{"slug": "from-now-on-companies-across-the-eu-must-be-clear-about-their-use-of-ai", "title": "From now on, companies across the EU must be clear about their use of AI", "summary": "The European Union's AI Act, Regulation (EU) 2024/1689, is now in effect, making it the first comprehensive legal framework for artificial intelligence worldwide. The regulation bans nine specific AI practices, including harmful manipulation, social scoring, and untargeted facial recognition scraping, with prohibitions effective February 2025. The European Commission has launched the AI Pact and an AI Act Service Desk to support compliance and implementation across member states.", "body_md": "The AI Act is the first-ever legal framework on AI, which addresses the risks of AI and positions Europe to play a leading role globally.\n\nThe [AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689) (Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence) is the first-ever comprehensive legal framework on AI worldwide. The aim of the rules is to foster trustworthy AI in Europe. For any **questions on the AI Act**, check out the [ AI Act Single Information platform](https://ai-act-service-desk.ec.europa.eu/en).\n\nThe AI Act sets out a risk-based rules for AI developers and deployers regarding specific uses of AI. The AI Act is part of a wider package of policy measures to support the development of trustworthy AI, which also includes the [AI Continent Action Plan](https://digital-strategy.ec.europa.eu/en/factpages/ai-continent-action-plan), the [AI Innovation Package](https://ec.europa.eu/commission/presscorner/detail/en/ip_24_383) and the launch of [AI Factories](https://digital-strategy.ec.europa.eu/en/policies/ai-factories). Together, these measures guarantee safety, fundamental rights and human-centric AI, and strengthen uptake, investment and innovation in AI across the EU.\n\nTo facilitate the transition to the new regulatory framework, the Commission has launched the [AI Pact](https://digital-strategy.ec.europa.eu/en/policies/ai-pact), a voluntary initiative that seeks to support the future implementation, engage with stakeholders and invite AI providers and deployers from Europe and beyond to comply with the key obligations of the AI Act ahead of time. In parallel, the [AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en) is also providing information and support for a smooth and effective implementation of the AI Act across the EU.\n\n## Why do we need rules on AI?\n\nThe AI Act ensures that Europeans can trust what AI has to offer. While most AI systems pose limited to no risk and can contribute to solving many societal challenges, certain AI systems create risks that we must address to avoid undesirable outcomes.\n\nFor example, it is often not possible to find out why an AI system has made a decision or prediction and taken a particular action. So, it may become difficult to assess whether someone has been unfairly disadvantaged, such as in a hiring decision or in an application for a public benefit scheme.\n\nAlthough existing legislation provides some protection, it is insufficient to address the specific challenges AI systems may bring.\n\n## A Risk-based Approach\n\nThe AI Act defines 4 levels of risk for AI systems:\n\n### Unacceptable risk\n\nAll AI systems considered a clear threat to the safety, livelihoods and rights of people are banned. The **AI Act prohibits nine practices**, namely:\n\n- harmful AI-based manipulation and deception\n- harmful AI-based exploitation of vulnerabilities\n- social scoring\n- Individual criminal offence risk assessment or prediction\n- untargeted scraping of the internet or CCTV material to create or expand facial recognition databases\n- emotion recognition in workplaces and education institutions\n- biometric categorisation to deduce certain protected characteristics\n- real-time remote biometric identification for law enforcement purposes in publicly accessible spaces\n- AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse (CSAM) material, such as AI ‘nudification' apps\n\nProhibitions 1-8 became effective in February 2025. The Commission published 2 key documents to support the practical application of the prohibited practices:\n\n- The\n[guidelines on prohibited AI practices under the AI Act](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act), which offer legal explanations and practical examples to help stakeholders understand and comply with the prohibitions. - The\n[guidelines on the AI system definition of the AI Act](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application), to assist stakeholders in determining the scope of the AI Act\n\nProhibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus package.\n\n### High risk\n\nAI use cases that can pose serious risks to health, safety or fundamental rights are classified as high-risk. These **high-risk **use-cases include:\n\n- AI safety components in critical infrastructures (e.g. transport), the failure of which could put the life and health of citizens at risk\n- AI solutions used in education institutions, that may determine the access to education and course of someone’s professional life (e.g. scoring of exams)\n- AI-based safety components of products (e.g. AI application in robot-assisted surgery)\n- AI tools for employment, management of workers and access to self-employment (e.g. CV-sorting software for recruitment)\n- Certain AI use-cases utilised to give access to essential private and public services (e.g. credit scoring denying citizens opportunity to obtain a loan)\n- AI systems used for remote biometric identification, emotion recognition and biometric categorisation (e.g. AI system to retroactively identify a shoplifter)\n- AI use-cases in law enforcement that may interfere with people’s fundamental rights (e.g. evaluation of the reliability of evidence)\n- AI use-cases in migration, asylum and border control management (e.g. automated examination of visa applications)\n- AI solutions used in the administration of justice and democratic processes (e.g. AI solutions to prepare court rulings)\n\nStarting on 2 December 2027,** high-risk AI systems** will be subject to **strict obligations** before they can be put on the market:\n\n- adequate risk assessment and mitigation systems\n- high-quality of the datasets feeding the system to minimise risks of discriminatory outcomes\n- logging of activity to ensure traceability of results\n- detailed documentation providing all information necessary on the system and its purpose for authorities to assess its compliance\n- clear and adequate information to the deployer\n- appropriate human oversight measures\n- high level of robustness, cybersecurity and accuracy\n\n### Transparency risk\n\nThis refers to the risks associated with a need for transparency around the use of AI. The AI Act introduces specific disclosure obligations to ensure that humans are informed when necessary to preserve trust. For instance, when using AI systems such as chatbots, humans should be made aware that they are interacting with a machine so they can take an informed decision.\n\nMoreover, providers of generative AI have to ensure that AI-generated content is identifiable. On top of that, certain AI-generated content should be clearly and visibly labelled, namely deep fakes and text published with the purpose to inform the public on matters of public interest.\n\nThe transparency rules of the AI Act will come into effect in August 2026.\n\n### Minimal or no risk\n\nThe AI Act does not introduce rules for AI that is deemed minimal or no risk. The vast majority of AI systems currently used in the EU fall into this category. This includes applications such as AI-enabled video games or spam filters.\n\n## How does it all work in practice for providers of high-risk AI systems?\n\nOnce an AI system is on the market, authorities are in charge of market surveillance, deployers ensure human oversight and monitoring, and providers have a post-market monitoring system in place. Providers and deployers will also report serious incidents and malfunctioning.\n\n## What are the rules for General-Purpose AI models?\n\nGeneral-purpose AI (GPAI) models can perform a wide range of tasks and are becoming the basis for many AI systems in the EU. Some of these models could carry systemic risks if they are very capable or widely used. To ensure safe and trustworthy AI, the AI Act puts in place rules for providers of such models. This includes transparency and copyright-related rules. For models that may carry systemic risks, providers should assess and mitigate these risks. The AI Act rules on GPAI became effective in August 2025.\n\n## Supporting compliance\n\nIn July 2025, the Commission published 3 key instruments to support the responsible development and deployment of GPAI models:\n\n- The\n[Guidelines on the scope of the obligations for providers of GPAI models](https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act)clarify the scope of the GPAI obligations under the AI Act, helping actors along the AI value chain understand who must comply with these obligations. - The\n[GPAI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai)is a voluntary compliance tool submitted to the Commission by independent experts, which offers practical guidance to help providers comply with their obligations under the AI Act related to transparency, copyright, and safety & security. - The\n[Template for the public summary of training content of GPAI models](https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models)requires providers to give an overview of the data used to train their models. This includes the sources from which the data was obtained (comprising large datasets and top domain names).The template also requests information about data processing aspects to enable parties with legitimate interests to exercise their rights under EU law.\n\nThese tools are designed to work hand-in-hand. Together, they provide a clear and actionable framework for providers of GPAI models to comply with the AI Act, reducing administrative burden, and fostering innovation while safeguarding fundamental rights and public trust.\n\nThe Commission is also developing support other tools that offer guidance on how to comply with the AI Act’s transparency rules:\n\n- The\n[Code of Practice on marking and labelling of AI-generated content](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)selected by the AI Office. The code will be a voluntary tool to guide providers and deployers of generative AI systems to comply with transparency obligations. These include marking AI generated content and disclosing the artificial nature of images, and audio (including deepfakes) as well as text. - The Guidelines on transparent AI systems to clarify the scope of application, relevant legal definitions, the transparency obligations, the exceptions and related horizontal issues.\n\nThese support instruments are under preparation and will be published in the second quarter of 2026. Find out more about [how the AI Office is supporting the implementation of the AI Act](https://digital-strategy.ec.europa.eu/en/news/supporting-implementation-ai-act-clear-guidelines).\n\n## Governance and enforcement\n\nFrom 2 August 2026, the AI Office and authorities of the Member States are responsible for implementing, [supervising and enforcing the AI Act](https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act). The AI Office holds enforcement powers over GPAI models. It can request technical documentation, evaluate models, require corrective measures and issue fines for non-compliance.\n\nThe AI Board, the Scientific Panel and the Advisory Forum steer and advise the [AI Act’s governance](https://digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement).\n\nThe July 2026 [action plan on Cybersecurity and AI](https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence) sets out a coordinated approach to help Member States, businesses and public authorities address cybersecurity and resilience challenges posed by the most advanced AI models. The Commission will launch a call to increase EU evaluation capacity of AI models, before they are placed in the EU market. Expected to be operational by 2027, this will strengthen third-party assessment of AI capabilities and risks and contribute to the regulatory function of the AI Office.\n\nThe Commission and the [European Union Agency for Cybersecurity (ENISA)](https://www.enisa.europa.eu/) will also create a blueprint to secure access to advanced AI systems for cybersecurity purposes and establish a secure testing platform to help organisations in critical sectors - such as energy, transport, health, finance and public administration - safely test and deploy AI solutions.\n\n## Application timeline\n\nThe AI Act entered into force on 1 August 2024, and becomes on 2 August 2026, with some exceptions:\n\n- prohibited AI practices and AI literacy obligations entered into application from 2 February 2025\n- the governance rules and the obligations for GPAI models became applicable on 2 August 2025\n- the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027 as a result of the political agreement on the proposal to simplify the AI Act – '\n[AI Omnibus](https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal)'\n\n## How has the Commission simplified the implementation of the AI Act?\n\nThe [Digital Package on Simplification](https://digital-strategy.ec.europa.eu/en/policies/digital-rulebook) proposed amendments to simplify the AI Act implementation and ensure the rules remain clear, simple, and innovation-friendly. This legislative proposal (dubbed as the '[AI Omnibus](https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal)') was adopted on 19 November 2025, a [political agreement](https://digital-strategy.ec.europa.eu/en/news/eu-agrees-simplify-ai-rules-boost-innovation-and-ban-nudification-apps-protect-citizens) was reached on 7 May 2026 and [entered into force on 27 July 2026](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force). Find the final text of the [AI Omnibus Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744).\n\nAs a result, a **clear implementation timeline** is set for the rules governing** high-risk AI systems**:\n\n- Rules for\n**systems used in certain high-risk areas**— including biometrics, critical infrastructure, education, employment, migration, asylum and border control — will** apply from 2 December 2027**. - For\n**systems integrated into products** such as lifts or toys, the rules will**apply from 2 August 2028**.\n\nThis ensures the rules apply when companies have the right support tools to facilitate implementation, such as standards.\n\nIn addition, the following **amends **were added to the** AI Act**:\n\n**Prohibition of AI systems that generate non-consensual sexually explicit and intimate content** or child sexual abuse material, such as AI ‘nudification' apps**Reinforce the AI Office’s powers** and centralise oversight of AI systems built on general-purpose AI models, reducing governance fragmentation**Certain simplified requirements** granted to small and medium-sized enterprises are extended to small mid-cap companies (SMEs and SMCs), including simplified technical documentation requirements- More innovators will gain access to\n**regulatory sandboxes**, including an EU-level sandbox, to test their AI solutions in real-world conditions - The\n**interplay between the AI Act and EU product safety laws**, in particular the Machinery Regulation, is clarified, avoiding duplication between sectoral and AI rules.\n\nAll this complements AI Office actions already in place to provide clarity for businesses and national authorities. For instance, through guidelines, codes of practice, and the [AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en).\n\n## Latest News\n\n## Report / Study\n\n- 15-07-2026\n[AI Office publishes frontier AI expert findings on EU competitiveness, sovereignty and security](/en/library/ai-office-publishes-frontier-ai-expert-findings-eu-competitiveness-sovereignty-and-security) - 13-07-2026\n[New feasibility study for introducing an EU-level registry of Text and Data Mining opt-out](/en/library/new-feasibility-study-introducing-eu-level-registry-text-and-data-mining-opt-out) - 19-05-2026\n[European Commission and OECD collaborate on monitoring national AI strategies and AI investments](/en/library/european-commission-and-oecd-collaborate-monitoring-national-ai-strategies-and-ai-investments)\n\n## Factsheet / infographic\n\n## Related Content\n\n### Big Picture\n\n### Dig deeper\n\n-\nThe enforcement of the AI Act is shared between the European Commission’s AI Office, the European...\n\n-\nThe Commission aims to increase the number of AI experts by training and attracting more researchers...\n\n-\nHarmonised standards will offer legal certainty under the AI Act, support innovation, and position...\n\n-\nThe AI Act Whistleblower Tool empowers individuals to securely submit a report and contribute...\n\n-\nThe AI Act Complaint Tool allows individuals and organisations to submit complaints to the AI...", "url": "https://wpnews.pro/news/from-now-on-companies-across-the-eu-must-be-clear-about-their-use-of-ai", "canonical_source": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai", "published_at": "2026-08-02 16:18:14+00:00", "updated_at": "2026-08-02 16:53:37.596823+00:00", "lang": "en", "topics": ["ai-policy", "ai-ethics", "ai-safety"], "entities": ["European Union", "European Commission", "AI Act", "AI Pact", "AI Act Service Desk"], "alternates": {"html": "https://wpnews.pro/news/from-now-on-companies-across-the-eu-must-be-clear-about-their-use-of-ai", "markdown": "https://wpnews.pro/news/from-now-on-companies-across-the-eu-must-be-clear-about-their-use-of-ai.md", "text": "https://wpnews.pro/news/from-now-on-companies-across-the-eu-must-be-clear-about-their-use-of-ai.txt", "jsonld": "https://wpnews.pro/news/from-now-on-companies-across-the-eu-must-be-clear-about-their-use-of-ai.jsonld"}}