The EU AI Act, officially Regulation (EU) 2024/1689 of the European Parliament and of the Council, is the world's first comprehensive legal framework dedicated to artificial intelligence. Adopted on 13 June 2024 and published in the Official Journal of the European Union on 12 July 2024, it entered into force on 1 August 2024.
Its objective is twofold: to protect the fundamental rights of European citizens against the potential risks of AI, while enabling the development of trustworthy AI in the European Union. The regulation takes a risk-based approach: the higher the potential risk of an AI system, the stricter the obligations imposed on it.
The EU AI Act is not a data protection law. It complements the GDPR without replacing it. If you use AI and process personal data, both texts apply simultaneously.
The regulation applies to any organisation that places AI systems on the European market or puts them into service in the European Union, regardless of its geographical location. A US, Canadian or Japanese company that deploys an AI system used in Europe is therefore affected.
A provider is any person or organisation that develops an AI system or has it developed, with the intention of placing it on the market under their own name. If you have developed an AI tool internally for your own use, you may also be considered a provider if that tool is high-risk.
A deployer is any organisation that uses an AI system in a professional context. If you purchase and use AI-based recruitment software to analyse applications, you are a deployer. Deployers have their own obligations, distinct from those of providers.
The regulation classifies AI systems into four categories according to their potential risk level:
Systems prohibited since 2 February 2025. Examples: social scoring by public authorities, subliminal manipulation, real-time biometric recognition in public spaces (with exceptions).
Systems in sensitive sectors (HR, healthcare, education, finance, justice). Obligations for documentation, human oversight, risk management, registration with the EU AI Office.
Chatbots, content generators, deepfakes. Main obligation: inform users they are interacting with AI. In force since August 2026.
Spam filters, content recommendations, AI in video games. No specific regulatory obligation imposed by the EU AI Act.
Systems classified as high-risk are subject to a set of detailed obligations before being placed on the market and throughout their entire operational life:
Providers must maintain complete technical documentation describing the system: purpose, training data, architecture, performance, limitations, bias testing. This documentation must be available on request from supervisory authorities.
High-risk systems must allow effective human oversight. This means that qualified persons must be able to understand the system's capabilities and limitations, monitor its operation, intervene or stop it, and not blindly rely on its decisions.
A risk management system must be established, maintained and documented throughout the lifecycle of the AI system. This system must identify reasonably foreseeable risks, assess them and implement appropriate management measures.
High-risk systems must automatically record relevant events (logs) during their operation, to enable traceability of decisions and possible post-deployment investigations.
Providers must design their systems so as to allow deployers to understand how they work. Clear instructions for use and information on performance, limitations and residual risks must be provided.
The Digital Omnibus, adopted by the EU Council on 29 June 2026, has pushed back certain deadlines. Obligations for Annex III high-risk systems are now scheduled for December 2027, subject to the availability of harmonised standards.
Violations of the EU AI Act can result in significant financial penalties, calculated as a percentage of annual global turnover:
For SMEs and startups, lower caps apply if the proportional amount is less than the absolute amount. The national supervisory authority is competent to investigate and sanction, except for GPAI systems which fall under the European Commission.
General-purpose AI models (GPAI) - such as GPT, Claude, Gemini or Llama - have been subject to a specific regime since August 2025 (Articles 51-56). These models are trained on large amounts of data and can perform a wide range of distinct tasks.
If your company uses a GPAI model via an API to build a product or service, you are considered a deployer of the model. Obligations vary depending on whether the model is open-source or proprietary, and depending on the level of computing power used for training.
Do you use ChatGPT, Claude or Gemini in your product? You have had transparency obligations towards your users since August 2026 (Article 50). They must know they are interacting with AI.
Answer 17 questions and get an analysis of your situation. Free educational simulator.
Start the free simulatorNot legal advice. Educational simulator only.