EUAIFit

Resource · EU AI Act

The EU AI Act, explained plainly

A practical guide for teams building or deploying AI in Europe. No legal jargon, no fear-mongering — just what you need to do, when, and how.

What is the AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal law for artificial intelligence. It entered into force on 1 August 2024 and applies to any organisation that places AI systems on the EU market or uses them within the EU — regardless of where the organisation is based.

The Act uses a risk-based approach. Instead of regulating the technology itself, it regulates the use case. The more potential for harm, the more obligations apply.

If you deploy, develop, import, or distribute AI in the EU, this affects you. The penalties are significant: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for other violations.

The four risk classes

Every AI system falls into one of these categories. Your obligations depend on which one applies.

Prohibited

AI practices banned outright: social scoring, real-time biometric ID in public spaces, manipulative or exploitative systems.

  • Social scoring by public authorities
  • Untargeted facial image scraping
  • Emotion recognition in workplaces and schools

High-risk

Systems that significantly affect health, safety, fundamental rights, or critical infrastructure. Full Article 8–17 obligations apply.

  • Recruitment and CV-screening tools
  • Credit scoring and insurance pricing
  • Medical diagnosis aids
  • Critical infrastructure management

Limited-risk

Systems with specific transparency obligations under Article 50. Users must be informed they are interacting with AI.

  • Chatbots and virtual assistants
  • Deepfakes and synthetic media
  • Emotion recognition (with consent)
  • Biometric categorisation

Minimal-risk

All other AI systems. No specific obligations under the AI Act, though existing GDPR and sectoral rules still apply.

  • Spam filters
  • Recommendation engines
  • Inventory forecasting
  • Search ranking

The compliance timeline

The AI Act is being phased in. Transparency duties now apply, while the principal high-risk dates are 2 December 2027 and 2 August 2028.

2 February 2025

Prohibited practices take effect

Article 5 bans on certain AI practices — social scoring, untargeted facial scraping, manipulative AI, exploitation of vulnerabilities — became enforceable.

2 August 2025

GPAI transparency obligations

General-purpose AI model providers must comply with Article 53: technical documentation, downstream-provider information, copyright policy, and training-data summary.

2 August 2026

Transparency rules apply

Article 50 disclosure duties apply to relevant chatbots, synthetic content, deepfakes, emotion-recognition systems, and biometric categorisation systems.

2 December 2027

Annex III high-risk rules apply

High-risk rules apply to listed stand-alone use cases including biometrics, critical infrastructure, education, employment, essential services, migration, and justice.

2 August 2028

Regulated-product high-risk rules apply

The extended date applies to high-risk AI systems embedded in regulated products covered by the product-safety legislation listed in Annex I.

High-risk obligations

If your AI system is classified as high-risk, you must comply with the following requirements. These apply to both providers and deployers, though the specific duties differ.

Risk management system

Art. 9

Establish, implement, document, and maintain a risk management system for the AI system's lifecycle.

Data governance

Art. 10

Ensure training, validation, and testing data are relevant, representative, and free of errors to the extent possible.

Technical documentation

Art. 11

Maintain technical documentation demonstrating conformity before market placement.

Record-keeping and logging

Art. 12

Implement automatic logging of events relevant for traceability and post-market monitoring.

Transparency to deployers

Art. 13

Provide instructions for use so deployers can interpret system output and exercise meaningful human oversight.

Human oversight

Art. 14

Design the system so it can be effectively overseen by natural persons during use.

Accuracy, robustness, cybersecurity

Art. 15

Achieve appropriate levels of accuracy, robustness, and cybersecurity throughout the lifecycle.

Post-market monitoring

Art. 72

Establish a system to monitor performance and serious incidents after the AI system has been placed on the market.

What about general-purpose AI models?

GPAI model providers (like OpenAI, Anthropic, Google) have their own set of obligations under Article 53–55. These include:

  • Technical documentation for the model and its training process
  • Information and documentation for downstream providers who integrate the model
  • A policy to comply with EU copyright law (including the TDM opt-out)
  • A publicly available summary of training data content

If you're a deployer using a GPAI model (e.g. you build a product on top of GPT-4 or Claude), your obligations depend on how the model is used. If the use case is high-risk, the full high-risk regime applies to you as a deployer — even though the model provider handles the GPAI transparency side.

Ready to check your compliance?

Run our free risk classifier to see which class your AI systems fall into and what you need to do about it.

Start free assessment