What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

EU AI Act

The EU AI Act, formally Regulation (EU) 2024/1689, is the European Union law on artificial intelligence. The Act sets binding rules for AI systems placed on the market or used in the EU, and for general-purpose AI models placed on the EU market. It bans certain practices, sets requirements for high-risk systems and imposes transparency duties on certain systems.

Last reviewed

Key points

  • The EU AI Act is Regulation (EU) 2024/1689, binding law in every member state and in force since 1 August 2024.
  • It bans some AI practices, sets requirements for high-risk systems, imposes transparency duties on certain AI systems, and regulates providers of general-purpose AI models.
  • It reaches providers outside the EU when they place AI on the EU market or when their system's output is used in the EU.
  • The European Commission describes four risk levels. The Regulation's text sets prohibitions, high-risk rules and transparency duties, but has no "minimal risk" tier, and general-purpose models sit outside the levels.
  • The Digital Omnibus on AI delayed the high-risk requirements to 2 December 2027 for sensitive uses the Act lists, such as employment, and 2 August 2028 for AI in regulated products such as toys.

What the Act regulates

The EU AI Act regulates the AI system, which Article 3(1) defines as a machine-based system that “infers, from the input it receives, how to generate outputs”. It also regulates the general-purpose AI model that many such systems are built on.

Article 1(2) lists what the Act lays down, including these four sets of rules:

  • Prohibited practices (Article 5), such as manipulative techniques that cause significant harm. Breaching one can cost a company up to EUR 35 million or 7% of the previous year’s worldwide turnover, whichever is higher; for SMEs and start-ups, whichever is lower.
  • High-risk systems, which must meet requirements before reaching the market. Article 6 decides which systems are high-risk; Article 15 sets their accuracy, robustness and cybersecurity duty.
  • Transparency duties (Article 50), such as telling people they are talking to an AI system.
  • General-purpose AI models, with extra duties (Article 55) for models classified as posing systemic risk (Article 51), which is presumed for any model trained with more than 10^25 operations of compute.

Why it matters

The EU AI Act is binding law, not guidance. It is “directly applicable in all Member States”, and Article 2 reaches providers outside the EU whose AI output is used there. For AI security, Article 15 requires high-risk systems to include, “where appropriate”, measures against named attacks such as data poisoning.

Where definitions disagree

The European Commission’s AI Act page says “The AI Act defines 4 levels of risk for AI systems”: unacceptable, high, transparency, and “minimal or no risk”.

The Regulation’s text does not use those levels. Recital 26 describes a “risk-based approach” in three parts: prohibitions, high-risk requirements and transparency obligations. The phrase “minimal risk” never appears. General-purpose models sit outside the four levels entirely. The levels are not exclusive either: Article 50(6) says transparency duties “shall not affect” the high-risk requirements, so one system can carry both.

When the rules apply

The Act entered into force on 1 August 2024 and applies in stages. The prohibitions applied from 2 February 2025, general-purpose AI model duties from 2 August 2025, and most other rules from 2 August 2026.

The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, delayed the high-risk requirements. For the sensitive uses listed in Annex III, such as employment or education, they apply from 2 December 2027. For AI in regulated products under Annex I, such as toys, they apply from 2 August 2028.

The Omnibus also added two prohibitions from 2 December 2026, on AI systems that produce non-consensual intimate imagery of real people or child sexual abuse material. Both bind providers only where that output is the system’s purpose or a foreseeable result without adequate safeguards.

Questions and answers

Does the EU AI Act apply to companies outside the EU?

Yes. Article 2 applies the Act to providers that place AI systems or general-purpose AI models on the EU market wherever they are based, and to providers and professional users outside the EU when the output of their AI system is used in the EU.

What are the four risk levels of the EU AI Act?

The four levels (unacceptable, high, transparency, and minimal or no risk) are the European Commission's summary, not categories written into the Regulation. The Act itself sets prohibitions, high-risk requirements, transparency duties and separate rules for general-purpose AI models, and a system can fall under more than one.

When does the EU AI Act apply?

The Act entered into force on 1 August 2024. The original prohibitions applied from 2 February 2025, general-purpose AI model obligations from 2 August 2025, and most other rules from 2 August 2026. The Digital Omnibus on AI added two prohibitions from 2 December 2026, and delayed the high-risk requirements to 2 December 2027 for sensitive uses such as employment and 2 August 2028 for AI in regulated products such as toys.

Sources

  1. Regulation (EU) 2024/1689 (EU AI Act), Article 113, as published in the Official JournalEuropean Union, 12 Jul 2024
  2. AI Act (Shaping Europe's digital future: Regulatory framework for AI)European Commission
  3. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 1, point amending Article 113European Union, 24 Jul 2026

Guides that use this term