EU AI Act

European Union · AI regulation · Risk-based framework

What it governs

AI systems placed on the EU market, or whose outputs are used in the Union, under the risk-based obligations set out in Regulation (EU) 2024/1689.

Why it matters for AI agents

Transparency duties, prohibited-practice bans, high-risk obligations, human oversight requirements, and, increasingly, evidence of how a deployed system actually behaves.

Riverfront coverage

Behavioral testing against the obligations applicable to your deployment. Not legal certification.

The EU AI Act in plain English for people who are not lawyers

The high-risk deadline moved in May 2026. The law did not go away, and neither did the parts already in force.

Published 2 September 2026

The EU AI Act is the first horizontal AI law from a major regulator, meaning it does not target one sector or one type of harm. It sorts AI systems by risk and attaches obligations to each level, and its reach extends beyond the EU's own borders under conditions the Act itself defines.

Most explainers of it read like the statute. This one is organized around the three questions a non-lawyer actually needs answered: what does it cover, what is actually due and when, and what happens if you get it wrong.

Four broad risk levels, in one pass

A useful way to understand the Act is through four broad levels of regulatory risk. It is shorthand, not a literal statutory taxonomy, and where a specific system lands can depend on facts about how it is actually used, not just what category it seems to belong to on first read. Still, the shorthand is a fair starting map.

Unacceptable risk systems are banned outright. The original 2024 list covers eight practices: manipulative or deceptive techniques that materially distort behavior and cause harm, exploiting the vulnerabilities of specific groups, biometric categorization to infer sensitive attributes like political opinion or sexual orientation, social scoring, most real-time remote biometric identification in public spaces for law enforcement, predictive-policing systems based on profiling alone, untargeted scraping to build facial recognition databases, and emotion recognition in workplaces or schools. The May 2026 revision added two more: generating or manipulating child sexual abuse material, and generating non-consensual intimate or sexually explicit imagery of identifiable people, the kind of prohibition aimed squarely at "nudifier" style applications. If your system does one of these things, there is no compliance path. It cannot be deployed in the EU.

High-risk systems are legal but heavily obligated. This level covers AI used in areas like employment decisions, credit scoring, access to essential services, law enforcement, and migration, the kind of use where a wrong output has a material effect on a person's life. Providers of high-risk systems must run risk management processes, maintain technical documentation, ensure human oversight, and register the system in an EU database before it goes to market. This is the level that carries the most compliance weight, and it is also the one whose timeline just moved, which is the point worth sitting with below.

Limited risk systems carry transparency duties rather than structural ones. If a person is interacting with a chatbot, or content has been generated or manipulated by AI, they have to be told.

Minimal risk covers most everyday AI, spam filters and inventory tools, and carries no obligations under the Act at all.

Who it actually applies to, and how far it reaches

The Act uses two roles. A provider builds or places an AI system on the market. A deployer uses one under its own authority. An organization that buys a third-party agent and puts it in front of its own customers is usually a deployer, not a provider, and deployer obligations are lighter than provider obligations, but they are not zero: deployers of high-risk systems still owe human oversight, monitoring, and, in some cases, their own impact assessment.

The reach is extraterritorial by design, and the Act says so directly rather than leaving it to analogy. Article 2 extends the Act to providers and deployers that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. Whether a given deployment falls inside that language is a scope question worth checking against the Act's own text for the specific facts of your deployment, not one to assume from how similar rules have worked in other data or privacy laws.

What actually changed in May 2026, and what did not

This is the part most likely to be outdated in explainers published before May 2026, so it is worth being precise. In May 2026, the Council and Parliament reached political agreement on an omnibus package that delayed and simplified parts of the Act; it entered into force on July 27, 2026.

The high-risk system obligations, the tier with the heaviest compliance load, were due to apply from August 2, 2026. Under the revised timeline, per the European Commission's own account of the agreement, those rules now apply from December 2, 2027 for high-risk systems in sensitive areas, and from August 2, 2028 for AI embedded in already-regulated products like lifts, toys, and machinery. Access to regulatory sandboxes, including an EU-level sandbox, was also expanded as part of the same package.

What did not move: the prohibited-practices ban has applied since February 2025. General-purpose AI model obligations, the rules that apply to foundation model providers, have applied since August 2025, and so has the penalty structure described below.

The practical read for anyone deploying agents into the EU market: the delay buys time on the high-risk documentation tier specifically. It does not touch the obligations that were already live, and it says nothing about whether the agent you are shipping this quarter behaves the way your own policies say it should. That question does not wait for a regulatory deadline.

What it costs to get wrong

Article 99 sets three penalty tiers, and they are designed to remain material at any company size.

Violating the banned-practices list under Article 5 carries administrative fines of up to EUR 35 million or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Failing other operator obligations, high-risk requirements, or transparency duties carries fines of up to EUR 15 million or 3 percent of turnover, whichever is higher. Giving incorrect, incomplete, or misleading information to a notified body or national authority carries up to EUR 7.5 million or 1 percent of turnover, whichever is higher. For SMEs, including start-ups, each of those figures applies at whichever amount is lower instead, which softens the exposure without removing it.

The "whichever is higher" structure for larger companies is the detail worth noticing. It means the fine scales with company size specifically so that a large multinational cannot treat it as a rounding error.

What this means if you are not sure which level you are in

Many customer-facing AI agents will primarily trigger the Act's transparency obligations rather than its high-risk requirements. But classification depends on what the system actually does and the context it operates in, not on what kind of agent it was built to be or who it was built for. An employee-facing system used in recruitment, performance evaluation, or promotion decisions, for instance, can sit squarely inside high-risk territory even though it looks, on the surface, like an ordinary internal tool rather than the kind of system the word "AI regulation" tends to conjure.

As an agent gains authority to make or materially influence consequential decisions, such as resolving eligibility questions or adjudicating disputes, its regulatory analysis can change accordingly. That is why classification is not a one-time documentation exercise, decided once at launch and filed away. Documentation describes what a system is supposed to do. It does not verify what the system actually did the last time a real user pushed it somewhere the documentation did not anticipate.


This is one layer of a compliance program, not a substitute for one, and it does not constitute legal advice. Riverfront tests agent behavior against the obligations in frameworks like this one; it does not certify compliance with them.


Sources: Regulation (EU) 2024/1689 (the EU AI Act), Article 2 (scope), Article 5 (prohibited practices), and Article 99 (penalties), EUR-Lex, CELEX:32024R1689 (eur-lex.europa.eu/eli/reg/2024/1689/oj/eng). European Commission, "AI Act" policy page (digital-strategy.ec.europa.eu), on the May 7, 2026 political agreement, its July 27, 2026 entry into force, and the revised December 2, 2027 / August 2, 2028 high-risk deadlines. Council of the European Union, press release on the provisional agreement to simplify and streamline AI rules, May 7, 2026, as a second, corroborating official source for the same timeline. White & Case, "EU AI Omnibus enters into force, amending the AI Act," and Orrick, "EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes," both July 2026, on the new Article 5 prohibitions covering CSAM and non-consensual intimate imagery.