Skip to main content
Zubnet AILearnWiki › EU AI Act
Safety

EU AI Act

Also known as: AI Act, European AI Act
The European Union's comprehensive law regulating artificial intelligence, in force since August 2024. It takes a risk-based approach: the more harm an AI system could cause, the stricter the obligations, ranging from outright bans on a handful of practices to light transparency duties for low-risk tools.

Why it matters

If you build, sell, or deploy AI in the EU — or your model's output is used there — the Act likely applies to you, regardless of where your company is headquartered. Violations of the banned-practice rules can cost up to 7% of global annual turnover, and the law is becoming the de facto compliance baseline for the industry much as GDPR did for data protection.

Deep Dive

The Act entered into force in August 2024 but applies in phases rather than all at once. The prohibitions on unacceptable-risk practices, along with a general AI-literacy requirement, kicked in from February 2025. Obligations for general-purpose AI models followed in August 2025, and the bulk of the high-risk regime was due in August 2026 until the Digital Omnibus, in force since July 2026, pushed it back to 2 December 2027, with AI embedded in already-regulated products (medical devices, machinery, vehicles) getting until 2 August 2028. The result is a rolling compliance calendar that legal and engineering teams track alongside broader AI regulation efforts worldwide, and it has become the anchor document for most corporate AI governance programs.

The Four Risk Tiers

The Act sorts AI systems into four tiers. Unacceptable-risk uses are banned outright: government social scoring, manipulative techniques that exploit vulnerabilities, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, and most real-time remote biometric identification by law enforcement in public spaces. High-risk uses — hiring and promotion screening, credit scoring, education admissions, critical infrastructure, biometric identification, and AI used as a safety component of regulated products — are legal but carry heavy obligations: a risk-management system, data-governance controls to catch bias in training data, technical documentation, logging, human oversight, and registration in an EU database before deployment. Limited-risk systems owe mainly transparency: chatbots must disclose that they are AI, and synthetic content such as deepfakes must be labeled. Everything else — spam filters, game AI, most recommendation tweaks — is minimal risk and faces no new obligations at all.

Rules for General-Purpose AI

A dedicated chapter covers general-purpose AI (GPAI) models — the foundation models and frontier LLMs that downstream products are built on. Providers must maintain technical documentation, publish a sufficiently detailed summary of training content, and adopt a policy for respecting EU copyright law, so that companies fine-tuning or building on the model have the information they need to comply themselves, much like a standardized model card with legal force. Models trained with more than 10^25 cumulative FLOPs are presumed to carry systemic risk and face a second layer: model evaluations including adversarial testing and red-teaming, serious-incident reporting to the EU AI Office, and cybersecurity requirements. Models released under free and open-source licenses get partial exemptions from the documentation duties — but not once they cross the systemic-risk threshold, a carve-out that matters to the open-weights ecosystem.

It's Not an AI Permit Office

A common misconception is that the Act requires government approval before any AI system can ship in Europe. It doesn't. The overwhelming majority of AI applications land in the minimal-risk tier and carry no new obligations whatsoever. Even for high-risk systems, compliance is mostly self-assessed: the provider runs a conformity assessment, documents it, affixes a CE-style marking, and registers the system — there is no pre-market licensing queue at a regulator. Only the small list of prohibited practices is flatly banned, and only general-purpose models with systemic risk interact directly with the EU AI Office before and after release. The law also largely leaves pure research, personal non-commercial use, and much open-source development outside its scope.

Enforcement and the Road Ahead

Enforcement is split: the European Commission's AI Office supervises general-purpose and systemic-risk models, while national market-surveillance authorities in each member state police everything else. Penalties scale with the offense — up to 35 million euros or 7% of global turnover for prohibited practices, up to 3% for most other violations — calculated on worldwide revenue, which is why even non-European companies pay attention. The remaining milestones now run through 2027 and 2028 as the high-risk regime phases in, harmonized standards are finalized, and codes of practice for GPAI providers settle into day-to-day expectations. Because rewriting products per jurisdiction is expensive, many vendors are standardizing on the Act's requirements globally, giving it influence well beyond Europe's borders.

← All Terms
ESC