EU Artificial Intelligence Act
European AI Office + National Market Surveillance Authorities (27 member states)
August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)
Status
In Force
Risk Level
Critical
Jurisdiction
European Union
Enforcement
August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)
critical risk framework
Any organization placing AI systems on the EU market or putting AI systems into service in the EU - including non-EU companies serving EU users.
Overview
The world's first comprehensive AI regulatory framework. Takes a risk-based approach, categorizing AI systems into four risk tiers: unacceptable risk (banned), high risk (regulated), limited risk (transparency obligations), and minimal risk (voluntary codes). Applies to providers, deployers, importers, and distributors placing AI systems on the EU market.
Scope
All AI systems placed on the EU market or put into service in the EU - regardless of where the provider is based. Covers the full AI lifecycle: design, development, deployment, and post-market monitoring.
Applicability
Who Is Affected
- AI providers: any entity developing or placing an AI system on the EU market
- AI deployers: businesses and public bodies using AI systems
- Importers: EU-based entities importing AI from non-EU providers
- Distributors: entities making AI systems available in the EU
- Non-EU providers whose AI systems affect EU users
- GPAI model providers (separate obligations under Title VIII)
Who Is Exempt
- Military and national security AI (member state jurisdiction)
- AI used exclusively for research, testing, or development not deployed to market
- Open-source AI models (partial exemption for non-commercial)
- AI purely for personal non-professional use
Key Prohibitions
- Social scoring by public authorities based on behavior or personal characteristics
- Real-time biometric identification in public spaces by law enforcement (with narrow exceptions)
- Biometric categorization based on race, religion, political opinion, sexual orientation
- Emotion recognition in workplace and educational institutions
- Predictive policing based solely on profiling individuals
- AI that exploits vulnerabilities (age, disability, social circumstances) to manipulate behavior
- Untargeted scraping of facial images from the internet or CCTV
- AI systems that distort human behavior causing physical or psychological harm
Risk Tier Classification
Unacceptable Risk
prohibitedAI systems banned outright - pose unacceptable threat to fundamental rights.
Examples
- • Real-time biometric surveillance in public spaces
- • Social credit scoring
- • Subliminal manipulation
- • Predictive policing
- • Emotion recognition in schools/workplaces
Requirements
- ✓ Complete prohibition - cannot be developed, deployed, or used in EU
High Risk
highAI in critical infrastructure, biometrics, employment, education, essential services, law enforcement, migration, justice. Full regulatory compliance required.
Examples
- • CV screening tools
- • Credit scoring algorithms
- • Medical diagnostic AI
- • Biometric verification
- • AI for loan decisions
- • Educational assessment AI
- • Critical infrastructure control
Requirements
- ✓ Mandatory conformity assessment before deployment
- ✓ Registration in EU AI database
- ✓ CE marking
- ✓ Detailed technical documentation
- ✓ Human oversight mechanisms
- ✓ Bias and accuracy testing across demographic groups
- ✓ Post-market monitoring plan
- ✓ Logging and audit trails
Limited Risk
limitedSpecific transparency obligations apply - users must know they are interacting with AI.
Examples
- • Chatbots and virtual assistants
- • Deep fake and synthetic media generation
- • AI-generated text presented as human-written
- • Emotion recognition in commercial products
Requirements
- ✓ Disclose AI-generated nature of content
- ✓ Label synthetic audio/video/image/text
- ✓ Disclose when users interact with an AI system
Minimal Risk
minimalAll other AI - voluntary adherence to codes of practice.
Examples
- • AI-powered spam filters
- • AI in video games
- • AI inventory management
- • Recommendation engines (non-regulated sectors)
Requirements
- ✓ Voluntary codes of practice encouraged
- ✓ No mandatory obligations
Key Requirements
- Risk classification of all AI systems before market placement
- Mandatory conformity assessment (CE marking) for high-risk AI
- Human oversight and right-of-intervention for high-risk systems
- Transparency and disclosure obligations for GPAI models
- Right to explanation for AI-driven decisions affecting individuals
- Technical documentation (Article 11) and instruction manuals
- Registration in EU database for high-risk systems (Annex III)
- Post-market monitoring and serious incident reporting
- Bias testing and data governance for training datasets
- Cybersecurity and accuracy requirements for high-risk AI
Guardrails & Operational Controls
- Human oversight: deployers must ensure a trained person can monitor, override, and stop the AI system
- Accuracy: AI must perform at the accuracy level stated in technical documentation
- Robustness: AI must be resilient to errors, faults, and adversarial manipulation
- Cybersecurity: protection against unauthorized access and data poisoning
- Data governance: training data must be relevant, representative, and free from biases
- Transparency: AI must provide outputs that are interpretable by deployers
- Access logging: high-risk AI must maintain automatic event logs for at least 6 months
- Bias monitoring: ongoing monitoring for emergent discriminatory outcomes
Technical Requirements
- Technical documentation per Annex IV: architecture, training methodology, datasets used
- Instructions for use per Annex IX: operating conditions, intended purpose, performance metrics
- Automatic event logs: timestamps, decisions, data processed
- Data governance procedures: data quality criteria for training/validation/test sets
- Accuracy metrics across demographic groups and operating conditions
- FRIA (Fundamental Rights Impact Assessment) for public sector deployers
- Change management: re-conformity assessment for substantial modifications
Compliance Roadmap
- 1STEP 1 - AI Inventory: Catalogue all AI systems across your organization
- 2STEP 2 - Risk Classification: Classify each system against Annex III high-risk criteria
- 3STEP 3 - Prohibitions Check: Verify no systems fall in the unacceptable risk category
- 4STEP 4 - Appoint AI Compliance Officer or designate EU representative
- 5STEP 5 - Technical Documentation: Develop Annex IV documentation for high-risk systems
- 6STEP 6 - Conformity Assessment: Conduct self-assessment or notified body audit
- 7STEP 7 - EU Database Registration: Register high-risk systems before deployment
- 8STEP 8 - Human Oversight Implementation: Define and train oversight roles
- 9STEP 9 - Post-Market Monitoring: Establish reporting, logging, and incident response
- 10STEP 10 - GPAI Obligations: If developing foundation models, comply with Title VIII
Implementation Guidance
- 1Classify all AI systems by risk tier using the Act's Annex III criteria
- 2Appoint an EU AI Act compliance officer or designate an EU representative
- 3Conduct fundamental rights impact assessments for high-risk systems
- 4Implement technical documentation and QMS procedures per Annex IV/IX
- 5Register qualifying high-risk systems in the EU AI database before deployment
Industry Impact
Financial Services
Credit scoring, fraud detection, insurance AI all qualify as high-risk. DPIA + conformity assessment required for each.
Healthcare
AI medical devices overlap with MDR/IVDR regulation. Double regulatory burden. Clinical validation and bias testing essential.
Human Resources
CV screening, candidate ranking, employee monitoring AI are explicitly listed in Annex III. Significant compliance investment required.
Education
AI for student assessment, proctoring, and admissions are high-risk. Transparency to students required.
Law Enforcement
Near-prohibition on predictive policing. Biometric identification strictly regulated with judicial/emergency exceptions only.
Retail & eCommerce
Product recommendation, pricing engines: minimal risk. AI customer service chatbots require limited transparency disclosure.
Manufacturing
AI in safety-critical systems (robotics, quality control in critical infrastructure) requires conformity assessment.
Marketing & Advertising
Profiling for advertising: limited risk. Manipulative personalization that exploits vulnerabilities is prohibited.
Regulatory Timeline
Apr 2021
European Commission publishes AI Act proposal
Dec 2023
Political agreement reached between Council, Parliament, Commission
Aug 2024
AI Act enters into force (published in Official Journal)
Feb 2025
Prohibited AI provisions apply - banned systems must be removed
Aug 2025
GPAI model obligations apply (Title VIII) - foundation model compliance required
Aug 2026
High-risk AI obligations (Annex III) fully apply
Aug 2027
High-risk AI in existing regulated products (Annex I) must comply
Notable Enforcement Cases
- 1Feb 2025: First prohibitions active - companies using social scoring or biometric identification must cease immediately
- 2EU AI Office established to oversee GPAI model compliance and systemic risk assessment
- 3Major HR software vendors rushing to reclassify CV screening tools under high-risk provisions
Penalties for Non-Compliance
Up to €35M or 7% of global annual turnover for prohibited AI violations; up to €15M or 3% for high-risk AI violations; up to €7.5M or 1.5% for incorrect information
Framework Details
Short Name
EU AI Act
Jurisdiction
European Union
Enforcement Date
August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)
Enforcing Authority
European AI Office + National Market Surveillance Authorities (27 member states)
Status
Risk Level
Affected Organizations
Any organization placing AI systems on the EU market or putting AI systems into service in the EU - including non-EU companies serving EU users.
Exposure Areas
- HR & Recruiting: CV screening and interview scoring tools are Annex III high-risk
- Financial Services: credit scoring, fraud detection, insurance pricing AI
- Healthcare: diagnostic AI, clinical decision support, patient triage
- Education: automated grading, student profiling, learning assessment
- Law Enforcement: predictive tools, biometric identification
- GPAI models (>10^25 FLOPs): systemic risk obligations, red-teaming, reporting
- Facial recognition: strict limitations in public spaces, near-prohibition
Tags
This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.