Adopted in 2024, the EU AI Act has established one of the world's most comprehensive frameworks for regulating artificial intelligence (AI). It seeks to protect consumers and fundamental rights while providing companies with clearer rules for developing and deploying the rapidly evolving technology.
Some parts of the law were introduced earlier. A series of prohibited practices, including certain forms of AI manipulation and exploitation, have been banned since February 2025, while obligations covering providers of general-purpose AI models began to apply in August last year.
From Sunday, however, the European Commission gained the power to enforce those obligations directly, including by conducting investigations and issuing fines.
New transparency requirements have also taken effect, obliging providers and users of certain AI systems to make it clear when material has been artificially generated or manipulated.
EU unveils plan to cut dependence on US and Asian technology
Greater transparency
The rules require AI-generated content to carry markings that can be detected electronically. People or organisations publishing deepfakes – highly realistic manipulated images, audio or video – must also disclose that the material has been altered or artificially created.
AI-generated or manipulated text published to inform the public about matters of public interest must generally be labelled, although exemptions apply when the content has undergone human editorial review and a person or organisation accepts responsibility for it.
Special provisions apply to artistic, satirical and fictional works to ensure that labels do not unnecessarily interfere with their display or enjoyment.
Systems placed on the EU market before 2 August have until 2 December to meet some of the new technical marking and detection requirements.
EU moves to cut red tape with overhaul of AI and data privacy laws
The legislation also places strict limits on biometric identification and facial recognition. Some uses are permitted for law enforcement under tightly controlled circumstances, but practices such as indiscriminate collection of facial images to build recognition databases are prohibited.
AI systems cannot use deliberately deceptive or subliminal methods to manipulate people in ways likely to cause significant harm. They are also barred from exploiting vulnerabilities linked to age, disability or a person's social or economic circumstances.
Providers of powerful general-purpose models must maintain technical documentation, publish information about the material used to train their systems and establish policies to comply with EU copyright law.
Those developing the most advanced models – which may pose what the legislation calls a systemic risk – face additional requirements, including safety assessments, cybersecurity protections, incident reporting and measures to mitigate potential harm.
Stronger enforcement powers
The Commission's AI Office, established to oversee implementation of the law, can now assess general-purpose models and investigate whether their providers are meeting the requirements.
Companies may be ordered to supply documents and information or grant regulators access to their models for evaluation. In some cases, the AI Office can examine a model before it is released on the European market.
National regulators will oversee other AI systems, including many smaller or more specialised applications.
EU investigators can require companies to take corrective action when they identify a breach. The Commission can also restrict the availability of a model or ask its provider to withdraw it from the market.
The expanded powers mark an important step for Brussels as regulators seek greater access to increasingly capable systems developed by companies based outside Europe, including Anthropic's Mythos models.
Penalties will vary according to the seriousness of the infringement.
New York Times chief slams AI companies for 'theft' of intellectual property
Companies using prohibited AI practices may be fined as much as €35 million or 7 percent of their total worldwide annual turnover – whichever is higher.
Breaches of other requirements can carry penalties of up to €15 million or 3 percent of global annual turnover. Providers of general-purpose models can also be penalised for supplying inaccurate or misleading information, failing to cooperate with regulators or refusing access to their systems.
Smaller companies will face proportionate penalties based on their size and financial circumstances.
Further rules will follow – from December 2027, stricter requirements will apply to high-risk AI used in areas including healthcare, employment, education, migration and security.
Rules covering AI embedded in regulated products such as medical devices, machinery, toys and lifts will take effect in August 2028.
The EU also plans to ban systems designed to create non-consensual sexually explicit images, including so-called nudification tools.
(with newswires)



Health Ministry sets up committee to investigate unrest at Techiman-Krobo Nursin...
NACOC arrests 10 KTU students over alleged trafficking of cannabis-infused drink...
Bank of Ghana warns public against 20 unlicensed digital loan apps
'We have not lost GH¢200 million to Dominic Bonsu Ventures' — GoldBod
'Gender equality is key to building stronger ECOWAS institutions' — Amb Gana
Cameroon government says President Biya's prolonged absence no cause for concern
Another video surfaces showing moment coffin was moved from pickup truck during ...
You are ineffective, inefficient and incompetent – Solomon Owusu fires Godfred D...
Stop harassing opposition MPs for simply holding different views — Minority Lead...
High Court freezes five bank accounts, four properties of NPP's Miracles Aboagye...