The EU AI Act Explained

The world's first comprehensive AI law classifies systems by risk. If you operate in the EU, enforcement has already begun.

Risk Tier Classification

The EU AI Act assigns applications to three broad risk categories, determining the regulatory burden.

Fines are severe

Non-compliance with prohibited AI practices can result in fines up to €35 million or 7% of global annual turnover, whichever is higher.

Risk Tier Examples Obligations
Unacceptable Risk Social scoring, subliminal manipulation, real-time biometric identification (exceptions apply). Banned entirely within the EU.
High Risk CV scanning tools, credit scoring, medical device AI. Strict conformity assessments, logging, human oversight, and registration in an EU database.
Minimal/Limited Risk Spam filters, basic chatbots (must declare they are AI). Transparency obligations (e.g., users must know they are interacting with an AI).

Timeline to Enforcement

  • May 2024: Official adoption.
  • November 2024: Prohibitions on unacceptable risk systems take effect (6 months post-entry).
  • May 2025: General purpose AI (GPAI) rules apply.
  • May 2026: High-risk system obligations fully enforceable.

Common Mistakes in Implementation

Firms frequently underestimate the scope of "AI". Even traditional statistical models embedded in HR software may qualify as high-risk systems under Annex III.