The EU AI Act enters into force
The world's first comprehensive AI law took effect, banning some uses outright and imposing obligations on general-purpose models by capability.
- Government & policy
- Courts & copyright
- Era-defining
Regulation (EU) 2024/1689 entered into force, three years after it was first proposed and following a negotiation that generative AI had substantially rewritten mid-passage. It was the first comprehensive statutory framework for artificial intelligence anywhere.
The structure is risk-tiered. A short list of practices is prohibited outright — social scoring by public authorities, untargeted scraping of facial images, emotion recognition in workplaces and schools, and most real-time remote biometric identification in public by law enforcement. A larger category of high-risk uses, covering areas such as employment, credit, education, medical devices and critical infrastructure, carries obligations on data governance, documentation, human oversight, accuracy and post-market monitoring. Limited-risk systems face transparency duties, including labelling of synthetic content and disclosure that a user is talking to a machine.
The general-purpose AI chapter was added late, after ChatGPT, and is the part that bears on frontier labs. All GPAI model providers face documentation, copyright-policy and training-data-summary obligations. Models presumed to carry systemic risk — with a threshold set at 10²⁵ floating-point operations of training compute — additionally face model evaluation, adversarial testing, incident reporting and cybersecurity requirements. Fines reach 7% of global turnover for prohibited practices.
Application was staged rather than immediate: prohibitions from February 2025, GPAI obligations from August 2025, most high-risk rules from August 2026. That schedule kept the Act politically live long after passage, and industry lobbying for delay and simplification intensified through 2025 as European competitiveness became the dominant frame.
Its wider significance is as a reference point. Every subsequent jurisdiction drafting AI rules positioned itself relative to Brussels — adopting its definitions, or explicitly rejecting its approach.