Artificial Intelligence in the European Union

Law / proposed law in the European Union

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (the EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapters I and II).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models, governance and competent authorities (Chapters V and VII), and penalties (Chapter XII).
  • 2 August 2026: Original enforcement date for most of the AI Act's remaining provisions, including the requirements for Annex III high-risk AI systems, AI regulatory sandboxes (Article 57(1)), and certain transparency obligations relating to chatbots, deepfakes and AI-generated content. However, under the Digital Omnibus for AI (defined below), the timeline for Annex III high-risk AI systems is extended to 2 December 2027, with a further extension to 2 August 2030 for high-risk AI systems intended to be used by public authorities. Similarly, the watermarking obligations imposed on generative AI content (Article 50(2)) are extended to 2 December 2026.
  • 2 August 2027: Original enforcement date for provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e., AI systems covered by Annex I). However, under the Digital Omnibus for AI (defined below), the timeline for Annex I high-risk AI systems is extended to 2 August 2028, with a further extension to 2 August 2030 for high-risk AI systems intended to be used by public authorities.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

On 24 July 2026, the Council of the European Union adopted the proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on AI (Digital Omnibus for AI). The Digital Omnibus for AI was published in the Official Journal of the European Union on 24 July 2026 (OJ L, 2026/1744) and entered into force on 27 July 2026. Key elements include:

  • a new prohibition on non-consensual intimate AI-generated content and child sexual abuse material;
  • extension of small and medium-sized enterprise (SME) regulatory exemptions to small mid-caps;
  • clarification of the AI Office’s supervisory powers over general-purpose AI models, including enforcement powers over AI systems embedded in very large online platforms (VLOPs) and very large online search engines (VLOSEs), and centralisation of enforcement of certain GPAI systems within the AI Office; national competent authorities retain jurisdiction over law enforcement, border management, the judiciary, and financial institutions;
  • clarification of the AI literacy obligation;
  • reduced administrative burden (e.g., registration simplification for non‑high‑risk systems falling into Article 6(3) exemptions); and
  • extension of access to AI regulatory sandboxes, including through an EU-level sandbox, with national competent authorities required to establish AI regulatory sandboxes by 2 August 2027.

The Commission’s 2022 proposal on adapting non-contractual civil liability rules to artificial intelligence (COM(2022) 496) (AI Liability Directive) was withdrawn under the Commission Work Programme 2025 (COM(2025) 45 final, Annex IV), with the withdrawal formalised in the Official Journal in October 2025. No replacement proposal is currently tabled. As proposed, the AI Liability Directive would have complemented the EU AI Act and the revised Product Liability Directive by harmonising national civil liability regimes and rules on the burden of proof in relation to AI. However, this ambitious project was ultimately abandoned, notably due to the significant divergence across Member States’ legal frameworks.

On 22 June 2026, the European Parliament and Council reached a provisional agreement on a Directive aimed at combating the sexual abuse and sexual exploitation of children and child sexual abuse material (CSAM) (CSAM Directive). The CSAM Directive updates existing offences and introduces new criminal offences to address technological developments and emerging forms of CSAM, including the criminalisation of the production, possession, and dissemination of instructions on how to commit child sexual abuse or produce CSAM. The CSAM Directive also establishes offences related to AI, making it unlawful to design, adapt, acquire, possess, or distribute AI systems intended to generate CSAM. Additional offences include paying for access to livestreamed child sexual abuse, livestreaming such abuse, organising travel for the purpose of child sexual abuse, and sexual extortion of children through threats to disclose CSAM. The Directive expands provisions on grooming, criminalising soliciting a child to produce or share CSAM, and increases penalties for offences such as the acquisition, possession, or access to CSAM, as well as its distribution or dissemination.

On 3 June 2026, the European Commission published a proposal for a Regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem (Cloud and AI Development Act or CADA) (COM(2026) 502 final). CADA is addressed at the EU's limited computing capacity and dependence on non-European cloud providers, and aims to increase sustainable computing capacity, ensure data sovereignty and operational continuity, and enhance public sector resilience. While the EU AI Act regulates AI systems and GPAI models, CADA focuses on cloud and AI computing services and their underlying infrastructure. It establishes a four-level Union cloud computing sovereignty framework, with higher levels requiring that data generated by audited services cannot be used to train AI systems operated by entities outside the European Economic Area (EEA). The proposal also establishes ‘Cloud and AI Leadership Initiatives’ supporting frontier, physical, and industrial AI development. The AI Board would coordinate AI adoption activities under CADA.

Continue reading

  • no results

Back to top