The EU AI Act, explained.
The world's first comprehensive law on artificial intelligence takes a risk-based approach: the higher the risk an AI system poses to health, safety, or fundamental rights, the stricter the rules. Here's how the tiers work, what each demands, and when it all applies.
What the Act actually does.
The AI Act sorts every AI system into one of four risk tiers and attaches obligations to each. A handful of uses are banned outright; a defined set of "high-risk" uses carry substantial duties; a lighter tier only requires transparency; and everything else is largely unregulated.
It applies extraterritorially. Most obligations fall on providers the organisations that develop an AI system and place it on the EU market whether they're based in the EU or not, as long as the system's output is used in the Union. Deployers (the businesses using AI) carry fewer, lighter duties.
Four tiers of risk.
Obligations scale with risk from an outright ban at the top to no requirements at the base.
What's banned outright.
These practices are considered a clear threat to people's rights and are prohibited under Article 5.
- Manipulative techniques. Subliminal or deceptive methods that distort behaviour and impair informed decisions.
- Exploiting vulnerabilities. Targeting people's age, disability, or socio-economic situation to influence them.
- Social scoring. Classifying people by their behaviour in ways that lead to unfair or detrimental treatment.
- Predictive policing of individuals. Assessing the risk of someone offending based solely on profiling or personality traits.
- Untargeted face scraping. Building facial-recognition databases by scraping the internet or CCTV footage.
- Emotion recognition in workplaces and schools (outside genuine medical or safety uses).
- Sensitive biometric categorisation. Inferring race, political views, religion, or sexual orientation from biometrics.
- Live biometric ID in public for law enforcement save for narrow, authorised exceptions.
Permitted with real obligations.
A system is high-risk if it's a safety component of a regulated product (Annex I), or if it falls into one of the sensitive use cases listed in Annex III.
Biometrics
Remote identification, sensitive categorisation, and emotion recognition (where not banned).
Critical infrastructure
Safety components in traffic, water, gas, heating, and electricity supply.
Education
Admissions, evaluating learning outcomes, and monitoring exams.
Employment
Recruitment, candidate screening, promotion, termination, and performance monitoring.
Essential services
Benefits eligibility, credit scoring, insurance pricing, and emergency dispatch.
Law enforcement
Victimisation risk, polygraphs, evidence evaluation, and re-offending assessment.
Migration & borders
Risk assessments and reviewing asylum, visa, and residence applications.
Justice & democracy
Assisting legal interpretation and systems that could influence elections.
What providers must put in place.
Before a high-risk system goes to market, its provider has to build and evidence a full compliance stack (Articles 8–17).
- Risk management maintained across the system's whole lifecycle.
- Data governance training, validation, and test data that's relevant, representative, and as error-free as possible.
- Technical documentation that demonstrates compliance.
- Record-keeping automatic logging of events relevant to risk.
- Clear instructions so downstream deployers can comply.
- Human oversight designed in for deployers to exercise.
- Accuracy, robustness & cybersecurity appropriate to the system.
- A quality management system to keep all of the above in order.
Transparency, then freedom.
Limited risk
The obligation here is honesty. People must be told when they're interacting with an AI a chatbot must identify itself, and AI-generated or manipulated content such as deepfakes must be disclosed as such.
Minimal risk
The vast majority of AI in use today spam filters, recommendation engines, video-game AI sits here with no new obligations, though generative AI shifts some of these into the transparency tier.
Voluntary codes
Providers of lower-risk systems are encouraged to adopt voluntary codes of conduct, applying high-risk-style safeguards where it makes sense to build trust.
Special rules for foundation models.
General-purpose AI (GPAI) models trained at scale to perform a wide range of tasks get their own regime, layered on top of the risk tiers.
- Technical documentation covering training, testing, and evaluation.
- Downstream documentation so integrators understand capabilities and limits.
- A copyright policy that respects EU copyright law.
- A public training-data summary a "sufficiently detailed" account of what the model learned from.
Models released under a genuinely free and open licence get a lighter touch only the copyright and training-summary duties unless they're deemed to carry systemic risk.
A GPAI model is presumed to pose systemic risk once the compute used to train it exceeds 10²⁵ floating-point operations. Providers must notify the European Commission within two weeks of crossing that line — though they can argue the presumption doesn't apply, and the Commission can designate a model systemic on capability grounds regardless.
If a model carries systemic risk…
- Adversarial evaluation. Documented model testing to find and mitigate systemic risks.
- Risk mitigation. Assess and reduce possible systemic risks and their sources.
- Incident reporting. Track and report serious incidents to the AI Office without undue delay.
- Cybersecurity. Adequate protection for the model and its physical infrastructure.
Who enforces it.
The AI Office
Housed within the European Commission, it oversees GPAI providers, fields complaints from downstream developers, runs compliance evaluations, and investigates systemic risk.
Scientific Panel
A body of independent experts that issues qualified reports on systemic risks and high-impact capabilities, backing up the Commission's assessments.
Advisory Forum
Provides technical expertise and balanced stakeholder input to the Commission and the AI Board.
When the rules bite.
The Act's provisions phase in over three years from entry into force.
Prohibited practices banned
The unacceptable-risk practices become illegal across the EU.
Codes of practice ready
Voluntary codes of practice for GPAI providers are finalised.
GPAI obligations apply
Rules for general-purpose AI models take effect.
High-risk (Annex III) applies
Obligations for the Annex III high-risk use cases come into force.
High-risk (Annex I) applies
Obligations for high-risk safety components of regulated products come into force.
Preparing for the EU AI Act?
We help you classify your AI, close the gaps, and build audit-ready evidence turning the regulation into a competitive edge rather than a blocker.