What Is the EU AI Act?
The EU AI Act is the EU's regulation for artificial intelligence. It is risk-based: the greater the risk an AI system poses to people's safety and rights, the stricter the requirements. Systems are divided into four levels, from prohibited to minimal risk, and both those who develop and those who use AI take on obligations.
The EU AI Act is the EU’s regulation for artificial intelligence, the first comprehensive framework of its kind. The basic idea is simple: the rules should be proportionate to the risk. An AI system that can affect people’s safety or rights faces strict requirements, while a harmless system is barely touched at all. The regulation is risk-based, not technology-based, which makes it easier to understand than it might sound.
The four risk levels
The AI Act divides systems into four levels based on how much risk they pose. The higher up, the heavier the requirements.
- Unacceptable risk (prohibited). Systems considered to threaten fundamental rights are completely banned. One example is social scoring, where authorities rate citizens based on their behavior.
- High risk. Systems used in sensitive contexts that can affect people’s lives, for example AI in recruitment or credit scoring. Allowed, but only with extensive requirements.
- Limited risk. Systems where the main risk is that the user is misled about what they’re dealing with, such as chatbots. Transparency requirements apply here: it must be clear that you’re talking to an AI.
- Minimal risk. The vast majority of AI systems, such as spam filters or AI in a game. In principle no special requirements beyond existing legislation.
| Risk level | Example |
|---|---|
| Unacceptable (prohibited) | Social scoring of citizens |
| High | AI in recruitment and credit scoring |
| Limited | Chatbots and AI-generated content |
| Minimal | Spam filters and AI in games |
Most of what an ordinary company uses falls far down the scale. It’s only when the AI makes or prepares decisions about people, such as employment or loans, that the heavy part of the regulation kicks in. The key, then, isn’t how advanced the technology is, but what it’s used for. The same language model can be minimal risk in an internal text assistant and high risk if it’s set to screen job applications. It’s the use, not the model, that decides which level you land on.
The timeline in brief
The regulation doesn’t take effect on a single day but is phased in step by step. The bans on the highest-risk systems start applying first, while the full requirements for high-risk systems come later, with applicability rolling out during 2026 and 2027. The gradual phase-in gives organizations time to adapt, but anyone who waits until the last date risks being unprepared for requirements that take time to meet. Mapping which AI systems you already use, and where they land on the risk scale, is a reasonable first step regardless of where you are on the timeline.
Both providers and deployers take on obligations
A common misconception is that the AI Act only applies to those who build AI. It doesn’t. The regulation places responsibility on both providers, who develop and place systems on the market, and users (referred to in the regulation as deployers), who bring AI into their own operations.
For you as a buyer of an AI tool, that means you can’t push all the responsibility onto the provider. If you use a high-risk system, you have your own obligations around how it’s used, that there is human oversight, and that it’s applied as intended. Companies outside the EU are covered too if their systems are used within the Union, so the reach is broad.
A concrete scenario
Say a company wants to introduce AI support in recruitment that ranks applicants. That’s a high-risk system. Before it’s put into use, the company needs to make sure the provider meets the requirements for documentation and data quality, that a human makes the final decision, and that the process can be traced afterward. If the company instead just wants to add a chatbot to its website for common questions, in practice it’s enough to be clear that the visitor is talking to an AI. Same technology, completely different requirements, depending on the risk.
That’s the core of the AI Act: let the use determine the requirements. If you’re planning AI where regulatory compliance and data handling are central, our AI services factor that in from the start, so the solution is built right from the beginning instead of being patched afterward. If you have a concrete idea, you’re welcome to get in touch.
Frequently asked questions
Who is covered by the EU AI Act?
Both providers who develop AI systems and organizations that use them in their operations. Companies outside the EU are covered too if their AI system is used within the Union. That means you, as the buyer and user of an AI tool, also take on responsibility, not just whoever built it.
What counts as a prohibited AI system?
Systems considered to pose an unacceptable risk to people's rights. Examples include social scoring of citizens and certain forms of manipulative influence that exploit vulnerabilities. Such use is completely prohibited within the EU, no matter how well the system otherwise works or who is behind it.
When do the rules take effect?
The regulation is phased in gradually rather than taking effect all at once. The bans on the highest-risk systems apply earliest, and the requirements for high-risk systems are phased in later, with full applicability during 2026 and 2027. The timeline gives organizations time to adapt, but preparations need to start well in advance.
What is required for a high-risk system?
High-risk systems, such as AI in recruitment or credit scoring, must meet requirements including risk management, documentation, data quality, human oversight, and traceability. The requirements are meant to show the system is safe and fair before it goes into use, and they apply throughout the system's entire lifetime, not just at launch.
Does the AI Act also apply to simple chatbots and generated content?
Yes, but more lightly. Limited-risk systems, such as chatbots and AI that generates images or text, are mainly covered by transparency requirements: the user must be told they're interacting with AI or that the content is AI-generated. That's a considerably lighter burden than the one that applies to high-risk systems.