What Is the EU AI Act?
The EU AI Act is the European Union's foundational AI law, and it works by regulating AI according to risk: the more harm a system could cause, the more strictly it's controlled.
It sorts every AI system into one of four tiers:
- Unacceptable risk — banned outright, no compliance path available.
- High-risk — permitted, but under heavy regulation.
- Limited-risk — must disclose that AI is involved, nothing more.
- Minimal-risk — no mandated controls.
Prohibited practices include social scoring by public authorities, manipulative techniques that exploit a person's vulnerabilities, and real-time biometric surveillance in public spaces for law enforcement, with only narrow exceptions.
High-risk systems, AI used in hiring, credit scoring, law enforcement, or critical infrastructure, carry the heaviest obligations before reaching market: conformity assessments, technical documentation, registration in an EU database, a documented risk management system, and human oversight.
Limited-risk systems, like a customer-facing chatbot, mainly need to disclose that a person is interacting with AI rather than a human.
Penalties scale with the violation. The most serious, deploying a prohibited practice, carries fines up to €35 million or 7% of global annual turnover, whichever is higher, a noticeably higher ceiling than GDPR's.
Obligations are also phasing in on different timelines rather than all at once. Prohibited practices and the rules for general-purpose AI models are already enforceable; the bulk of high-risk system requirements are still being phased in and adjusted.
It has become the reference point other jurisdictions measure their own AI regulation against, making it relevant to any organization operating in or selling into the EU regardless of headquarters location.
Why the EU AI Act Matters
- Obligations scale with how risky a given AI use case is classified, not a flat rule applied to every system equally.
- Different provisions take effect on different timelines, so compliance is an ongoing process, not a single deadline to hit once.
- Applies extraterritorially: any organization operating in or selling into the EU needs to account for it, regardless of where the company itself is headquartered.