Every statement this site makes about AI Act, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
Primary lawlaw
The AI Act applies to providers and deployers of AI systems established or located in a third country where the output produced by the AI system is used in the Union.
Primary lawlaw
GDPR Article 22 is the pre-existing European law of automated decision-making: it did not wait for the AI Act and applies to systems the AI Act classifies as minimal risk.
Primary lawlaw
Under AI Act Article 25 a distributor, importer or deployer becomes a provider — assuming the full obligation set — if it puts its name or trademark on a high-risk system, substantially modifies it, or modifies its intended purpose.
Primary lawlaw
The GPAI Code of Practice supplies the operative detail behind AI Act Articles 53 and 55, and it is voluntary.
Tier 1 · primary lawstates this
Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 53(4) and Art. 55(2) (providers 'may rely on codes of practice' to demonstrate compliance; those who do not adhere 'shall demonstrate alternative adequate means of compliance'); Art. 56(2) (codes to cover the obligations in Arts 53 and 55)
Tier 2 · regulatorstates this
General-Purpose AI Code of Practice — European Commission 10 July 2025 "The Code of Practice details out these rules, representing a voluntary tool prepared by independent experts"
Primary lawlaw
The AI Omnibus delayed the AI Act's high-risk obligations by sixteen months for Annex III systems and twelve for Annex I product-embedded systems, while leaving prohibitions, GPAI duties and transparency close to the original schedule.
Tier 2 · regulatorsupports in part
AI Omnibus enters into force — European Commission 27 July 2026 Annex III high-risk from 2 December 2027; product-embedded high-risk from 2 August 2028
Primary lawlaw
The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026, amending the AI Act.
Tier 2 · regulatorstates this
AI Omnibus enters into force — European Commission 27 July 2026 "On 27 July 2026, the AI Omnibus enters into force across the EU"
Primary lawlaw
Article 5 AI Act prohibits manipulative or deceptive techniques, exploitation of vulnerabilities due to age, disability or a social or economic situation, social scoring leading to detrimental treatment, criminal-risk prediction based solely on profiling, untargeted scraping of facial images for facial recognition databases, emotion inference in workplaces and education institutions, biometric categorisation deducing sensitive attributes, and real-time remote biometric identification in publicly accessible spaces for law enforcement, save for narrow exceptions.
Primary lawlaw
Article 50 AI Act requires that people be informed when they interact with an AI system, that synthetic audio, image, video or text outputs be marked in a machine-readable format, and that deep fakes and AI-generated text published to inform the public on matters of public interest be disclosed.
Primary lawlaw
Article 3(63) AI Act defines a general-purpose AI model as one that displays significant generality, is capable of competently performing a wide range of distinct tasks and can be integrated into a variety of downstream systems or applications.
Primary lawlaw
Every provider of a general-purpose AI model must keep technical documentation (Annex XI), provide information to downstream providers (Annex XII), put in place a policy to comply with Union copyright law and publish a sufficiently detailed summary of training content; the documentation duties do not apply to models released under a free and open-source licence, except models with systemic risk.
Primary lawlaw
Article 51(2) AI Act presumes a general-purpose AI model to have high-impact capabilities, and so systemic risk, when the cumulative compute used for its training exceeds 10^25 floating point operations.
Primary lawlaw
The AI Omnibus replaced Article 4 of the AI Act: providers and deployers must now take measures to support the development of AI literacy of their staff, and the obligation does not require them to guarantee any specific level of AI literacy — where the original text required measures to ensure a sufficient level.
Primary lawlaw
The AI Act does not apply to AI systems placed on the market, put into service or used exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.
Primary lawlaw
The AI Act Article 5 prohibitions bind public authorities as well as firms: social scoring by government, predictive policing based solely on profiling, and emotion recognition in workplaces and schools are prohibited outright for states as well as companies.
Official sourcefact
The GPAI Code of Practice was finalised on 10 July 2025 after three drafts and a final text.
Tier 2 · regulatorstates this
General-Purpose AI Code of Practice — European Commission 10 July 2025 Timeline: '19 December 2024 AI Office publishes the second draft of the Code (first draft)'; '11 March 2025 Third draft of the Code of Practice'; '10 July 2025 The Commission received the final version of the Code'
Official sourcefact
The AI Omnibus was proposed on 19 November 2025; the Council adopted its general approach on 13 March 2026 and Parliament its mandate on 26 March 2026, by 569 votes to 45; agreement was reached on 7 May 2026; Parliament approved the text on 16 June and the Council on 29 June 2026.
Tier 2 · regulatorstates this
Legislative Train — Digital Omnibus on AI — European Parliament 2026 'The Council agreed its general approach on 13 March 2026. The co-legislators reached a trilogue agreement on the file on 7 May 2026'; 'Parliament's plenary approved the agreement on 16 June 2026 ... and the Council adopted the act on 29 June 2026'
Official sourcefact
The Commission's July 2025 guidelines on general-purpose AI models add an indicative criterion: a model trained with more than 10^23 FLOP that can generate language, text-to-image or text-to-video output.
Attributed viewattributed
The AI Act does not regulate all AI: the Commission's position is that it introduces no rules for AI deemed minimal or no risk — applications such as AI-enabled video games or spam filters — and that the vast majority of AI systems currently used in the Union fall into that category.
Tier 2 · regulatorstates this
AI Act — regulatory framework for artificial intelligence — European Commission Section 'Minimal or no risk': 'The AI Act does not introduce rules for AI that is deemed minimal or no risk. The vast majority of AI systems currently used in the EU fall into this category. This includes applications such as AI-enabled video games or spam filters.'
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationinterpretationunverified
Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I
Interpretationinterpretation
The instruments following the GDPR reproduce the same institutional shape — a specialised vocabulary, principles, case-specific rights and a supervisory apparatus — a pattern described as act-ification and GDPR mimesis.
Interpretationcritique
The recurring objection across every instrument is a capacity-ambition gap: broad obligations assigned either to a single Commission directorate with a few hundred staff or to twenty-seven national authorities of radically unequal resource.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I, Part IX
Interpretationinterpretationunverified
The operative standards of the EU digital rulebook — systemic risk, high-impact capabilities, effective interoperability, genuinely equivalent alternative — are almost all open-textured, so the law's effective content is set by Commission guidelines, delegated acts, codes of practice and harmonised standards rather than by the legislature.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
A single recommender system can engage the GDPR, the DSA, the AI Act and, for a gatekeeper, the DMA at once, so the rational compliance strategy is one control set mapped to several regimes.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
2016-2024 was the accumulation phase of EU digital regulation and 2025-2027 is a consolidation phase, but consolidation is contested from within: simplification and expansion are happening in the same instruments.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Interpretationinterpretation
The AI Act is structurally product-safety legislation — conformity assessment, technical documentation, notified bodies, CE marking, post-market monitoring — and that choice determines both its strengths and the specific way it is failing to arrive on schedule.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationcritique
The 10^25 FLOP systemic-risk presumption is an administrable proxy for an unadministrable concept: risk does not scale linearly with compute, the threshold ages downward as efficiency improves, and domain-specific risk below it escapes entirely.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationcritiqueunverified
The harmonised standards needed to demonstrate conformity were not ready; requiring conformity assessment against standards that do not exist is not regulation but a trap, and their non-arrival despite being commissioned years in advance is an institutional failure.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationcritique
The AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationinterpretation
Amendments passed by the Hungarian Parliament in March 2025 extending police use of facial recognition to all infractions constitute real-time remote biometric identification in breach of AI Act Article 5 and of the Charter, according to legal analysis by EDRi, ECNL, Liberties and the Hungarian Civil Liberties Union.
Interpretationcritiqueunverified
This body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part XI
Unresolvedfact
The Commission has not opened infringement proceedings against Hungary on the basis of the biometric surveillance legislation.