LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:ai_act

This is an old revision of the document!


Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

Draft – editorial review pending. As of 27 September 2026.

Type EU regulation
Adopted by European Parliament and Council of the European Union
Adopted 13 June 2024
Legal status In force since 1 August 2024; staggered application (prohibitions under Art. 5 since 2 February 2025; Art. 50 since 2 August 2026); amended by Regulation (EU) 2026/1744 (“Digital Omnibus on AI”), in force since 27 July 2026; binding and directly applicable in all EU Member States
Official text EUR-Lex
Subject area Artificial intelligence and autonomous weapons; Propaganda, disinformation and elections

Overview

The AI Act establishes a risk-based framework for AI systems placed on the market or used in the EU: certain practices are prohibited, high-risk systems are subject to requirements, specific transparency obligations apply to some systems, and general-purpose AI models are regulated separately. Art. 5(1)(a) and (b) prohibit manipulative and exploitative AI practices; Art. 50 requires disclosure of AI interaction and of synthetic or manipulated content (“deep fakes”). Under Art. 2(3), AI systems used exclusively for military, defence or national security purposes are outside its scope. The Act is referred to in debates on AI-enabled disinformation and manipulation of public opinion.

Provisions relevant to the cyber and information sphere

  • Art. 5(1)(a) – Prohibits AI systems that deploy subliminal techniques or purposefully manipulative or deceptive techniques with the objective or effect of materially distorting behaviour by appreciably impairing informed decision-making, causing or reasonably likely to cause significant harm.
  • Art. 5(1)(b) – Prohibits AI systems that exploit vulnerabilities of a person or group due to age, disability or a specific social or economic situation, with the objective or effect of materially distorting behaviour in a manner causing or reasonably likely to cause significant harm.
  • Art. 50(1) – Providers must ensure that persons are informed that they are interacting with an AI system, unless obvious.
  • Art. 50(2) – Providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
  • Art. 50(4) – Deployers of systems generating or manipulating deep fakes must disclose that the content is artificially generated or manipulated; deployers of systems generating or manipulating text published to inform the public on matters of public interest must disclose this, subject to exceptions (e.g. human review and editorial responsibility).
  • Annex III, point 8(b) – Classifies as high-risk AI systems intended to influence the outcome of an election or referendum or voting behaviour (with exceptions for tools used to organise campaigns).

Application to cyber and information operations

On 4 February 2025 the Commission published Guidelines on prohibited AI practices (C(2025) 884), which are non-binding and interpret, among others, Art. 5(1)(a) and (b). A voluntary Code of Practice on marking and labelling of AI-generated content was published on 10 June 2026, and Commission guidelines on the transparency obligations under Art. 50 were made available in July 2026 [to be verified: exact publication date].

Recent developments

  • 2025-02-02: Prohibitions under Art. 5 apply.
  • 2025-02-04: Commission Guidelines on prohibited AI practices published.
  • 2026-06-10: Code of Practice on marking and labelling of AI-generated content published (European Commission).
  • 2026-07-24: Regulation (EU) 2026/1744 (“Digital Omnibus on AI”) published in the Official Journal; in force 27 July 2026. It adds a prohibition concerning AI systems generating non-consensual intimate imagery and child sexual abuse material (applicable from 2 December 2026), requires providers of generative systems placed on the market before 2 August 2026 to comply with Art. 50(2) by 2 December 2026, and postpones obligations for high-risk systems (Annex III: 2 December 2027; Annex I: 2 August 2028).
  • 2026-08-02: Art. 50 transparency obligations apply.

Sources

Change log

  • 2026-09-27: Entry created (draft).
law/eu/ai_act.1790536042.txt.gz · Last modified: by lfpo