The European Union’s Artificial Intelligence Act, formally Regulation (EU) 2024/1689, is the world’s first comprehensive law governing artificial intelligence, and this is the version of the EU AI Act explained for someone who needs the whole picture without wading through the regulation itself. Published in the EU’s Official Journal on 12 July 2024, the Act sorts AI technologies into four risk tiers and imposes obligations that scale with potential harm, from outright bans on the most dangerous uses to light transparency rules for ordinary tools.1EU Artificial Intelligence Act. The Act Texts Its rules are phasing in between February 2025 and August 2027, with the broadest wave of enforcement starting on 2 August 2026.2AI Act Service Desk. Timeline for the Implementation of the EU AI Act Penalties reach €35 million or 7% of worldwide annual turnover, whichever is higher.
Who Has to Comply
The Act reaches everyone involved in putting AI systems on the European market or using them there: developers (called “providers” in the law), businesses deploying AI tools, importers, distributors, and product manufacturers who embed AI in their goods.3EU Artificial Intelligence Act. Article 2 Scope It also covers the people on the receiving end of AI-driven decisions, and gives them enforceable rights.
Being based outside Europe is not a shield. If a provider sits in the United States, China, or anywhere else, the Act still applies whenever the output of their AI system is used within the EU.3EU Artificial Intelligence Act. Article 2 Scope Non-EU providers offering high-risk systems or general-purpose AI models on the European market must appoint an authorized representative inside the Union as a contact point for regulators.
The Act’s definition of an “AI system” is deliberately broad: a machine-based system operating with varying levels of autonomy that, from the input it receives, generates outputs such as predictions, content, recommendations, or decisions capable of influencing physical or virtual environments, and that may adapt after deployment.4European Union. Regulation (EU) 2024/1689 – Artificial Intelligence Act That wording is wide enough to capture everything from large language models to automated hiring screeners.
The Four Risk Tiers
The whole regulatory structure rests on a risk pyramid. Rather than treating all AI the same, the Act asks how much damage a system could cause to health, safety, or fundamental rights, and applies rules accordingly.6European Commission. AI Act
Where a system lands depends on its intended purpose and how it is actually used, not on the underlying technology alone. The same model can be minimal risk in one deployment and high risk in another.
What the Act Bans
The prohibitions in Article 5 took effect on 2 February 2025, making them the first part of the law to bite.5AI Act Service Desk. Timeline for the Implementation of the EU AI Act The banned uses include:
- Social scoring that evaluates or classifies people over time based on behavior or personality, where the score leads to unfavorable treatment unrelated to the original context or out of proportion to the behavior.7EU Artificial Intelligence Act. Article 5 Prohibited AI Practices
- Biometric categorization by race, political opinions, religious beliefs, sexual orientation, or similar protected characteristics.
- Scraping facial images from the internet or CCTV without a specific target to build or expand recognition databases.
- Emotion recognition in the workplace and in education.
- Subliminal manipulation, and exploitation of vulnerabilities tied to age, disability, or economic situation, in ways likely to cause harm.
Real-time biometric identification in public spaces for law enforcement is banned by default. Narrow exceptions cover imminent terrorist threats, searches for victims of abduction or trafficking, and locating suspects of serious crimes punishable by at least four years’ imprisonment, and each use requires prior authorization from a court or independent administrative body.8AI Act Service Desk. Article 5 Prohibited AI Practices
High-Risk AI Systems
How a System Ends Up High-Risk
A system is high-risk under one of two routes. First, if the AI is used as a safety component of a product already covered by EU product safety rules (medical devices or machinery, for instance) and that product requires a third-party conformity assessment.9EU Artificial Intelligence Act. Article 6 Classification Rules for High-Risk AI Systems Second, if the system falls into one of the use cases listed in Annex III.
Annex III covers eight areas: biometrics; critical infrastructure such as utilities and traffic; education, including admissions and exam monitoring; employment decisions from recruitment to termination; access to essential services and benefits, including creditworthiness; law enforcement risk assessments and evidence analysis; migration and border control; and justice and democratic processes, including tools that assist courts or aim to influence elections.10EU Artificial Intelligence Act. Annex III High-Risk AI Systems Referred to in Article 6(2)
There is a safety valve. A provider can argue that its Annex III system does not actually pose significant risk because, for example, it performs only a narrow procedural task or improves on prior human work. But any system that profiles individuals is always classified as high risk, regardless of that filter.9EU Artificial Intelligence Act. Article 6 Classification Rules for High-Risk AI Systems
What Providers of High-Risk Systems Must Do
The compliance load here is the heaviest in the Act. Before placing a system on the market, a provider must run a risk management process, apply data governance practices to keep training data relevant and sufficiently free of bias, and prepare technical documentation that explains how the system works. Automated logging has to be built in so regulators can audit the system’s behavior over its lifetime.
Transparency toward users is required: clear instructions on what the system can and cannot do, how it should be supervised, and its known limitations. Human oversight must be designed into the system, so a person can intervene, override, or shut it down.
Each high-risk system must pass a conformity assessment before deployment. Once it passes, the provider issues an EU Declaration of Conformity and applies the CE marking; a digital CE marking accessible through the system’s interface is acceptable for digital products.11AI Act Service Desk. Article 48 CE Marking
General-Purpose AI Models
Foundation models get their own track. Because a general-purpose AI (GPAI) model can be adapted for countless downstream uses, regulating only the applications would leave gaps. The GPAI rules took effect on 2 August 2025.2AI Act Service Desk. Timeline for the Implementation of the EU AI Act
All GPAI providers must maintain technical documentation, respect EU copyright law, and publish a sufficiently detailed summary of the data used to train the model.12EU Artificial Intelligence Act. High-Level Summary of the AI Act Providers of models released under free and open-source licenses only have to meet the copyright and training data summary requirements, unless the model is classified as posing systemic risk.
GPAI models with systemic risk carry extra obligations that reflect their potential to cause large-scale harm. Providers must run model evaluations using standardized protocols, conduct adversarial testing to identify and reduce risks, track and report serious incidents to the EU AI Office without undue delay, and maintain adequate cybersecurity for the model and its physical infrastructure.13EU Artificial Intelligence Act. Article 55 Obligations for Providers of General-Purpose AI Models with Systemic Risk
Providers who had GPAI models on the market before 2 August 2025 get a longer runway and must comply by 2 August 2027.14Shaping Europe’s Digital Future. Guidelines for Providers of General-Purpose AI Models
Transparency, Labels, and Deepfakes
AI systems that interact directly with people must be designed so the person knows they are dealing with a machine, unless that would be obvious to any reasonable observer. The rule applies to chatbots, virtual assistants, and similar tools.15EU Artificial Intelligence Act. Article 50 Transparency Obligations for Providers and Deployers of Certain AI Systems AI systems authorized by law for criminal investigations are exempt, though even they must include safeguards for third parties’ rights.
Providers of systems that generate synthetic text, images, audio, or video must mark outputs in a machine-readable format so they can be detected as AI-generated. The technical solutions must be effective, interoperable, and robust, though the Act acknowledges feasibility will vary by content type and by evolving standards.15EU Artificial Intelligence Act. Article 50 Transparency Obligations for Providers and Deployers of Certain AI Systems A standardized EU label for AI-generated content and an accompanying Code of Practice are still being developed.16EU Artificial Intelligence Act. The EU AI Act’s Transparency Rules – A Practical Guide to Article 50
Deepfakes carry their own disclosure rule. Anyone using AI to create or manipulate image, audio, or video content that resembles real people or events must disclose that the content is artificially generated. Clearly artistic, satirical, or fictional works are exempt from the strictest version of the duty, but must still acknowledge AI use in a way that does not hamper enjoyment of the work. AI-generated text published to inform the public on matters of public interest must also be labeled, unless a human reviewed the content and holds editorial responsibility for it.
Rights for People on the Receiving End
The Act does not just regulate businesses. Anyone who believes it has been violated can lodge a complaint with the market surveillance authority of the EU country where they live or where the violation occurred. The authority must investigate and keep the complainant informed about progress and outcomes, including whether a judicial remedy may be available.17EU Artificial Intelligence Act. Article 85 Right to Lodge a Complaint with a Market Surveillance Authority
People subject to decisions made using high-risk AI systems in Annex III also have a right to an explanation. If the decision produces legal effects, or similarly significant impacts on health, safety, or fundamental rights, the person can demand clear and meaningful explanations of the AI system’s role and the main elements behind the decision.18EU Artificial Intelligence Act. Article 86 Right to Explanation of Individual Decision-Making This right does not apply where EU or national law provides an exception, and it defers to any equivalent right already established under other EU legislation.
The AI Literacy Requirement
Since 2 February 2025, all providers and deployers of AI systems have had to ensure their staff and anyone else involved in operating their systems has a sufficient level of AI literacy.19EU Artificial Intelligence Act. Article 4 AI Literacy What counts as “sufficient” depends on the person’s technical background, the complexity of the system, and who is affected by it. This is not a box-checking exercise with a standardized test; it is an ongoing obligation that scales with the stakes.
When Each Part Takes Effect
The Act phases in over roughly three years:2AI Act Service Desk. Timeline for the Implementation of the EU AI Act
- 2 February 2025. Prohibited practices become enforceable. AI literacy duties and general provisions take effect.
- 2 August 2025. Rules for general-purpose AI models apply. EU-level governance (AI Board, Scientific Panel, Advisory Forum) and national competent authorities must be in place, and member states must adopt national penalty laws.
- 2 August 2026. The broadest enforcement date. High-risk rules for Annex III systems, Article 50 transparency duties, and innovation support measures all take effect. Each member state must have at least one operational AI regulatory sandbox.
- 2 August 2027. Rules for high-risk AI systems embedded in regulated products (Annex I) take effect. GPAI models placed on the market before August 2025 must be fully compliant.
The timeline for high-risk systems may shift depending on the availability of harmonized standards and support tools, as indicated by the EU’s Digital Omnibus package.
Fines and Enforcement
Penalties are tiered by severity:
- Prohibited practice violations: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.20EU Artificial Intelligence Act. Article 99 Penalties
- High-risk system or transparency violations: up to €15 million or 3% of global annual turnover, whichever is higher.
- Supplying incorrect information to regulators: up to €7.5 million or 1% of global annual turnover, whichever is higher.
Small and medium-sized enterprises, including startups, get meaningful protection. When authorities fine an SME, they must consider the company’s financial situation and its efforts to comply, and the SME’s fine caps at the lower of the applicable percentage or euro amount rather than the higher. For most violations, that means an SME’s maximum fine is €7.5 million or 1% of turnover for lesser breaches, and €15 million or 1.5% for more serious ones.20EU Artificial Intelligence Act. Article 99 Penalties
Enforcement runs on two levels. The European AI Office oversees GPAI model providers and coordinates enforcement at the Union level, while national market surveillance authorities handle enforcement within each member state. A company can face scrutiny from both its home country’s regulator and the AI Office in Brussels.
Regulatory Sandboxes
Each member state must establish at least one AI regulatory sandbox by 2 August 2026, and countries can meet the requirement by joining a shared sandbox with other member states.21EU Artificial Intelligence Act. Article 57 AI Regulatory Sandboxes These are controlled environments where developers can build, train, test, and validate innovative AI systems under a specific plan agreed with regulators, including testing in real-world conditions with supervision. The program is aimed particularly at SMEs and startups, giving smaller companies a structured route to compliance without having to guess what regulators expect.