service chatbot? It has to tell you it's AI, so you can decide how much to trust what it says.
There's a separate set of rules for "general purpose AI" — the large language models behind most modern chatbots. Their developers have to publish summaries of what data they trained on and clearly label AI-generated content, including deepfakes.
05Fines & Enforcement
The Act's penalties aren't symbolic. They're set high enough that breaking the rules should cost more than complying with them.
| Violation Type | Maximum Fine | Alternative Fine |
|---|---|---|
| Banned AI Practices | €35 Million | 7% of global turnover |
| High-Risk Non-Compliance | €15 Million | 3% of global turnover |
| Supplying False Info | €7.5 Million | 1% of global turnover |
Whichever amount is higher — the flat fee or the percentage of turnover — is the one that applies. See the enforcement mechanics on artificialintelligenceact.eu's high-level summary, an independent legal reference maintained by AI Act researchers.