Legalifi Logo
Back to blog
ComplianceLegal InsightsAI Regulation
July 1, 2026·11 min read

EU AI Act: The European Union Artificial Intelligence Act

A comprehensive overview of the EU AI Act, including AI risk categories, high-risk system obligations, GPAI rules, transparency requirements, administrative fines, and the regulation’s implications for companies in Türkiye.

Alperen Turhal

Alperen Turhal

Tech Lawyer

European Union stars combined with an artificial intelligence network, representing the EU AI Act and the regulation of artificial intelligence in Europe.

1. What Is the EU AI Act?

The European Union Artificial Intelligence Act (EU AI Act), which officially entered into force on 1 August 2024, has had significant cross-border and international implications. It can also be described as the world’s first comprehensive and harmonised regulatory framework specifically addressing artificial intelligence.

The regulation does not apply only to companies physically established within the European Union. It also directly imposes obligations on global actors that place products on the EU market, make their systems available to EU users, or whose artificial intelligence system outputs are used within the EU.

This extraterritorial reach requires technology developers and corporate users in countries such as Türkiye, which maintain close commercial and technological integration with the European Union, to align themselves with European standards.

The implementation timetable of the regulation was substantially revised by the “Digital Omnibus” package adopted by the European Parliament and the Council in mid-2026 and heavily criticised by civil society organisations. To provide companies subject to the regulation with additional preparation time and to allow technical standards to mature, the application dates of certain critical obligations were postponed to 2027 and 2028.

2. Risk Categories

The EU AI Act classifies artificial intelligence systems into four main risk categories according to their potential level of danger and their capacity to affect fundamental rights:

  • Unacceptable risk
  • High risk
  • Limited risk
  • Minimal risk

A. Unacceptable Risk

Artificial intelligence systems that pose a clear threat to human dignity, civil liberties and democratic values, particularly systems with a high capacity for manipulation, are classified as “Unacceptable Risk” systems and are prohibited from the EU market.

Under Article 5 of the regulation, these prohibitions became legally binding as of 2 February 2025 without a transitional period.

Prohibited practices include specific use cases that reflect some of the most problematic applications of artificial intelligence.

Systems that manipulate individuals’ behaviour without their awareness, including through subliminal techniques, in a manner capable of causing physical or psychological harm are prohibited.

Applications involving large-scale “social scoring” are also prohibited. These systems assign individuals scores based on factors such as social behaviour, personal characteristics or online activity and then use those scores to impose discriminatory or disproportionate disadvantages, similar to certain social credit systems.

In addition to these prohibitions, two further restrictions were introduced within the scope of Article 5 through the “Digital Omnibus” package adopted by the European Parliament in June 2026.

These concern:

  • Artificial intelligence systems used to generate child sexual abuse material (CSAM).
  • Systems used to create sexual or nude images of identifiable individuals without their consent, including deepfake or “nudifier” applications.

These new prohibitions apply both to providers and users of such systems, with 2 December 2026 designated as the compliance date.

B. High-Risk Systems

The regulatory architecture of the EU AI Act places particular emphasis on “High-Risk” artificial intelligence systems: systems capable of having a significant adverse impact on individuals’ health, safety or fundamental rights.

Under Article 6, the Act divides high-risk systems into two main categories based on their structure and intended use: Annex I and Annex III.

First Category: Annex I

The first category covers artificial intelligence systems used as safety components of products that are already subject to EU product safety harmonisation legislation and require third-party conformity assessments.

Examples include products governed by legislation concerning:

  • Toys
  • Lifts
  • Medical devices
  • Radio equipment
  • Civil aviation

Artificial intelligence systems that themselves constitute such products may also fall into this category.

Examples include medical diagnostic software, autonomous vehicle safety algorithms and AI modules used to monitor gas concentrations in explosive environments.

Second Category: Annex III

The second category covers stand-alone artificial intelligence systems used in sensitive areas that directly affect individuals’ fundamental rights and opportunities, independently from conventional product safety legislation.

These areas include:

  • Biometric identification
  • Management of critical infrastructure such as water, gas and electricity supply
  • Access to education and vocational training, including examination grading and admissions
  • Employment and worker management, including recruitment algorithms and performance assessments
  • Access to essential public and private services, including credit scoring and social benefit eligibility
  • Law-enforcement analysis
  • Migration and border control
  • Administration of justice and democratic processes

C. High-Risk Exception Filter: Article 6(3)

To prevent systems from being unnecessarily classified as high risk, the European Commission established an exception mechanism under Article 6(3).

Draft Guidelines published in May 2026 interpret this mechanism narrowly, making it difficult for providers to rely on the exception.

A system may qualify for an exemption from high-risk classification only if it satisfies one of the following conditions and does not “materially” influence the outcome of a decision-making process:

  1. The system performs only a narrow procedural task.
  2. It improves the result of a previously completed human activity only in a formal manner without changing its substance or meaning, such as correcting grammar.
  3. It detects decision-making patterns or deviations without intending to replace or influence a previously completed human assessment.
  4. It performs only a preparatory task within a broader assessment process.

The most important limitation to this exemption concerns profiling.

If the system processes personal data automatically to analyse characteristics such as an individual’s work performance, economic situation, health, preferences, behaviour or location, it may be considered profiling.

In such circumstances, the system cannot benefit from the exemption even if one of the four conditions above is satisfied and may therefore be classified as high risk.

The guidelines also make clear that the presence of “human-in-the-loop” oversight does not automatically remove a system from the high-risk category.

Any party that develops a high-risk artificial intelligence system as a provider or places such a system on the market under its own name must comply with extensive regulatory and supervisory requirements.

These obligations have the potential to fundamentally change engineering and product-development practices.

Providers are required to establish a comprehensive Risk Management System under Article 9, through which the system’s known and reasonably foreseeable risks are continuously analysed, documented and mitigated.

A strict Data Governance framework must also be implemented.

Training, validation and testing datasets must be:

  • Appropriate for their intended purpose
  • Sufficiently representative
  • Reviewed for errors
  • Assessed for potential bias

Providers must prepare comprehensive Technical Documentation describing how the system was designed, how it operates and the logic behind its outputs.

Detailed automatic logging mechanisms must also be incorporated into the system to allow national authorities to conduct audits and to enable changes and events within the system to be retrospectively traced.

As a safeguard against excessive technological autonomy, high-risk systems must also be designed for effective Human Oversight.

Their outputs should be understandable by human operators, and authorised persons should be capable of intervening, overriding the system or shutting it down when necessary.

Finally, high-risk systems must undergo the applicable Conformity Assessment procedures before being placed on the market and must satisfy relevant regulatory requirements in order to obtain CE marking where required.

4. General-Purpose Artificial Intelligence (GPAI) and Foundation Models

The original drafts of the EU AI Act were prepared before the widespread emergence of large language models and generative AI systems such as ChatGPT, Claude, Llama and Gemini.

To address the rapidly increasing impact of these technologies, the concept of “General-Purpose Artificial Intelligence” (GPAI) was later incorporated into Chapter V of the regulation.

GPAI models are foundation models trained using substantial amounts of data and computational resources that demonstrate a significant degree of generality and can perform a wide variety of tasks.

The Act distinguishes between the underlying GPAI model providing the technological infrastructure and the final GPAI system made available to end users through integration of that model.

Specific responsibilities for GPAI model providers entered into application from 2 August 2025, independently from the risk level of systems into which those models may subsequently be integrated.

GPAI model providers, including certain open-source providers, are subject to several key obligations.

First, they must prepare detailed technical documentation concerning the model’s architecture, intended uses and limitations and make relevant information available to downstream integrators.

Second, providers must publish a sufficiently detailed summary of the datasets and content used in model training in accordance with templates provided by the European Commission.

Third, and perhaps most significantly from a legal perspective, providers must establish and implement a robust Copyright Policy designed to ensure compliance with EU copyright legislation, particularly the rules concerning text and data mining under Directive (EU) 2019/790.

Where the model was trained geographically is not necessarily decisive.

If the model is made available on the EU market, its compliance with applicable EU copyright requirements may still be subject to scrutiny.

Although open-source GPAI models may benefit from partial exemptions from certain transparency or technical documentation obligations, copyright compliance requirements may continue to apply.

5. Transparency Obligations: Article 50 and Content Transparency

Article 50 is among the most relevant provisions for the everyday interaction between users and artificial intelligence systems.

Unlike many parts of the regulation that primarily focus on high-risk systems, Article 50 imposes transparency obligations in situations where individuals interact with artificial intelligence, encounter synthetic content or are exposed to emotion-recognition and biometric categorisation technologies.

These rules began applying from 2 August 2026 and have a particularly broad impact on systems generally associated with limited-risk use cases.

To facilitate practical implementation, the European Commission published Draft Guidelines in May 2026, followed by the final “Code of Practice on Transparency of AI-Generated Content” on 10 June 2026 after negotiations involving technology companies, civil society organisations and experts.

Article 50 and the related Code of Practice address four key scenarios.

Direct Interaction Disclosure — Article 50(1)

When artificial intelligence systems such as customer-service chatbots or virtual assistants interact directly with individuals, providers must clearly inform users that they are interacting with an AI system.

According to the draft guidelines, this disclosure should take place at the beginning of the interaction and may be communicated using text, audio or visual indicators.

An exception may apply where it is obvious to a reasonably well-informed and observant person that they are interacting with artificial intelligence.

However, the guidelines indicate that this exception should be interpreted narrowly and assessed in light of the target audience, including groups such as children and elderly users.

Labelling AI-Generated Content — Article 50(2)

Systems generating synthetic audio, images, video or text must enable their outputs to be identified as artificially generated or manipulated.

This includes technical requirements intended to make AI-generated content detectable in a machine-readable format.

Emotion Recognition and Biometric Categorisation — Article 50(3)

Emotion-recognition systems are prohibited in certain contexts, such as particular workplace and educational uses, under Article 5.

Where such systems or biometric categorisation technologies are legally permitted in other contexts, transparency requirements still apply.

Individuals whose emotions are analysed or who are categorised using biometric data must be clearly informed that they are subject to such a system.

Deepfakes and Public-Interest Text — Article 50(4)

Article 50(4) focuses particularly on deployers: parties using artificial intelligence systems to create and publish content rather than the original developers of the technology.

Where audio, images or videos depicting real persons, objects or events are artificially generated or manipulated in a manner that could falsely appear authentic, the content must generally be accompanied by an appropriate disclosure indicating that it was artificially generated or manipulated.

AI-generated text published for the purpose of informing the public on matters of public interest may also be subject to disclosure requirements unless it has undergone appropriate human review or editorial control.

For artistic, satirical and creative works, disclosure may be implemented in a manner that preserves the enjoyment and integrity of the work.

6. Administrative Penalties

The EU AI Act establishes a strict administrative penalty regime intended to make serious regulatory violations significantly more costly than compliance.

The potential fines may exceed even the percentage-based ceiling associated with the GDPR and are structured according to the seriousness and category of the violation under Article 99.

For prohibited artificial intelligence practices falling within Article 5 and the unacceptable-risk category, fines may reach whichever is higher of:

  • EUR 35 million, or
  • 7% of the company’s total worldwide annual turnover.

Failure to comply with obligations applicable to high-risk systems may result in fines of up to whichever is higher of:

  • EUR 15 million, or
  • 3% of the company’s total worldwide annual turnover.

Providing incorrect, incomplete or misleading information to notified bodies or national supervisory authorities may result in fines of up to whichever is higher of:

  • EUR 7.5 million, or
  • 1% of the company’s total worldwide annual turnover.

Supervisory responsibilities are divided between national authorities and central EU institutions.

For General-Purpose Artificial Intelligence models and certain large technology platforms, significant supervisory and enforcement powers are allocated to the European AI Office established within the European Commission.

The AI Office may exercise extensive supervisory powers in connection with GPAI compliance, including investigations, inspections and restrictions on market access where legally applicable.

7. Conclusion and Implications for Türkiye

Similar to the “Brussels Effect” associated with the GDPR, the EU AI Act extends its influence beyond organisations physically established within the European Union.

Under the extraterritorial scope established by Article 2, the regulation may apply to:

  • Providers placing artificial intelligence systems or GPAI models on the EU market regardless of where their headquarters are located.
  • Distributors and deployers established within the European Union.
  • Providers and deployers established outside the EU, including in Türkiye, the United States or Asia, where the outputs produced by their systems are used within or have relevant effects inside the EU.

This makes the regulation particularly significant for Türkiye’s technology ecosystem.

For example, if a Türkiye-based software company develops an HR profiling system that is subsequently used by a German company to evaluate candidates in Europe, the Turkish provider may fall within the scope of the EU AI Act’s high-risk requirements under Annex III.

The company could consequently face obligations relating to data governance, risk management, documentation, conformity assessment and other regulatory requirements.

Businesses that fail to achieve compliance may face significant financial penalties or difficulties accessing the EU market.

The EU AI Act therefore represents more than a regulatory development limited to European companies.

Businesses whose activities fall within its territorial and material scope should assess their artificial intelligence systems, operational processes and commercial relationships in light of the regulation.

Following its work on MiCA and GDPR compliance projects and the development of KVKK-oriented software solutions, the Legalifi team continues to expand its work relating to the EU AI Act.

Companies seeking to navigate rapidly evolving national and international technology regulations can work with a multidisciplinary team that continuously monitors relevant regulatory developments.

Alperen Turhal

Written by

Alperen Turhal

Tech Lawyer

He graduated from the Ankara University Faculty of Law. He then completed his mandatory legal internship at a corporate law firm in 2025 and obtained his attorney’s license. Within Karakod, he actively works on the Legalifi RegTech software, focusing particularly on intellectual property law (trademarks), personal data protection, and AI law.