EU AI Act
Also known as: AI Act, Artificial Intelligence Act, Regulation (EU) 2024/1689
The EU law that sorts AI systems by how much harm they could cause and sets stricter rules the higher the risk.
Draft - this entry has not been reviewed yet.
Formal
An EU regulation, in force from 1 August 2024 and applying directly in every member state, that bans some uses of AI, sets duties for high-risk systems, requires openness about chat assistants and deepfakes, and places duties on makers of general-purpose AI models.
In plain English
Like food safety rules that barely touch a bakery selling bread but put a baby-food factory under close inspection - the rules grow with what could go wrong.
In practice
A Danish recruitment firm finds its CV-screening tool counts as high-risk, so before 2 December 2027 it must document the system, keep logs, test for unfairness and make sure a person can override it.
Why it matters
As the first broad AI law, it reaches organisations that build, sell or use AI in the EU, in stages - bans from February 2025, general-purpose model rules from August 2025, openness duties from August 2026, most high-risk rules from December 2027 (August 2028 for AI in products). Fines reach 7% of global turnover.
Technical deep dive
Regulation (EU) 2024/1689 was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It is built on the New Legislative Framework for product safety: obligations attach to roles defined in Art. 3 (provider, deployer, importer, distributor, authorised representative) and to the act of placing on the market or putting into service. Art. 2 reaches providers anywhere whose systems or outputs are used in the Union. A deployer that puts its name on a high-risk system, substantially modifies it or changes its intended purpose becomes its provider under Art. 25.
Art. 5 lists prohibited practices such as harmful manipulation, social scoring, untargeted scraping of facial images and emotion recognition in workplaces and education. High-risk status arises under Art. 6(1) when the AI is a safety component of a product covered by Annex I legislation requiring third-party conformity assessment, or under Art. 6(2) when it falls in an Annex III area (e.g. employment, education, credit, law enforcement). Art. 6(3) lets a provider document that an Annex III system poses no significant risk, but never where it profiles natural persons.
High-risk providers must meet Arts. 9-15 (risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy, robustness and cybersecurity), operate a quality management system (Art. 17), pass conformity assessment (Art. 43 - for most Annex III systems internal control under Annex VI), affix CE marking, register in the EU database (Art. 49), run post-market monitoring (Art. 72) and report serious incidents (Art. 73). Deployers carry Art. 26 duties, and public bodies and certain private deployers must perform a fundamental rights impact assessment (Art. 27). Art. 50 imposes transparency duties for chatbots, synthetic content and deepfakes, and Chapter V (Arts. 51-55) regulates general-purpose AI models, supervised by the Commission's AI Office. Fines under Art. 99 reach EUR 35 million or 7 % of worldwide turnover for prohibited practices and EUR 15 million or 3 % for most other breaches, with the lower figure applying to SMEs.
Application is staged under Art. 113, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force since 27 July 2026): prohibitions and AI literacy from 2 February 2025; GPAI rules, governance and penalties from 2 August 2025; Art. 50 transparency from 2 August 2026; Annex III high-risk obligations from 2 December 2027; Annex I product-embedded high-risk obligations from 2 August 2028. The omnibus changed dates rather than the substance of the high-risk requirements, softened Art. 4 AI literacy, and added a prohibition on systems generating non-consensual intimate imagery. In Denmark, Law no. 467 of 14 May 2025 designates Digitaliseringsstyrelsen as notifying and main market surveillance authority, with Datatilsynet and Domstolsstyrelsen covering specific areas.
What to learn first
Everything this builds on, foundations first.
Relationships
- A kind of
- EU regulation
- Requires
- RiskArtificial intelligence (AI)
- Don't confuse with
- GDPR
Sources & further reading
Standards & official texts
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…