EUAICheck is an educational simulator. We are not a law firm and have no affiliation with any official body.
EUAICheck is an independent educational simulator. This content is provided for informational purposes only and does not constitute legal advice.

What is the EU AI Act?

In one sentence: The EU AI Act is the world's first law on artificial intelligence. It classifies every AI system by risk level and imposes proportional obligations on companies that develop or use them in Europe.
Updated: September 2026 · Regulation (EU) 2024/1689 · Official sources: EUR-Lex and European Commission

Table of contents

  1. Definition and context
  2. Who is affected?
  3. The 4 risk levels
  4. Key obligations
  5. Application timeline
  6. Penalties
  7. General-purpose AI models (GPAI)

1. Definition and context

The EU AI Act, officially Regulation (EU) 2024/1689 of the European Parliament and of the Council, is the world's first comprehensive legal framework dedicated to artificial intelligence. Adopted on 13 June 2024 and published in the Official Journal of the European Union on 12 July 2024, it entered into force on 1 August 2024.

Its objective is twofold: to protect the fundamental rights of European citizens against the potential risks of AI, while enabling the development of trustworthy AI in the European Union. The regulation takes a risk-based approach: the higher the potential risk of an AI system, the stricter the obligations imposed on it.

The EU AI Act is not a data protection law. It complements the GDPR without replacing it. If you use AI and process personal data, both texts apply simultaneously.

2. Who is affected?

The regulation applies to any organisation that places AI systems on the European market or puts them into service in the European Union, regardless of its geographical location. A US, Canadian or Japanese company that deploys an AI system used in Europe is therefore affected.

Who is considered a provider?

A provider is any person or organisation that develops an AI system or has it developed, with the intention of placing it on the market under their own name. If you have developed an AI tool internally for your own use, you may also be considered a provider if that tool is high-risk.

Who is considered a deployer?

A deployer is any organisation that uses an AI system in a professional context. If you purchase and use AI-based recruitment software to analyse applications, you are a deployer. Deployers have their own obligations, distinct from those of providers.

3. The 4 risk levels

The regulation classifies AI systems into four categories according to their potential risk level:

Unacceptable risk - Prohibited

Systems prohibited since 2 February 2025. Examples: social scoring by public authorities, subliminal manipulation, real-time biometric recognition in public spaces (with exceptions).

High risk - Strict obligations

Systems in sensitive sectors (HR, healthcare, education, finance, justice). Obligations for documentation, human oversight, risk management, registration with the EU AI Office.

Limited risk - Transparency

Chatbots, content generators, deepfakes. Main obligation: inform users they are interacting with AI. In force since August 2026.

Minimal risk - No specific obligation

Spam filters, content recommendations, AI in video games. No specific regulatory obligation imposed by the EU AI Act.

4. Key obligations for high-risk systems

Systems classified as high-risk are subject to a set of detailed obligations before being placed on the market and throughout their entire operational life:

Technical documentation (Article 11 and Annex IV)

Providers must maintain complete technical documentation describing the system: purpose, training data, architecture, performance, limitations, bias testing. This documentation must be available on request from supervisory authorities.

Effective human oversight (Article 14)

High-risk systems must allow effective human oversight. This means that qualified persons must be able to understand the system's capabilities and limitations, monitor its operation, intervene or stop it, and not blindly rely on its decisions.

Risk management (Article 9)

A risk management system must be established, maintained and documented throughout the lifecycle of the AI system. This system must identify reasonably foreseeable risks, assess them and implement appropriate management measures.

Logging and traceability (Article 12)

High-risk systems must automatically record relevant events (logs) during their operation, to enable traceability of decisions and possible post-deployment investigations.

Transparency (Article 13)

Providers must design their systems so as to allow deployers to understand how they work. Clear instructions for use and information on performance, limitations and residual risks must be provided.

5. Application timeline

Août 2024
Entry into force - The regulation is officially in force.
Feb. 2025
Prohibitions applicable - Prohibited practices (Article 5) are enforceable. AI literacy obligations for employees.
Aug. 2025
GPAI - Obligations for general-purpose AI models (Article 51-56) applicable.
Aug. 2026
General application - Article 50 (transparency) applicable. Users must be informed they are interacting with AI.
Dec. 2027
High-risk Annex III - Full obligations for Annex III high-risk systems (post Digital Omnibus).
Aug. 2028
Embedded products - AI systems embedded in regulated products (medical devices, vehicles, toys).

The Digital Omnibus, adopted by the EU Council on 29 June 2026, has pushed back certain deadlines. Obligations for Annex III high-risk systems are now scheduled for December 2027, subject to the availability of harmonised standards.

6. Penalties

Violations of the EU AI Act can result in significant financial penalties, calculated as a percentage of annual global turnover:

For SMEs and startups, lower caps apply if the proportional amount is less than the absolute amount. The national supervisory authority is competent to investigate and sanction, except for GPAI systems which fall under the European Commission.

7. General-purpose AI models (GPAI)

General-purpose AI models (GPAI) - such as GPT, Claude, Gemini or Llama - have been subject to a specific regime since August 2025 (Articles 51-56). These models are trained on large amounts of data and can perform a wide range of distinct tasks.

If your company uses a GPAI model via an API to build a product or service, you are considered a deployer of the model. Obligations vary depending on whether the model is open-source or proprietary, and depending on the level of computing power used for training.

Do you use ChatGPT, Claude or Gemini in your product? You have had transparency obligations towards your users since August 2026 (Article 50). They must know they are interacting with AI.

Is your system affected?

Answer 17 questions and get an analysis of your situation. Free educational simulator.

Start the free simulator

Not legal advice. Educational simulator only.

Official sources