LIVE
EU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series E

EU Artificial Intelligence Act

In Force
critical risk
European Union

European AI Office + National Market Surveillance Authorities (27 member states)

August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)

Official Text

Status

In Force

Risk Level

Critical

Jurisdiction

European Union

Enforcement

August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)

critical risk framework

Any organization placing AI systems on the EU market or putting AI systems into service in the EU - including non-EU companies serving EU users.

Overview

The world's first comprehensive AI regulatory framework. Takes a risk-based approach, categorizing AI systems into four risk tiers: unacceptable risk (banned), high risk (regulated), limited risk (transparency obligations), and minimal risk (voluntary codes). Applies to providers, deployers, importers, and distributors placing AI systems on the EU market.

Scope

All AI systems placed on the EU market or put into service in the EU - regardless of where the provider is based. Covers the full AI lifecycle: design, development, deployment, and post-market monitoring.

Applicability

Who Is Affected

  • AI providers: any entity developing or placing an AI system on the EU market
  • AI deployers: businesses and public bodies using AI systems
  • Importers: EU-based entities importing AI from non-EU providers
  • Distributors: entities making AI systems available in the EU
  • Non-EU providers whose AI systems affect EU users
  • GPAI model providers (separate obligations under Title VIII)

Who Is Exempt

  • Military and national security AI (member state jurisdiction)
  • AI used exclusively for research, testing, or development not deployed to market
  • Open-source AI models (partial exemption for non-commercial)
  • AI purely for personal non-professional use

Key Prohibitions

  • Social scoring by public authorities based on behavior or personal characteristics
  • Real-time biometric identification in public spaces by law enforcement (with narrow exceptions)
  • Biometric categorization based on race, religion, political opinion, sexual orientation
  • Emotion recognition in workplace and educational institutions
  • Predictive policing based solely on profiling individuals
  • AI that exploits vulnerabilities (age, disability, social circumstances) to manipulate behavior
  • Untargeted scraping of facial images from the internet or CCTV
  • AI systems that distort human behavior causing physical or psychological harm

Risk Tier Classification

Unacceptable Risk

prohibited

AI systems banned outright - pose unacceptable threat to fundamental rights.

Examples

  • Real-time biometric surveillance in public spaces
  • Social credit scoring
  • Subliminal manipulation
  • Predictive policing
  • Emotion recognition in schools/workplaces

Requirements

  • Complete prohibition - cannot be developed, deployed, or used in EU

High Risk

high

AI in critical infrastructure, biometrics, employment, education, essential services, law enforcement, migration, justice. Full regulatory compliance required.

Examples

  • CV screening tools
  • Credit scoring algorithms
  • Medical diagnostic AI
  • Biometric verification
  • AI for loan decisions
  • Educational assessment AI
  • Critical infrastructure control

Requirements

  • Mandatory conformity assessment before deployment
  • Registration in EU AI database
  • CE marking
  • Detailed technical documentation
  • Human oversight mechanisms
  • Bias and accuracy testing across demographic groups
  • Post-market monitoring plan
  • Logging and audit trails

Limited Risk

limited

Specific transparency obligations apply - users must know they are interacting with AI.

Examples

  • Chatbots and virtual assistants
  • Deep fake and synthetic media generation
  • AI-generated text presented as human-written
  • Emotion recognition in commercial products

Requirements

  • Disclose AI-generated nature of content
  • Label synthetic audio/video/image/text
  • Disclose when users interact with an AI system

Minimal Risk

minimal

All other AI - voluntary adherence to codes of practice.

Examples

  • AI-powered spam filters
  • AI in video games
  • AI inventory management
  • Recommendation engines (non-regulated sectors)

Requirements

  • Voluntary codes of practice encouraged
  • No mandatory obligations

Key Requirements

  • Risk classification of all AI systems before market placement
  • Mandatory conformity assessment (CE marking) for high-risk AI
  • Human oversight and right-of-intervention for high-risk systems
  • Transparency and disclosure obligations for GPAI models
  • Right to explanation for AI-driven decisions affecting individuals
  • Technical documentation (Article 11) and instruction manuals
  • Registration in EU database for high-risk systems (Annex III)
  • Post-market monitoring and serious incident reporting
  • Bias testing and data governance for training datasets
  • Cybersecurity and accuracy requirements for high-risk AI

Guardrails & Operational Controls

  • Human oversight: deployers must ensure a trained person can monitor, override, and stop the AI system
  • Accuracy: AI must perform at the accuracy level stated in technical documentation
  • Robustness: AI must be resilient to errors, faults, and adversarial manipulation
  • Cybersecurity: protection against unauthorized access and data poisoning
  • Data governance: training data must be relevant, representative, and free from biases
  • Transparency: AI must provide outputs that are interpretable by deployers
  • Access logging: high-risk AI must maintain automatic event logs for at least 6 months
  • Bias monitoring: ongoing monitoring for emergent discriminatory outcomes

Technical Requirements

  • Technical documentation per Annex IV: architecture, training methodology, datasets used
  • Instructions for use per Annex IX: operating conditions, intended purpose, performance metrics
  • Automatic event logs: timestamps, decisions, data processed
  • Data governance procedures: data quality criteria for training/validation/test sets
  • Accuracy metrics across demographic groups and operating conditions
  • FRIA (Fundamental Rights Impact Assessment) for public sector deployers
  • Change management: re-conformity assessment for substantial modifications

Compliance Roadmap

  1. 1STEP 1 - AI Inventory: Catalogue all AI systems across your organization
  2. 2STEP 2 - Risk Classification: Classify each system against Annex III high-risk criteria
  3. 3STEP 3 - Prohibitions Check: Verify no systems fall in the unacceptable risk category
  4. 4STEP 4 - Appoint AI Compliance Officer or designate EU representative
  5. 5STEP 5 - Technical Documentation: Develop Annex IV documentation for high-risk systems
  6. 6STEP 6 - Conformity Assessment: Conduct self-assessment or notified body audit
  7. 7STEP 7 - EU Database Registration: Register high-risk systems before deployment
  8. 8STEP 8 - Human Oversight Implementation: Define and train oversight roles
  9. 9STEP 9 - Post-Market Monitoring: Establish reporting, logging, and incident response
  10. 10STEP 10 - GPAI Obligations: If developing foundation models, comply with Title VIII

Implementation Guidance

  1. 1Classify all AI systems by risk tier using the Act's Annex III criteria
  2. 2Appoint an EU AI Act compliance officer or designate an EU representative
  3. 3Conduct fundamental rights impact assessments for high-risk systems
  4. 4Implement technical documentation and QMS procedures per Annex IV/IX
  5. 5Register qualifying high-risk systems in the EU AI database before deployment

Industry Impact

Financial Services

Credit scoring, fraud detection, insurance AI all qualify as high-risk. DPIA + conformity assessment required for each.

critical

Healthcare

AI medical devices overlap with MDR/IVDR regulation. Double regulatory burden. Clinical validation and bias testing essential.

critical

Human Resources

CV screening, candidate ranking, employee monitoring AI are explicitly listed in Annex III. Significant compliance investment required.

high

Education

AI for student assessment, proctoring, and admissions are high-risk. Transparency to students required.

high

Law Enforcement

Near-prohibition on predictive policing. Biometric identification strictly regulated with judicial/emergency exceptions only.

critical

Retail & eCommerce

Product recommendation, pricing engines: minimal risk. AI customer service chatbots require limited transparency disclosure.

low

Manufacturing

AI in safety-critical systems (robotics, quality control in critical infrastructure) requires conformity assessment.

medium

Marketing & Advertising

Profiling for advertising: limited risk. Manipulative personalization that exploits vulnerabilities is prohibited.

medium

Regulatory Timeline

PastCurrentUpcoming

Apr 2021

European Commission publishes AI Act proposal

Dec 2023

Political agreement reached between Council, Parliament, Commission

Aug 2024

AI Act enters into force (published in Official Journal)

Feb 2025

Prohibited AI provisions apply - banned systems must be removed

Aug 2025

GPAI model obligations apply (Title VIII) - foundation model compliance required

Aug 2026

High-risk AI obligations (Annex III) fully apply

Aug 2027

High-risk AI in existing regulated products (Annex I) must comply

Notable Enforcement Cases

  • 1Feb 2025: First prohibitions active - companies using social scoring or biometric identification must cease immediately
  • 2EU AI Office established to oversee GPAI model compliance and systemic risk assessment
  • 3Major HR software vendors rushing to reclassify CV screening tools under high-risk provisions

Penalties for Non-Compliance

Up to €35M or 7% of global annual turnover for prohibited AI violations; up to €15M or 3% for high-risk AI violations; up to €7.5M or 1.5% for incorrect information

Framework Details

Short Name

EU AI Act

Jurisdiction

European Union

Enforcement Date

August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)

Enforcing Authority

European AI Office + National Market Surveillance Authorities (27 member states)

Status

In Force

Risk Level

critical

Affected Organizations

Any organization placing AI systems on the EU market or putting AI systems into service in the EU - including non-EU companies serving EU users.

Exposure Areas

  • HR & Recruiting: CV screening and interview scoring tools are Annex III high-risk
  • Financial Services: credit scoring, fraud detection, insurance pricing AI
  • Healthcare: diagnostic AI, clinical decision support, patient triage
  • Education: automated grading, student profiling, learning assessment
  • Law Enforcement: predictive tools, biometric identification
  • GPAI models (>10^25 FLOPs): systemic risk obligations, red-teaming, reporting
  • Facial recognition: strict limitations in public spaces, near-prohibition

Tags

EnterpriseConsumerGovernmentRegulationEU

This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.