What it is
The EU AI Act is the European Union’s law on artificial intelligence. It sorts AI systems by the risk they pose and attaches duties to each class. It applies to anyone who offers or uses AI in the EU, including companies outside the EU.1
The four risk classes
| Class | Examples | Consequence |
|---|---|---|
| Unacceptable | Social scoring, manipulative techniques, certain biometric surveillance | Banned |
| High | AI in hiring, credit scoring, education, critical infrastructure | Risk management, documentation, human oversight, conformity assessment |
| Limited | Chatbots, AI-generated images, video and text | Transparency: people must know they deal with AI |
| Minimal | Spam filters, AI in games | No new duties |
General-purpose AI models such as large language models have their own set of duties for their providers.1
When what applies
- 1 Aug 2024The regulation enters into force.1
- 2 Feb 2025Bans on unacceptable practices; duty to ensure staff AI literacy.2
- 2 Aug 2025Duties for providers of general-purpose AI models; penalties and supervisory structure.2
- 2 Aug 2026Most remaining rules, including high-risk systems listed in Annex III and the transparency duties of Article 50.2
- 2 Aug 2027High-risk AI inside products already regulated, such as medical devices or machinery.2
In November 2025 the European Commission proposed, as part of a “digital omnibus” package, to postpone parts of the high-risk obligations. Check the current state before planning.3
What it means for a company
- Make a list of the AI tools in use and what they are used for.
- Check for banned uses and for high-risk uses such as screening job applicants.
- Train staff who work with AI; this duty has applied since February 2025.
- Label AI-generated content and tell people when they talk to a machine (Article 50).
- Ask suppliers for the documentation they must provide.
Fines
- Banned practices: up to €35 million or 7% of worldwide annual turnover.
- Most other breaches: up to €15 million or 3%.
- Wrong or misleading information to authorities: up to €7.5 million or 1%.1
Key terms
- Provider
- Whoever develops an AI system or model and places it on the market under its own name.
- Deployer
- Whoever uses an AI system in its own work, for example a company using a chatbot.
- High-risk system
- AI used in areas listed by the Act, with strict duties.
- Article 50
- The transparency duties: disclosure of AI interaction and labelling of AI-generated content.
Latest research
New papers and reports that mention this term, found by our daily source scan. One line per source, quoted as published.