Since July 2026, the European Union has launched the most ambitious phase of its Artificial Intelligence Act (AI Act), originally approved in 2024. This regulatory milestone makes Europe the first bloc in the world with a complete legal framework for the development and use of artificial intelligence systems.
What does this new phase imply?
The AI Act classifies AI systems according to their level of risk: minimal, limited, high and prohibited. Since this month, the strictest rules apply to the so-called general-purpose AI models (GPAI), those that can be used for multiple purposes, such as GPT, Gemini, Claude or Meta Llama.
The key obligations include:
- Mandatory transparency: Developers must document how their models work, their training data and the security measures implemented.
- Risk assessments: Before launching a model on the European market, companies must carry out external security audits.
- Citizens’ rights: Any person in the EU can file a complaint if they consider that an AI system has violated their rights.
- Specific prohibitions: The use of social scoring systems, real-time biometric recognition in public spaces (with very limited exceptions for security) and behavioral manipulation is prohibited.
How does it affect users?
For the average user, the changes will be incremental but noticeable. The applications and services we use every day —from virtual assistants to recommendations on platforms— will have to clearly inform us when we are interacting with an AI.
In addition, technology companies have started to include transparency labels similar to nutritional ones, where they explain what data they collect, how it is processed and what rights the user has over their interactions.
Sector reactions
Major tech companies such as OpenAI, Google and Microsoft have adapted their models to comply with European regulations. Although some voices in the sector criticize that the regulation could hold back innovation, the European Commission argues that the law creates a “safe space for responsible innovation” and that it will serve as a global reference, just as GDPR marked a before and after in data protection.
Conclusions
Europe once again positions itself at the forefront of technological regulation. The AI Act not only seeks to protect citizens, but also to establish a standard that other countries —such as Japan, Canada or Brazil— are closely watching to design their own regulations. Understanding these rules is key for any professional, company or user who wants to confidently navigate the future of artificial intelligence.






