Skip to content
Live
AI/Explainer

The EU AI Act, decoded: what actually changes, and when

Europe's artificial intelligence law lands in stages rather than all at once. Here is the structure of the rules, the phased dates, and who each obligation falls on.

Meridians Tech Desk

Published 18 June 2026 · Updated 29 July 2026 · 9 min read

The EU AI Act, decoded: what actually changes, and whenAI
Photo: Meridians illustration

The short answer

  • The AI Act is risk-tiered: the same technology can be unregulated in one use and prohibited in another.
  • Obligations phase in over several years from entry into force, rather than switching on together.
  • Most duties fall on providers who place a system on the market; deployers carry lighter, use-specific duties.
  • If you only read one section, read the definitions — 'provider', 'deployer' and 'general-purpose AI model' decide what applies to you.

The European Union's Artificial Intelligence Act is frequently described as the world's first comprehensive AI law. That description is accurate but unhelpful for anyone trying to work out what they personally have to do. The Act is not a single switch. It is a layered regime that classifies uses of AI by the risk they pose, attaches different duties to each layer, and brings those duties into force on a staggered timetable.

The risk tiers

The Act's central design choice is that regulation attaches to the use, not to the technology. The same underlying model can sit in an unregulated product and, deployed differently, sit in a prohibited one.

  • Prohibited practices: a narrow list of uses considered incompatible with fundamental rights, banned outright.
  • High-risk systems: permitted, but subject to the heaviest obligations — risk management, data governance, technical documentation, logging, human oversight and conformity assessment.
  • Transparency-risk systems: permitted with disclosure duties, such as making clear that a person is interacting with a machine or that content has been artificially generated.
  • Minimal risk: the large majority of AI uses, which the Act leaves substantially untouched.

General-purpose AI is handled separately

Large general-purpose models sit outside the use-based tiers because their eventual use is unknown at the point they are released. The Act therefore imposes model-level duties on their providers — documentation, information for downstream developers, a copyright policy and a summary of training content — with additional obligations for models judged to carry systemic risk.

The phased timetable

The Act entered into force in 2024, but its provisions apply from different dates. The prohibitions and AI literacy duties come first, the general-purpose model rules follow, and the bulk of the high-risk regime applies later, with a longer runway for high-risk AI embedded in products already covered by EU product-safety law.

Because those dates have been the subject of continuing implementation work and guidance at EU level, we link the official consolidated text and the Commission's implementation pages below rather than restating dates that may since have been adjusted. Check the primary source before relying on a specific deadline.

What this means in practice

  1. Inventory what AI you actually use, including features quietly embedded in existing software.
  2. Classify each use against the tiers — not each vendor, each use.
  3. Establish whether you are a provider or a deployer for each one.
  4. Where a use is high-risk, start with documentation and human oversight; those take longest to build.
  5. Track the official guidance, because the operational detail is still being filled in through standards and Commission guidance.

The honest caveat

Much of the Act's real-world effect will be determined by harmonised standards and guidance that are still being produced. Anyone promising you a complete, final compliance checklist today is selling certainty that does not yet exist. The structure above, however, is stable, and it is the right frame to plan against.

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Tech Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Tessera Cloud · Business software

Infrastructure that stays boring.

European hosting, predictable billing and migrations handled by engineers. Sponsored modules are produced outside our editorial desks and are always labelled.

Talk to Tessera
Tessera Cloud

Why am I seeing this? · Demonstration creative from a fictional advertiser. Advertising never influences our journalism.

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.