The EU AI Act
What it is, how the risk tiers work, and what businesses need to do now
What is the EU AI Act?
The EU AI Act is a comprehensive legal framework governing AI available on the EU market. As a product safety legislation, its purpose is to protect the fundamental rights, health, and safety of EU citizens against AI through its risk-based approach. The AI Act, launched in 2024, is part of the EU Commission’s initiative to create “A Europe fit for the digital age” for the 2019–2024 term.
What is the EU AI Act’s risk-based approach?
Under the EU AI Act’s risk-based approach, obligations for AI systems are proportionate to the level of risk they present, taking into account factors such as the design and intended use. Based on risk level, the EU AI Act specifies corresponding requirements for documentation, auditing, transparency, and obligations, where there are three distinct levels of risk:

Figure 1. Overview of risk levels under the EU AI Act.
- Systems with unacceptable risk: AI systems prohibited from being sold on the EU market under Article 5 of the Act due to their unacceptably high risk to fundamental rights, health, and safety.
- High-risk systems: AI systems that are considered to pose a risk to health, safety, and fundamental rights but are nevertheless allowed on the market, provided that these systems meet certain requirements.
- Low-risk systems: Systems that are neither prohibited nor high-risk. These include spam filters or AI-enabled video games and comprise the majority of the systems currently being used on the market. These systems do not have any obligations under the rules in their current form but must comply with existing legislation and may be subject to voluntary codes of conduct.
In addition to these three distinct risk levels, some systems may have limited risk or transparency risk in addition to their risk level above, providing the system is not prohibited. Systems with transparency risk are those that interact with end-users. Users of these systems must be informed that they are interacting with an AI system, that an AI system will be used to infer their characteristics or emotions, or that the content they are interacting with has been generated using AI. Examples are chatbots and deepfakes.
AI Risk Categories
Category 1: Unacceptable-Risk AI (e.g., social scoring by governments)
- Chapter 2 of the EU AI Act defines the ‘Unacceptable Risk’ category for AI systems and the regulations applied to them. Systems considered a threat to individuals, such as those manipulating vulnerable groups, engaging in social scoring, or using biometric identification and categorization.
- Regulation: These systems are banned, including real-time and remote biometric identification like facial recognition, except under strict law enforcement conditions which first gain court approval. As of the Digital Omnibus, this ban has been extended to explicitly cover AI-generated non-consensual intimate imagery (“nudifier” apps) and CSAM.
Category 2: High-Risk AI (e.g., healthcare applications)
- Chapter 3 of the EU AI Act defines the ‘High Risk’ category for AI systems and the regulations applied to them.
- Systems impacting safety or fundamental rights, including AI in toys, medical devices, critical infrastructure, education, employment, essential services, law enforcement, migration, and legal interpretation.
- Regulation: These systems must be registered in an EU database, thoroughly risk-assessed and regularly reported on to ensure strict compliance and oversight. Assessment will have to be conducted prior to high-risk AI systems being put on the market and monitored throughout their lifecycle. People will also have the right to lodge complaints against AI systems to their designated national authorities.
- Obligations: Businesses must group any high-risk AI they employ into one of two subcategories: high-risk systems used in products covered by the EU’s product safety legislation and those which fall into other specific areas, such as those listed in the definition above.
- Compliance obligations for this category apply from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).
Category 3: Limited-Risk AI (e.g., AI systems with transparency obligations)
- Chapter 4 of the EU AI Act defines the ‘Limited Risk’ category for AI systems and the regulations applied to them.
- Definition: The limited-risk category includes AI systems with specific transparency duties (including certain generative AI system uses under Article 50). General-purpose AI (GPAI) models (e.g., foundation models) are regulated separately under the AI Act’s GPAI rules. These are not high-risk per se but must meet transparency requirements and publish a public summary of the training content using the Commission’s template, while implementing measures to comply with EU copyright rules. In July of 2025, the Commission published the General-Purpose AI Code of Practice to help providers demonstrate compliance.
- Regulation: Providers of limited-risk AI models and applications must disclose to users that their content is AI-generated, must prevent illegal content generation, and must also publish summaries of copyrighted data used for training. High-impact AI models must undergo thorough evaluations and report serious incidents to the European Commission. AI-generated or modified content (e.g., deepfakes) must be clearly labeled as such.
- The Commission’s Code of Practice on marking and labelling AI-generated content underpins these obligations, which took effect as scheduled on 2 August 2026. Providers with systems already on the market before that date have until 2 December 2026 to implement machine-readable marking; new systems must comply from 2 August 2026.
Category 4: Minimal-Risk AI (e.g., AI used in games or spam filters)
- Chapter 5 of the EU AI Act defines the ‘Minimal Risk’ or ‘General Purpose’ category for AI systems and the regulations applied to them.
- Definition: These applications are already widely deployed and make up most of the AI systems we interact with today. Examples include spam filters, AI-enabled video games, and inventory-management systems.
- Regulation: Most AI systems in this category face no obligation under the AI Act, but companies can voluntarily adopt additional codes of conduct. Primary responsibility will be shouldered by the “providers” of AI systems, though any business which utilizes them should remain vigilant of their compliance obligations.
- What this means for business owners and executives: As a business owner utilizing minimal-risk AI from a third-party vendor, it is necessary for you to responsibly source, employ, and risk-assess the adoption of each new AI system, though you will not be required to comply with the EU AI Act.
What is Article 50?
Article 50 states that providers must ensure that AI systems intended to directly interact with individuals are designed and developed so that those individuals are informed they are engaging with an AI system.
Article 50 transparency duties typically apply in the following situations:
- When you deploy a system that interacts with people (e.g., chatbots), users must be informed unless it is obvious that they are interacting with a system.
- When you use emotion recognition or biometric categorization, users must be informed, although there are limited exceptions.
- When you generate or manipulate synthetic content (e.g., deepfakes), this content must be marked or labeled in relevant contexts.
What are the penalties for non-compliance?
Non-compliance comes with steep penalties of up to €35 million or 7% of global turnover, whichever is higher, for the use of prohibited systems. However, the severity of fines will depend on the level of transgression, with lower penalties of up to €7.5 million or 1% of turnover for supplying incorrect, incomplete, or misleading information.
Figure 2. Tiers of fines under the EU AI Act.
Who has to comply with the EU AI Act?
The EU AI Act imposes obligations on a number of parties such as importers, distributors, deployers, and operators, although the Act primarily applies to the providers of AI systems and GPAI models. The EU AI Act governs the EU market, meaning that entities placing their systems or models on the market or putting them into service within the EU must comply regardless of whether they are physically based in the EU.
What is the EU AI Act timeline now?
EU AI legislation is made applicable via a phased approach. The timeline below reflects the regulation as adopted (Regulation (EU) 2024/1689), as subsequently amended by the Digital Omnibus (Regulation (EU) 2026/1744).
- The first phase of implementation happened on February 2, 2025. This means that AI systems that pose unacceptable risks are now banned and that organizations operating in the European market must ensure adequate AI literacy among employees involved in the use and deployment of AI systems.
- On August 2, 2025, the second implementation phase took place, meaning that general purpose AI (GPAI) models have to abide by a specific set of rules, including technical documentation and a public summary of training content (using the Commission template), alongside measures to comply with EU copyright rules.
- On August 2, 2026, the Act’s main transparency duties (including Article 50) took effect as originally scheduled, and the AI Office’s enforcement powers over GPAI providers became active. The high-risk obligations that were also originally due on this date did not take effect — see below.
- On December 2, 2027, the rules for stand-alone high-risk AI systems (Annex III) apply.
- On August 2, 2028, the rules for high-risk AI systems embedded into regulated products (Annex I) apply.
What businesses require to do right now
There are several obligations that either are already in effect or will be coming in the coming months. Below is the list of practical aspects.
1. Determine the type of your AI systems
First, you have to have an inventory: all the AI systems you create, deploy, or acquire, aligned by level of risk (unacceptable, high, limited, minimal) in accordance with the Act. Many organisations report not having this fundamental first step, and even for those that do have an inventory, they often find that they do not know it falls into a regulated category when they apply the criteria laid out in Annex III.
2. Eliminate the delay of transparency obligations — these obligations are met now
Article 50 applies to all entities that build and deploy chatbots, virtual assistants, emotion-recognition systems, deepfake generators, and all other entities that generate synthetic audio, video, or text, from August 2, 2026.
- If it’s not clear from context, indicate to users that they are engaging with an AI system.
- Identify AI-generated and manipulated information (deepfakes) and mark it as such.
- If the content is already available in the market prior to December 2, 2026, then the watermarking/labeling requirement has a bit more runway without the underlying disclosure duty waiting in the wings.
3. Avoid prohibited practices
There is a list of uses of AI that are completely restricted, such as manipulative or subliminal use of AI resulting in harm, exploitation of vulnerabilities (such as age, disability, socioeconomic status, etc.), social scoring, and real-time remote biometric identification for law enforcement in public spaces. As of December 2, 2026, this list is extended to include tools related to CSAM and non-consensual generators of intimate images. This is not a compliance project — it is a hard stop if you are anywhere near these use cases.
4. General purpose AI (GPAI) obligations are in effect
In general, obligations have been in place since August 2, 2025, covering technical documentation, transparency about training data and capabilities, copyright disclosures, and (in the case of systemic risk) enhanced risk assessments, incident reporting, and cybersecurity. This is a track that did not receive any changes from the Digital Omnibus.
5. Create, but don’t rush, risk documentation of your systems
For Annex III systems, the deadline was just pushed out until December 2027, but the work that goes into creating a robust risk management system — data governance, technical documentation, design of human oversight, conformity assessments, quality management systems, and so on — takes months to develop properly. Organisations that have embarked on this path are using the extension as an opportunity to get it right, rather than an opportunity to let it go.
6. Be aware of grandfathering procedures and follow them accordingly
Systems currently on the market prior to the deadlines can qualify for grandfathering “until a substantial modification,” but not after. Determining what constitutes a “substantial modification” in your particular system becomes a real question, since it will decide whether or not the clock resets.
7. Keep an eye on the value chain you are playing in
The obligations vary significantly between provider, deployer, importer, and distributor, and the Act takes effect where your AI system’s output is made available to the EU market, rather than where your company is based. Any non-EU companies serving the EU, or with EU users, customers, or downstream integration, are directly in scope.
Frequently Asked Questions (FAQs)
Q: What is the EU AI Act?
A: The EU AI Act is a comprehensive legal framework designed as product safety legislation to protect the fundamental rights, health, and safety of EU citizens through a risk-based approach. Launched in 2024, it forms part of the EU Commission’s initiative to prepare Europe for the digital age.
Q: What is the EU AI Act’s risk-based approach?
A: Under this approach, obligations for AI systems are proportionate to the level of risk they present. Risk levels are determined by design and intended use, dictating corresponding requirements for documentation, auditing, transparency, and compliance.
Q: What are the four AI Risk Categories?
- Unacceptable Risk: Prohibited systems that pose severe threats to fundamental rights, such as social scoring, harmful manipulation, biometric categorization, non-consensual intimate imagery, and CSAM.
- High Risk: Permitted systems that impact safety or fundamental rights (e.g., healthcare, critical infrastructure, toys) subject to strict risk assessments, EU database registration, and lifecycle monitoring.
- Limited Risk: Systems subject to specific transparency duties, such as informing users they are interacting with an AI or marking synthetic content.
- Minimal Risk: Widely deployed systems (e.g., spam filters, video games) that face no mandatory obligations under the Act, though voluntary codes of conduct apply.
Q: What is Article 50?
A: Article 50 mandates that AI systems designed to directly interact with individuals (e.g., chatbots) must inform users of AI interaction unless obvious. It also requires notifying individuals when using emotion recognition or biometric categorization, and labeling synthetic content (deepfakes).
Q: What are the penalties for non-compliance?
A: Fines depend on the severity of the violation:
- Prohibited AI Practices: Up to €35 million or 7% of global annual turnover.
- Failure to Mitigate Safety Risks: Up to €15 million or 3% of turnover.
- Other Violations / Misleading Info: Up to €7.5 million or 1% of turnover.
Q: Who has to comply with the EU AI Act?
A: The Act applies to providers, deployers, importers, and distributors. It governs any entity making AI systems available on the EU market, meaning non-EU companies with EU customers or integration are directly in scope regardless of physical location.
Q: What is the current timeline for enforcement?
- Feb 2, 2025: Banned unacceptable-risk AI; required AI literacy for relevant personnel.
- Aug 2, 2025: Rules for General-Purpose AI (GPAI) models took effect.
- Aug 2, 2026: Main transparency duties (Article 50) and AI Office GPAI enforcement took effect.
- Dec 2, 2027: Obligations apply to stand-alone high-risk AI systems (Annex III).
- Aug 2, 2028: Obligations apply to high-risk AI embedded in regulated products (Annex I).
Q: What do businesses need to do to comply right now?
A: Businesses should build an inventory of all AI systems categorized by risk, comply with active transparency obligations (Article 50), eliminate prohibited AI practices, ensure GPAI models meet copyright and documentation rules, prepare documentation for high-risk systems, determine grandfathering status for existing systems, and map out their role in the value chain.
