EU AI Act
Artificial Intelligence Act (Regulation (EU) 2024/1689)
Overview
The AI Act lays down harmonised rules for artificial intelligence in the EU. It prohibits certain AI practices, sets obligations for high-risk AI systems and general-purpose AI models, and adds transparency duties. It entered into force on 1 August 2024 and became generally applicable on 2 August 2026. Prohibited practices have applied since 2 February 2025 and obligations for general-purpose AI models since 2 August 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026) postponed the high-risk rules to 2 December 2027 for Annex III use cases, which include biometrics, and to 2 August 2028 for AI embedded in regulated products. For identity teams the Act matters in three areas: biometric identification, named human oversight of high-risk systems, and logging.
IAM Requirements
Biometric Identification and Categorisation
- Prohibited: AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage (Article 5)
- Prohibited: biometric categorisation systems that infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation from biometric data (Article 5)
- High-risk (Annex III): remote biometric identification systems, biometric categorisation by sensitive attributes, and emotion recognition systems
- Biometric verification whose sole purpose is to confirm that a person is who they claim to be is not classed as remote biometric identification
- For remote biometric identification, no action or decision may be based on a match unless it has been separately verified and confirmed by at least two natural persons, with exceptions for law enforcement, migration, border control and asylum (Article 14(5))
Human Oversight
- High-risk AI systems must be designed so that natural persons can effectively oversee them while in use (Article 14)
- Overseers must be able to disregard, override or reverse the output and to interrupt the system through a stop procedure (Article 14(4))
- Deployers must assign human oversight to natural persons who have the necessary competence, training and authority (Article 26(2))
- Deployers must use high-risk systems in accordance with the instructions for use and monitor their operation (Article 26)
Logging and Traceability
- High-risk AI systems must technically allow automatic recording of events (logs) over the lifetime of the system (Article 12)
- For remote biometric identification, logs must record the period of each use, the reference database, the input data that led to a match, and the identity of the persons who verified the results (Article 12(3))
- Providers must keep automatically generated logs under their control for at least six months (Article 19)
- Deployers must keep automatically generated logs under their control for at least six months (Article 26(6))
Cybersecurity
- High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity throughout their lifecycle (Article 15)
- High-risk AI systems must be resilient against attempts by unauthorised third parties to alter their use, outputs or performance (Article 15(5))
Application Timeline
- 2 February 2025: prohibited AI practices and AI literacy obligations apply
- 2 August 2025: governance rules and obligations for general-purpose AI models apply
- 2 August 2026: general date of application
- 2 December 2027: high-risk rules apply to Annex III systems, including biometrics
- 2 August 2028: high-risk rules apply to AI systems embedded in regulated products (Annex I)
Compliance Checklist
Penalties for Non-Compliance
Up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices; up to €15 million or 3% for other operator obligations; up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information (Article 99).
Quick Facts
- Region
- European Union
- Effective Date
- August 2, 2026
- Enforcing Body
- National market surveillance authorities in each Member State; the European Commission's AI Office for general-purpose AI models