EU AI Act
European Union regulation establishing a risk-based framework for AI systems, including prohibited practices, high-risk requirements, and general-purpose AI obligations.
The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, the world's first comprehensive horizontal AI regulation. The Parliament adopted it March 13, 2024, the Council May 21, 2024; published in the Official Journal July 12, 2024 and entered into force August 1, 2024. The Act establishes a four-tier risk-based framework: Unacceptable Risk (prohibited practices including social scoring by public authorities, untargeted facial-image scraping, manipulative AI exploiting vulnerabilities), High Risk (substantial obligations for AI in employment, education, credit, law enforcement, critical infrastructure, and Annex I regulated product safety), Limited Risk (transparency obligations including disclosure that users are interacting with AI), and Minimal Risk (no specific obligations). General-Purpose AI (GPAI) models receive distinct treatment with additional obligations for systemic-risk models. Phased applicability: prohibitions February 2025, GPAI provisions August 2025, most high-risk obligations August 2026, Annex I high-risk and large GPAI transitions August 2027. Maximum penalties €35 million or 7% of global annual turnover.
Core components
- Four-tier risk-based framework: Unacceptable Risk (Article 5 prohibitions), High Risk (Annex I product safety + Annex III use-case enumeration), Limited Risk (Article 50 transparency), Minimal Risk (no obligations)
- Prohibited practices: social scoring by public authorities
- untargeted facial-image scraping for biometric databases
- manipulative AI exploiting age/disability/socioeconomic vulnerabilities
- predictive policing based solely on profiling
- emotion recognition in workplace and education (with exceptions)
- biometric categorization inferring sensitive characteristics
- real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions)
- High-risk obligations: risk-management system, data and data-governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy/robustness/cybersecurity, conformity assessment, post-market monitoring, registration in EU database
- GPAI obligations: technical documentation, copyright-compliance policy, training-data summary
- additional obligations for systemic-risk GPAI (10^25 FLOPs threshold)
- Penalties: up to €35M or 7% of global annual turnover for prohibited-AI violations
- up to €15M or 3% for other violations
- up to €7.5M or 1% for incorrect information
- EU AI Office: central coordination body for GPAI and cross-border issues
Primary use case
Comprehensive horizontal AI regulation applicable to providers, deployers, importers, distributors, and product manufacturers placing AI systems on the EU market or whose outputs are used in the EU; extraterritorial application to non-EU providers where outputs are used within the Union; compliance reference framework for multinational technology companies, financial-services firms deploying AI for credit and employment decisions, and high-risk-sector deployers; intellectual reference and de-facto regulatory model for other jurisdictions (the 'Brussels effect' phenomenon documented by Anu Bradford); interaction framework with sectoral regulation (banking prudential supervision, medical devices, automotive safety) where AI is embedded in regulated products.
Common criticisms
- The Act's compliance burden has been substantially debated — industry stakeholders including digital-economy associations (DigitalEurope, Computer & Communications Industry Association) argued during legislative negotiation that high-risk obligations create disproportionate compliance costs particularly for SMEs, while civil-society groups (European Digital Rights, AlgorithmWatch, Access Now) argued the final Act's exceptions for law-enforcement biometric identification and national-security exclusions undermine fundamental-rights protections
- the text's substantial ambiguity in key definitions (what constitutes 'high-risk' use of an AI system, where 'general-purpose' AI ends and specific-purpose AI begins, what 'human oversight' requires in practice) creates implementation uncertainty that Commission delegated acts and CJEU case law will resolve incrementally
- the GPAI 10^25 FLOPs systemic-risk threshold is technically arbitrary and will require recalibration as model capabilities advance
- the Act's interaction with GDPR (particularly automated decision-making rules under Article 22) and sectoral regulation produces overlapping compliance obligations whose coherent integration remains to be developed
- conformity assessment infrastructure (notified bodies, harmonized standards under CEN-CENELEC JTC 21) is being developed in parallel with the Act's phased applicability, producing a substantial readiness gap
- the regulation's primary enforcement through national competent authorities raises concerns about consistent application across Member States, reproducing GDPR-era fragmentation issues
- non-EU providers face uncertain extraterritorial compliance posture
- the Brussels-effect framing has been argued to overstate EU regulatory influence in jurisdictions (US, China, India) with substantively different regulatory philosophies
- the substantive contestation about what constitutes AI 'risk' is unresolved — the use-case-based Annex III framework treats some applications as high-risk regardless of actual implementation, while permitting potentially harmful uses outside the enumerated categories.
Lineage
- Siblings
- NIST AI Risk Management Framework, OECD AI Principles, ISO/IEC 42001