Digital & Tech

EU AI Act Explained (2026): What the World's First AI Law Means for Your Job, Loans, and Online Safety

The EU AI Act sets rules for how artificial intelligence is developed and used across Europe. It bans harmful AI practices, introduces strict safeguards for high-risk systems, and gives people stronger rights to transparency, safety, and human oversight.

Tamari Tabatadze·25 Jul 2026·6 min de lectura
Puntos clave
1. Certain AI practices are already illegal in the EU. Since 2 February 2025, the AI Act has banned manipulative techniques, social scoring, predictive policing based solely on profiling, untargeted facial image scraping, and most real-time biometric surveillance in public spaces. A new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material takes effect on 2 December 2026. 2. High-risk AI systems must meet strict safety rules before organisations use them in areas such as jobs, credit scores, education, healthcare, and law enforcement. By 2 December 2027, these systems must be tested for safety, checked for unfair bias, include human oversight, and be listed in a public EU database. 3. The AI Act doesn't ban artificial intelligence. It bans the dangerous uses of AI and forces them to prove they are safe, fair, and transparent before they can affect your life.

The Artificial Intelligence Act, formally Regulation (EU) 2024/1689, is the world's first horizontal, legally binding framework governing the development, deployment, and use of artificial intelligence systems. Adopted by the European Parliament and the Council on 13 June 2024 and published in the Official Journal of the EU on 12 July 2024, it entered into force on 1 August 2024 .

  The Act is built on a risk-based approach: the stricter the potential harm to health, safety, or fundamental rights, the heavier the regulatory burden. It classifies AI systems into four tiers:

  - 𝐔𝐧𝐚𝐜𝐜𝐞𝐩𝐭𝐚𝐛𝐥𝐞 𝐫𝐢𝐬𝐤 (𝐏𝐫𝐨𝐡𝐢𝐛𝐢𝐭𝐞𝐝): Banned outright. These are AI practices deemed to violate EU values and fundamental rights.

 -  𝐇𝐢𝐠𝐡 𝐫𝐢𝐬𝐤: Subject to strict pre-market and post-market obligations, including conformity assessments, risk management, data governance, human oversight, and registration.

 -  𝐋𝐢𝐦𝐢𝐭𝐞𝐝 𝐫𝐢𝐬𝐤:  Subject to transparency obligations — users must know they are interacting with an AI system.

 - 𝐌𝐢𝐧𝐢𝐦𝐚𝐥 𝐫𝐢𝐬𝐤: Largely unregulated; voluntary codes of conduct encouraged.

𝐓𝐡𝐞 𝐋𝐚𝐰 𝐄𝐱𝐩𝐥𝐚𝐢𝐧𝐞𝐝: 𝐖𝐡𝐚𝐭 𝐈𝐬 𝐭𝐡𝐞 𝐀𝐈 𝐀𝐜𝐭, 𝐑𝐞𝐚𝐥𝐥𝐲?

In June 2026, the EU passed the first updates to the AI Act — called the 𝐃𝐢𝐠𝐢𝐭𝐚𝐥 𝐎𝐦𝐧𝐢𝐛𝐮𝐬 𝐨𝐧 𝐀𝐈. Think of it as a software patch for the original law. It did three main things:

𝟏. Pushed back some deadlines for the strictest AI safety checks, giving companies more time to comply.

𝟐. Gave regulators sharper teeth: stronger powers to investigate and punish rule-breakers.

𝟑. Added new bans on harmful AI uses that weren't fully covered in the original text.

𝐖𝐡𝐲 𝐰𝐚𝐬 𝐭𝐡𝐞 𝐥𝐚𝐰 𝐩𝐚𝐬𝐬𝐞𝐝?

For years, artificial intelligence was spreading through our lives faster than the laws could keep up. AI was deciding who got hired, who got a loan, what medical treatment you received, and what content you saw online, all without a unified set of rules to keep it in check.

The EU identified four big problems that needed fixing:

𝟏. 𝐀𝐈 𝐰𝐚𝐬 𝐞𝐫𝐨𝐝𝐢𝐧𝐠 𝐟𝐮𝐧𝐝𝐚𝐦𝐞𝐧𝐭𝐚𝐥 𝐫𝐢𝐠𝐡𝐭𝐬 𝐚𝐭 𝐬𝐜𝐚𝐥𝐞

Biased algorithms in job recruitment or policing could discriminate against thousands of people automatically. Meanwhile, companies were scraping faces from the internet and CCTV to build massive facial recognition databases, and governments were experimenting with real-time facial tracking in public spaces,  all of which threatened your right to privacy and anonymity.

𝟐. 𝐀𝐈 𝐰𝐚𝐬 𝐛𝐞𝐢𝐧𝐠 𝐮𝐬𝐞𝐝 𝐭𝐨 𝐦𝐚𝐧𝐢𝐩𝐮𝐥𝐚𝐭𝐞 𝐩𝐞𝐨𝐩𝐥𝐞 𝐰𝐢𝐭𝐡𝐨𝐮𝐭 𝐭𝐡𝐞𝐢𝐫 𝐤𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞

"Subliminal" techniques and exploitative design could nudge your behavior in ways you didn't even notice, keeping you addicted to apps, pushing you toward harmful content, or exploiting your emotions. Children and vulnerable people were especially at risk.

𝟑. 𝐀𝐈 𝐝𝐞𝐜𝐢𝐬𝐢𝐨𝐧𝐬 𝐰𝐞𝐫𝐞 𝐛𝐥𝐚𝐜𝐤 𝐛𝐨𝐱𝐞𝐬 𝐰𝐢𝐭𝐡 𝐧𝐨 𝐚𝐜𝐜𝐨𝐮𝐧𝐭𝐚𝐛𝐢𝐥𝐢𝐭𝐲

If an AI rejected your job application, denied your loan, or flagged your social media post, you usually had no idea why. You couldn't see how the system was trained, you couldn't appeal the decision effectively, and you often didn't even know a machine had made the call in the first place.

𝟒. 𝐅𝐚𝐤𝐞 𝐀𝐈-𝐠𝐞𝐧𝐞𝐫𝐚𝐭𝐞𝐝 𝐜𝐨𝐧𝐭𝐞𝐧𝐭 𝐰𝐚𝐬 𝐫𝐮𝐧𝐧𝐢𝐧𝐠 𝐰𝐢𝐥𝐝

Deepfakes, AI-generated scams, and non-consensual intimate imagery (so-called "nudifier" AI) were spreading misinformation and causing real harm, and there was no legal requirement to label synthetic content or trace who created it.

The AI Act was passed to fix all of this. Its core promise is that any 𝐀𝐈 𝐬𝐲𝐬𝐭𝐞𝐦 𝐬𝐨𝐥𝐝 𝐨𝐫 𝐮𝐬𝐞𝐝 𝐢𝐧 𝐭𝐡𝐞 𝐄𝐔 𝐦𝐮𝐬𝐭 𝐛𝐞 𝐬𝐚𝐟𝐞, 𝐭𝐫𝐚𝐧𝐬𝐩𝐚𝐫𝐞𝐧𝐭, 𝐭𝐫𝐚𝐜𝐞𝐚𝐛𝐥𝐞, 𝐧𝐨𝐧-𝐝𝐢𝐬𝐜𝐫𝐢𝐦𝐢𝐧𝐚𝐭𝐨𝐫𝐲, 𝐚𝐧𝐝 𝐞𝐧𝐯𝐢𝐫𝐨𝐧𝐦𝐞𝐧𝐭𝐚𝐥𝐥𝐲 𝐫𝐞𝐬𝐩𝐨𝐧𝐬𝐢𝐛𝐥𝐞, while still leaving room for innovation through controlled testing environments called regulatory sandboxes.

𝐖𝐡𝐚𝐭 𝐓𝐡𝐢𝐬 𝐀𝐜𝐭𝐮𝐚𝐥𝐥𝐲 𝐌𝐞𝐚𝐧𝐬 𝐟𝐨𝐫 𝐘𝐨𝐮

 -𝐏𝐫𝐨𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐟𝐫𝐨𝐦 𝐡𝐢𝐝𝐝𝐞𝐧 𝐦𝐚𝐧𝐢𝐩𝐮𝐥𝐚𝐭𝐢𝐨𝐧 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓(𝟏)(𝐚))

It is now illegal to deploy AI systems that use subliminal or manipulative techniques to influence your behavior without you realizing it, the kind of design that bypasses your rational thinking to keep you scrolling, clicking, or buying. If an AI is designed to hack your brain, it is banned.

-  𝐏𝐫𝐨𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐟𝐨𝐫 𝐯𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐥𝐞 𝐩𝐞𝐨𝐩𝐥𝐞 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓(𝟏)(𝐛))

AI cannot exploit weaknesses related to your age, disability, or economic situation to manipulate your behavior. A system cannot target a child, an elderly person, or someone in financial distress with addictive or coercive design. This directly protects the most vulnerable users.

 - 𝐍𝐨 𝐬𝐨𝐜𝐢𝐚𝐥 𝐜𝐫𝐞𝐝𝐢𝐭 𝐬𝐜𝐨𝐫𝐞𝐬 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓(𝟏)(𝐜))

Public authorities are banned from using AI to evaluate or rank you over time based on your social behavior, personality traits, or who you associate with. The "social credit" model used in some other parts of the world is categorically illegal in the EU.

-  𝐍𝐨 𝐩𝐫𝐞𝐝𝐢𝐜𝐭𝐢𝐯𝐞 𝐩𝐨𝐥𝐢𝐜𝐢𝐧𝐠 𝐛𝐚𝐬𝐞𝐝 𝐨𝐧 𝐩𝐫𝐨𝐟𝐢𝐥𝐢𝐧𝐠 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓(𝟏)(𝐝))

Police cannot use AI to predict whether you will commit a crime based solely on your personality, behavior patterns, or demographic profile. There must be a concrete link to actual criminal activity before AI can be used in law enforcement contexts.

-  𝐍𝐨 𝐦𝐚𝐬𝐬 𝐟𝐚𝐜𝐢𝐚𝐥 𝐬𝐜𝐫𝐚𝐩𝐢𝐧𝐠 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓(𝟏)(𝐞))

AI systems cannot indiscriminately scrape facial images from the internet, including your Instagram photos, or from CCTV footage to build or expand facial recognition databases. Your face cannot be vacuumed into surveillance infrastructure without your knowledge.

- 𝐍𝐨 𝐫𝐞𝐚𝐥-𝐭𝐢𝐦𝐞 𝐛𝐢𝐨𝐦𝐞𝐭𝐫𝐢𝐜 𝐬𝐮𝐫𝐯𝐞𝐢𝐥𝐥𝐚𝐧𝐜𝐞 𝐢𝐧 𝐩𝐮𝐛𝐥𝐢𝐜 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓(𝟏)(𝐡))

Real-time facial recognition in public spaces for policing is banned. The only three narrow exceptions are:

  • Searching for a specific victim of crime;
  • Preventing an imminent terrorist attack;
  • Locating a suspect of a serious crime.

Even then, police must get judicial authorization and oversight. You cannot be scanned and identified by cameras as you walk down the street.

-  𝐘𝐨𝐮 𝐦𝐮𝐬𝐭 𝐤𝐧𝐨𝐰 𝐰𝐡𝐞𝐧 𝐲𝐨𝐮 𝐚𝐫𝐞 𝐭𝐚𝐥𝐤𝐢𝐧𝐠 𝐭𝐨 𝐚 𝐦𝐚𝐜𝐡𝐢𝐧𝐞 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞 𝟓𝟎)

From 2 August 2026, any chatbot must tell you it is AI. Any emotion-recognition system analyzing your facial expressions must disclose itself. Any biometric categorization system sorting you by age, gender, or ethnicity must inform you. And any AI-generated image, video, or audio, including deepfakes, must be clearly labelled so you know it is synthetic.

-  𝐇𝐢𝐠𝐡-𝐬𝐭𝐚𝐤𝐞𝐬 𝐀𝐈 𝐦𝐮𝐬𝐭 𝐡𝐚𝐯𝐞 𝐡𝐮𝐦𝐚𝐧 𝐠𝐮𝐚𝐫𝐝𝐫𝐚𝐢𝐥𝐬 (𝐀𝐫𝐭𝐢𝐜𝐥𝐞𝐬 𝟗–𝟏𝟓)

By 2 December 2027, any AI system used to make decisions about your job interview, bank loan, university exam, insurance premium, or medical device must meet strict safety standards before it ever touches your life. Specifically, it must:

-  Include human oversight by design : a person must be able to step in and override the machine;

- Pass documented risk management checks;

-  Use training data that has been tested for bias;

- Keep automatic logs of its decisions;

- Be registered in a public EU database before it can be deployed.

This means you will never again be rejected for a mortgage or passed over for a promotion by an algorithm that no one has checked for fairness.

𝐓𝐡𝐞 𝐦𝐨𝐬𝐭 𝐢𝐦𝐩𝐨𝐫𝐭𝐚𝐧𝐭 𝐭𝐚𝐤𝐞𝐚𝐰𝐚𝐲 𝐟𝐫𝐨𝐦 𝐭𝐡𝐢𝐬 𝐚𝐫𝐭𝐢𝐜𝐥𝐞 𝐢𝐬 𝐭𝐨 𝐮𝐧𝐝𝐞𝐫𝐬𝐭𝐚𝐧𝐝 𝐭𝐡𝐚𝐭 𝐭𝐡𝐞 𝐀𝐈 𝐀𝐜𝐭 𝐝𝐨𝐞𝐬𝐧'𝐭 𝐛𝐚𝐧 𝐚𝐫𝐭𝐢𝐟𝐢𝐜𝐢𝐚𝐥 𝐢𝐧𝐭𝐞𝐥𝐥𝐢𝐠𝐞𝐧𝐜𝐞. 𝐈𝐭 𝐛𝐚𝐧𝐬 𝐭𝐡𝐞 𝐝𝐚𝐧𝐠𝐞𝐫𝐨𝐮𝐬 𝐮𝐬𝐞𝐬 𝐨𝐟 𝐀𝐈 𝐚𝐧𝐝 𝐟𝐨𝐫𝐜𝐞𝐬 𝐭𝐡𝐞𝐦 𝐭𝐨 𝐩𝐫𝐨𝐯𝐞 𝐭𝐡𝐞𝐲 𝐚𝐫𝐞 𝐬𝐚𝐟𝐞, 𝐟𝐚𝐢𝐫, 𝐚𝐧𝐝 𝐭𝐫𝐚𝐧𝐬𝐩𝐚𝐫𝐞𝐧𝐭 𝐛𝐞𝐟𝐨𝐫𝐞 𝐭𝐡𝐞𝐲 𝐜𝐚𝐧 𝐚𝐟𝐟𝐞𝐜𝐭 𝐲𝐨𝐮𝐫 𝐥𝐢𝐟𝐞.

  𝐖𝐡𝐚𝐭 𝐭𝐡𝐢𝐬 𝐥𝐚𝐰 𝐦𝐞𝐚𝐧𝐬 𝐟𝐨𝐫 w𝐨𝐫𝐤𝐞𝐫𝐬 𝐚𝐧𝐝 𝐉𝐨𝐛 𝐒𝐞𝐞𝐤𝐞𝐫𝐬:

- AI used for recruitment, selection, promotion, termination, or task allocation is classified as high-risk. Providers must prove the system does not discriminate based on gender, ethnicity, or age. Deployers must inform you that AI is being used and, where appropriate, that you are subject to automated decision-making.

  𝐅𝐨𝐫 𝐏𝐚𝐭𝐢𝐞𝐧𝐭𝐬 𝐚𝐧𝐝 𝐒𝐭𝐮𝐝𝐞𝐧𝐭𝐬:

 - AI in medical devices and educational assessment falls under high-risk or product-safety rules. By 2 August 2028, AI embedded in regulated medical products must comply with both sectoral safety legislation and AI Act requirements, ensuring diagnostic algorithms are accurate, robust, and explainable.

  𝐅𝐨𝐫 𝐁𝐮𝐬𝐢𝐧𝐞𝐬𝐬𝐞𝐬:

- Providers of general-purpose AI (GPAI) models, including major foundation models,  must publish technical documentation, comply with EU copyright law, and provide training data summaries.

 - Deployers of high-risk AI must conduct Fundamental Rights Impact Assessments, monitor performance, retain logs for at least six months, and inform affected individuals.

Compartir
Sobre Tamari Tabatadze

Tamari is the founder and author of Behind the Policy. She holds a Bachelor’s degree in Political Science and is completing a Master’s degree in International Politics at KU Leuven. Her work focuses on translating EU laws, regulations, and policy developments into clear explanations of their impact on citizens and society.

Fuentes y créditos

Fuentes
  • 1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — Official text published in OJ L 2024/1689, 12.7.2024.
  • https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • 2. European Commission AI Act Service Desk — Timeline for the Implementation of the EU AI Act — Official implementation calendar reflecting Digital Omnibus amendments.
  • https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
  • 3. Gibson Dunn — EU AI Act Omnibus Agreement (27 May 2026) — Detailed analysis of provisional agreement and timeline changes.
  • gibsondunn.com
  • 4. European Commission — AI Pact and Voluntary Commitments — Overview of industry pledges toward AI Act compliance.
  • digital-strategy.ec.europa.eu
Créditos de imágenes
  • Cover image created by Tamari Tabatadze

El resumen semanal.

Un correo por semana. Las decisiones de la UE que importan, explicadas en lenguaje claro. Sin manipulación. Sin spam.