Skip to content

Type a term, e.g. API, Shopware or SEO.

    EU AI Act · Regulation (EU) 2024/1689

    AI needs rules. We stand behind them.

    Regulation (EU) 2024/1689, known as the EU AI Act, is the world’s first comprehensive law on artificial intelligence. It applies directly in every EU member state. vona knows the regulation, supports it and complies with it – in our own work and in the solutions we build for clients. Here we explain what it covers and link to the current official version.

    Current version

    Regulation (EU) 2024/1689 – consolidated text

    The authoritative wording is published on EUR-Lex, the EU’s legal portal. The consolidated text combines the original regulation and all later amendments in one document.

    Consolidated version as of
    (CELEX 02024R1689-20260727)
    Last checked against the Publications Office of the EU on

    Source: EUR-Lex and the Publications Office of the European Union. Only the texts published in the Official Journal are legally binding; the consolidated version is a documentation tool.

    Overview

    The higher the risk, the stricter the rules.

    The regulation is built around the risk an AI system poses. Obligations mainly fall on providers, who develop an AI system and place it on the market, and deployers, who use it under their own authority in a professional context. For most everyday office applications, only a few, manageable obligations apply.

    Prohibited

    Unacceptable risk

    Certain practices have been banned since 2 February 2025, such as social scoring, manipulative techniques, exploiting vulnerabilities, emotion recognition in the workplace and in education, or untargeted scraping of facial images from the internet (Art. 5).

    High risk

    Strict requirements

    AI in sensitive areas, for example recruitment, education, creditworthiness or critical infrastructure (Annex III), and AI as a safety component of regulated products (Annex I). Requirements include risk management, data quality, technical documentation, logging and human oversight.

    Transparency

    Disclose when AI is involved

    People must be able to tell that they are talking to an AI. AI-generated content is marked in a machine-readable way, and deepfakes are disclosed (Art. 50). This covers chatbots and generated images, audio, video and text.

    Minimal

    No specific obligations

    Most applications, such as spam filters, translation aids or recommendations, remain free of specific rules. All providers and deployers, however, support the AI literacy of the people working with AI on their behalf (Art. 4).

    Deadlines

    Coming into force step by step.

    The regulation applies in stages. With the Digital Omnibus on AI (Regulation (EU) 2026/1744), the EU postponed the deadlines for high-risk systems in July 2026 and added new prohibitions. Information as of the consolidated version of 27 July 2026.

    1. 1 August 2024

      Entry into force

      The regulation enters into force 20 days after its publication in the Official Journal.

    2. 2 February 2025

      Prohibitions and AI literacy

      Prohibited practices (Art. 5) and the AI literacy obligation (Art. 4) apply.

    3. 2 August 2025

      General-purpose AI models

      Obligations for providers of such models – for example the language models behind well-known chatbots – plus governance and penalties.

    4. 2 August 2026

      General application

      Most of the regulation applies, including the transparency obligations of Art. 50.

    5. 2 December 2026

      New prohibitions, transition for marking

      AI systems that generate sexualised images of identifiable people without consent, or child sexual abuse material, become prohibited. Generative systems already on the market before 2 August 2026 must apply machine-readable marking by this date.

    6. 2 December 2027

      High risk under Annex III

      Requirements for high-risk systems in areas such as employment, education or lending (previously 2 August 2026).

    7. 2 August 2028

      High risk under Annex I

      Requirements for AI as a safety component of regulated products such as machinery or medical devices (previously 2 August 2027).

    Where we stand

    We support the EU AI Act.

    We believe clear rules are right: they build trust, and trust is what it takes for AI to genuinely help in everyday work. That is why we see the regulation not as a hurdle but as a benchmark for our work. This is how we put it into practice:

    01

    Classification from the start

    At the start of every AI project we assess which risk class the planned system falls into and who is the provider and who the deployer. We do not build prohibited practices.

    02

    People decide

    Our solutions include approval steps, logs and clear escalation rules. AI delivers drafts and suggestions; decisions stay with people.

    03

    Clearly labelled

    When something is made with AI, we say so. Our weekly AI review, for example, is explicitly marked as “compiled with AI, reviewed by” a named person.

    04

    No AI judging people

    Recruitment is one of the high-risk areas. We do not assess applications to vona with AI; only people make those decisions.

    05

    Privacy and choice of provider

    Data minimisation, data processing agreements, models and storage in the EU or locally run models on request – and providers that do not use your data for training.

    06

    Staying competent and current

    Every week we follow what is happening in AI and its regulation. We check automatically whether there is a new official version of the regulation and update this page.

    FAQ

    Questions about the EU AI Act.

    Does the EU AI Act apply to small businesses?
    Yes. The regulation applies regardless of company size to everyone who offers or professionally uses AI systems in the EU. It does, however, provide relief for small and medium-sized enterprises, such as simplified documentation and access to regulatory sandboxes; the Digital Omnibus extended such relief to small mid-cap enterprises.
    What does a company using ChatGPT or a chatbot have to do?
    Anyone using AI professionally is a deployer under the regulation. For most uses this means: enabling staff to work with AI (Art. 4) and disclosing when customers are talking to an AI or when AI-generated deepfakes are published (Art. 50). Stricter obligations only apply to high-risk uses, for example when AI helps decide on job applications or loans.
    Does this page replace legal advice?
    No. We explain the regulation from a practical perspective and implement the technical requirements. For a legal assessment of your specific case, please consult a lawyer or your data protection officer. Only the official text is binding.

    This page is a practical overview and not legal advice. Only the text published in the Official Journal of the EU is binding.

    Newsletter

    News from the vona workshop.

    AI tools we actually use, our weekly AI review & insights from our projects – short, practical and without spam.