Security Quotient

EU AI Act Guide

Covering scope, the four-tier risk framework, high-risk obligations, penalties, and the phased compliance timeline through 2026.

Artificial intelligence is reshaping industries, economies, and societies at a speed that few could have predicted even a decade ago. From healthcare diagnostics and credit scoring to recruitment tools and autonomous vehicles, AI systems are making decisions that profoundly affect human lives. Yet until recently, this transformation was unfolding largely without a comprehensive legal framework to govern it.

That changed on 1 August 2024, when the EU AI Act officially entered into force — the world's first binding, comprehensive legal framework specifically designed to regulate artificial intelligence. Passed by the European Parliament and adopted by the European Council, the Act represents a generational shift in how governments approach technology governance. It is to AI what the GDPR was to data privacy: a global standard-setter with far-reaching implications for any organization that develops, deploys, or uses AI systems touching the European market.

This page is your definitive guide to the EU AI Act — what it says, who it applies to, what it demands, and how organizations can prepare for compliance.

What Is the EU AI Act?

The EU AI Act (formally Regulation (EU) 2024/1689) is a regulation of the European Parliament and of the Council laying down harmonized rules on artificial intelligence. It follows a risk-based regulatory approach — the higher the risk an AI system poses to fundamental rights, health, safety, or democratic processes, the more stringent the obligations placed on those who create or deploy it.

The Act was first proposed by the European Commission in April 2021 and underwent years of negotiation, debate, and amendment — including a significant expansion in scope following the rise of large language models and generative AI. It was formally adopted in March 2024 and published in the Official Journal of the EU in July 2024.\

Find key milestones in the history of the EU AI Act here - EU AI Act Historic Timeline

Click here to go to the_AI Act Explorer.

Core Objectives of the Act

The EU AI Act was designed with four overarching goals in mind:

Protect fundamental rights and safety — ensuring AI systems do not harm individuals or undermine democratic institutions.

Build trust in AI — creating a predictable, transparent regulatory environment that encourages responsible innovation.

Facilitate the internal market — establishing harmonized rules across all EU member states to prevent regulatory fragmentation.

Position Europe as a global leader — setting a benchmark for AI governance that other jurisdictions can follow.

Who Does the EU AI Act Apply To?

The territorial scope of the EU AI Act is broad and deliberate. It applies to:

Providers — organizations or individuals who develop AI systems or general-purpose AI models and place them on the EU market or put them into service in the EU, regardless of whether they are established in the EU or in a third country.

Deployers — organizations or individuals who use AI systems under their authority within the EU, except where AI is used for personal non-professional activities.

Importers — entities established in the EU that place on the market or put into service an AI system bearing the name of a person outside the EU.

Distributors — entities in the supply chain that make AI systems available on the EU market without altering them.

Product manufacturers — entities that place an AI system on the market or put it into service together with their product under their own name.

Affected persons — the Act also creates rights and protections for individuals subject to AI decision-making.

Like the GDPR, the EU AI Act has a significant extraterritorial reach. If your AI system's output is used within the EU — regardless of where your organization is headquartered — the Act likely applies to you.

Who Is Exempt?

The Act does not apply to AI systems developed or used exclusively for military, national security, defense, or research and development purposes before market placement. AI used for purely personal non-professional purposes is also excluded. Public authorities in third countries using AI for international cooperation on law enforcement or judicial matters may also fall outside scope.

The Risk-Based Framework: Four Tiers of AI Systems

The cornerstone of the EU AI Act is its tiered, risk-proportionate approach. Every AI system must be classified into one of four risk categories, each carrying a distinct set of obligations.

Tier 1 — Unacceptable Risk: Prohibited AI Practices

At the top of the risk pyramid sit AI applications deemed so fundamentally dangerous to human dignity, freedom, and democratic values that they are banned outright. These prohibited practices include:

Subliminal manipulation — AI systems that deploy techniques beyond a person's consciousness to distort their behavior in a way that causes or is likely to cause harm.

Exploitation of vulnerabilities — AI that exploits specific vulnerabilities of individuals or groups due to age, disability, or social and economic situations.

Social scoring by public authorities — AI systems used by governments to evaluate or classify individuals based on social behavior or personal characteristics, leading to detrimental or unfavorable treatment.

Real-time remote biometric identification in public spaces — with very limited exceptions for law enforcement, the use of real-time AI-powered facial recognition and similar biometric systems in publicly accessible spaces is prohibited.

Biometric categorization based on sensitive attributes — systems that categorize individuals based on biometric data to infer race, political opinion, trade union membership, religious beliefs, or sexual orientation.

Emotion recognition in workplace and educational settings — AI systems that infer emotions of individuals in workplaces or educational institutions are prohibited, with narrow exceptions for medical or safety-related purposes.

Predictive policing — AI systems that make risk assessments of individuals based solely on profiling or on the assessment of personality traits to predict criminal behavior.

Organizations that deploy any of the above face the most severe penalties under the Act.

Tier 2 — High Risk: Permitted but Strictly Regulated

High-risk AI systems are allowed but subject to extensive pre-market obligations and ongoing compliance requirements. An AI system qualifies as high-risk if it falls within one of two categories:

Category A — AI systems in regulated products covered by existing EU product safety legislation, including:

  • Machinery
  • Medical devices and in vitro diagnostic medical devices
  • Lifts and pressure equipment
  • Radio equipment
  • Motor vehicles
  • Aviation components
  • Agricultural machinery and marine equipment

Category B — AI systems in specific high-risk use cases listed in Annex III of the Act, spanning eight domains:

  • Biometric identification and categorization of natural persons
  • Critical infrastructure management — including road traffic, water, gas, heating, and electricity supply
  • Education and vocational training — AI used to determine access to educational institutions or evaluate learning outcomes
  • Employment and workforce management — AI used in recruitment, task allocation, promotion, termination, and worker monitoring
  • Access to essential private and public services — including credit scoring, insurance risk assessment, and eligibility for public benefits
  • Law enforcement — AI used to assess the risk of an individual becoming a victim or perpetrator of crime, or to evaluate the reliability of evidence
  • Migration, asylum, and border control — risk assessment of individuals crossing borders or applying for asylum
  • Administration of justice and democratic processes — AI used to research and interpret law, apply it in a concrete case, or influence electoral outcomes

Tier 3 — Limited Risk: Transparency Obligations

AI systems in this category are not considered high-risk but interact with humans in ways that could cause confusion about the nature of the interaction. The primary obligation is transparency.

Key requirements include:

Chatbots and conversational AI — must clearly disclose to users that they are interacting with an AI system, not a human.

Deepfakes and synthetic media — AI-generated images, video, audio, or text that could be mistaken for real content must be labeled as artificially generated or manipulated.

Emotion recognition and biometric categorization systems (outside prohibited categories) — must inform individuals when they are being subjected to such systems.

The burden here is relatively light, but non-compliance — especially around deceptive deepfakes used in political or commercial contexts — can still attract regulatory attention.

Tier 4 — Minimal Risk: No Specific Obligations

The vast majority of AI systems fall into this category — spam filters, AI-powered video games, inventory management tools, recommendation engines, and the like. These are permitted without any specific obligations under the Act, though providers are encouraged to adopt voluntary codes of conduct and adhere to AI ethics frameworks.

General-Purpose AI Models: A New Regulatory Category

One of the most significant additions to the Act during its legislative journey was the introduction of specific rules for General-Purpose AI (GPAI) models — large-scale foundation models such as large language models (LLMs) that can be used across a wide range of tasks and applications.

Who Is Affected?

GPAI obligations apply to providers who develop and place GPAI models on the EU market — this includes companies offering models via APIs, open-source releases, or integration into downstream products.

Obligations for All GPAI Providers

Regardless of scale or risk, all GPAI model providers must:

  • Prepare and maintain technical documentation of the model
  • Comply with EU copyright law, including implementing a policy to respect rights-holders' opt-outs
  • Publish a sufficiently detailed summary of the training data used

Additional Obligations for Systemic Risk GPAI Models

GPAI models that exceed a certain computational threshold (10^25 FLOPs, as set in the current guidelines) or that the European AI Office determines pose systemic risk face elevated obligations:

  • Conduct adversarial testing and red-teaming before deployment
  • Report serious incidents to the European AI Office
  • Implement cybersecurity protections
  • Report on energy consumption during training

Open-source GPAI models benefit from some exemptions, particularly around documentation requirements, unless they present systemic risk.

Key Obligations for High-Risk AI Systems

For organizations operating in the high-risk space, the EU AI Act introduces a comprehensive compliance architecture. These are the principal obligations:

Risk Management System

Providers must establish, implement, document, and maintain a risk management system throughout the entire lifecycle of the AI system. This is an ongoing process — not a one-time assessment — that must identify, analyze, evaluate, and mitigate reasonably foreseeable risks.

Data Governance

Training, validation, and testing datasets must be subject to appropriate data governance practices. This includes:

  • Ensuring datasets are relevant, representative, and free of errors to the extent possible
  • Addressing biases that could lead to discriminatory outcomes
  • Ensuring data protection compliance, particularly where personal data is involved

Technical Documentation

Before placing a high-risk AI system on the EU market, providers must compile extensive technical documentation demonstrating compliance. This documentation must be kept up to date throughout the system's lifecycle and made available to regulators on request.

Record-Keeping and Logging

High-risk AI systems must be designed to automatically log events relevant to the identification of risks and substantial modifications throughout the system's lifetime. These logs must be retained for an appropriate period.

Transparency and User Information

Deployers and providers must furnish users with clear, concise, and relevant information about the AI system, including its capabilities, limitations, intended purpose, and the human oversight measures in place.

Human Oversight

One of the most philosophically significant requirements: high-risk AI systems must be designed and developed in a way that allows effective oversight by natural persons. This includes enabling operators to understand the system's outputs and intervene or override decisions when necessary.

Accuracy, Robustness, and Cybersecurity

High-risk AI systems must achieve appropriate levels of accuracy and perform consistently across their intended purpose, including in conditions of foreseeable misuse. They must also be resilient against adversarial manipulation.

Conformity Assessment

Before market placement, most high-risk AI systems must undergo a conformity assessment to verify that they meet the Act's requirements. For many systems, this can be a self-assessment by the provider. For biometric identification and certain safety-critical systems, third-party assessment by a notified body is mandatory.

CE Marking and Registration

High-risk AI systems that pass conformity assessment must bear the CE marking before being placed on the EU market. They must also be registered in a new EU-wide database of high-risk AI systems maintained by the European Commission.

Post-Market Monitoring

Providers must implement a post-market monitoring system to actively collect and review data on the performance of their AI systems after deployment and take corrective action where needed.

Obligations for Deployers of High-Risk AI Systems

The Act does not only regulate providers. Organizations that deploy high-risk AI systems — even if they did not build them — carry significant obligations:

  • Use the AI system in accordance with the provider's instructions
  • Ensure the system is monitored by human operators with appropriate competence
  • Conduct a fundamental rights impact assessment before deploying certain high-risk AI systems
  • Inform employees and their representatives when AI is used for workplace monitoring or decision-making
  • Register as a deployer in the EU database where required
  • Maintain logs of the system's use where technically feasible

The Role of Fundamental Rights Impact Assessments (FRIAs)

A Fundamental Rights Impact Assessment is a structured process that deployers of certain high-risk AI systems — particularly public bodies and private entities performing public functions — must conduct before deployment. A FRIA requires organizations to:

  • Describe the deployment context and the categories of persons likely to be affected
  • Identify the specific fundamental rights that may be impacted
  • Assess the probability and severity of potential harms
  • Identify and implement mitigation measures
  • Document outcomes and make them available to the supervisory authority on request

FRIAs sit alongside — not instead of — Data Protection Impact Assessments (DPIAs) under GDPR. Where a DPIA is already required, both must be conducted.

Governance and Enforcement Architecture

The European AI Office

The Act establishes the European AI Office within the European Commission as the central body responsible for:

  • Overseeing and enforcing rules on GPAI models
  • Coordinating AI governance across member states
  • Developing technical standards and evaluation methodologies
  • Investigating systemic risk incidents

National Competent Authorities

Each EU member state must designate one or more national competent authorities to supervise and enforce the Act's application at the national level. These authorities have powers to conduct audits, request documentation, impose corrective measures, and levy fines.

AI Advisory Forum and Scientific Panel

A multi-stakeholder AI Advisory Forum and an independent panel of scientific experts support the AI Office in technical assessment, standard-setting, and identification of systemic risks.

Market Surveillance Authorities

Existing product market surveillance bodies are designated to oversee high-risk AI embedded in regulated products, ensuring integration with existing sectoral regulatory regimes.

Penalties and Fines

The EU AI Act adopts a tiered penalty structure similar to the GDPR:

Prohibited practices — up to €35 million or 7% of global annual turnover, whichever is higher.

Violations of obligations for high-risk AI systems, GPAI models, and other provisions — up to €15 million or 3% of global annual turnover, whichever is higher.

Supply of incorrect or misleading information to regulators — up to €7.5 million or 1.5% of global annual turnover, whichever is higher.

For SMEs and startups, the Act allows member states to apply proportionate penalties. However, the size of potential fines underscores that non-compliance carries genuine financial risk.

Timeline: When Do the Rules Apply?

The EU AI Act has a phased implementation schedule from its entry into force on 1 August 2024:

6 months (February 2025) — Prohibitions on unacceptable risk AI practices apply. Member states must designate competent authorities.

12 months (August 2025) — Rules on general-purpose AI models and the AI Office apply. Codes of practice for GPAI providers become active.

24 months (August 2026) — The majority of the Act's obligations apply, including all high-risk AI system requirements, transparency rules, and the EU database for high-risk systems.

36 months (August 2027) — High-risk AI systems embedded in regulated products covered by existing EU sectoral legislation must comply.

Organizations should note that the 2026 deadline is not far away. Building compliance infrastructure takes time — gap assessments, system inventories, documentation, and staff training cannot be left to the final months.

How the EU AI Act Interacts with Other Regulations

The EU AI Act does not exist in isolation. It is part of a broader regulatory ecosystem that organizations must navigate holistically.

EU AI Act and GDPR

The relationship between the AI Act and GDPR is both complementary and complex. Many high-risk AI systems process personal data, triggering obligations under both regulations simultaneously. Key interaction points include:

  • AI systems used for biometric identification must comply with both frameworks
  • DPIAs and FRIAs may overlap in scope and must be coordinated
  • Data minimization and purpose limitation principles under GDPR constrain what data can be used for AI training
  • AI-driven automated decision-making is also addressed in GDPR Article 22 and must be reconciled with AI Act transparency and human oversight requirements

EU AI Act and the Product Liability Directive

The AI Act works alongside the updated Product Liability Directive to ensure that individuals harmed by defective AI systems have clear legal recourse for compensation.

EU AI Act and the AI Liability Directive

A proposed directive on AI liability (still under legislative development) would create a framework for non-contractual liability arising from AI-caused harm, easing the burden of proof for claimants in civil cases.

EU AI Act and Sector-Specific Regulations

In financial services, healthcare, and transport, the AI Act layers on top of existing sectoral rules — MiFID II, the MDR, and aviation safety regulations, for example. Organizations in these sectors must map AI Act requirements against existing compliance obligations to identify overlaps and gaps.

EU AI Act and Generative AI: Special Considerations

The explosion of generative AI tools — Large language models, image generators, multimodal systems — created regulatory challenges that the original 2021 proposal did not anticipate. The final text addresses this in several ways:

GPAI obligations require providers of foundational models to document their systems, respect copyright, and — where systemic risk is present — conduct adversarial testing and report incidents.

Transparency for AI-generated content — Generative AI outputs that could be mistaken for real human-generated content must be labeled. This applies to synthetic images, audio, video, and text.

Downstream responsibility — Where a GPAI model is integrated into a downstream high-risk AI system, responsibilities are shared between the GPAI provider and the downstream provider. Contractual arrangements and technical documentation must clearly delineate accountability.

Copyright and training data — GPAI providers must comply with EU copyright law. Where right-holders have exercised their opt-out rights under the Text and Data Mining exception, providers must not use that content for training.

Building an EU AI Act Compliance Program

Compliance with the EU AI Act is not a one-time project. It requires a sustained, organization-wide effort. Here is a structured approach for organizations beginning their compliance journey.

Step 1: Conduct an AI System Inventory

Before you can assess risk, you need to know what AI systems your organization uses, provides, or has integrated into products. Map every AI application across business units, including third-party AI tools embedded in software you use.

Step 2: Classify Each System by Risk Tier

Using the Act's definitions and Annex III, classify each identified AI system into the appropriate risk category. Pay careful attention to whether the use case, not just the technology, qualifies as high-risk.

Step 3: Conduct Gap Assessments

For each high-risk system, assess the gap between your current documentation, governance, and technical practices and what the Act requires. This includes reviewing data governance policies, risk management frameworks, logging capabilities, and human oversight mechanisms.

Step 4: Appoint an AI Governance Lead

Designate a senior person or team responsible for AI compliance. In larger organizations, this may be a dedicated AI Officer role or an extension of the DPO's remit. Regardless of title, this person needs authority, resources, and cross-functional access.

Step 5: Develop or Update Documentation

Create or update the technical documentation, conformity declarations, and risk management records required for each high-risk AI system. Establish a template library and version control process.

Step 6: Implement Human Oversight Mechanisms

Review each high-risk AI system for the adequacy of human oversight controls. Update system design, operational procedures, and user training to ensure meaningful human review of consequential AI-generated outputs.

Step 7: Establish Post-Market Monitoring

Put in place processes to continuously monitor the performance of deployed high-risk AI systems. Define thresholds for corrective action, incident reporting, and regulatory notification.

Step 8: Train Your People

Technical compliance without human understanding is fragile. Ensure that developers, data scientists, procurement teams, legal counsel, HR, and operational staff all receive role-appropriate AI Act training. This is not a one-off exercise — it must be refreshed as the regulatory landscape and your AI systems evolve.

Step 9: Update Contracts and Third-Party Management

Review contracts with AI vendors, cloud providers, and integrators. Ensure they clearly allocate responsibility for compliance obligations and include appropriate representations about the systems they supply. Establish due diligence processes for AI procurement.

Step 10: Engage with Standards

The EU AI Act mandates the European Standards Organizations (CEN/CENELEC, ETSI) to develop harmonized technical standards. Monitoring these standards and aligning your systems with them as they emerge will streamline conformity assessment.

EU AI Act Training: Building Organizational Capability

Training deserves its own focus within any AI Act compliance program. Unlike technical measures, training addresses the human dimension of compliance — the decisions people make every day about how AI systems are designed, deployed, and monitored.

Who Needs Training?

Leadership and Boards — must understand the strategic implications, liability exposure, and governance obligations the Act creates.

Legal and Compliance Teams — need in-depth knowledge of the Act's requirements, enforcement landscape, and interaction with GDPR and other regulations.

AI and Data Science Teams — must understand risk classification, technical documentation requirements, data governance standards, and design obligations for human oversight and robustness.

Product and Procurement Teams — need training on assessing the risk classification of AI they are building or buying and embedding compliance requirements into procurement processes.

HR and Workforce Management — particularly important given the Act's specific focus on AI in recruitment, performance evaluation, and worker monitoring.

Customer-Facing and Operational Staff — need awareness of transparency obligations, user rights, and escalation procedures.

What Should Training Cover?

A comprehensive EU AI Act training program should address:

  • The fundamentals of the Act: scope, definitions, and risk tiers
  • The prohibited practices and why they are banned
  • The high-risk use cases in Annex III and how to identify them
  • Obligations for providers, deployers, importers, and distributors
  • GPAI-specific rules and how they apply to LLM-based tools
  • Technical documentation and conformity assessment processes
  • Fundamental Rights Impact Assessments
  • Human oversight: what it means in practice
  • Transparency and labeling obligations
  • Incident detection, logging, and reporting
  • Enforcement, penalties, and regulatory expectations
  • Intersection with GDPR and other applicable regulations

Common Misconceptions About the EU AI Act

"It only applies to AI companies."

Wrong. Any organization that deploys a high-risk AI system — even one built by a third party — has compliance obligations.

"We're outside the EU, so it doesn't apply to us."

If your AI system's outputs are used within the EU, the Act applies to you, regardless of where you are based.

"All AI is heavily regulated."

The Act explicitly adopts a risk-based approach. Most AI systems fall into the minimal-risk category and require no specific compliance action.

"GDPR compliance means we're AI Act compliant."

GDPR and the AI Act address different things and have different requirements. Being compliant with one does not ensure compliance with the other.

We have until 2026 — there's no urgency.

Building compliance infrastructure across complex AI portfolios takes time. The organizations beginning now will be far better positioned than those who wait.

The Global Influence of the EU AI Act

The EU AI Act is already shaping AI governance conversations far beyond Europe's borders. The Brussels Effect — the phenomenon by which EU regulation becomes a de facto global standard because multinational companies find it more efficient to apply a single, high-compliance standard worldwide — is already visible in AI.

Several jurisdictions are developing or have developed AI governance frameworks that reference the EU AI Act's approach:

United Kingdom — has adopted a principles-based, sector-specific approach through existing regulators, but continues to watch EU developments closely.

United States — the Biden administration's Executive Order on AI Safety and the AI RMF from NIST reflect similar risk-based thinking, though the legislative landscape remains fragmented.

Canada — the proposed Artificial Intelligence and Data Act (AIDA) mirrors the EU's risk classification approach.

China — has enacted specific regulations on algorithmic recommendations and generative AI with some structural similarities to the EU framework.

Brazil, India, and the UAE — are actively developing AI governance frameworks that look to the EU AI Act as a reference point.

For global organizations, aligning with the EU AI Act is increasingly a strategic baseline — not just a regional compliance obligation.

Key Definitions to Know

AI System — a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

General-Purpose AI Model — an AI model trained on large amounts of data that can serve a variety of general purposes with a high degree of generality, including when it is fine-tuned for specific tasks.

Provider — a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model and places it on the market or puts it into service.

Deployer — a natural or legal person, public authority, agency or other body that uses an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.

Intended Purpose — the use for which an AI system is intended by the provider, including the specific context and conditions of use.

Reasonably Foreseeable Misuse — the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behavior.

Serious Incident — an incident or malfunctioning of an AI system that directly or indirectly leads to death, serious harm to health, serious and irreversible disruption of critical infrastructure, or infringement of fundamental rights.

Conclusion: Compliance as Competitive Advantage

The EU AI Act is ambitious, comprehensive, and unprecedented in scope. It will require significant investment from organizations across all sectors and geographies. But it also offers something in return: a framework for building AI systems that people can trust.

Organizations that treat EU AI Act compliance as a burden to be minimized will find themselves perpetually reactive — scrambling to update documentation, address incidents, and respond to regulators. Organizations that treat it as a strategic foundation will find themselves building stronger products, earning deeper customer trust, and establishing durable competitive advantages in a market where AI trustworthiness is increasingly a differentiator.

The Act does not seek to slow AI innovation. It seeks to direct it — toward systems that are transparent, accountable, safe, and respectful of the fundamental rights that Europe has long championed. For organizations willing to rise to that standard, the opportunity is significant.

The question is not whether to comply. It is whether to lead.

The EU AI Act represents one of the most consequential technology policy developments of the decade. Staying informed, acting early, and investing in genuine compliance capability is the surest path through a changing regulatory landscape.

Frequently Asked Questions

What is the EU AI Act?

The EU AI Act is the world's first comprehensive legal framework for regulating artificial intelligence. It was adopted by the European Parliament in March 2024 and establishes binding rules for AI systems developed, deployed, or used within the European Union.

When does the EU AI Act come into force?

The EU AI Act entered into force on 1 August 2024. It is being implemented in phases: prohibited AI practices apply from February 2025, high-risk AI obligations apply from August 2026, and general-purpose AI requirements apply from August 2025.

Who does the EU AI Act apply to?

The Act applies to providers (developers) of AI systems, deployers (organisations using AI systems), importers and distributors of AI systems within the EU, and any organisation outside the EU whose AI system outputs are used within the EU. It has extraterritorial reach similar to GDPR.

What are the risk categories under the EU AI Act?

The Act classifies AI systems into four risk levels: unacceptable risk (banned outright, e.g. social scoring, real-time biometric surveillance), high risk (heavily regulated, e.g. AI in hiring, credit scoring, law enforcement), limited risk (transparency obligations, e.g. chatbots must disclose they are AI), and minimal risk (no specific obligations, e.g. spam filters, AI in video games).

What AI practices are banned under the EU AI Act?

Prohibited practices include social scoring by governments, real-time remote biometric identification in public spaces (with limited exceptions for law enforcement), AI that exploits vulnerabilities of specific groups, and AI systems that manipulate human behaviour to cause harm.

What are the penalties for non-compliance with the EU AI Act?

Fines can reach up to 35 million euros or 7% of global annual turnover for violations related to prohibited AI practices. For other violations, fines can be up to 15 million euros or 3% of global turnover. For providing incorrect information, fines can reach 7.5 million euros or 1% of turnover.

How does the EU AI Act affect companies outside Europe?

Any organisation whose AI system produces outputs that are used within the EU falls under the Act's jurisdiction, regardless of where the company is headquartered. This extraterritorial scope means companies in Asia, the Middle East, and the Americas may need to comply if their AI outputs reach EU users.

What is a high-risk AI system under the EU AI Act?

High-risk AI systems include those used in critical infrastructure, education and vocational training, employment and worker management, essential services (credit scoring, insurance), law enforcement, migration and border control, and administration of justice. These systems must undergo conformity assessments and meet strict documentation, transparency, and oversight requirements.

How does the EU AI Act relate to GDPR?

The two regulations complement each other. GDPR protects personal data, while the AI Act regulates the systems that process that data. AI systems that process personal data must comply with both. The AI Act adds specific requirements around transparency, human oversight, and bias testing that go beyond GDPR's data protection requirements.

What is a conformity assessment under the EU AI Act?

A conformity assessment is a mandatory evaluation process for high-risk AI systems. It verifies that the system meets the Act's requirements for safety, transparency, documentation, human oversight, accuracy, and robustness. Most high-risk systems can be self-assessed by the provider, but certain categories (such as biometric identification) require assessment by an independent notified body.

Need help with EU AI Act compliance?

Talk to a Security Quotient advisor about an AI governance training programme tailored to your organisation.

Request a demo