EU AI Act
Europe's binding legal framework for regulating artificial intelligence.
What is the EU AI Act?
The EU AI Act is the world's first comprehensive legal framework for regulating artificial intelligence. It was adopted by the European Parliament in March 2024 and establishes binding rules for AI systems developed, deployed, or used within the European Union.
When does the EU AI Act come into force?
The EU AI Act entered into force on 1 August 2024. It is being implemented in phases: prohibited AI practices apply from February 2025, high-risk AI obligations apply from August 2026, and general-purpose AI requirements apply from August 2025.
Who does the EU AI Act apply to?
The Act applies to providers (developers) of AI systems, deployers (organisations using AI systems), importers and distributors of AI systems within the EU, and any organisation outside the EU whose AI system outputs are used within the EU. It has extraterritorial reach similar to GDPR.
What are the risk categories under the EU AI Act?
The Act classifies AI systems into four risk levels: unacceptable risk (banned outright, e.g. social scoring, real-time biometric surveillance), high risk (heavily regulated, e.g. AI in hiring, credit scoring, law enforcement), limited risk (transparency obligations, e.g. chatbots must disclose they are AI), and minimal risk (no specific obligations, e.g. spam filters, AI in video games).
What AI practices are banned under the EU AI Act?
Prohibited practices include social scoring by governments, real-time remote biometric identification in public spaces (with limited exceptions for law enforcement), AI that exploits vulnerabilities of specific groups, and AI systems that manipulate human behaviour to cause harm.
What are the penalties for non-compliance with the EU AI Act?
Fines can reach up to 35 million euros or 7% of global annual turnover for violations related to prohibited AI practices. For other violations, fines can be up to 15 million euros or 3% of global turnover. For providing incorrect information, fines can reach 7.5 million euros or 1% of turnover.
How does the EU AI Act affect companies outside Europe?
Any organisation whose AI system produces outputs that are used within the EU falls under the Act's jurisdiction, regardless of where the company is headquartered. This extraterritorial scope means companies in Asia, the Middle East, and the Americas may need to comply if their AI outputs reach EU users.
What is a high-risk AI system under the EU AI Act?
High-risk AI systems include those used in critical infrastructure, education and vocational training, employment and worker management, essential services (credit scoring, insurance), law enforcement, migration and border control, and administration of justice. These systems must undergo conformity assessments and meet strict documentation, transparency, and oversight requirements.
How does the EU AI Act relate to GDPR?
The two regulations complement each other. GDPR protects personal data, while the AI Act regulates the systems that process that data. AI systems that process personal data must comply with both. The AI Act adds specific requirements around transparency, human oversight, and bias testing that go beyond GDPR's data protection requirements.
What is a conformity assessment under the EU AI Act?
A conformity assessment is a mandatory evaluation process for high-risk AI systems. It verifies that the system meets the Act's requirements for safety, transparency, documentation, human oversight, accuracy, and robustness. Most high-risk systems can be self-assessed by the provider, but certain categories (such as biometric identification) require assessment by an independent notified body.
Does the EU AI Act apply to general-purpose AI like ChatGPT?
Yes. The Act includes specific provisions for general-purpose AI (GPAI) models. All GPAI providers must provide technical documentation and comply with EU copyright law. GPAI models with systemic risk (based on computing power thresholds) face additional obligations including model evaluation, adversarial testing, incident reporting, and cybersecurity measures.
How should organisations prepare for the EU AI Act?
Start by inventorying all AI systems in use across the organisation. Classify each system by risk level. For high-risk systems, conduct gap analyses against the Act's requirements. Establish AI governance structures including documentation, human oversight processes, and bias monitoring. Begin compliance work now, as the phased implementation means some obligations are already in effect.