1. Digital Policy
  2. Instruments
  3. AI Act

Regulation · directly applicable · CELEX 32024R1689

AI Act

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence

Known as the Artificial Intelligence Act. Official text: Regulation (EU) 2024/1689 (Artificial Intelligence Act)Tier 1 · primary law

Status
Partly applicable as of 19 August 2026
Competent authority
National competent authoritiesand 1 more — see below
Sanction ceiling
7% of global turnover / EUR 35m

In force since 2024. Prohibitions, AI-literacy, GPAI duties and governance apply; the high-risk tier does not yet. The scalar alone is insufficient — read the milestones.

What it does

Harmonised rules on artificial intelligence, structured as product-safety legislation: conformity assessment, technical documentation, notified bodies, CE marking, post-market monitoring.

How it allocates obligations

Four-tier risk pyramid — unacceptable, high, transparency, minimal — with a separate compute-based presumption for general-purpose models.

Regulated actor
AI provider · AI deployer · AI importer · AI distributor · GPAI model provider
Protected party
Affected person · AI deployer
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Directly applicable
Enforcement mechanism
AI Office for general-purpose AI models; national competent authorities for AI systems; conformity assessment and market surveillance.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 13 June 2024AdoptionAdoption
  2. 12 July 2024Publication in the Official JournalPublication in the Official Journal
  3. 1 August 2024Entry into forceEntry into force
  4. 2 February 2025Application dateArticle 5 prohibitions and the AI-literacy obligations become applicable.What it requires: Cease any prohibited practice; ensure staff AI literacy.
  5. 10 July 2025Guidance or code of practiceThe General-Purpose AI Code of Practice is finalised. It is voluntary.What it requires: Consider adherence. The Code supplies the operative detail behind Articles 53 and 55, which are drafted at a high level of abstraction.
  6. 2 August 2025Application dateGeneral-purpose AI obligations and the governance structures become applicable.What it requires: GPAI providers: technical documentation, downstream information pack, copyright policy, public training-content summary. Systemic-risk models additionally owe Art. 55.
  7. 2 August 2026Application dateThe AI Act's general date of application. Article 101 also applies from this date: the Commission may fine providers of general-purpose AI models up to 3% of annual worldwide turnover or EUR 15 million, whichever is higher (GPAI obligations themselves have applied since 2 August 2025).
  8. 2 December 2026Application dateThe new Article 5(1), first subparagraph, points (ba) and (bb) prohibitions — AI systems generating or manipulating non-consensual intimate imagery of an identifiable person, and material within Article 2(c) and (e) of Directive 2011/93/EU — together with the new Article 5(1a) and (1b), apply from this date. They were inserted into the AI Act by the Digital Omnibus on AI.What it requires: Do not place on the market, put into service or use an AI system within the new Article 5(1)(ba) or (bb) prohibitions from this date.
  9. 2 December 2026Compliance deadlineEnd of a transitional period, not an application date. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026 must comply with Article 50(2) machine-readable marking by this date. For systems placed on the market from 2 August 2026, Article 50 already applies.What it requires: Bring synthetic-content-generating systems placed on the market before 2 August 2026 into line with Article 50(2) marking.
  10. 2 December 2027Application dateAnnex III stand-alone high-risk systems become subject to the Chapter III obligations.What it requires: Complete conformity assessment, technical documentation, risk management, logging, human oversight and registration for Annex III systems.
  11. 2 August 2028Application dateAnnex I product-embedded high-risk systems become subject to the Chapter III obligations.What it requires: Integrate AI Act conformity assessment into existing product-safety conformity procedures.
  12. 2 August 2030Compliance deadlineProviders and deployers of high-risk AI systems intended to be used by public authorities, already on the market or in service, must comply with the AI Act by this date (Art. 111(2)).

The whole compliance calendar, filterable →

Who it applies to

7 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Yes

actor AI provider or AI deployer or GPAI model provideractivity Developing AI systems or Deploying AI systems or Placing a general-purpose AI model on the market

The Article 5 prohibitions and the AI-literacy duty have applied since 2 February 2025 to every provider and deployer, at every risk tier. This is the part of the AI Act that is in force now and is not affected by the Omnibus deferral.

Exemptions: The AI Act does not apply to AI systems used exclusively for military, defence or national security purposes.

Last verified 27 August 2026

Yes

actor GPAI model provideractivity Placing a general-purpose AI model on the market

Every provider of a general-purpose AI model owes Article 53 since 2 August 2025: Annex XI technical documentation, an Annex XII information pack for downstream providers, a copyright compliance policy and a sufficiently detailed public summary of training content. The operative detail sits in the Code of Practice, which is voluntary.

Exemptions: Article 53(2) partially exempts models released under a genuinely free and open-source licence — but the exemption evaporates entirely for systemic-risk models.

Last verified 27 August 2026

Potentially applicable

actor GPAI model provideractivity Placing a general-purpose AI model on the market

Article 51(2) presumes high-impact capabilities where cumulative training compute exceeds 10^25 FLOP, which brings the Article 55 frontier duties: model evaluation including documented adversarial testing, Union-level systemic risk assessment and mitigation, serious-incident reporting and adequate cybersecurity. The threshold is a rebuttable presumption, and the Commission may also designate by decision.

Last verified 27 August 2026

Potentially applicable

actor AI provider or AI deployeractivity Deploying AI systems or Developing AI systems

The Chapter III high-risk obligations — risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, conformity assessment and registration — reach a system only through one of the two Article 6 entry routes. Most deployed AI never leaves the minimal-risk tier. Following the AI Omnibus these duties arrive on 2 December 2027 for Annex III systems and 2 August 2028 for product-embedded ones.

Exemptions: Article 6(3) filters out an Annex III system that does not pose a significant risk of harm — but the provider must document that assessment and register the system.

Last verified 27 August 2026

Potentially applicable

actor AI deployer or Manufacturer or Large company or SMEactivity Deploying AI systems

Article 25 is the trap most often missed: a distributor, importer or deployer becomes a provider — assuming the full obligation set — if it puts its name or trademark on a high-risk system, substantially modifies it, or modifies its intended purpose. Buying rather than building is not by itself a way out.

Last verified 27 August 2026

Yes

actor Public authorityactivity Deploying AI systems

The Article 5 prohibitions bind public authorities as well as firms. Social scoring by government, predictive policing based solely on profiling, and emotion recognition in workplaces and educational institutions are prohibited outright. Real-time remote biometric identification in publicly accessible spaces for law enforcement is prohibited subject to narrow exceptions.

Exemptions: Article 4(2) TEU reserves national security to the Member States, and the AI Act does not apply to systems placed on the market, put into service or used exclusively for military, defence or national security purposes (Art. 2(3)). The brief argues this carve-out is the structural source of the asymmetry between constraint on corporate and on state power.

Last verified 27 August 2026

Potentially applicable

actor AI provider or AI deployer or GPAI model providerterritory Outside the EU, serving EU users

The AI Act reaches providers placing systems on the Union market and, on the marketing criterion the brief identifies across the rulebook, providers whose system output is used in the Union irrespective of where they are established.

Last verified 27 August 2026

Run these against your situation →

Key provisions

13 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 2(3)Scope — exclusion of military, defence and national securityThe Regulation does not apply to AI systems where and in so far as they are placed on the market, put into service, or used with or without modification exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities; nor does it affect Member States' competences concerning national security.not recordedApplies from 2 February 2025
Art. 3(63)Definition of a general-purpose AI modelDisplays significant generality, is capable of competently performing a wide range of distinct tasks and can be integrated into a variety of downstream systems or applications. The Article sets no compute figure: the indicative criterion of more than 10^23 training FLOP comes from the Commission's July 2025 guidelines, not from the Regulation.not recordedApplies from 2 February 2025
Art. 4AI literacyProviders and deployers of AI systems must take measures to support the development of AI literacy of their staff and of others operating or using AI systems on their behalf. As replaced by the AI Omnibus, the Article does not require them to guarantee any specific level of AI literacy; the original text required measures to ensure a sufficient level.AI provider · AI deployerApplies from 2 February 2025
Art. 5load-bearingProhibited AI practicesManipulative or deceptive techniques; exploitation of vulnerabilities; social scoring; individual criminal-risk prediction based solely on profiling; untargeted facial-image scraping; emotion inference in workplaces and education; biometric categorisation inferring sensitive attributes; real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Binds public authorities as well as firms.AI provider · AI deployer · Public authorityApplies from 2 February 2025then from 2 December 2026: application date inserted by AI Omnibus
Art. 6load-bearingClassification rules for high-risk AI systemsTwo entry routes: 6(1) safety component of a product covered by Annex I harmonisation legislation; 6(2) falling within Annex III. 6(3) provides a filter where no significant risk of harm is posed, subject to documentation and registration.AI providerApplies from 2 December 2027then from 2 August 2028: application date
Art. 9Risk management systemAI providerApplies from 2 December 2027then from 2 August 2028: application date
Art. 25Responsibilities along the AI value chainA distributor, importer or deployer becomes a provider — assuming the full obligation set — if it puts its name or trademark on a high-risk system, substantially modifies it, or modifies its intended purpose.AI distributor · AI importer · AI deployerApplies from 2 December 2027then from 2 August 2028: application date
Art. 27Fundamental rights impact assessmentAI deployerApplies from 2 December 2027then from 2 August 2028: application date
Art. 50load-bearingTransparency obligationsUsers must be informed they are interacting with an AI system; synthetic content must be marked in a machine-readable format; deep fakes and AI-generated text on matters of public interest must be disclosed.AI provider · AI deployerApplies from 2 August 2026deadline 2 December 2026: Bring synthetic-content-generating systems placed on the market before 2 August 2026 into line with Article 50(2) marking.
Art. 51Classification of general-purpose AI models with systemic risk51(1)(a) high-impact capabilities or 51(1)(b) Commission decision. 51(2) supplies the operative presumption: cumulative training compute greater than 10^25 FLOP.GPAI model providerApplies from 2 August 2025
Art. 53load-bearingObligations for providers of general-purpose AI modelsAnnex XI technical documentation; Annex XII information pack for downstream providers; a copyright compliance policy; a sufficiently detailed public summary of training content. 53(2) partially exempts genuinely free and open-source models, but not systemic-risk models.GPAI model providerApplies from 2 August 2025
Art. 55load-bearingObligations for providers of general-purpose AI models with systemic riskModel evaluation against standardised protocols including documented adversarial testing; assessment and mitigation of Union-level systemic risks; tracking and prompt reporting of serious incidents; adequate cybersecurity protection.GPAI model providerApplies from 2 August 2025
Art. 99PenaltiesUp to 7% of global annual turnover or EUR 35 million.not recordedApplies from 2 August 2025

Enforcement

EUR 0announced across 1 records
unknowndemonstrably collected

0 of 1 records cannot settle whether money moved. That is not zero, and the announced figure is not a total of anything that has been paid.

Hungary

—announced
Not applicablepayment
no decisiondecision
Authority
European Commission
Issue
No infringement proceedings opened
Legal basis
Art. 5
Full record and derivation →Last verified 26 September 2026

Evidence and sources

Every statement this site makes about AI Act, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

14 Primary law3 Official source1 Attributed view13 Interpretation1 Unresolved
Primary lawlaw

The AI Act applies to providers and deployers of AI systems established or located in a third country where the output produced by the AI system is used in the Union.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 2(1)(c)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

GDPR Article 22 is the pre-existing European law of automated decision-making: it did not wait for the AI Act and applies to systems the AI Act classifies as minimal risk.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 22

Tier 1 · primary lawsupports in part

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 6

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

Under AI Act Article 25 a distributor, importer or deployer becomes a provider — assuming the full obligation set — if it puts its name or trademark on a high-risk system, substantially modifies it, or modifies its intended purpose.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 25

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

The GPAI Code of Practice supplies the operative detail behind AI Act Articles 53 and 55, and it is voluntary.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 53(4) and Art. 55(2) (providers 'may rely on codes of practice' to demonstrate compliance; those who do not adhere 'shall demonstrate alternative adequate means of compliance'); Art. 56(2) (codes to cover the obligations in Arts 53 and 55)

Tier 2 · regulatorstates this

General-Purpose AI Code of Practice — European Commission 10 July 2025 "The Code of Practice details out these rules, representing a voluntary tool prepared by independent experts"

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The AI Omnibus delayed the AI Act's high-risk obligations by sixteen months for Annex III systems and twelve for Annex I product-embedded systems, while leaving prohibitions, GPAI duties and transparency close to the original schedule.

Tier 1 · primary lawstates this

Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — EUR-Lex 8 July 2026 Art. 1, point (40)(b), replacing Art. 113, third paragraph, point (c); point (40)(a) (Art. 5 additions from 2 December 2026); point (39)(b) (new Art. 111(4), Art. 50(2) by 2 December 2026); recital 40

Tier 1 · primary lawsupports in part

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 113 as adopted (general application 2 August 2026; Chapter V from 2 August 2025; Art. 6(1) from 2 August 2027)

Tier 2 · regulatorsupports in part

AI Omnibus enters into force — European Commission 27 July 2026 Annex III high-risk from 2 December 2027; product-embedded high-risk from 2 August 2028

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026, amending the AI Act.

Tier 1 · primary lawstates this

Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — EUR-Lex / ELI 24 July 2026 OJ L, 24 July 2026

Tier 1 · primary lawstates this

Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — EUR-Lex 8 July 2026 Art. 4 (entry into force on the third day following publication); OJ L series, 2026/1744, 24.7.2026

Tier 2 · regulatorstates this

AI Omnibus enters into force — European Commission 27 July 2026 "On 27 July 2026, the AI Omnibus enters into force across the EU"

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 5 AI Act prohibits manipulative or deceptive techniques, exploitation of vulnerabilities due to age, disability or a social or economic situation, social scoring leading to detrimental treatment, criminal-risk prediction based solely on profiling, untargeted scraping of facial images for facial recognition databases, emotion inference in workplaces and education institutions, biometric categorisation deducing sensitive attributes, and real-time remote biometric identification in publicly accessible spaces for law enforcement, save for narrow exceptions.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 5(1)(a)–(h)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 50 AI Act requires that people be informed when they interact with an AI system, that synthetic audio, image, video or text outputs be marked in a machine-readable format, and that deep fakes and AI-generated text published to inform the public on matters of public interest be disclosed.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 50(1), (2), (4)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 3(63) AI Act defines a general-purpose AI model as one that displays significant generality, is capable of competently performing a wide range of distinct tasks and can be integrated into a variety of downstream systems or applications.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 3(63)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Every provider of a general-purpose AI model must keep technical documentation (Annex XI), provide information to downstream providers (Annex XII), put in place a policy to comply with Union copyright law and publish a sufficiently detailed summary of training content; the documentation duties do not apply to models released under a free and open-source licence, except models with systemic risk.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 53(1)(a)–(d); Art. 53(2)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 51(2) AI Act presumes a general-purpose AI model to have high-impact capabilities, and so systemic risk, when the cumulative compute used for its training exceeds 10^25 floating point operations.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 51(1)(a), 51(2)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The AI Omnibus replaced Article 4 of the AI Act: providers and deployers must now take measures to support the development of AI literacy of their staff, and the obligation does not require them to guarantee any specific level of AI literacy — where the original text required measures to ensure a sufficient level.

Tier 1 · primary lawstates this

Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — EUR-Lex 8 July 2026 Art. 1, point (5) (replacing Art. 4 AI Act)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The AI Act does not apply to AI systems placed on the market, put into service or used exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 2(3), second and third subparagraphs

Tier 4 · press / advocacysupports in part

EU AI Act Explorer — Article 2 (Scope) and Article 4 (AI literacy), as amended — artificialintelligenceact.eu (unofficial AI Act Explorer) Art. 2(3)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The AI Act Article 5 prohibitions bind public authorities as well as firms: social scoring by government, predictive policing based solely on profiling, and emotion recognition in workplaces and schools are prohibited outright for states as well as companies.

Tier 1 · primary lawstates this

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 5

Read it in the brief →Last verified 27 August 2026
Official sourcefact

The GPAI Code of Practice was finalised on 10 July 2025 after three drafts and a final text.

Tier 2 · regulatorstates this

General-Purpose AI Code of Practice — European Commission 10 July 2025 Timeline: '19 December 2024 AI Office publishes the second draft of the Code (first draft)'; '11 March 2025 Third draft of the Code of Practice'; '10 July 2025 The Commission received the final version of the Code'

Read it in the brief →Last verified 27 September 2026
Official sourcefact

The AI Omnibus was proposed on 19 November 2025; the Council adopted its general approach on 13 March 2026 and Parliament its mandate on 26 March 2026, by 569 votes to 45; agreement was reached on 7 May 2026; Parliament approved the text on 16 June and the Council on 29 June 2026.

Tier 2 · regulatorstates this

Procedure file 2025/0359(COD): Simplification of the implementation of harmonised rules on artificial intelligence – Digital Omnibus on AI — European Parliament Key events: 19/11/2025 proposal (COM(2025)0836); 26/03/2026 decision by Parliament, 1st reading (T10-0098/2026), referred back for interinstitutional negotiations; 16/06/2026 decision by Parliament (T10-0198/2026); 29/06/2026 act adopted by Council. Summary of 26/03/2026: 'adopted by 569 votes to 45 against and 23 abstentions'

Tier 2 · regulatorstates this

Legislative Train — Digital Omnibus on AI — European Parliament 2026 'The Council agreed its general approach on 13 March 2026. The co-legislators reached a trilogue agreement on the file on 7 May 2026'; 'Parliament's plenary approved the agreement on 16 June 2026 ... and the Council adopted the act on 29 June 2026'

Tier 1 · primary lawsupports in part

Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — EUR-Lex 8 July 2026 Footnote 4: 'Position of the European Parliament of 16 June 2026 ... and decision of the Council of 29 June 2026'

Read it in the brief →Last verified 27 September 2026
Official sourcefact

The Commission's July 2025 guidelines on general-purpose AI models add an indicative criterion: a model trained with more than 10^23 FLOP that can generate language, text-to-image or text-to-video output.

Tier 2 · regulatorstates this

Commission publishes guidelines for providers of general-purpose AI models — European Commission 18 July 2025 Commission news item and FAQ on the GPAI guidelines: "indicative criterion"

Read it in the brief →Last verified 26 September 2026
Attributed viewattributed

The AI Act does not regulate all AI: the Commission's position is that it introduces no rules for AI deemed minimal or no risk — applications such as AI-enabled video games or spam filters — and that the vast majority of AI systems currently used in the Union fall into that category.

Tier 2 · regulatorstates this

AI Act — regulatory framework for artificial intelligence — European Commission Section 'Minimal or no risk': 'The AI Act does not introduce rules for AI that is deemed minimal or no risk. The vast majority of AI systems currently used in the EU fall into this category. This includes applications such as AI-enabled video games or spam filters.'

Tier 1 · primary lawcontext only

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 6

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretationunverified

Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretation

The instruments following the GDPR reproduce the same institutional shape — a specialised vocabulary, principles, case-specific rights and a supervisory apparatus — a pattern described as act-ification and GDPR mimesis.

Tier 3 · researchstates this

The Regulation of Digital Technologies in the EU: the law-making phenomena of “act-ification”, “GDPR mimesis” and “EU law brutality” — Papakonstantinou and De Hert 21 May 2022 Abstract: "three basic phenomena common to all, or most, EU new technology-relevant regulatory initiatives, namely (a) act-ification, (b) GDPR mimesis, and (c) regulatory brutality"

Read it in the brief →Last verified 27 September 2026
Interpretationcritique

The recurring objection across every instrument is a capacity-ambition gap: broad obligations assigned either to a single Commission directorate with a few hundred staff or to twenty-seven national authorities of radically unequal resource.

Tier 4 · press / advocacysupports in part

The case for a European Union digital enforcement authority — Bruegel 5 March 2026

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I, Part IX

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretationunverified

The operative standards of the EU digital rulebook — systemic risk, high-impact capabilities, effective interoperability, genuinely equivalent alternative — are almost all open-textured, so the law's effective content is set by Commission guidelines, delegated acts, codes of practice and harmonised standards rather than by the legislature.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

A single recommender system can engage the GDPR, the DSA, the AI Act and, for a gatekeeper, the DMA at once, so the rational compliance strategy is one control set mapped to several regimes.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

2016-2024 was the accumulation phase of EU digital regulation and 2025-2027 is a consolidation phase, but consolidation is contested from within: simplification and expansion are happening in the same instruments.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretation

The AI Act is structurally product-safety legislation — conformity assessment, technical documentation, notified bodies, CE marking, post-market monitoring — and that choice determines both its strengths and the specific way it is failing to arrive on schedule.

Tier 1 · primary lawsupports in part

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Chapter III

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →Last verified 27 August 2026
Interpretationcritique

The 10^25 FLOP systemic-risk presumption is an administrable proxy for an unadministrable concept: risk does not scale linearly with compute, the threshold ages downward as efficiency improves, and domain-specific risk below it escapes entirely.

Tier 1 · primary lawsupports in part

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 51(2)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →Last verified 27 August 2026
Interpretationcritiqueunverified

The harmonised standards needed to demonstrate conformity were not ready; requiring conformity assessment against standards that do not exist is not regulation but a trap, and their non-arrival despite being commissioned years in advance is an institutional failure.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →no verification date recorded
Interpretationcritique

The AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.

Tier 1 · primary lawsupports in part

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 22

Tier 1 · primary lawsupports in part

Directive (EU) 2024/2853 on liability for defective products — EUR-Lex 18 November 2024

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretation

Amendments passed by the Hungarian Parliament in March 2025 extending police use of facial recognition to all infractions constitute real-time remote biometric identification in breach of AI Act Article 5 and of the Charter, according to legal analysis by EDRi, ECNL, Liberties and the Hungarian Civil Liberties Union.

Tier 4 · press / advocacystates this

Hungary's new biometric surveillance laws violate the AI Act — European Digital Rights (EDRi) 6 May 2025 6 May 2025: the four organisations "believe that this broadened application of FRT … violates the EU AI Act and the Charter of Fundamental Rights of the EU"

Tier 4 · press / advocacystates this

Civil society urges the European Commission to uphold the AI Act in Hungary — European Center for Not-for-Profit Law 2025 30 September 2025: "urging the European Commission to launch infringement proceedings against Hungary for violating the EU Artificial Intelligence Act"

Read it in the brief →Last verified 27 September 2026
Interpretationcritiqueunverified

This body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part XI

Read it in the brief →Last verified 27 August 2026
Unresolvedfact

The Commission has not opened infringement proceedings against Hungary on the basis of the biometric surveillance legislation.

Tier 4 · press / advocacysupports in part

When National Security Becomes a Shield for Evading AI Accountability — Tech Policy Press 16 February 2026 Hungary has not invoked the national security exemption

Tier 4 · press / advocacysupports in part

Civil society urges the European Commission to uphold the AI Act in Hungary — European Center for Not-for-Profit Law 2025

Tier 4 · press / advocacysupports in part

Hungary's new biometric surveillance laws violate the AI Act — European Digital Rights (EDRi) 6 May 2025

Tier 4 · press / advocacycontext only

Péter Magyar sworn in as Hungary's new prime minister after landslide April election victory — Euronews 9 May 2026

Tier 4 · press / advocacycontext only

Budapest free to celebrate Pride again, but Orbán-surveillance machine still in place — EUobserver 25 June 2026

Read it in the brief →Last verified 26 September 2026

The full bibliography and the evidence method →

How it interacts

5 recorded interactions with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.

AI Act Overlaps with GDPR

Both instruments reach the same conduct.

GDPR Art. 22 has governed solely-automated decision-making since 2018, including systems the AI Act classifies as minimal risk. The AI Act arrived into a field the GDPR already occupied.

Carried byGDPR Art. 22AI Act Art. 6
What the brief argues
  • Primary lawGDPR Article 22 is the pre-existing European law of automated decision-making: it did not wait for the AI Act and applies to systems the AI Act classifies as minimal risk.
  • InterpretationThe AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.

Recorded as at August 27, 2026

AI Act Overlaps with GDPR

Both instruments reach the same conduct.

GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties that regulators themselves acknowledge are duplicated.

Carried byGDPR Art. 35DSA Art. 34AI Act Art. 27
What the brief argues
  • InterpretationGDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.
Sources
  • The European Legal Framework for the Digital World (this brief)Unverified · the brief itself

Recorded as at August 27, 2026

TEU Carves out from AI Act

Article 4(2) TEU reserves national security to the Member States, and the AI Act does not apply to AI systems placed on the market, put into service or used exclusively for military, defence or national security purposes (Art. 2(3)). This is the structural source of the asymmetry between constraint on corporate and on state power.

Carried byTEU Art. 4(2)AI Act Art. 2(3)
What the brief argues
  • Primary lawArticle 4(2) TEU reserves national security to the Member States: it remains the sole responsibility of each Member State.
  • InterpretationThis body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.
Sources
  • The European Legal Framework for the Digital World (this brief)Unverified · the brief itself

Recorded as at August 27, 2026

AI Act Complements Revised PLD

The AI Act is product-safety legislation; the revised Product Liability Directive brings software and AI within strict product liability. The proposed AI Liability Directive, which would have covered the fault-based route, was abandoned.

What the brief argues
  • Official sourceThe proposed AI Liability Directive was abandoned, leaving a gap in the fault-based liability route.
  • Primary lawThe revised Product Liability Directive brings software and AI within strict product liability, applying to products placed on the market or put into service after 9 December 2026.

Recorded as at August 27, 2026

AI Omnibus Amends AI Act

Regulation (EU) 2026/1744 amends the AI Act, deferring the high-risk tier while leaving prohibitions, GPAI duties and transparency close to the original schedule.

What the brief argues
  • Primary lawThe AI Omnibus delayed the AI Act's high-risk obligations by sixteen months for Annex III systems and twelve for Annex I product-embedded systems, while leaving prohibitions, GPAI duties and transparency close to the original schedule.

Recorded as at August 27, 2026