1 Overview and Objectives

The EU AI Act (Regulation (EU) 2024/1689) is a comprehensive legal framework adopted by the European Union in 2024 to govern the development, deployment, and use of artificial intelligence systems. Its primary objective is to ensure that AI systems placed on the Union market and used in the EU are safe, respect fundamental rights and EU values, while fostering innovation and economic growth. The Act establishes a single set of rules across all member states, replacing fragmented national regulations.

1.1 Background and Legislative History

The proposal for an AI Act was first introduced by the European Commission in April 2021, following years of policy discussions and a 2019 White Paper on AI. The legislative process involved extensive negotiations between the European Parliament and the Council of the EU, culminating in a political agreement in December 2023 and final adoption in May 2024. The Act entered into force on 1 August 2024. Its development was partly driven by the rapid advancement of AI technologies, including generative AI models, and the need for a harmonised legal framework alongside existing digital regulations.

1.2 Purpose and Scope

The Act aims to establish a predictable, proportionate, and risk‑based regulatory environment for AI. It applies to providers placing AI systems on the market or putting them into service in the EU, irrespective of whether they are established inside or outside the Union, as well as to deployers of AI systems located in the EU. Certain activities, such as AI systems used exclusively for national security or military purposes, and research and development, are partially or fully exempt from the scope.

1.3 Relationship with Existing EU Law (GDPR, Product Liability)

The AI Act operates alongside existing EU legislation, notably the General Data Protection Regulation (GDPR), the Product Liability Directive, and sector‑specific laws (e.g., medical devices, automotive). Where AI systems process personal data, GDPR obligations continue to apply. The AI Act supplements these frameworks by adding AI‑specific requirements, such as transparency and risk management, and by clarifying liability issues for AI‑related harm through a revised Product Liability Directive adopted in parallel. The Act does not duplicate but rather complements existing rules.

2 Risk‑Based Classification System

The EU AI Act adopts a tiered approach, classifying AI systems into four risk categories: unacceptable, high, limited, and minimal risk. This classification determines the regulatory obligations that apply.

2.1 Unacceptable Risk (Prohibited Practices)

Systems that pose an unacceptable threat to persons' safety, livelihoods, or rights are prohibited. The Act explicitly bans certain AI practices, with limited exceptions for law enforcement under strict conditions.

2.1.1 Social Scoring and Manipulation

AI systems that evaluate or classify individuals based on their social behaviour or personal characteristics leading to detrimental treatment (e.g., social scoring by public authorities) are prohibited. Also banned are AI systems that deploy subliminal, manipulative, or deceptive techniques to materially distort a person's behaviour in a harmful manner.

2.1.2 Real‑Time Biometric in Public Spaces

The use of real‑time remote biometric identification (RBI) systems in publicly accessible spaces for law enforcement purposes is generally prohibited. Limited exceptions apply for specific, serious crimes (e.g., kidnapping, terrorism) and require prior judicial authorisation, strict time and location limits, and notification obligations.

2.2 High‑Risk AI Systems

High‑risk AI systems are those that can significantly harm health, safety, or fundamental rights. They are subject to mandatory requirements before being placed on the market or put into service.

2.2.1 Criteria for Classification

An AI system is classified as high‑risk if it is intended to be used as a safety component of a product covered by EU harmonisation legislation (e.g., medical devices, machinery), or if it falls into one of the specific use‑cases listed in Annex III of the Act and is not considered low‑risk. The classification can be overridden if the system is clearly not harmful.

2.2.2 Categories (e.g., biometrics, critical infrastructure, employment)

Annex III specifies categories including: biometric identification and categorisation of natural persons; management and operation of critical infrastructure (e.g., water, electricity); educational and vocational training (e.g., determining access to institutions); employment, worker management, and access to self‑employment; essential private and public services (e.g., credit scoring); law enforcement (except prohibited uses); migration, asylum, and border control; and administration of justice and democratic processes. Each category requires careful assessment of risk.

2.2.3 Conformity Assessment and CE Marking

Providers of high‑risk AI systems must undergo a conformity assessment procedure to demonstrate compliance with the Act's requirements. For most high‑risk systems, this is a self‑assessment (internal control). For certain systems (e.g., biometrics, those used in law enforcement), a third‑party assessment by a notified body is required. Upon successful assessment, the provider affixes the CE marking, indicating conformity, allowing the system to be placed on the EU market.

2.3 Limited Risk (Transparency Obligations)

AI systems that pose limited risk are subject solely to transparency obligations. Users must be made aware that they are interacting with AI, and any AI‑generated synthetic content must be labelled as such.

2.3.1 Chatbots and Deep Fakes

Systems such as chatbots, voice assistants, or other conversational AI must clearly inform users that they are interacting with an AI, unless it is obvious from the context. Creators of deep fakes (AI‑generated or manipulated images, audio, or video) must disclose the artificial nature of the content. Deployers of AI systems that generate or manipulate text published for public information (e.g., news) must also disclose that it is AI‑generated.

2.4 Minimal Risk (No Additional Obligations)

All other AI systems that do not fall into the above categories are considered minimal risk. They are not subject to any additional obligations under the AI Act beyond existing general product safety and data protection rules. The vast majority of AI applications (e.g., spam filters, AI‑powered video games) fall into this category. The Act encourages voluntary codes of conduct for such systems.

3 Obligations for Providers and Deployers

The Act imposes distinct obligations on providers (those who develop or place AI systems on the market) and deployers (those who use AI systems), particularly for high‑risk AI systems.

3.1 Providers of High‑Risk AI Systems

Providers bear primary responsibility for ensuring that their high‑risk systems meet all mandatory requirements.

3.1.1 Risk Management System

Providers must establish, implement, document, and maintain a continuous, iterative risk management system throughout the lifecycle of the high‑risk AI system. This process includes identifying known and foreseeable risks, analysing likely impacts, and taking appropriate risk‑mitigation measures.

3.1.2 Data Governance and Training

Training, validation, and testing datasets used for high‑risk AI systems must be subject to appropriate data governance practices. Datasets must be relevant, representative, free from errors, and address potential biases. For biometric identification systems, fairness metrics and bias‑monitoring are required. Data collection must respect EU data protection and privacy rules.

3.1.3 Technical Documentation and Record‑Keeping

Providers are required to draw up technical documentation demonstrating compliance with the Act. This includes a description of the system's design, development methodology, training data, performance metrics, and intended purpose. They must also design the system to enable automatic recording of events (logs) during operation for traceability, with logs retained for a period appropriate to the system's lifecycle.

3.1.4 Human Oversight and Accuracy

High‑risk AI systems must be designed and developed to enable effective human oversight, allowing human operators to monitor, interpret, and override the system's output. Additionally, the systems must achieve an appropriate level of accuracy, robustness, and cybersecurity based on their intended purpose and the state of the art.

3.2 Deployers of High‑Risk AI Systems

Deployers (users) of high‑risk AI systems have specific obligations, especially when they are public authorities or entities providing essential services.

3.2.1 Impact Assessment for Fundamental Rights

Before deploying a high‑risk AI system, deployers who are public authorities, or private entities providing public services such as credit scoring or insurance, must conduct a fundamental rights impact assessment (FRIA). The FRIA evaluates the system's potential adverse impacts on fundamental rights (e.g., non‑discrimination, privacy, data protection) and identifies measures to mitigate them.

3.2.2 Human Oversight Responsibilities

Deployers must ensure that human oversight is exercised by competent persons who are trained and authorised to oversee the AI system. They must assign clear roles and responsibilities, and take measures to avoid over‑reliance on the AI's output. Deployers are also responsible for reporting serious incidents or malfunctions to the relevant national authority.

3.3 General‑Purpose AI Models

General‑purpose AI models (GPAI), such as large language models or generative AI, are subject to specific obligations that differ from those for high‑risk systems.

Providers of GPAI models must draw up and make publicly available a detailed summary of the content used for training the model, in accordance with EU copyright law. They must also implement a policy to respect copyright and related rights, for instance by adhering to opt‑out mechanisms for rights holders.

3.3.2 Systemic Risk Management

GPAI models that are classified as posing systemic risk (based on computational power or capabilities) are subject to additional requirements, including conducting model evaluations, mitigating systemic risks (e.g., potential for causing harm at scale), and reporting serious incidents to the European AI Office. The Act mandates that the Commission, in consultation with an independent scientific panel, set benchmarks for classifying systemic risk.

4 Governance and Enforcement

The AI Act establishes a multi‑level governance system to ensure consistent implementation across the EU.

4.1 European Artificial Intelligence Board (EAIB)

The EAIB is an independent body composed of representatives from each member state, the European Data Protection Supervisor, and the European Commission. It advises the Commission and member states on AI‑related matters, facilitates cooperation, issues guidelines, and contributes to the development of harmonised standards. The Board meets regularly and aims to ensure a coordinated approach.

4.2 National Competent Authorities and Market Surveillance

Each member state must designate one or more national competent authorities to supervise the application of the AI Act. These authorities have powers to carry out market surveillance, investigate complaints, order corrective actions, and impose penalties. They also serve as the contact point for providers and deployers. Market surveillance activities are coordinated through the EU's general product safety framework.

4.3 Penalties and Fines

Non‑compliance with the AI Act can result in substantial administrative fines.

4.3.1 Calculation and Maximum Amounts

Fines are calculated as a percentage of the infringer's total worldwide annual turnover from the preceding financial year, or a fixed amount (whichever is higher). For prohibited practices, the maximum fine is 7% of annual turnover or €35 million. For non‑compliance with high‑risk requirements, the maximum is 3% of turnover or €15 million. For supplying incorrect information to authorities, the maximum is 1.5% of turnover or €7.5 million. For small and medium‑sized enterprises, lower caps apply.

4.3.2 Criteria for Allocation

When determining the amount of a fine, authorities consider the nature, gravity, and duration of the infringement, the degree of culpability, the infringer's cooperation with authorities, and any previous infringements. The same enforcement principles as under GDPR (proportionality, deterrence) apply.

4.4 Codes of Conduct and Voluntary Measures

The Act encourages, but does not mandate, the development of voluntary codes of conduct for AI systems that are not high‑risk. These codes can address best practices for transparency, environmental sustainability, accessibility, and stakeholder involvement. Providers and deployers of minimal‑risk systems are invited to adhere to such codes, which help foster trust and innovation.

5 Implementation Timeline and Transitional Provisions

The AI Act enters into force in phases, giving stakeholders time to adapt.

5.1 Phased Entry into Force

The Act came into force on 1 August 2024. Prohibitions on unacceptable‑risk AI systems apply from 2 February 2025 (six months after entry into force). Rules on general‑purpose AI models apply from 2 August 2025 (12 months). Obligations for most high‑risk AI systems apply from 2 August 2026 (24 months). High‑risk systems that are already on the market and are not subject to significant design changes have until 2 August 2027 to comply.

5.2 Exemptions for Research and Open‑Source

The Act exempts AI systems developed solely for research and development purposes from its obligations, provided they are not placed on the market or put into service. Open‑source AI components (such as models released under an open licence) are generally not considered high‑risk, unless they are integrated into a high‑risk system by a provider. The Act also includes a regulatory sandbox mechanism to foster innovation in a controlled environment.

5.3 Review and Future Amendments

The Commission is required to periodically review the Act to keep pace with technological developments.

5.3.1 Planned Updates for Emerging Technologies

The Act mandates a review every two years (starting 2028) of the list of high‑risk use‑cases in Annex III, and regular assessment of the need to update rules for general‑purpose AI. The Commission is also tasked with monitoring the impact on fundamental rights, cybersecurity, and the environment.

5.3.2 International Cooperation and Standards

The AI Act encourages the development of international standards for AI through bodies like ISO and IEC, and promotes EU participation in global AI governance dialogues. The Commission may adopt implementing acts to recognise standards developed by international organisations, facilitating mutual recognition and interoperability with non‑EU frameworks.