EU AI Act

framework · governance and compliance · regulatory-standard

European Union regulation establishing a risk-based framework for AI systems, including prohibited practices, high-risk requirements, and general-purpose AI obligations.

The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, the world's first comprehensive horizontal AI regulation. The Parliament adopted it March 13, 2024, the Council May 21, 2024; published in the Official Journal July 12, 2024 and entered into force August 1, 2024. The Act establishes a four-tier risk-based framework: Unacceptable Risk (prohibited practices including social scoring by public authorities, untargeted facial-image scraping, manipulative AI exploiting vulnerabilities), High Risk (substantial obligations for AI in employment, education, credit, law enforcement, critical infrastructure, and Annex I regulated product safety), Limited Risk (transparency obligations including disclosure that users are interacting with AI), and Minimal Risk (no specific obligations). General-Purpose AI (GPAI) models receive distinct treatment with additional obligations for systemic-risk models. Phased applicability: prohibitions February 2025, GPAI provisions August 2025, most high-risk obligations August 2026, Annex I high-risk and large GPAI transitions August 2027. Maximum penalties €35 million or 7% of global annual turnover.

Originators

European Commission (Regulatory proposal, April 21, 2021); European Parliament (Co-legislator, IMCO and LIBE committees lead); Council of the European Union (Co-legislator); trilogue negotiations concluded December 8, 2023; intellectual antecedents in EU's 2018 AI strategy, the High-Level Expert Group on AI Ethics Guidelines for Trustworthy AI (2019), and broader EU technology-regulation tradition (GDPR, Digital Services Act, Digital Markets Act); implementation through the EU AI Office (established 2024 within DG CNECT) and national competent authorities high

Year / Decade

April 2021 (Commission proposal); December 2023 (trilogue agreement); March-May 2024 (Parliament-Council adoption); August 2024 (entry into force); 2025-2027 (phased applicability) high

Primary sources

European Parliament and Council (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal of the European Union L 1689, 12 July 2024, European Commission (2021). Proposal for a Regulation Laying Down Harmonised Rules on Artificial Intelligence (COM/2021/206 final), High-Level Expert Group on AI (2019). Ethics Guidelines for Trustworthy AI (foundational policy antecedent), Bradford, A. (2020). The Brussels Effect: How the European Union Rules the World high

Core components

Primary use case

Comprehensive horizontal AI regulation applicable to providers, deployers, importers, distributors, and product manufacturers placing AI systems on the EU market or whose outputs are used in the EU; extraterritorial application to non-EU providers where outputs are used within the Union; compliance reference framework for multinational technology companies, financial-services firms deploying AI for credit and employment decisions, and high-risk-sector deployers; intellectual reference and de-facto regulatory model for other jurisdictions (the 'Brussels effect' phenomenon documented by Anu Bradford); interaction framework with sectoral regulation (banking prudential supervision, medical devices, automotive safety) where AI is embedded in regulated products.

Common criticisms

Lineage

Siblings
NIST AI Risk Management Framework, OECD AI Principles, ISO/IEC 42001