European Union
Comprehensive, risk-based binding regulation (AI Act), now simplified via the 2026 Digital Omnibus
Regulatory posture
The EU remains the global pace-setter with the AI Act's risk-based regime, an AI Office supervising general-purpose models, and a dense ecosystem of codes of practice and harmonised standards. The July 2026 Digital Omnibus pushed high-risk obligations to Dec 2027 / Aug 2028 in a bid to balance competitiveness with protection, while transparency duties began applying on 2 August 2026.
Tracked
- In force4
- Early signal1
- Signals7
Set last reviewed 5 September 2026
Next review 3 October 2026
Tracked instruments
- AI Liability DirectiveThe Commission withdrew its proposed AI Liability Directive in February 2025, citing no foreseeable agreement. Civil liability for AI harms now runs through the revised P…Standards & Assurance
- EU Digital OmnibusThe first formal simplification of the AI Act. Adopted July 2026, it delays high-risk obligations to December 2027 (standalone Annex III systems) and August 2028 (systems…Standards & AssuranceFrontier AI Safety
- GPAI Code of PracticeA voluntary code operationalizing the AI Act's GPAI chapter across transparency, copyright and safety/security. Major model providers signed; signatories received a one-y…Frontier AI SafetyIP & Copyright
- EU AI ActThe world's first comprehensive, risk-based AI law. It bans a set of unacceptable practices (social scoring, manipulative AI, most real-time remote biometric ID), imposes…Frontier AI SafetyBiometrics & SurveillanceStandards & Assurance
- GDPR × AIThe EU's data-protection regime remains a primary AI constraint: legal bases for training data, automated-decision rights (Art. 22), and DPIAs for high-risk processing. E…Data & Privacy
Upcoming compliance dates
EU AI Act — content-marking grace period ends
End of the grace period for the machine-readable marking obligation for AI systems placed on the market before 2 August 2026. From this date, all covered generative AI systems in the EU must mark outputs as AI-generated.
EU revised Product Liability Directive applies to AI products
Directive (EU) 2024/2853 applies to products placed on the market from this date — explicitly covering software and AI systems, with disclosure-of-evidence tools and eased burden of proof for claimants.
EU DSA duties bite for ChatGPT as a designated search engine
Four months after the 31 August 2026 designation, ChatGPT must meet the Digital Services Act's systemic-risk obligations: annual risk assessment and mitigation, independent audit, researcher data access, transparency reporting and a crisis-response mechanism.
EU AI Act — legacy GPAI models must comply
General-purpose AI models placed on the market before 2 August 2025 must be brought into full compliance with the AI Act's GPAI obligations by this date.
EU AI Act — high-risk obligations apply (Annex III)
Post-Omnibus application date for standalone high-risk AI systems (employment, credit, education, essential services, law enforcement): full risk-management, data-governance, human-oversight and conformity obligations.
EU AI Act — high-risk obligations apply (Annex I, embedded)
Post-Omnibus application date for AI systems embedded in regulated products (machinery, medical devices, vehicles): AI Act high-risk duties integrate with sectoral conformity regimes.
Signals
Commission designates ChatGPT a very large online search engine under the DSA
ChatGPT becomes the first generative AI service brought inside the Digital Services Act's strictest tier, alongside Reddit and Roblox as very large online platforms. Systemic-risk assessment, mitigation, audit and data-access duties follow four months after notification.
ContextEU AI Act transparency obligations become applicable
Chatbot disclosure, machine-readable AI-content marking and deepfake labeling duties now apply EU-wide; the GPAI Code of Practice enforcement grace period ends the same day.
ContextDigital Omnibus on AI enters into force, delaying high-risk deadlines
Regulation (EU) 2026/1744 pushes high-risk AI Act obligations to Dec 2027 (Annex III) and Aug 2028 (Annex I) and simplifies documentation duties — the EU's first formal AI Act correction.
ContextEU AI Act GPAI model obligations become applicable
General-purpose model providers must maintain technical documentation, publish training-content summaries and comply with EU copyright law; systemic-risk models face safety duties.
EU publishes General-Purpose AI Code of Practice; major labs sign
The voluntary code operationalizes GPAI duties across transparency, copyright and safety — with a one-year enforcement grace period for signatories.
European Commission withdraws the AI Liability Directive
The first major EU retreat on AI rules; civil liability now channels through the revised Product Liability Directive from December 2026.
Related reading
- Issue 17Denmark met the deadline. Sweden is late. Norway is outside the regime.A model classified Critical for cyber capability shipped this month and no Nordic AI authority has issued operational guidance in response. What policymakers, businesses and citizens should do — and what the region is getting right.
- Issue 08The clause is the policyThe world's largest buyer of AI cannot show that its own contracts carry the provisions its own policy requires. That is not an audit failure. It is a diagnosis.
- Issue 05The sovereign-AI trilemmaEvery state pursuing AI sovereignty in 2026 is making the same trade-off — usually without admitting it.