EU AI Act
The EU's risk-based AI law, in force since August 2024 and phasing in. It reaches Australian businesses through EU customers, EU users and contracts, not through Australian regulators.
- Status
- In force · European Union · EU
- Applies to
- Australian businesses that sell AI-enabled products or services into the EU, or whose AI outputs are used in the EU, and their suppliers by contract
- Key date
- 2 December 2027: High-risk AI obligations apply to standalone systems (embedded systems follow 2 Aug 2028)
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
The European Union’s law on artificial intelligence, in force since 1 August 2024 and applying in stages. It sorts AI uses by risk: a short list of prohibited practices, a longer list of “high-risk” uses (recruitment, credit, education, access to essential services, biometrics and others) that carry the heaviest duties, transparency duties for AI that interacts with people or generates content, and nothing for the rest. It applies to anyone who places an AI system on the EU market or uses one in the EU, wherever they are based, and to providers and users outside the EU whose AI output is used inside it. That last clause is what reaches Australia. Penalties run to EUR 35 million or 7 per cent of global turnover for prohibited practices, EUR 15 million or 3 per cent for most other breaches.
What it requires
The duties depend on which role you play. A deployer uses an AI system someone else built: the duties are to use it as intended, keep a person in a position to oversee it, tell people when they are dealing with AI or with generated content, and, for high-risk uses, keep records and assess the impact on the people affected. A provider builds an AI system and puts it on the market: for high-risk uses that means a risk management system, data governance, technical documentation, logging, human oversight design, accuracy and security testing, a conformity assessment and registration before the system is sold, and monitoring afterwards. The prohibitions and the duty to keep staff AI-literate have applied since 2 February 2025; duties on general-purpose model providers since 2 August 2025; the transparency duties from 2 August 2026. The Digital Omnibus, agreed in May 2026 and formally adopted in June, moved the high-risk obligations from August 2026 to 2 December 2027 for standalone systems and 2 August 2028 for AI built into regulated products, and gave generative models released before August 2026 until 2 December 2026 to meet the content-labelling rule.
Does this reach your business?
Only through Europe. If you have no EU customers, no EU users and no EU contracts, it does not apply to you. It does apply if you sell software or a service with AI in it to EU customers, if EU residents use an AI feature you run (a chatbot on a site that serves Europeans, a tool that scores or ranks EU applicants or customers), or if an EU customer’s contract requires you to meet it as their supplier, which is the way most Australian businesses meet it first. Work out your role before anything else: most Australian businesses are deployers, and a deployer’s duties are real but manageable; a provider’s are a product-development programme. Our EU AI Act guide walks through the scoping questions step by step.
What we recommend
Our advice is to answer three questions in writing and keep the answers: does any AI output of ours reach the EU, are we a deployer or a provider for each such system, and does any use fall in a high-risk category. For most Australian businesses the honest answers are “no”, “deployer” and “no”, and the record of having asked is the whole obligation. If an answer is yes, the first date that matters is now, not 2027: the transparency duties already apply, and an EU customer will ask for your position long before the high-risk deadline. Treat your governance record, which system, who owns it, what it touches, who reviews it, as the evidence, because it is the same record the Act asks a deployer to keep.
Questions people ask
Only where the AI's output is used in the EU, the system is sold into the EU, or an EU customer's contract requires it. Australian regulators do not enforce it.
A deployer uses an AI system built by someone else and has duties around intended use, oversight and transparency. A provider builds the system and puts it on the market, and carries the full high-risk obligations.
From 2 December 2027 for standalone high-risk systems and 2 August 2028 for AI built into regulated products, after the 2026 Digital Omnibus delay. Prohibitions, AI literacy and transparency duties already apply.
Up to EUR 35 million or 7 per cent of worldwide turnover for prohibited practices, and EUR 15 million or 3 per cent for most other breaches, whichever is higher.