EU AI Act explained: Meaning, purpose, and key provisions
October 9, 2026Understand the EU AI Act, who it applies to, its risk categories, prohibited practices, transparency requirements, penalties, and the steps businesses should take toward compliance.
In this new era of AI shopping, shoppers begin by stating their goals, allowing an AI agent to interpret their intent, weigh trade-offs across various brands, and present a short list of options. These agents increasingly assemble shopping baskets and complete checkout through payment protocols and merchant integrations.
As a result, merchants are adapting their services because the customer they serve may now be an AI agent acting on a person’s behalf. This shift means product data must be readable by both AI agents and humans. Payment providers, such as Visa, have introduced AI-ready cards that enable merchants to verify whether a consumer’s agent is authorized to make purchases. Additionally, software vendors are transforming tools that once supported work into platforms that can perform tasks autonomously.
The EU AI Act, officially known as Regulation (EU) 2024/1689, is the world’s first comprehensive legal framework for AI. It addresses chatbots, AI agents, and AI-generated content that now mediate interactions between brands and buyers. The Act aims to improve the functioning of the internal market, promote human-centric and trustworthy AI, protect health, safety, and fundamental rights, and encourage innovation.
In this guide, you will find:
- What is the AI content control problem in product operations, and why does it happen?
- What layers of control does AI-generated product content need?
- Who decides what AI can change, and how much human review does each type of product content need?
- How do you verify AI-generated product content before it reaches a channel?
- Where should you start fixing AI content control?
- What platform capabilities support AI content control in product operations?
- FAQs
What is the EU AI Act?
The EU AI Act is a regulation that sets risk-based rules for AI developers and deployers according to the specific use of AI, and the European Parliament and the Council adopted it on 13 June 2024. It rests on four main points.
- It adds separate obligations for providers of general-purpose AI models.
- It bans nine practices that threaten people’s safety, livelihoods, and rights.
- It sets strict obligations for high-risk AI systems before they can be placed on the market.
- It requires transparency for chatbots, deepfakes, and AI-generated content.
Key facts about the EU AI Act
| Official title | Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence |
| Adopted | 13 June 2024, by the European Parliament and the Council |
| Published in the Official Journal | 12 July 2024 |
| Entered into force | 1 August 2024 |
| Amended by | Regulation (EU) 2026/1744 (Digital Omnibus on AI), dated 8 July 2026 and in force since 27 July 2026 |
Why was the EU AI Act introduced?
Most AI systems pose little to no risk and can help solve many societal challenges, yet rules were still needed for three reasons.
- Certain AI systems create risks that must be addressed to avoid undesirable outcomes.
- It is often impossible to find out why an AI system made a decision, which makes it hard to assess whether someone was unfairly disadvantaged, for example, in a hiring decision or a public benefit application.
- Existing legislation offers some protection but is insufficient for the challenges AI systems bring.
When do the EU AI Act’s rules take effect?
The rules phase in over four years from entry into force, with the first obligations applying on 2 February 2025 and the last on 2 August 2028. The Omnibus bullet on the ninth ban shortens to the line below, and the other four bullets stay as they are.

The key changes for 2026 come from the Digital Omnibus on AI, which amended the Act in five ways.
- High-risk deadlines. Rules for Annex III use cases moved from 2 August 2026 to 2 December 2027, and rules for AI embedded in Annex I products moved from 2 August 2027 to 2 August 2028.
- Ninth prohibition. Article 5 gained a ninth ban, which applies from 2 December 2026.
- AI literacy. Article 4 changed from requiring providers and deployers to ensure, to their best extent, a sufficient level of AI literacy among their staff to requiring measures that support its development, without guaranteeing a specific level for any individual.
- Small mid-cap companies. Simplified requirements for SMEs, including simplified technical documentation, now extend to small mid-cap companies.
- AI Office and sandboxes. The AI Office gained stronger powers and now centralizes oversight of AI systems built on general-purpose AI models, and more innovators can access regulatory sandboxes, including an EU-level sandbox.
Who does the EU AI Act apply to?
The AI Act applies to providers that place an AI system on the EU market, wherever they are established, and to providers and deployers in third countries whose AI system’s output is used in the EU. Six types of parties count as operators, and the Act also covers affected persons located in the EU.
- Provider. A provider develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, for payment or free of charge.
- Deployer. A deployer uses an AI system under its authority, except for personal non-professional activity.
- Importer. An importer is located or established in the EU and places on the market an AI system that bears the name or trademark of a person established in a third country.
- Distributor. A distributor makes an AI system available on the EU market without being its provider or importer.
- Product manufacturer. A product manufacturer places an AI system on the market or puts it into service together with its own product and under its own name or trademark.
- Authorized representative. An authorized representative is established in the EU and carries out a non-EU provider’s obligations on its behalf under a written mandate.
If you use an AI system under your company’s authority for professional work, you are a deployer, and if you build an AI system or have one built and release it under your own name, you are a provider.
What counts as an AI system, and which AI uses fall outside the EU AI Act?
An AI system is a machine-based system with four further characteristics:
- It is designed to operate with varying levels of autonomy.
- It may exhibit adaptiveness after deployment.
- It infers, from the input it receives and for explicit or implicit objectives, how to generate outputs.
- Its outputs, such as predictions, content, recommendations, or decisions, can influence physical or virtual environments.
Non-binding guidelines on the AI system definition help determine whether a system falls inside the Act.
Beyond that definition, five uses of AI fall outside the Act:
- Military, defense, and national security uses, together with areas outside the scope of EU law
- Systems and models developed and used solely for scientific research and development
- Research, testing, and development before a system is placed on the market, except for testing in real-world conditions
- Personal non-professional use by natural persons
- Free and open-source AI systems, unless they are high-risk, banned under Article 5, or subject to the transparency rules in Article 50
To check whether the Act applies to your system, work through the AI system definition, the scope rules, and the exclusions in that order, which leads to your role.
What are the EU AI Act’s risk categories, and what counts as high-risk AI?
The Act sorts AI systems into four risk levels, from banned practices at the top to systems with no new rules at the bottom.

| Risk level | What it covers | What the Act requires |
|---|---|---|
| Unacceptable risk | Clear threats to the safety, livelihoods, and rights of people, such as social scoring | Banned |
| High risk | Serious risks to health, safety, or fundamental rights, such as CV-sorting software for recruitment | Strict obligations before the system reaches the market |
| Transparency risk | Risks linked to the need for transparency, such as chatbots | Disclosure duties and identifiable or labeled AI-generated content |
| Minimal or no risk | Most AI systems in use, such as spam filters and AI-enabled video games | No new rules |
An AI system becomes high-risk through one of two routes.
- Annex I products. AI that is a safety component of a product, or is itself a product, covered by EU harmonization legislation and subject to third-party conformity assessment, such as an AI application in robot-assisted surgery.
- Annex III areas. AI used in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and the administration of justice.
High-risk systems must meet seven requirements before they reach the market.
- ☐ Adequate risk assessment and mitigation systems
☐ High-quality datasets that minimize the risk of discriminatory outcomes
☐ Activity logging that ensures traceability of results
☐ Detailed documentation that lets authorities assess compliance
☐ Clear information for the deployer
☐ Appropriate human oversight measures
☐ A high level of robustness, cybersecurity, and accuracy
Deployers must also assign human oversight to natural persons with the necessary competence, training, and authority and keep the system’s automatically generated logs for at least six months.
What is banned under the EU AI Act?
The Act bans nine AI practices that threaten people’s safety, livelihoods, and rights.
- Harmful AI-based manipulation and deception
- Harmful AI-based exploitation of vulnerabilities, such as age, disability, or a social or economic situation
- Social scoring that leads to detrimental or unjustified treatment
- Individual criminal offense risk assessment or prediction based solely on profiling or personality traits
- Untargeted scraping of the internet or CCTV material to build facial recognition databases
- Emotion recognition in workplaces and educational institutions, except for medical or safety reasons
- Biometric categorization that deduces race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation
- Real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow exceptions
- AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material, such as AI “nudification” apps
The ninth ban applies where generating that material is a system’s intended purpose, or where the system’s design makes that output reasonably foreseeable and the system lacks adequate safeguards. Legal explanations and practical examples for the first eight bans are in the guidelines on prohibited AI practices.
What rules apply to AI-generated content and general-purpose AI?
Regulation adds a second reason to keep these records, because the European Commission states that providers and deployers within the scope of Article 50(2) and (4) of the EU AI Act must comply with transparency obligations for AI-generated or manipulated content from 2 August 2026, while AI systems placed on the market before that date have a transitional period until 2 December 2026. Your team can see which workflows fall within that scope by reviewing the EU AI Act’s impact on product content and PIM.
Chatbots, deepfakes, and generative AI systems that produce synthetic audio, image, video, or text must tell people when they are dealing with AI, no later than the first interaction or exposure.
General-purpose AI models, which perform a wide range of distinct tasks and can be integrated into many downstream systems, follow separate obligations for their providers.
| AI-generated content (Article 50) | General-purpose AI models (Articles 53 and 55) |
|---|---|
| Interaction with AI. Providers must design AI systems that interact directly with people so users know they are dealing with an AI system, unless that is obvious. | Technical documentation. Providers must keep documentation of the model, including its training, testing, and evaluation results, for the AI Office and national authorities. |
| Marking of outputs. Providers of generative AI systems must mark synthetic audio, image, video, and text outputs in a machine-readable format, except for assistive standard editing. | Information for downstream providers. Providers must give documentation on the model’s capabilities and limitations to the providers that build AI features on it. |
| Emotion recognition and biometric categorization. Deployers must inform the people exposed to these systems. | Copyright policy. Providers must put in place a policy to comply with EU copyright law. |
| Deepfakes. Deployers must disclose that deepfake content was artificially generated or manipulated, with a lighter disclosure for evidently artistic, creative, satirical, or fictional works. | Training content summary. Providers must publish a sufficiently detailed summary of the training content, following the AI Office’s template. |
| Public-interest text. Deployers must disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless it has human review or editorial control and a person holds editorial responsibility. | Systemic risk models. Providers of models with systemic risk must also run model evaluations, including adversarial testing; mitigate systemic risks; report serious incidents to the AI Office; and ensure adequate cybersecurity. |
What are the penalties for breaking the EU AI Act?
The Act sets fines of up to €35 million or 7% of total worldwide annual turnover for banned practices, up to €15 million or 3% for most other obligations, including the transparency rules, and up to €7.5 million or 1% for giving authorities incorrect or misleading information. Companies face the higher amount in each tier, while SMEs and start-ups face the lower amount, and small mid-cap companies face the lower amount in the second and third tiers.

The Commission can also fine providers of general-purpose AI models up to €15 million or 3% of worldwide turnover, whichever is higher, for intentional or negligent infringements. Authorities set each amount by weighing the gravity and duration of the infringement, the operator’s size and turnover, any financial benefit gained, the operator’s cooperation, and whether the infringement was intentional or negligent.
Enforcement is split between the EU and national levels:
- National level. Market surveillance authorities appointed by each Member State enforce the rules for AI systems, including the bans and the high-risk rules, and Member States lay down the rules on penalties.
- EU level. The AI Office, established within the Commission, enforces the rules for general-purpose AI models; it can request technical documentation, evaluate models, require corrective measures, and issue fines.
How do you comply with the EU AI Act?
Complying with the AI Act means determining which of your AI systems it covers and then meeting the duties that apply to your role and each system’s risk level.
- ✔️ Map your AI systems
Match each one to your role as provider, deployer, importer, or distributor and to a risk level, using the banned practices, the Annex III areas, and the transparency situations. - ✔️ Support AI literacy
Take measures that support the development of AI literacy among your staff and the other people who operate AI systems on your behalf. - ✔️ Assign oversight
Name the people who oversee each high-risk system and retain its logs. - ✔️ Check your disclosures
Make sure your chatbots tell people they are dealing with AI, your generative outputs are marked, and published text on matters of public interest has human review or editorial control, and decide whether to adhere to the voluntary Code of Practice on Transparency of AI-generated Content. - ✔️ Request model documentation
If you build on a general-purpose AI model, ask the provider for the documentation on its capabilities and limitations.
Product teams that use AI to enrich, translate, and generate content already need someone to approve each output, record it, and decide what reaches a channel.
Inriver handles this through product information orchestration, which coordinates enrichment, approvals, and channel activation in one governed flow. Its flexible data model ingests product data from any source as-is, without the usual cleanup or ETL project, and its agentic orchestration runs AI agent and LLM workflows with a verification and validation layer that checks each output against trusted product data before it reaches a channel.
The platform fits teams that want agentic speed with control over what AI-generated content reaches each channel, and Inriver Inspire AI applies the same approach to enrichment and translation with full traceability. Teams that publish AI-assisted product content also need to work out how the Act applies to product content and PIM, since the disclosure duties depend on the type of content and on the review it receives before publication.
Ready to see Inriver in action?
Inriver transforms the way your business thinks about product data. Let an Inriver expert explain the many benefits of the enterprise-ready, fully adaptable Inriver platform.
- Get a personalized, guided demo of the Inriver platform
- Have all your PIM questions answered
- Free consultation, zero commitment
Thanks for choosing Inriver! We’ll be in touch soon.
Please try again in a moment.