Prohibition of Practices Presenting an Unacceptable Risk
The strictest and earliest-applicable elements of the regulatory framework concern the prohibition of artificial intelligence practices presenting an unacceptable risk. As certain uses are incompatible with the fundamental values of the European Union, the provisions governing these prohibited practices have applied since 2 February 2025.
Strictly prohibited practices include, for example, the use of manipulative or deceptive techniques that target the human subconscious. Such techniques may materially distort human behaviour and thereby cause significant harm. The social scoring of natural persons based on their social behaviour or personal characteristics is likewise prohibited. By introducing these prohibitions after a transition period of only six months, the EU legislature sought to ensure that the most serious risks would be addressed as soon as possible.
Penalties, Legal Liability and General-Purpose AI Models
Although the Regulation will not become fully applicable for several years, the EU legislature established another critical milestone for 2 August 2025, which has a significant impact on the legal liability of market operators.
The Regulation provides that Member States must establish penalties for infringements that are proportionate and dissuasive. Most importantly, the provisions concerning penalties and administrative fines have applied since 2 August 2025. This earlier date of application means that market surveillance authorities may take enforcement action and impose fines on persons who breach provisions that have already become applicable, well before the Regulation applies in its entirety.
The obligations applicable to general-purpose artificial intelligence models are also linked to the 2 August 2025 deadline. These models, which are trained on vast amounts of data and display significant generality, can readily be integrated into other systems. In their case, the exceptionally rapid development and adoption of the technology justified an earlier date of application. In addition, the institutional infrastructure required for effective enforcement must also be established. Accordingly, the provisions relating to notified bodies and governance structures also became applicable on that date.
General Application and Requirements for High-Risk Systems
The principal date of general application of the Regulation is 2 August 2026, from which date most of its provisions will become mandatory. These include the particularly stringent requirements and obligations applicable to high-risk AI systems.
From that date, providers of high-risk systems will be required to operate a quality management system and maintain detailed technical documentation. They must ensure appropriate human oversight, as well as the accuracy and cybersecurity of their systems. From August 2026, the placing on the market or putting into service of such systems will also be subject to strict conformity assessment procedures and the affixing of the CE marking.
By providing a two-year preparation period, the EU legislature sought to ensure legal certainty, avoid excessive disruption to the market and allow economic operators sufficient time to comply with the relatively complex administrative and technical requirements.











