The EU AI Act, decoded: what actually changes, and when
Europe's artificial intelligence law lands in stages rather than all at once. Here is the structure of the rules, the phased dates, and who each obligation falls on.
Meridians Tech Desk
Published 18 June 2026 · Updated 29 July 2026 · 9 min read
AIThe short answer
- The AI Act is risk-tiered: the same technology can be unregulated in one use and prohibited in another.
- Obligations phase in over several years from entry into force, rather than switching on together.
- Most duties fall on providers who place a system on the market; deployers carry lighter, use-specific duties.
- If you only read one section, read the definitions — 'provider', 'deployer' and 'general-purpose AI model' decide what applies to you.
The European Union's Artificial Intelligence Act is frequently described as the world's first comprehensive AI law. That description is accurate but unhelpful for anyone trying to work out what they personally have to do. The Act is not a single switch. It is a layered regime that classifies uses of AI by the risk they pose, attaches different duties to each layer, and brings those duties into force on a staggered timetable.
The risk tiers
The Act's central design choice is that regulation attaches to the use, not to the technology. The same underlying model can sit in an unregulated product and, deployed differently, sit in a prohibited one.
- Prohibited practices: a narrow list of uses considered incompatible with fundamental rights, banned outright.
- High-risk systems: permitted, but subject to the heaviest obligations — risk management, data governance, technical documentation, logging, human oversight and conformity assessment.
- Transparency-risk systems: permitted with disclosure duties, such as making clear that a person is interacting with a machine or that content has been artificially generated.
- Minimal risk: the large majority of AI uses, which the Act leaves substantially untouched.
General-purpose AI is handled separately
Large general-purpose models sit outside the use-based tiers because their eventual use is unknown at the point they are released. The Act therefore imposes model-level duties on their providers — documentation, information for downstream developers, a copyright policy and a summary of training content — with additional obligations for models judged to carry systemic risk.
The phased timetable
The Act entered into force in 2024, but its provisions apply from different dates. The prohibitions and AI literacy duties come first, the general-purpose model rules follow, and the bulk of the high-risk regime applies later, with a longer runway for high-risk AI embedded in products already covered by EU product-safety law.
Because those dates have been the subject of continuing implementation work and guidance at EU level, we link the official consolidated text and the Commission's implementation pages below rather than restating dates that may since have been adjusted. Check the primary source before relying on a specific deadline.
What this means in practice
- Inventory what AI you actually use, including features quietly embedded in existing software.
- Classify each use against the tiers — not each vendor, each use.
- Establish whether you are a provider or a deployer for each one.
- Where a use is high-risk, start with documentation and human oversight; those take longest to build.
- Track the official guidance, because the operational detail is still being filled in through standards and Commission guidance.
The honest caveat
Much of the Act's real-world effect will be determined by harmonised standards and guidance that are still being produced. Anyone promising you a complete, final compliance checklist today is selling certainty that does not yet exist. The structure above, however, is stable, and it is the right frame to plan against.
Sources
Every factual claim above is traceable to these documents. Check them — that is why they are here.
- Regulation (EU) 2024/1689 — the AI Act (full text)EUR-Lex, Publications Office of the EU
- AI Act implementation and guidanceEuropean Commission
- European AI OfficeEuropean Commission
About this byline
Meridians Tech Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.
Sponsored
Paid placement · not editorial
Tessera Cloud · Business software
Infrastructure that stays boring.
European hosting, predictable billing and migrations handled by engineers. Sponsored modules are produced outside our editorial desks and are always labelled.
Talk to Tessera →
Tessera CloudWhy am I seeing this? · Demonstration creative from a fictional advertiser. Advertising never influences our journalism.
Passkeys, explained: what replaces the password, and what it doesn't
8 min read · 12 July 2026
EV charging speeds: why '150 kW' rarely means 150 kW at your car
6 min read · 11 July 2026
The Meridians Brief
One considered email a week
What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.
Sign-up opens with our launch issue. Nothing is sent or stored yet.



