EU AI Act explained: Meaning, purpose, and key provisions

October 9, 2026

Understand the EU AI Act, who it applies to, its risk categories, prohibited practices, transparency requirements, penalties, and the steps businesses should take toward compliance.

In this new era of AI shopping, shoppers begin by stating their goals, allowing an AI agent to interpret their intent, weigh trade-offs across various brands, and present a short list of options. These agents increasingly assemble shopping baskets and complete checkout through payment protocols and merchant integrations.

As a result, merchants are adapting their services because the customer they serve may now be an AI agent acting on a person’s behalf. This shift means product data must be readable by both AI agents and humans. Payment providers, such as Visa, have introduced AI-ready cards that enable merchants to verify whether a consumer’s agent is authorized to make purchases. Additionally, software vendors are transforming tools that once supported work into platforms that can perform tasks autonomously.

The EU AI Act, officially known as Regulation (EU) 2024/1689, is the world’s first comprehensive legal framework for AI. It addresses chatbots, AI agents, and AI-generated content that now mediate interactions between brands and buyers. The Act aims to improve the functioning of the internal market, promote human-centric and trustworthy AI, protect health, safety, and fundamental rights, and encourage innovation.

In this guide, you will find:

  1. What is the AI content control problem in product operations, and why does it happen?
  2. What layers of control does AI-generated product content need?
  3. Who decides what AI can change, and how much human review does each type of product content need?
  4. How do you verify AI-generated product content before it reaches a channel?
  5. Where should you start fixing AI content control?
  6. What platform capabilities support AI content control in product operations?
  7. FAQs

Know what AI publishes on your behalf

Explore how Inriver supports product content verification, human oversight, and traceability as your business adopts AI.

What is the EU AI Act?

The EU AI Act is a regulation that sets risk-based rules for AI developers and deployers according to the specific use of AI, and the European Parliament and the Council adopted it on 13 June 2024. It rests on four main points.

Key facts about the EU AI Act

Official titleRegulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence
Adopted13 June 2024, by the European Parliament and the Council
Published in the Official Journal12 July 2024
Entered into force1 August 2024
Amended byRegulation (EU) 2026/1744 (Digital Omnibus on AI), dated 8 July 2026 and in force since 27 July 2026

Why was the EU AI Act introduced?

Most AI systems pose little to no risk and can help solve many societal challenges, yet rules were still needed for three reasons.

  1. Certain AI systems create risks that must be addressed to avoid undesirable outcomes.
  2. It is often impossible to find out why an AI system made a decision, which makes it hard to assess whether someone was unfairly disadvantaged, for example, in a hiring decision or a public benefit application.
  3. Existing legislation offers some protection but is insufficient for the challenges AI systems bring.

When do the EU AI Act’s rules take effect?

The rules phase in over four years from entry into force, with the first obligations applying on 2 February 2025 and the last on 2 August 2028. The Omnibus bullet on the ninth ban shortens to the line below, and the other four bullets stay as they are.

The key changes for 2026 come from the Digital Omnibus on AI, which amended the Act in five ways.

Who does the EU AI Act apply to?

The AI Act applies to providers that place an AI system on the EU market, wherever they are established, and to providers and deployers in third countries whose AI system’s output is used in the EU. Six types of parties count as operators, and the Act also covers affected persons located in the EU.

If you use an AI system under your company’s authority for professional work, you are a deployer, and if you build an AI system or have one built and release it under your own name, you are a provider.

What counts as an AI system, and which AI uses fall outside the EU AI Act?

An AI system is a machine-based system with four further characteristics: 

  1. It is designed to operate with varying levels of autonomy.
  2. It may exhibit adaptiveness after deployment.
  3. It infers, from the input it receives and for explicit or implicit objectives, how to generate outputs.
  4. Its outputs, such as predictions, content, recommendations, or decisions, can influence physical or virtual environments.

Non-binding guidelines on the AI system definition help determine whether a system falls inside the Act.

Beyond that definition, five uses of AI fall outside the Act:

To check whether the Act applies to your system, work through the AI system definition, the scope rules, and the exclusions in that order, which leads to your role.

What are the EU AI Act’s risk categories, and what counts as high-risk AI?

The Act sorts AI systems into four risk levels, from banned practices at the top to systems with no new rules at the bottom.

Risk levelWhat it coversWhat the Act requires
Unacceptable riskClear threats to the safety, livelihoods, and rights of people, such as social scoringBanned
High riskSerious risks to health, safety, or fundamental rights, such as CV-sorting software for recruitmentStrict obligations before the system reaches the market
Transparency riskRisks linked to the need for transparency, such as chatbotsDisclosure duties and identifiable or labeled AI-generated content
Minimal or no riskMost AI systems in use, such as spam filters and AI-enabled video gamesNo new rules

An AI system becomes high-risk through one of two routes.

High-risk systems must meet seven requirements before they reach the market.

Deployers must also assign human oversight to natural persons with the necessary competence, training, and authority and keep the system’s automatically generated logs for at least six months.

What is banned under the EU AI Act?

The Act bans nine AI practices that threaten people’s safety, livelihoods, and rights.

  1. Harmful AI-based manipulation and deception
  2. Harmful AI-based exploitation of vulnerabilities, such as age, disability, or a social or economic situation
  3. Social scoring that leads to detrimental or unjustified treatment
  4. Individual criminal offense risk assessment or prediction based solely on profiling or personality traits
  5. Untargeted scraping of the internet or CCTV material to build facial recognition databases
  6. Emotion recognition in workplaces and educational institutions, except for medical or safety reasons
  7. Biometric categorization that deduces race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation
  8. Real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow exceptions
  9. AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material, such as AI “nudification” apps

The ninth ban applies where generating that material is a system’s intended purpose, or where the system’s design makes that output reasonably foreseeable and the system lacks adequate safeguards. Legal explanations and practical examples for the first eight bans are in the guidelines on prohibited AI practices.

What rules apply to AI-generated content and general-purpose AI?

Regulation adds a second reason to keep these records, because the European Commission states that providers and deployers within the scope of Article 50(2) and (4) of the EU AI Act must comply with transparency obligations for AI-generated or manipulated content from 2 August 2026, while AI systems placed on the market before that date have a transitional period until 2 December 2026. Your team can see which workflows fall within that scope by reviewing the EU AI Act’s impact on product content and PIM.

Chatbots, deepfakes, and generative AI systems that produce synthetic audio, image, video, or text must tell people when they are dealing with AI, no later than the first interaction or exposure. 

General-purpose AI models, which perform a wide range of distinct tasks and can be integrated into many downstream systems, follow separate obligations for their providers.

AI-generated content (Article 50)General-purpose AI models (Articles 53 and 55)
Interaction with AI. Providers must design AI systems that interact directly with people so users know they are dealing with an AI system, unless that is obvious.Technical documentation. Providers must keep documentation of the model, including its training, testing, and evaluation results, for the AI Office and national authorities.
Marking of outputs. Providers of generative AI systems must mark synthetic audio, image, video, and text outputs in a machine-readable format, except for assistive standard editing.Information for downstream providers. Providers must give documentation on the model’s capabilities and limitations to the providers that build AI features on it.
Emotion recognition and biometric categorization. Deployers must inform the people exposed to these systems.Copyright policy. Providers must put in place a policy to comply with EU copyright law.
Deepfakes. Deployers must disclose that deepfake content was artificially generated or manipulated, with a lighter disclosure for evidently artistic, creative, satirical, or fictional works.Training content summary. Providers must publish a sufficiently detailed summary of the training content, following the AI Office’s template.
Public-interest text. Deployers must disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless it has human review or editorial control and a person holds editorial responsibility.Systemic risk models. Providers of models with systemic risk must also run model evaluations, including adversarial testing; mitigate systemic risks; report serious incidents to the AI Office; and ensure adequate cybersecurity.

What are the penalties for breaking the EU AI Act?

The Act sets fines of up to €35 million or 7% of total worldwide annual turnover for banned practices, up to €15 million or 3% for most other obligations, including the transparency rules, and up to €7.5 million or 1% for giving authorities incorrect or misleading information. Companies face the higher amount in each tier, while SMEs and start-ups face the lower amount, and small mid-cap companies face the lower amount in the second and third tiers.

Source: Regulation (EU) 2024/1689, Articles 99 and 101, as amended by Regulation (EU) 2026/1744.

The Commission can also fine providers of general-purpose AI models up to €15 million or 3% of worldwide turnover, whichever is higher, for intentional or negligent infringements. Authorities set each amount by weighing the gravity and duration of the infringement, the operator’s size and turnover, any financial benefit gained, the operator’s cooperation, and whether the infringement was intentional or negligent.

Enforcement is split between the EU and national levels:

How do you comply with the EU AI Act?

Complying with the AI Act means determining which of your AI systems it covers and then meeting the duties that apply to your role and each system’s risk level.

Product teams that use AI to enrich, translate, and generate content already need someone to approve each output, record it, and decide what reaches a channel. 

Inriver handles this through product information orchestration, which coordinates enrichment, approvals, and channel activation in one governed flow. Its flexible data model ingests product data from any source as-is, without the usual cleanup or ETL project, and its agentic orchestration runs AI agent and LLM workflows with a verification and validation layer that checks each output against trusted product data before it reaches a channel.

The platform fits teams that want agentic speed with control over what AI-generated content reaches each channel, and Inriver Inspire AI applies the same approach to enrichment and translation with full traceability. Teams that publish AI-assisted product content also need to work out how the Act applies to product content and PIM, since the disclosure duties depend on the type of content and on the review it receives before publication.

Ready to see Inriver in action?

Inriver transforms the way your business thinks about product data. Let an Inriver expert explain the many benefits of the enterprise-ready, fully adaptable Inriver platform.

  • Get a personalized, guided demo of the Inriver platform
  • Have all your PIM questions answered
  • Free consultation, zero commitment

    Thanks for choosing Inriver! We’ll be in touch soon.

    Something went wrong

    Please try again in a moment.

    EU AI Act: Frequently asked questions

    You may also like…