Skip to main content
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Skip to main Content
Back to Glossary

EU AI Act

What Is the EU AI Act?

The EU AI Act is the European Union's foundational AI law, and it works by regulating AI according to risk: the more harm a system could cause, the more strictly it's controlled.

It sorts every AI system into one of four tiers:

  • Unacceptable risk — banned outright, no compliance path available.
  • High-risk — permitted, but under heavy regulation.
  • Limited-risk — must disclose that AI is involved, nothing more.
  • Minimal-risk — no mandated controls.

Prohibited practices include social scoring by public authorities, manipulative techniques that exploit a person's vulnerabilities, and real-time biometric surveillance in public spaces for law enforcement, with only narrow exceptions.

High-risk systems, AI used in hiring, credit scoring, law enforcement, or critical infrastructure, carry the heaviest obligations before reaching market: conformity assessments, technical documentation, registration in an EU database, a documented risk management system, and human oversight.

Limited-risk systems, like a customer-facing chatbot, mainly need to disclose that a person is interacting with AI rather than a human.

Penalties scale with the violation. The most serious, deploying a prohibited practice, carries fines up to €35 million or 7% of global annual turnover, whichever is higher, a noticeably higher ceiling than GDPR's.

Obligations are also phasing in on different timelines rather than all at once. Prohibited practices and the rules for general-purpose AI models are already enforceable; the bulk of high-risk system requirements are still being phased in and adjusted.

It has become the reference point other jurisdictions measure their own AI regulation against, making it relevant to any organization operating in or selling into the EU regardless of headquarters location.

Why the EU AI Act Matters

  • Obligations scale with how risky a given AI use case is classified, not a flat rule applied to every system equally.
  • Different provisions take effect on different timelines, so compliance is an ongoing process, not a single deadline to hit once.
  • Applies extraterritorially: any organization operating in or selling into the EU needs to account for it, regardless of where the company itself is headquartered.

FAQ

Yes, if they operate in or sell into the EU market, the Act's obligations can apply regardless of where the company is based.

Partially. Some provisions are already enforceable, while others continue to phase in and shift under ongoing negotiations, so this is worth rechecking periodically rather than treating as settled.

ISO/IEC 42001 is a voluntary management-system standard that can help demonstrate the kind of governance the EU AI Act requires, though certification against it doesn't automatically guarantee legal compliance. See that page for more.


Share this page

Related Terms


ISO/IEC 42001

ISO/IEC 42001 is the first international standard for managing AI systems responsibly, covering governance, risk, and continuous improvement across an organization's AI use.

Related Resources

The EU AI Act

The European Union's foundational AI law, and the benchmark other regulations are measured against.

Log In
Learn More
Book a Demo

Resources

Blog
AI Security Glossary
What is AI Security?
PromptCast: The Voice of AI & Security
ClawSec
OneClaw
Prompt Fuzzer
AI Security Startup Map
© {{year}} Prompt Security. All Rights Reserved.
Privacy Policy
Terms of Service

Follow Us