Resource · EU AI Act
The EU AI Act, explained plainly
A practical guide for teams building or deploying AI in Europe. No legal jargon, no fear-mongering — just what you need to do, when, and how.
What is the AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal law for artificial intelligence. It entered into force on 1 August 2024 and applies to any organisation that places AI systems on the EU market or uses them within the EU — regardless of where the organisation is based.
The Act uses a risk-based approach. Instead of regulating the technology itself, it regulates the use case. The more potential for harm, the more obligations apply.
If you deploy, develop, import, or distribute AI in the EU, this affects you. The penalties are significant: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for other violations.
The four risk classes
Every AI system falls into one of these categories. Your obligations depend on which one applies.
Prohibited
AI practices banned outright: social scoring, real-time biometric ID in public spaces, manipulative or exploitative systems.
- Social scoring by public authorities
- Untargeted facial image scraping
- Emotion recognition in workplaces and schools
High-risk
Systems that significantly affect health, safety, fundamental rights, or critical infrastructure. Full Article 8–17 obligations apply.
- Recruitment and CV-screening tools
- Credit scoring and insurance pricing
- Medical diagnosis aids
- Critical infrastructure management
Limited-risk
Systems with specific transparency obligations under Article 50. Users must be informed they are interacting with AI.
- Chatbots and virtual assistants
- Deepfakes and synthetic media
- Emotion recognition (with consent)
- Biometric categorisation
Minimal-risk
All other AI systems. No specific obligations under the AI Act, though existing GDPR and sectoral rules still apply.
- Spam filters
- Recommendation engines
- Inventory forecasting
- Search ranking
The compliance timeline
The AI Act is being phased in. Transparency duties now apply, while the principal high-risk dates are 2 December 2027 and 2 August 2028.
Prohibited practices take effect
Article 5 bans on certain AI practices — social scoring, untargeted facial scraping, manipulative AI, exploitation of vulnerabilities — became enforceable.
GPAI transparency obligations
General-purpose AI model providers must comply with Article 53: technical documentation, downstream-provider information, copyright policy, and training-data summary.
Transparency rules apply
Article 50 disclosure duties apply to relevant chatbots, synthetic content, deepfakes, emotion-recognition systems, and biometric categorisation systems.
Annex III high-risk rules apply
High-risk rules apply to listed stand-alone use cases including biometrics, critical infrastructure, education, employment, essential services, migration, and justice.
Regulated-product high-risk rules apply
The extended date applies to high-risk AI systems embedded in regulated products covered by the product-safety legislation listed in Annex I.
High-risk obligations
If your AI system is classified as high-risk, you must comply with the following requirements. These apply to both providers and deployers, though the specific duties differ.
Risk management system
Establish, implement, document, and maintain a risk management system for the AI system's lifecycle.
Data governance
Ensure training, validation, and testing data are relevant, representative, and free of errors to the extent possible.
Technical documentation
Maintain technical documentation demonstrating conformity before market placement.
Record-keeping and logging
Implement automatic logging of events relevant for traceability and post-market monitoring.
Transparency to deployers
Provide instructions for use so deployers can interpret system output and exercise meaningful human oversight.
Human oversight
Design the system so it can be effectively overseen by natural persons during use.
Accuracy, robustness, cybersecurity
Achieve appropriate levels of accuracy, robustness, and cybersecurity throughout the lifecycle.
Post-market monitoring
Establish a system to monitor performance and serious incidents after the AI system has been placed on the market.
What about general-purpose AI models?
GPAI model providers (like OpenAI, Anthropic, Google) have their own set of obligations under Article 53–55. These include:
- Technical documentation for the model and its training process
- Information and documentation for downstream providers who integrate the model
- A policy to comply with EU copyright law (including the TDM opt-out)
- A publicly available summary of training data content
If you're a deployer using a GPAI model (e.g. you build a product on top of GPT-4 or Claude), your obligations depend on how the model is used. If the use case is high-risk, the full high-risk regime applies to you as a deployer — even though the model provider handles the GPAI transparency side.
Ready to check your compliance?
Run our free risk classifier to see which class your AI systems fall into and what you need to do about it.
Start free assessment