Skip to main content
European Commission logo
AI Act Service Desk

Frequently Asked Questions

This list of FAQs has been compiled based on queries received during the AI Pact webinars as well as submissions from stakeholders. This list will be updated regularly and as needed.

  • General-purpose AI models
How are AI agents addressed within the AI Act?

The term ‘AI agent’ is often used inconsistently in public debate, due in part to a blurry and still evolving demarcation between AI agents and other kinds of AI. Nevertheless, there is broad agreement that an AI agent must have the ability to receive and process input from their environment, and execute actions based on this processing that may interact with or affect their environment (e.g., issuing function calls). The term ‘Agentic AI’ is sometimes used to describe more sophisticated configurations that integrate multiple AI agents. Nevertheless, the precise interrelation between these two terms is still evolving. 

Typically, an AI agent will contain at least a general-purpose AI (GPAI) model, and constitute an AI system as it will usually have some form of interface, which is considered a system component (recital 97 AI Act). A more precise statement than ‘typically’ is difficult to make as the term AI agent is not legally defined and is used colloquially for different kinds of artefacts. Thus, while AI agents are not a separate category of AI under the AI Act, the definitions of an AI system in Article 3(1) AI Act and of a GPAI model in Article 3(63) AI Act are sufficient to cover AI agents. This means that the rules applicable to AI systems and GPAI models under the AI Act also apply to AI agents. 

Of the rules for AI systems, particularly relevant are the AI Act’s prohibitions of harmful manipulation and exploitation of vulnerabilities (Article 5(1), points (a) and (b), AI Act), compliance with which may require safeguards in the design and development of the AI agents to avoid prohibited practices that are reasonably likely to cause significant harm. From 2 August 2026 onwards, if the AI agent is intended to interact with natural persons or generate content, transparency rules will apply (Article 50 AI Act) – a Code of Practice to operationalise these rules was recently published. Furthermore, from 2 Dec 2027 respective 2 Aug 2028 onwards, if the AI agent classifies as a high-risk AI system, it is also subject to additional requirements that ensure its safety and trustworthiness for its intended usage (Chapter III AI Act).

As regards the GPAI models typically underlying AI agents, factors like the level of autonomy or tool use of the model can be decisive in the designation of the model as a model with systemic risk (Article 51(1)(b), Annex XIII, point (e), AI Act). Moreover, providers of GPAI models with systemic risk are subject to risk management obligations, which include considerations regarding the model’s autonomous capabilities and its agentic use (operationalised for example in  Measure 5.1, point 7, Appendix 1.3.1, points (5) and (7), Appendix 1.3.3, points (1), (4), and (12), or Appendix 3.2, second paragraph, Safety and Security Chapter of the GPAI Code of Practice).

Given that developments related to AI agents are recent and fast evolving, the European Commission’s regulatory considerations are only preliminary at this stage. The AI Office continues to closely monitor these developments and, if need be, will consider developing strategies to address the potential risks posed by AI agents. For example, the AI Office’s recent call for tenders on technical assistance for AI safety includes a lot dedicated to the evaluation of the safety and security of AI agents. 

  • General-purpose AI models
The Commissions’ enforcement powers related to AI Act obligations for providers of the most advanced models enter into application on 2 August 2026. What will change then?

The AI Act foresees a one-year period, from 2 August 2025, in which providers of the most advanced models must comply with their obligations before the Commission’s enforcement powers enter into application on 2 August 2026. Providers must, for instance, notify the Commission when they know they are developing one of the most advanced models. They must also assess and mitigate systemic risks from those models and most of the relevant providers have signed and are implementing the GPAI Code of Practice to this end. Since last year, the Commission’s AI Office has therefore received information and held technical compliance dialogues with providers to improve their practices to assess and mitigate systemic risks.

The AI Office views these technical compliance dialogues as a first tool of choice to assess compliance and clarify questions to support providers’ efforts. So, in one important way, nothing changes in August – the AI Office will continue and, if anything, intensify, the ongoing technical compliance dialogues.

In preparation for 2 August 2026, the AI Office has also established the structures and competencies needed for using enforcement powers. The powers include requesting information, requesting access to a model for evaluations, requiring risk mitigation measures, and issuing fines of up to 3% of global annual turnover or requesting a provider to restrict the making available on the market, withdraw or recall the model. The AI Office may use these powers in cases where technical compliance dialogues are not sufficient.

  • Digital Omnibus
What are the new timelines proposed?

The proposal acknowledges the challenge that the delay of standards and other support tools cause for the implementation of the AI Act.

The timeline for the high-risk AI rules is aligned to the availability of standards and other support tools. Once the Commission confirms these are sufficiently available, the rules will start to apply after a transition period.

This flexibility has an end date: the rules for high-risk AI in sensitive areas like employment and law enforcement (Annex III) will in any case apply maximum 16 months later than originally envisaged, the rules for high-risk AI embedded in products like medical devices (Annex I) will apply a maximum 12 months later.

The proposal also suggests a transition period of 6 months for providers who need to retroactively include technical solutions into their generative AI systems to make them detectable.

  • Digital Omnibus
How will these changes benefit to businesses?

According to the Commission’s first estimations, the proposed measures on AI are expected to reduce compliance costs for businesses throughout the EU.

At the same time, by extending benefits granted to SMEs to include SMCs, the Commission is making implementation easier for an additional 8,250 companies in Europe.

Overall, the proposals presented by the Commission will help businesses meet their obligations. They also open up more opportunities to innovate in the EU, further facilitating the roll-out of the regulatory framework that is designed to create a single market for trustworthy AI.

  • Digital Omnibus
What are the main changes proposed to the AI Act?

The Commission is committed to a clear, simple and innovation friendly implementation of the AI Act, as set out in the AI Continent Action Plan and the Apply AI Strategy. Commission’s proposal brings the AI Act in line with this approach by:

Linking when rules apply to the availability of support

  • Linking the application of the rules for high-risk AI to the availability of support tools like standards. The Commission is adjusting the timeline for the application of high-risk rules to a maximum of 16 months.

Introducing simplification:

  • Extending certain simplified modalities of fulfilling the legal obligations from SMEs to small mid cap companies (SMCs), such as simplified technical documentation;
  • Requiring the Commission and Member States to foster AI literacy, and ensure continuous support to companies by building on existing efforts (such as the AI Office’s repository of AI literacy practices) instead of enforcing unspecified obligations on operators, while keeping training obligations for high-risk deployers in place remain.
  • Removing the prescription of a harmonised post-market monitoring plan, giving businesses more flexibility;
  • Reducing the registration burden for AI systems used in high-risk areas for tasks that are not considered high-risk.

Improving the effectiveness of the AI Act’s governance:

  • Centralising the oversight of AI systems built on general-purpose AI models with the AI Office, to reduce governance fragmentation for developers of these models and systems;
  • Concentrating the oversight of AI embedded in very large online platforms and search engines at Commission level by assigning this oversight to the AI Office.

Extending measures in support compliance:

  • Allowing providers and deployers to process special categories of personal data for ensuring bias detection and correction, subject to appropriate safeguards;
  • Broadening the use of AI regulatory sandboxes and real-world testing so more innovators can benefit from these tools. This includes setting up an EU-level regulatory sandbox from 2028 to support real-world testing.

Improving the AI Act’s procedures and operation:

  • Clarifying the interplay between the AI Act and other EU laws. Simplifying procedures to foster the timely availability of conformity assessment bodies.
  • Digital Omnibus
Why is the European Commission proposing to amend the AI Act?

The AI Act entered into force on 1 August 2024. It follows a staggered entry into application, with some parts already applicable such as certain prohibitions, AI literacy, and rules for general-purpose AI models. Other parts of the Act are set to apply on 2 August 2026 and 2 August 2027.

This progressive roll-out allows us to build on the experience gathered in applying the first part of the rules. The Commission is committed to continuously learn and stepping up its efforts. This is particularly important in the context of a fast-evolving technology like AI.

Stakeholder consultations throughout 2025 revealed implementation challenges that need to be addressed so that the AI Act can be successfully rolled-out. This proposal puts forwards legislative amendments to that effect and complements ongoing efforts to facilitate compliance with the AI Act, like the launch of an AI Act Service Desk.

  • AI Act: General questions
What is the AI Act, and what are its objectives?

The EU AI Act is the world's first comprehensive AI law.  It aims to promote innovation and uptake of AI, while ensuring a high level of protection of health, safety and fundamental rights, including democracy and the rule of law.  

The uptake of AI systems has a strong potential to bring societal benefits, economic growth and enhance EU innovation and global competitiveness. However, in certain cases, the specific characteristics of certain AI systems may create risks related to user safety, including physical safety, and fundamental rights. Some powerful AI models that are widely used could also pose systemic risks. 

This leads to legal uncertainty and potentially slower uptake of AI technologies by public authorities, businesses and citizens, due to the lack of trust. Disparate regulatory responses by national authorities could risk fragmenting the internal market. 

Responding to these challenges, legislative action was needed to ensure a well-functioning internal market for AI systems and models where both benefits and risks are adequately addressed.

Related resources
  • AI Act: General questions | Governance & Enforcement
When does the AI Act go into effect? What is its timeline for implementation?

The AI Act applies progressively, with a full roll-out by 2 August 2028. 

  • The prohibitions, definitions and provisions related to AI literacy became applicable on 2 February 2025; 

  • The rules on governance and the obligations for general-purpose AI models became applicable on 2 August 2025; 

  • The transparency requirements (Article 50) as well as the measures in support of innovation will apply as of 2 August 2026. This is also the date when the enforcement of AI Act will start;  

  • The obligations regarding high-risk systems listed in Annex III will enter into force on 2 December 2027 and the obligations for high-risk AI systems that classify as high-risk because they are embedded in regulated products, listed in Annex I (list of Union harmonisation legislation), will enter into force on 2 August 2028. 

Related resources
  • AI Act: General questions | Governance & Enforcement
Are revisions to the AI Act expected in the near future?

The AI Act is designed as a flexible and future-proof regulation that allows to adapt the rules to the rapid pace of technological development, as well as the potential changes in the use of AI systems and emerging risks. 

While in general the AI Act can only be amended through the legislative procedure, in certain cases, the Commission is empowered to amend certain parts of the AI Act. For instance, the following parts of the AI Act can be adapted by the Commission: 

  • The list of high-risk use-cases in Annex III. The Commission is obliged to carry out a yearly review to assess if changes to the list are needed. 

  • The threshold above which general-purpose AI models are presumed to have high impact capabilities and are classified as presenting systemic risks. 

The Commission also regularly assesses if other changes to the AI Act are needed and reports to the European Parliament and the Council. Such regular evaluation is foreseen directly in the AI Act. 

  • AI Act: General questions
What type of systems are regulated under the AI Act?

The AI Act does not apply to all AI solutions, but only to those that fulfil the definition of an ‘AI system’ within the meaning of Article 3(1) AI Act.

The AI Act follows a risk-based approach and introduces rules for AI systems based on the level of risk they can pose. Any AI practices with an unacceptable risk to health, safety or fundamental rights enshrined in the Charter of Fundamental Rights are prohibited (e.g. AI systems used to detect emotions of employees at work, except medical and safety reasons; certain social scoring practices). AI systems with high risk for health, safety or fundamental rights need to meet certain requirements to make sure they are safe and trustworthy (e.g. AI systems used at border control management; law enforcement, or autonomous vehicles could be examples of high-risk AI systems). Certain AI systems need to meet transparency requirements (e.g., deep fakes will have to be labelled as AI-generated; chatbots should inform that a person is not communicating with a human). All other AI systems remain unregulated and can be placed on the market, put into service or used in the EU without any requirements – at the time of preparation of the proposal of AI Act, it was estimated that these would be 85%.

Related resources