High-risk moved: Annex III 2 Dec 2027, Annex I 2 Aug 2028. Art. 50 still 2 Aug 2026.
| Tier | What | Applies | Max fine |
|---|---|---|---|
| Prohibited · Art. 5 | Banned practices. New Omnibus bans: non-consensual sexual deepfakes, CSAM. | 2 Feb 2025 New bans: 2 Dec 2026 | €35M / 7% |
| High-risk · Annex III | Stand-alone high-risk uses (e.g. hiring, credit, education, biometrics). | 2 Dec 2027 | €15M / 3% |
| High-risk · Annex I | AI embedded in regulated products. | 2 Aug 2028 | €15M / 3% |
| Limited · Art. 50 | Transparency for AI that interacts with people or generates content. | 2 Aug 2026 Legacy GenAI content: 2 Dec 2026 | €15M / 3% |
| GPAI models | General-purpose AI model providers. | 2 Aug 2025 Enforcement: 2 Aug 2026 | — |
| Minimal | Everything outside the tiers above. | — | — |
| Breach | Cap |
|---|---|
| Prohibited practices | €35M or 7% of worldwide annual turnover |
| Most operator obligations, incl. Art. 50 | €15M or 3% |
| Incorrect or misleading information | €7.5M or 1% |
SMEs: whichever is lower. Caps per Reg. (EU) 2024/1689 Art. 99.