---------------------------
Title: EU AI Act: A Compliance Support Guide for Websites
URL: https://www.cookiebot.com/en/eu-ai-act/
---------------------------

# EU AI Act: A Compliance Support Guide for Websites

## At a Glance

- **The EU AI Act**, in force August 2024, is the world’s first comprehensive AI law, classifying systems into risk tiers with tailored obligations.
- **The 2026 Digital Omnibus** delays "high-risk" obligations to late 2027/2028, but essential transparency rules remain effective from August 2, 2026.
- **Common AI tools**, such as chatbots, content generators, or personalization features, likely trigger Article 50 disclosure duties, regardless of high-risk grace periods.
- **Training AI on visitor data** requires fresh, specific GDPR consent; a standard analytics cookie banner is insufficient.
- **International reach:** The EU’s May 2026 ratification of the Council of Europe’s AI Convention reinforces these principles globally.
- **Penalties for non-compliance** are severe, reaching up to €35 million or 7% of global annual turnover.

AI-powered features and tools have become common on websites: a support chatbot, a product recommendation engine, an AI writing assistant behind the scenes.

While the EU AI Act was built with far bigger players in mind, its transparency and consent-adjacent rules reach smaller operators too. This guide covers what's actually in force, what's been delayed, and where it overlaps with the cookie and consent obligations you're likely already managing.

## What the EU AI Act Means for Your Website

The EU AI Act is a regulation adopted by the European Commission, Council, and Parliament in March 2024, entering into force on August 1, 2024. It's the first broad, horizontal law aimed specifically at artificial intelligence, and it works by sorting AI applications into risk categories: unacceptable, high, and lower/minimal. There are different requirements attached to each.

Two things matter most for a typical website operator. First, most of the Act's rules aren't about banning AI. They're about disclosure, including telling visitors when they're talking to a bot, or labeling content an AI produced.

Second, the Act's timeline has shifted since the law was first adopted, and not every provision moved by the same amount. Getting the dates right matters, because "the AI Act was delayed" is not accurate as a blanket statement. Some of it was, some of it wasn't.

## Key Dates: A Simplified Timeline of the EU AI Act

The AI Act proposal dates back to April 2021. Political agreement among the Commission, Council, and Parliament followed in December 2023, and the Act was formally adopted in March 2024, entering into force on August 1, 2024.

Implementation has always been staggered. The first substantive obligations, covering prohibited AI practices and AI literacy requirements, took effect on February 2, 2025.

Since late 2025, the EU has also been negotiating a separate "[Digital Omnibus on AI](https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal)," a package of amendments aimed at simplifying parts of the Act before its heaviest obligations landed.

That package has now cleared its final legislative hurdles. The European Parliament endorsed the final text on June 16, 2026, and the Council of the EU gave its final green light on June 29, 2026, with the regulation entering into force in July 2026.

Here's what that means for the dates that matter:

- **August 2, 2026** — Article 50 transparency obligations apply as originally scheduled. This includes telling visitors when they're interacting with an AI system, unless that's obvious from context.
- **December 2, 2026** — A shorter-than-first-proposed grace period for Article 50(2) machine-readable watermarking of AI-generated content, but only for systems that were already on the market before August 2, 2026. Anything placed on the market from August 2, 2026 onward must meet the watermarking requirement immediately.
- **December 2, 2026** — End of the transitional period for a new Article 5 prohibition on AI systems built (or reasonably likely) to generate non-consensual intimate imagery or child sexual abuse material.
- **August 2, 2027** — Revised deadline for EU member states to stand up national AI regulatory sandboxes.
- **December 2, 2027** — High-risk obligations apply to stand-alone Annex III systems (e.g., AI used in recruitment, credit scoring, or education). This is now a fixed date, not conditional on further EU rulemaking as originally proposed.
- **August 2, 2028** — High-risk obligations apply to Annex I systems, meaning AI embedded within already-regulated products.

Provider-side obligations for general-purpose AI models: [Article 51](https://artificialintelligenceact.eu/article/51/) to [Article 56](https://artificialintelligenceact.eu/article/56/) — the rules that apply to companies like the ones building large language models — were untouched by the Omnibus and have applied since August 2025.

## Which AI Practices Are Off-Limits

Some AI uses were judged too risky to permit at all, and have been prohibited outright since February 2025:

- Using manipulative techniques that bypass a person's free will or decision-making, such as neuromarketing designed to influence subconscious choices
- Exploiting vulnerabilities related to age or disability, for instance AI-targeted content aimed at children
- Building "social score" systems that evaluate or rank people based on behavior over time
- Running predictive policing programs based purely on profiling, without individualized suspicion
- Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases
- Inferring people's emotions in workplaces or schools, except for narrow medical or safety reasons

The Act also restricts certain uses of biometric categorization (e.g., inferring race, political views, or sexual orientation from biometric data) and real-time remote biometric identification by law enforcement in public spaces, with narrow, tightly defined exceptions for things like locating missing persons.

Since the Omnibus's adoption, a further prohibition has been added: AI systems designed, or reasonably foreseeable, to generate non-consensual intimate imagery or child sexual abuse material are now banned outright, with a transitional period running until December 2, 2026.

## How the Act Sorts AI Risk Levels

Beyond the outright bans, the Act assigns most AI applications to a risk tier:

- **Unacceptable risk** — Banned, as covered above.
- **High risk** — Permitted, but subject to conformity assessments, logging, human oversight, and documentation requirements. This covers things like AI used in employment decisions, credit scoring, education, critical infrastructure, and law enforcement. As noted above, these obligations now apply from December 2027 (stand-alone systems) or August 2028 (embedded systems).
- **Limited risk** — Subject to specific transparency duties, such as disclosing that content is AI-generated.
- **Minimal or no risk** — The large majority of everyday AI tools, permitted without extra requirements.

General-purpose AI models, which are the kind behind widely used chat and content tools, sit somewhat apart from this tiering. Providers of these models face baseline transparency and documentation duties, with additional obligations, including risk assessment, adversarial testing, and incident reporting for models judged to carry systemic risk.

## Who Enforces the Act, and What It Costs to Get It Wrong

An [AI Office, based within the European Commission](https://digital-strategy.ec.europa.eu/en/policies/ai-office), coordinates enforcement across member states and directly supervises general-purpose AI providers. National regulators handle enforcement more directly within their own markets.

Fines follow a tiered structure based on the severity of the violation:

- **Up to EUR 35 million or seven percent** of global annual turnover (whichever is higher) for breaching the Article 5 prohibited-practices list
- **Up to EUR 15 million or three percent** of global annual turnover for violations by providers, deployers, and other parties in the AI supply chain, including Article 50 transparency failures
- **Up to EUR 7.5 million or one percent** of global annual turnover for supplying incorrect or misleading information to regulators

SMEs and startups face whichever figure (the percentage or the fixed amount) is lower, across all three tiers

Where a violation also involves personal data, data protection authorities may pursue separate enforcement under the [GDPR](https://www.cookiebot.com/en/gdpr/).

Separately, in May 2026 the EU ratified the Council of Europe's Framework Convention on Artificial Intelligence, the first legally binding international AI treaty.

Within the EU, the AI Act remains the more detailed and directly enforceable instrument; the Convention extends comparable transparency, oversight, and human-rights principles to signatory countries beyond the EU's borders, including the U.K., Canada, and the U.S.

## Compliance Requirements: Consent, Transparency, and Your CMP

For most website and app operators, EU AI Act compliance is about consent and transparency, rather than risk assessments. These are two things a [consent management platform like Cookiebot™](https://www.cookiebot.com/en/cookie-consent-solution/) already touches, though it doesn't cover them automatically or completely.

There are a number of practical steps companies can take that support compliance with AI Act requirements.

### Update Your Notices When Your Data Use Changes

If visitor data collected for one purpose, such as personalization, is later reused to train or fine-tune an AI model, that's a new processing purpose. Under the GDPR, most privacy laws require you to inform visitors and, in many cases, get new consent before the new use begins.

### Offer Granular Choices, Not a Single AI Toggle

Visitors should be able to consent to some uses of their data — like standard analytics — while declining others — like having their inputs used for AI training. A CMP such as Cookiebot™ CMP is built to support exactly this kind of layered, purpose-specific consent, rather than a blanket accept/reject choice.

### Keep Consent Mechanisms Easy to Use

Declining should be no harder than accepting, and under most applicable privacy laws visitors need an easy way to change their mind later.

### Know Which Disclosure Rules Actually Apply to You

Article 50 requires organizations to check whether their customer-facing AI triggers labeling or disclosure duties. This includes chat tools, automated decision features, and generative content workflows. It often means adding a disclosure label to AI-generated content or a short "you're talking to an AI" note at the start of a chat interaction.

This is a reasonable starting checklist for most small and mid-sized sites. However, none of this is a substitute for legal advice specific to your business, and it's always worth consulting qualified counsel.

## Not sure which regulations apply to your site?

EU AI Act obligations often overlap with the GDPR and other data privacy rules. See which regulations apply to your business.

[Find My Regulations](https://www.cookiebot.com/en/regulations-finder/?step=1)

## Does the EU AI Act Cover Tools Like ChatGPT?

The AI Act doesn't ban any specific product or company, so tools like ChatGPT remain available in the EU. ChatGPT and similar tools are classified as general-purpose AI (GPAI) models under the Act.

GPAI models are split into two tiers: "conventional" GPAI, with relatively light documentation duties, and "systemic-risk" GPAI, which faces materially more oversight, including adversarial testing and incident reporting to the European Commission.

That distinction matters more to the model providers themselves than to businesses simply using these tools. But if your site embeds a third-party AI feature, it's worth knowing which tier the underlying model sits in, since it affects what documentation the provider is required to make available to you.

## Cookies, Consent, and AI: Why Your Current Banner May Not Be Enough

Cookie use has been declining for years as newer tracking methods emerge, and AI is accelerating that shift rather than reversing it. The more interesting question for most site owners isn't whether AI uses cookies, but rather whether AI-driven data collection can outpace what a standard cookie banner is built to handle.

AI systems can analyze large volumes of behavioral data in real time, in ways that don't always map neatly onto the "accept before a cookie is set" model most banners are built around. And some AI-driven personalization doesn't rely on collecting personally identifiable information at all. It groups visitors into audiences based on behavior patterns.

If no personal data is collected, consent obligations around that specific step may not apply. But visitors generally still need to be told, at a notice level, how their behavior may be analyzed and for what purpose, even where no cookie is involved.

Learn more about the requirements Google implemented to secure advertising in the EU, UK, and Switzerland.

## AI Training Data and Your Existing Privacy Obligations

Most of the world's population is now covered by at least one data privacy law, and training an AI model well requires enormous amounts of data. Much of that data was originally collected from, or about, identifiable individuals. That combination has already produced a wave of disputes over data scraped for AI training without the data subject's consent or compensation.

### New Purpose, New Consent

Many privacy laws, the GDPR included, require fresh consent when a company's reason for collecting or processing personal data changes. Reusing existing visitor data for AI training or model fine-tuning generally counts as a new purpose, which means new consent is typically needed from everyone whose data would be used.

### Children's Data Needs Extra Care

Most privacy laws set a higher bar for processing children's data, often requiring parental or guardian consent below a set age threshold. Younger visitors are also less likely to understand what "used to train an AI system" actually means in practice, which puts more weight on getting the notice itself right, not just the consent mechanism.

### Location Matters More Than Headquarters

Many privacy laws, including the GDPR, apply based on where the data subject is located rather than where the company is based, referred to in regulatory texts as extraterritoriality. A business headquartered outside the EU can still be squarely in scope if it processes EU residents' data.

## Where AI Consent Still Gets Tricky

A few open questions make AI-specific consent harder to get right than standard cookie consent.

### Purposes Can Shift After the Fact

Teams building or experimenting with AI features don't always know in advance exactly how the data will end up being used, which makes it harder to give visitors an accurate, specific notice up front.

### Volume and Speed Strain Traditional Banners

Where data is being analyzed continuously and at scale, a pop-up-per-purpose model can become impractical, for the visitor as much as for the business trying to implement it.

### AI Can Surface More Than It Collects

By connecting data points in new ways, AI systems can turn seemingly ordinary information into something closer to sensitive or identifying data, which existing consent language may not have anticipated.

## Design Patterns Matter

Deceptive interface choices, sometimes called [dark patterns](https://usercentrics.com/knowledge-hub/dark-patterns-and-how-they-affect-consent/), are already restricted under several privacy laws. AI-personalized interfaces open the door to more sophisticated versions of the same problem, which regulators are likely to scrutinize as this area matures.

## Beyond the EU: The Global AI Regulation Picture

The EU AI Act is influential well beyond EU borders, much as the GDPR became a reference point for privacy laws worldwide. A few developments worth tracking if your business operates internationally:

- **Council of Europe Framework Convention on AI** — Signed by the EU in September 2024, approved by the European Parliament in March 2026, and ratified by the EU in May 2026. Signatories beyond the EU include the U.K., Canada, and the U.S.
- **Colorado's Automated Decision-Making Technology Act (ADMTA)** — Colorado repealed its original AI Act before it took effect and replaced it, in May 2026, with a narrower transparency-and-disclosure law covering automated decision-making technology used in consequential decisions. It takes effect January 1, 2027.
- **U.S. federal proposals** — Bills such as the Future of Artificial Intelligence Innovation Act remain in early legislative stages and are, as of this writing, well short of becoming law.

For businesses with any EU exposure, the practical takeaway is the same regardless of where these other efforts land. Transparency, documentation, and consent are the common threads, and building toward them now will serve you regardless of which specific bill or treaty ends up governing a given market.

To dig deeper into how consent and data privacy law intersect with AI, read more about AI and data privacy.

## Ready to strengthen your consent infrastructure?

AI features add new complexity to how visitor data is collected and used. Granular, purpose-specific consent matters more than ever. See how Cookiebot™ CMP handles layered consent, transparency, and opt-outs.

[Start free trial](https://www.cookiebot.com/en/cookie-consent-solution/)

## Summary

The EU AI Act is now partly in force, with more obligations landing through 2028. This guide walks website owners through what's already required, what's been delayed by the EU's Digital Omnibus on AI, and how consent and transparency requirements intersect with existing cookie and data privacy rules. 

---

## Footer

### Product
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)
- [Cookiebot vs CookieYes](https://www.cookiebot.com/en/cookiebot-best-cookieyes-alternative/)
- [Cookiebot vs OneTrust](https://www.cookiebot.com/en/onetrust-alternative/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject Requests

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)