What Is the EU AI Act? A Practical Guide to the World's First Comprehensive AI Law

Why the EU AI Act Matters to Every Organization Using AI

By EuroQuest Editorial Team · Published 2026-06-17

The EU AI Act is the world's first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and phases obligations across 2025 to 2027. The Act applies a risk-based architecture — unacceptable, high, limited, and minimal — and reaches non-EU providers whose AI systems are placed on the EU market or whose outputs are used in the EU. Top fines run to €35 million or 7 per cent of global annual turnover, higher than GDPR. This guide is built for legal counsel, compliance leads, AI governance officers, and senior L&D teams who need a clear answer to what the Act is, who it covers, what the risk tiers actually require, and what to do this year.

1 Aug 2024Date the EU AI Act entered into force, with phased obligations rolling out across 2025 to 2027. [EU Commission]
4 tiersRisk levels in the Act: unacceptable (prohibited), high, limited, and minimal, each with distinct obligations. [AI Act text]
€35M / 7%Maximum fine for prohibited-practice violations, whichever is higher of €35 million or 7 per cent of global annual turnover. [EU Commission]
2 Aug 2026Headline application date for most high-risk AI system requirements, with some product-integrated systems extending to 2027. [AI Act text]

What the EU AI Act Actually Is

A Risk-Based Horizontal Regulation

The EU AI Act is a regulation, not a directive — it applies directly across all 27 EU member states without national transposition. It is horizontal, meaning it covers AI use across every sector rather than targeting one industry. It is risk-based, meaning obligations scale with the potential harm a given AI system can cause to people's safety, livelihoods, and fundamental rights.

What It Regulates

The Act regulates the placing on the market, putting into service, and use of AI systems in the EU. It defines an AI system broadly, in line with the OECD definition, to cover machine-learning and many rule-based or hybrid systems that infer outputs from inputs. It also creates a dedicated regime for general-purpose AI (GPAI) models, including additional obligations for those with systemic risk.

How It Sits Alongside Other EU Law

The Act does not replace GDPR, product-safety regulation, or sectoral rules — it stacks on top. A high-risk AI system in healthcare still has to meet medical-device rules. An AI-driven recruiting tool still has to meet GDPR. The European Commission's AI Act page frames this as a single coherent regulatory environment for trustworthy AI.

Who the Act Covers (Including Outside the EU)

Providers, Deployers, Importers, Distributors

The Act assigns obligations across the AI value chain. Providers (developers placing systems on the market) carry the heaviest load. Deployers (organizations using AI systems professionally) carry obligations particularly when the system is high-risk. Importers and distributors carry conformity-check duties. Most large organizations end up in more than one role at once.

The Extraterritorial Reach

The Act reaches well beyond the EU. A US, UK, GCC, or Asian provider that places an AI system on the EU market is in scope. A non-EU provider or deployer whose AI system's output is used in the EU is in scope. This is structurally similar to GDPR's extraterritorial reach and is one of the main reasons the Act is shaping global AI governance practice.

What Is Outside the Scope

Military, defence, and national-security uses fall outside the Act's scope. Pure research and development activity before placing on the market is also carved out, with conditions. Open-source GPAI models get a lighter regime, unless they qualify as systemic risk. The OECD AI Policy Observatory's entry on the Act documents these scope boundaries in detail.

The Four Risk Tiers and What Each Requires

Risk tier What it covers Headline obligation
UnacceptableSocial scoring, manipulative subliminal techniques, untargeted facial-image scraping, certain biometric categorization and real-time public biometric identification.Prohibited outright (in force since February 2025).
High-riskAI in safety components of products, plus listed uses in employment, education, credit, law enforcement, migration, justice, and critical infrastructure.Risk management, data governance, technical documentation, human oversight, accuracy, robustness, cybersecurity, conformity assessment, registration.
Limited-riskChatbots, emotion-recognition systems, AI-generated content, and similar systems that interact with people.Transparency obligations, including disclosure that users are interacting with AI and that content is AI-generated.
Minimal-riskAI-enabled spam filters, video games, inventory tools, and most other everyday AI applications.No mandatory obligations under the Act; voluntary codes of conduct encouraged.
GPAI (parallel regime)General-purpose AI models, with a stricter sub-tier for systemic-risk models above a compute threshold.Documentation, copyright policy, training-data summary; systemic-risk models add evaluation, incident reporting, and security obligations.

Most organizations end up with a portfolio across multiple tiers. A retailer might run minimal-risk recommendation engines, limited-risk chatbots, and one high-risk employment-screening tool, while also being a deployer of a GPAI model under a major-vendor contract. The compliance plan has to map each system to its tier rather than treating "AI" as one thing.

The Compliance Timeline Through 2027

Already in Force

Prohibited practices have been enforceable since 2 February 2025. AI literacy obligations on providers and deployers also began on that date. General-purpose AI model obligations began on 2 August 2025, with a transition period for models placed on the market before then.

The 2026 Headline Date

2 August 2026 is when most high-risk AI system requirements become applicable, alongside the bulk of the governance and enforcement architecture. Conformity assessment, technical documentation, human oversight, and registration in the EU database all crystallize on that date.

The 2027 Extensions

High-risk AI systems that are safety components of products already regulated by EU product-safety law have until 2 August 2027 to comply. A separate AI Omnibus package agreed politically in 2026 may push some high-risk dates further, with stand-alone high-risk AI extending to December 2027 and product-integrated AI to August 2028, but the legal text has not yet been adopted at the time of writing. The artificialintelligenceact.eu implementation timeline tracks the official dates.

What Organizations Should Do This Year

Inventory and Classify Every AI System in Use

The first move is an AI inventory across the organization, including AI features embedded in third-party tools. Every system needs a tier classification — unacceptable, high, limited, minimal, or GPAI — and a clear owner. Most organizations discover they have far more in-scope systems than they expected.

Build AI Literacy Across Affected Roles

The Act's AI literacy requirement applies to every provider and deployer, scaled to context, role, and the risk of the systems involved. Harvard Business Review's AI library documents how the most resilient organizations are building structured AI training across legal, HR, product, and operations functions rather than concentrating it in a small specialist team.

Stand Up an AI Governance Function

For organizations with any high-risk systems, governance has to move from project-level to enterprise-level: documented policies, a risk-management process, model-evaluation discipline, incident reporting, and clear accountability for human oversight. ISO/IEC 42001, the AI management system standard, is the most common scaffold organizations are mapping their AI Act readiness to. MIT Sloan Management Review's AI library documents the governance patterns that are working in early adopters.

Align Procurement and Vendor Contracts

Most enterprise AI comes through vendor relationships. Procurement and vendor-management functions need updated contractual clauses covering AI Act roles (provider, deployer), data and documentation rights, conformity assessment evidence, and incident-notification obligations. This work is slow and benefits from starting early.

The EU AI Act is not a one-off compliance exercise; it is a new operating environment for any organization that buys or builds AI. The organizations that will absorb it well are the ones that treat 2026 as the start of their AI governance journey, not the deadline.

Frequently Asked Questions

When does the EU AI Act apply to my organization?

The Act entered into force on 1 August 2024 and phases obligations across 2025 to 2027. Prohibited practices and AI literacy have applied since February 2025, GPAI rules since August 2025, and most high-risk obligations from August 2026. Some product-integrated high-risk systems have until August 2027.

Does the EU AI Act apply to non-EU companies?

Yes, in many cases. A non-EU provider placing an AI system on the EU market is in scope, and so is a non-EU provider or deployer whose AI system output is used in the EU. The extraterritorial reach is structurally similar to GDPR.

What counts as a high-risk AI system?

Two categories. First, AI used as a safety component in products already regulated by EU product-safety law (medical devices, machinery, lifts, toys, etc.). Second, listed uses in employment and HR, education and exams, credit scoring, law enforcement, migration, justice, and critical infrastructure.

How do the AI Act and ISO/IEC 42001 relate?

The AI Act is a binding regulation; ISO/IEC 42001 is a voluntary management-system standard for responsible AI. Many organizations are using ISO/IEC 42001 as the governance scaffold that operationalizes AI Act obligations, especially around risk management, data governance, and human oversight.

What are the fines for non-compliance?

Up to €35 million or 7 per cent of global annual turnover, whichever is higher, for prohibited-practice violations. Up to €15 million or 3 per cent for other obligation breaches, and up to €7.5 million or 1 per cent for supplying incorrect information. The thresholds exceed GDPR.

Build AI Governance the Board, Regulators, and Customers Can Trust

EuroQuest International delivers executive and professional programs across AI governance, data and analytics, cyber, and legal compliance categories. Treat 2026 as the start of your AI governance journey, not the deadline, and align inventory, classification, literacy, and vendor management against a credible plan.

Browse EuroQuest Training Categories