Background and Approach
The European Union Artificial Intelligence Act is the European Union’s comprehensive legal framework for regulating artificial intelligence.
It entered into force on 1 August 2024 and follows a risk-based approach, meaning regulatory obligations become stricter as the potential harm posed by an AI system increases.
The Act seeks to:
- protect fundamental rights and human safety;
- encourage trustworthy AI;
- create uniform rules across the EU;
- improve transparency and accountability;
- support innovation while controlling high-risk uses.
Its rules can also affect companies outside Europe when their AI systems or outputs are used within the European Union.
Risk-Based Classification
The Act broadly separates AI systems according to their level of risk.
Unacceptable risk
Certain uses are prohibited because they pose serious threats to rights and freedoms.
Examples include:
- manipulative AI that causes significant harm;
- exploitation of vulnerable persons;
- certain forms of social scoring;
- some biometric categorisation based on highly sensitive characteristics;
- indiscriminate scraping of facial images for recognition databases;
- certain uses of real-time remote biometric identification in public spaces, subject to narrow exceptions.
High risk
These systems are permitted but face strict obligations.
Important areas include AI used in:
- employment and recruitment;
- education and examinations;
- critical infrastructure;
- essential public and private services;
- law enforcement;
- migration and border control;
- administration of justice.
Transparency risk
Users must be informed when they interact with certain AI systems. Synthetic or manipulated content may also require disclosure or machine-readable marking.
Minimal risk
Most ordinary AI applications face limited additional regulation.
Obligations for High-Risk AI
Providers of high-risk systems may be required to establish:
- risk-management systems;
- high-quality data governance;
- technical documentation;
- logging and traceability;
- human oversight;
- cybersecurity safeguards;
- accuracy and robustness standards;
- post-market monitoring.
Deployers may also have duties concerning appropriate use, monitoring and human supervision.
The Act therefore regulates not only the AI model itself but also how it is developed, deployed and monitored.
General-Purpose AI
The Act contains specific rules for general-purpose AI models, which can perform many different tasks and may form the basis of numerous downstream applications.
Providers may have obligations relating to:
- technical documentation;
- information for downstream developers;
- compliance with European copyright law;
- publication of information regarding training content.
More powerful general-purpose models that pose systemic risks face additional requirements, including:
- model evaluation;
- adversarial testing;
- systemic-risk assessment;
- incident reporting;
- cybersecurity measures.
These rules are particularly relevant to large foundation and generative AI models.
Implementation and Significance
Implementation is phased rather than occurring on a single date.
Prohibitions on unacceptable-risk practices and AI-literacy requirements began applying in February 2025, while important governance and general-purpose AI provisions followed in August 2025.
Most of the Act became applicable from 2 August 2026. Implementation of some high-risk AI obligations has been postponed further because the necessary technical standards and compliance infrastructure were not ready on time.
The framework is significant because it may influence global AI governance through the so-called Brussels effect, where multinational companies adopt European standards more broadly to avoid maintaining different compliance systems.
Major challenges include:
- defining AI risk consistently;
- preventing excessive compliance burdens on smaller firms;
- keeping regulation relevant despite rapid technological change;
- avoiding regulatory fragmentation;
- ensuring independent enforcement;
- balancing innovation with fundamental rights.
Conclusion
The EU AI Act represents a shift from largely voluntary AI ethics towards legally enforceable, risk-based regulation. Its central principle is that the greater the potential impact of an AI system on safety and fundamental rights, the stronger the obligations placed on its developers and users.


