The Regulation establishes four main tiers: prohibited practices, high-risk systems subject to strict requirements, limited-risk uses that trigger transparency obligations, and general-purpose (GPAI) models. Application is phased; the prohibitions and AI literacy took effect in early 2025 and the GPAI rules in August 2025. The Digital Omnibus (2026) deferred the Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028; the Art. 50 transparency obligations start on 2 August 2026.
Overview
The EU Artificial Intelligence Act is the regulation that introduces the first comprehensive and binding framework for artificial intelligence. Its approach is risk-based: what is decisive is not what the system is, but the context in which and the risk with which it is used. Obligations are distributed among the provider, importer, distributor, and deployer roles.
Risk tiers
Applications carrying unacceptable risk (e.g. certain social scoring and manipulative techniques) are prohibited. High-risk systems in Annex III areas such as employment, credit, education, and critical infrastructure are subject to strict requirements. Uses such as chatbots and generative content carry transparency obligations, while a separate GPAI regime applies to general-purpose models.
Phased timeline
| Date | What takes effect |
|---|---|
| 02.02.2025 | Prohibited practices + AI literacy (Art. 4) |
| 02.08.2025 | GPAI obligations, governance and penalty framework |
| 02.08.2026 | Art. 50 transparency obligations (marking grace until 02.12.2026 for systems already on the market) |
| 02.12.2027 | High-risk (Annex III) main obligations — deferred by the Digital Omnibus |
| 02.08.2028 | High-risk systems embedded in product legislation (Annex I) |
Critical point for the Turkish dimension
The Regulation has a broad territorial reach: coverage may arise where the output of the system of a company established in Türkiye is used in the EU. For products aimed at the EU market, determining the role and class is the first step.
Roadmap
The sequence we recommend: system inventory and role/class determination; prohibited-practice screening; a usage policy and human-oversight thresholds; adding compliance undertakings to procurement contracts; and planning the technical-documentation work for high-risk candidates well ahead of the deferred December 2027 date. Running this within a single framework alongside KVKK/GDPR compliance avoids duplicated effort.
Penalties
The penalty architecture has three tiers: up to EUR 35 million or 7% of total worldwide annual turnover for prohibited practices; up to EUR 15 million / 3% for other breaches of obligations; and up to EUR 7.5 million / 1% for supplying misleading information to authorities. For SMEs, the figures are applied in the more favourable way.
Related content
For an implementation plan, see our AI Act roadmap, and for the full legal framework, our Artificial Intelligence focus area. The data dimension should be read together with the GDPR and KVKK records.


