Skip to main content
IAMRoadmapIAMRoadmap
Back to Compliance
Privacy Regulation

EU AI Act

Artificial Intelligence Act (Regulation (EU) 2024/1689)

European Union
Effective: August 2, 2026
Updated: July 27, 2026

Overview

The AI Act lays down harmonised rules for artificial intelligence in the EU. It prohibits certain AI practices, sets obligations for high-risk AI systems and general-purpose AI models, and adds transparency duties. It entered into force on 1 August 2024 and became generally applicable on 2 August 2026. Prohibited practices have applied since 2 February 2025 and obligations for general-purpose AI models since 2 August 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026) postponed the high-risk rules to 2 December 2027 for Annex III use cases, which include biometrics, and to 2 August 2028 for AI embedded in regulated products. For identity teams the Act matters in three areas: biometric identification, named human oversight of high-risk systems, and logging.

IAM Requirements

Biometric Identification and Categorisation

  • Prohibited: AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage (Article 5)
  • Prohibited: biometric categorisation systems that infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation from biometric data (Article 5)
  • High-risk (Annex III): remote biometric identification systems, biometric categorisation by sensitive attributes, and emotion recognition systems
  • Biometric verification whose sole purpose is to confirm that a person is who they claim to be is not classed as remote biometric identification
  • For remote biometric identification, no action or decision may be based on a match unless it has been separately verified and confirmed by at least two natural persons, with exceptions for law enforcement, migration, border control and asylum (Article 14(5))

Human Oversight

  • High-risk AI systems must be designed so that natural persons can effectively oversee them while in use (Article 14)
  • Overseers must be able to disregard, override or reverse the output and to interrupt the system through a stop procedure (Article 14(4))
  • Deployers must assign human oversight to natural persons who have the necessary competence, training and authority (Article 26(2))
  • Deployers must use high-risk systems in accordance with the instructions for use and monitor their operation (Article 26)

Logging and Traceability

  • High-risk AI systems must technically allow automatic recording of events (logs) over the lifetime of the system (Article 12)
  • For remote biometric identification, logs must record the period of each use, the reference database, the input data that led to a match, and the identity of the persons who verified the results (Article 12(3))
  • Providers must keep automatically generated logs under their control for at least six months (Article 19)
  • Deployers must keep automatically generated logs under their control for at least six months (Article 26(6))

Cybersecurity

  • High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity throughout their lifecycle (Article 15)
  • High-risk AI systems must be resilient against attempts by unauthorised third parties to alter their use, outputs or performance (Article 15(5))

Application Timeline

  • 2 February 2025: prohibited AI practices and AI literacy obligations apply
  • 2 August 2025: governance rules and obligations for general-purpose AI models apply
  • 2 August 2026: general date of application
  • 2 December 2027: high-risk rules apply to Annex III systems, including biometrics
  • 2 August 2028: high-risk rules apply to AI systems embedded in regulated products (Annex I)

Compliance Checklist

1
Inventory AI systems and classify each against the prohibited, high-risk and transparency categories
2
Identify any biometric identification, categorisation or emotion recognition use and check it against Article 5 and Annex III
3
Separate one-to-one biometric verification from remote biometric identification in system documentation
4
Name the people who hold human oversight for each high-risk system and record their competence, training and authority
5
Restrict override and stop functions to those named people and review that access regularly
6
Require two-person verification before acting on a remote biometric identification match
7
Retain automatically generated logs for at least six months and protect them from alteration
8
Record who used and who verified results in biometric identification systems
9
Control administrative and third-party access to high-risk AI systems against unauthorised changes
10
Track the 2 December 2027 and 2 August 2028 dates for high-risk obligations

Penalties for Non-Compliance

Up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices; up to €15 million or 3% for other operator obligations; up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information (Article 99).

Quick Facts

Region
European Union
Effective Date
August 2, 2026
Enforcing Body
National market surveillance authorities in each Member State; the European Commission's AI Office for general-purpose AI models

Related Vendors

Related Regulations & Frameworks