- Home
- AI & Machine Learning
- EU AI Act for Generative AI: Risk Classes, Obligations, and 2026 Deadlines
EU AI Act for Generative AI: Risk Classes, Obligations, and 2026 Deadlines
The rules of the game changed on August 1, 2024. That was when the EU AI Act is the world's first comprehensive legal framework regulating artificial intelligence systems based on a risk-based approach officially entered into force. But for companies building or using Generative AI is artificial intelligence capable of creating new content, such as text, images, code, or audio, often based on large language models, the real pressure didn't start then. It started ticking in early 2025, and it’s hitting hard now in mid-2026.
If you are developing an AI model, integrating one into your product, or even just using one to generate marketing copy, you need to know where you stand. The EU isn't banning AI; they are categorizing it. And if you get the category wrong, the fines can wipe out a significant chunk of your global turnover. Let’s break down exactly what this means for your business today.
Understanding the Four-Tier Risk Framework
The core philosophy of the regulation is simple: the higher the potential for harm, the stricter the rules. The Act divides all AI systems into four distinct buckets. Knowing which bucket your tool falls into is the single most important step in compliance.
- Unacceptable Risk: These are banned outright. Think government social scoring systems (like those seen in China) or real-time remote biometric identification in public spaces by law enforcement, with narrow exceptions. If your system does this, you don’t operate in the EU. This ban has been active since February 2, 2025.
- High-Risk: These systems pose serious risks to health, safety, or fundamental rights. Examples include AI used in critical infrastructure, education grading, employment screening (like CV scanners), and law enforcement. These face strict conformity assessments, data governance, and human oversight requirements. Most of these obligations kick in fully on August 2, 2026.
- Limited Risk: This is where most General-Purpose AI (GPAI) is foundational AI models designed to perform a wide variety of tasks, rather than a single specific function lives. Chatbots, deepfakes, and content generators fall here. The main rule? Transparency. Users must know they are interacting with a machine.
- Minimal Risk: Spam filters, video games, and other everyday apps. No specific obligations apply here.
For generative AI developers, the "Limited Risk" category is usually the starting point, but there is a catch. If your model has systemic risks, it gets upgraded to a higher tier of scrutiny.
Specific Obligations for Generative AI Providers
The EU treats General-Purpose AI (GPAI) differently from niche applications because these models are the "building blocks" for thousands of other tools. A single foundation model can be fine-tuned for medical diagnosis, legal advice, or children’s entertainment. Because of this ripple effect, the regulator places heavy burdens on the providers-the companies building the underlying models.
As of August 2, 2025, GPAI providers have had to implement several key measures. Here is what that looks like in practice:
- Copyright Compliance: You must prove your training data respects EU copyright laws. This means having licenses, respecting opt-out mechanisms, or providing clear attribution. You can no longer claim ignorance about where your data came from.
- Public Summaries: Providers must publish a summary of the copyrighted material used for training. The European Commission provided templates for this. It’s not enough to say "we used the internet." You need to show the scope and nature of the datasets.
- Technical Documentation: A private "black-box" dossier must be kept ready for regulators. This document details how the model was built, tested, and validated. It stays private but must be available upon request.
- Model Cards: Customers need a clear, concise "model card." This tells them what the model is good at, what it isn’t, and its known limitations. It prevents users from deploying a general chatbot as a certified medical diagnostic tool without understanding the gap.
- Transparency Labeling: Any content generated by the AI must be identifiable as such. Deepfakes require specific, visible labels. If you publish text intended to inform the public on matters of public interest, it must be labeled as AI-generated.
This shift forces transparency on processes that were previously proprietary secrets. For years, AI labs guarded their training data sources closely. Now, opacity is a liability.
The Critical Timeline: Where We Stand in July 2026
Timing is everything in regulatory compliance. Missing a deadline doesn't just mean a warning letter; it means automatic penalties. Let’s look at the clock.
| Date | Milestone | Impact on Generative AI |
|---|---|---|
| Feb 2, 2025 | Ban on Unacceptable Risk AI | Prohibited practices enforced immediately. |
| Aug 2, 2025 | GPAI Governance Rules Active | Providers must have copyright policies, technical docs, and model cards ready. |
| Aug 2, 2025 | Penalties Enter Force (Most Operators) | Fines apply for non-compliance, except for GPAI-specific fines. |
| Aug 2, 2026 | GPAI Fines Begin & High-Risk Rules Apply | Full penalty regime for GPAI starts. High-risk AI obligations become fully applicable. |
| Aug 2026 | Article 50 Transparency Rules | Broad transparency requirements for limited-risk AI take effect. |
| Aug 2, 2027 | Embedded High-Risk AI Deadline | AI in medical devices/cars must comply (extended transition). |
We are currently less than two months away from the biggest shift: August 2, 2026. On this date, two massive things happen. First, the specific fines for GPAI providers kick in. Second, the main obligations for high-risk AI systems become fully applicable for most operators. If you are using a generative AI model to screen job applicants (a high-risk use case), you are now fully under the microscope. If you are providing the model itself, you are now fully liable for financial penalties.
Systemic Risks: When Limited Becomes High
Not all generative AI is treated equally. The Act distinguishes between standard GPAI models and those deemed to have "systemic risks." These are typically very large models with massive computational power behind them.
If your model is classified as having systemic risks, the obligations intensify significantly. You must undergo thorough evaluations before market entry. You must conduct adversarial testing to check for robustness against attacks. Crucially, you must report any serious incidents to the European Commission. Think of this like the pharmaceutical industry reporting adverse drug reactions. If your AI hallucinates dangerously or spreads disinformation at scale, the regulator needs to know immediately.
This distinction is vital for startups versus tech giants. A small company building a niche image generator might stay in the standard GPAI lane. A giant building a foundational LLM used by millions will likely be flagged for systemic risk, requiring much heavier documentation and incident reporting protocols.
Penalties: The Cost of Getting It Wrong
The EU has teeth. The penalty structure is tiered, reflecting the severity of the violation. Since August 2, 2025, general penalties have been active, and since August 2, 2026, GPAI-specific fines are live.
- Minor Violations: Up to €7.5 million or 5% of global turnover.
- General Non-Compliance: Up to €15 million or 3% of global turnover. This covers failing to keep records, poor cooperation with authorities, or missing transparency labels.
- Prohibited Practices: Up to €35 million or 7% of global turnover. This is for using banned AI, like unapproved social scoring.
For a multinational corporation, 3% of global turnover is a staggering sum. For a startup, €15 million could be existential. The key takeaway? Compliance is not a "nice-to-have" feature; it is a survival requirement.
Practical Steps for Compliance Right Now
You don’t need to guess your way through this. The European Commission published the General-Purpose AI Code of Practice is a voluntary guideline issued by the EU Commission to help AI providers demonstrate compliance with transparency and copyright obligations in July 2025. Following this code is the best way to show regulators you are acting in good faith.
Here is your checklist for the next few weeks:
- Audit Your Data Sources: Map out every dataset used to train your model. Do you have licenses? Did you honor opt-outs? Document this clearly.
- Create Model Cards: Draft clear documentation for your customers explaining capabilities and limitations. Make it accessible, not just technical jargon.
- Implement Watermarking/Labeling: Ensure your output is detectable as AI-generated. Integrate metadata standards like C2PA if applicable.
- Check Use Cases: Are you selling your AI for high-risk purposes (employment, credit, law enforcement)? If so, ensure you meet the stricter high-risk obligations that are now fully active.
- Prepare for Sandboxes: By August 2, 2026, every EU member state must have an AI regulatory sandbox. These allow you to test AI in a controlled environment with reduced compliance burdens. Look into joining one to validate your compliance strategy.
Looking Ahead: The Digital Omnibus and Beyond
Regulation evolves. In November 2025, the Commission proposed the "Digital Omnibus," aiming to simplify certain administrative burdens. While adoption is still uncertain, it suggests the EU recognizes that red tape can stifle innovation. However, do not bet your compliance strategy on simplifications that haven't passed yet. Assume the current strict rules are the baseline.
The landscape continues to shift. The European Parliament adopted a resolution on copyright and generative AI in March 2026, signaling ongoing attention to the balance between IP rights and AI innovation. Expect more guidance on how to interpret "fair use" versus infringement in the context of training data.
The EU AI Act is not just a set of rules; it’s a new operating system for trust. Companies that embrace transparency, respect copyright, and document their processes will not only avoid fines but also build stronger trust with users who are increasingly wary of AI deception. Those who treat it as an afterthought will find themselves paying dearly.
Does the EU AI Act apply to my company if we are not based in Europe?
Yes. The EU AI Act applies to any provider or deployer of AI systems offering services or outputs in the European Union, regardless of where the company is headquartered. If your generative AI tool is used by consumers or businesses in the EU, you must comply.
What is the difference between a GPAI model and a high-risk AI system?
A GPAI (General-Purpose AI) model is a foundational model designed for a wide variety of tasks (like a large language model). It is generally classified as "limited risk" unless it poses systemic risks. A high-risk AI system is defined by its application-such as in healthcare, education, or employment-and faces stricter, pre-market conformity assessments regardless of the underlying model type.
When do fines for Generative AI providers actually start?
While general AI penalties began on August 2, 2025, specific fines for GPAI providers were deferred until August 2, 2026. As of today, July 2026, you are just one month away from facing full financial liability for non-compliance with GPAI obligations.
Do I need to reveal my entire training dataset to the public?
No, you do not need to release the raw data. However, you must publish a summary of the copyrighted material used for training, following Commission templates. You must also maintain a detailed private technical dossier for regulators to inspect upon request.
How does the AI Act handle deepfakes?
Deepfakes fall under the limited-risk category. The primary obligation is transparency. Providers must ensure that AI-generated or manipulated content is clearly labeled as such. For text intended to inform the public on matters of public interest, specific labeling requirements apply to prevent deception.
What are AI regulatory sandboxes?
Regulatory sandboxes are controlled environments established by EU member states (required by August 2, 2026) where companies can test AI innovations. Participants receive regulatory guidance and may benefit from reduced compliance burdens during the testing phase, helping them navigate complex requirements before full market deployment.
Susannah Greenwood
I'm a technical writer and AI content strategist based in Asheville, where I translate complex machine learning research into clear, useful stories for product teams and curious readers. I also consult on responsible AI guidelines and produce a weekly newsletter on practical AI workflows.
About
EHGA is the Education Hub for Generative AI, offering clear guides, tutorials, and curated resources for learners and professionals. Explore ethical frameworks, governance insights, and best practices for responsible AI development and deployment. Stay updated with research summaries, tool reviews, and project-based learning paths. Build practical skills in prompt engineering, model evaluation, and MLOps for generative AI.