Skip to content

AI Outlooks

News and viewpoints on the latest in AI security

Primary Menu
  • Home
  • What’s new in AI
    • AI Security News
    • Agentic AI News
    • AI Regulation News
    • AI Research News
    • AI Model News
  • Solutions
  • Cybersecurity
    • AI security
    • OWASP
    • Ransomware
    • Shadow AI
  • Learn
    • AI security
    • LLM security
    • AI governance
    • AI compliance
    • Agentic AI
    • AI infrastructure
    • AI data security
  • Home
  • Law
  • What is the EU AI Act?
  • Law

What is the EU AI Act?

A complete guide to Europe's AI regulation
Staff May 19, 2026
EU flag

The EU AI Act (Regulation (EU) 2024/1689) is a European Union regulation that governs how artificial intelligence is developed, sold, and used within the EU.

It is the first law of its kind from any major regulator, establishing a legal framework that covers the full AI lifecycle from development through deployment and use. The Act sorts AI systems into risk categories and attaches different rules to each.

Some AI uses are banned outright. Others get strict governance, transparency, and risk management obligations. Penalties reach up to 7% of global annual turnover or EUR 35 million, whichever is higher.

If your organization builds, sells, or uses AI, and that AI touches the EU in any way, this law applies to you. Not just EU companies. Not just big tech. It reaches far beyond Europe’s borders.

Why the EU AI Act matters

The EU AI Act does for artificial intelligence what the General Data Protection Regulation did for data privacy in 2018, creating a new standard for AI governance that regulators worldwide are watching.

GDPR reshaped how companies worldwide handle personal data. When it took effect, jurisdictions from Brazil to California to Japan drafted or updated their own privacy laws in response. The EU AI Act is already producing similar ripple effects. Canada is advancing its own Artificial Intelligence and Data Act. Multiple US states have introduced AI bills that borrow from the EU’s structure. South Korea and Brazil are developing their own AI governance frameworks. The blueprint is spreading.

The answer, for most organizations with any European presence, is yes. And the list of things you need to do depends entirely on what kind of AI you’re dealing with.

How the EU AI Act works: the risk-based approach

The Act uses four risk tiers, as defined by the European Commission’s regulatory framework.

First, applications and systems that create an unacceptable risk, such as government-run social scoring of the type used in China, are banned.

Second, high-risk applications, such as a CV-scanning tool that ranks job applicants, are subject to specific legal requirements.

Third, AI systems that interact with people or generate content carry transparency obligations.

Fourth, everything else, like spam filters and AI-powered video games, is left largely unregulated.

Most AI systems in use today fall into that minimal risk category. What separates minimal from unacceptable is not always intuitive, and the European Commission updates the list of high-risk and prohibited practices over time. More on that shortly.

Who does the EU AI Act apply to?

The Act targets multiple operators in the AI value chain. These definitions matter because obligations differ depending on your role.

Providers develop an AI system or general-purpose AI model and place it on the market under their own name or trademark. If you build a chatbot and sell it to businesses, you are a provider.

Deployers use AI systems in their own operations. A bank that buys a third-party AI tool to screen mortgage applications is a deployer. Deployers carry different obligations than providers, including the duty to follow instructions for use and, in some cases, conduct fundamental rights impact assessments.

Importers are entities located in the EU that bring AI systems from companies outside the EU onto the European market. If a US company sells its AI tool through a European distributor, that distributor is an importer under the Act.

The Act also applies to providers and deployers outside the EU if the output of their AI system is used within the EU. This is the extraterritorial reach that catches organizations off guard. A company in Singapore that processes data for an EU customer using AI, and sends the results back to the EU, is bound by the Act. Providers outside the EU selling into the EU must also designate an authorized representative within the EU to coordinate compliance.

There are exemptions. Purely personal, non-professional AI use sits outside the Act’s scope. AI models used solely for research, development, and prototyping before being placed on the market are also exempt, though once such a model is commercialized, the full obligations apply.

Prohibited AI practices

The Act bans certain AI uses entirely, as enumerated in the AI Act’s list of prohibited practices. These prohibitions took effect on February 2, 2025, and violating them triggers the highest penalty tier: up to EUR 35 million or 7% of worldwide annual turnover.

The prohibited practices at time of writing include:

  • AI systems that use subliminal techniques to manipulate behavior in ways that cause harm
  • AI that exploits vulnerabilities tied to age, disability, or socioeconomic status
  • Social scoring by public authorities that evaluates people based on social behavior or personality traits
  • Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases
  • Emotion recognition systems in workplaces and educational institutions, except for medical or safety purposes
  • Biometric categorization systems that infer protected characteristics such as race, political opinions, or sexual orientation
  • Specific predictive policing applications that profile individuals based on past behavior
  • Real-time remote biometric identification by law enforcement in publicly accessible spaces, subject to narrow exceptions with prior judicial authorization

In May 2026, EU lawmakers reached political agreement on the AI omnibus simplification package, which added a prohibition on AI systems that generate non-consensual sexually explicit content, including AI nudification apps. This is a new addition that many existing explainers do not yet cover.

The European Commission publishes guidelines on interpreting these prohibitions, and the list can expand. The prohibited practices section is not static law; it is an actively maintained list.

High-risk AI systems: requirements and obligations

High-risk classification applies in two scenarios. The first is when the AI system is a product, or a safety component of a product, covered by specific EU product safety laws, such as rules for toy safety, medical devices, or lifts. The second is when the AI system is used in one of the specific areas the Act designates as high-risk.

Those designated areas include employment, where AI used to recruit, filter, evaluate, or promote candidates qualifies. Education and vocational training systems that determine admissions, assess learning outcomes, or monitor behavior during exams. Access to essential private and public services, such as credit scoring, benefits eligibility, and insurance pricing. Critical infrastructure management for water, gas, and electricity. Biometric identification systems not covered by the prohibition list, except those whose sole purpose is verifying a person’s identity. Law enforcement, migration and border control, and administration of justice and democratic processes.

An exception exists for AI systems that perform a narrow procedural task without posing a significant threat to health, safety, or fundamental rights. The provider must document its assessment, and regulators can request to see it. The exception does not apply to AI systems that profile individuals.

What high-risk AI providers must do

Providers of high-risk AI systems carry the heaviest obligations under the Act. They must implement a continuous risk management system that monitors the AI throughout its lifecycle. They must adopt rigorous data governance practices: the training, validation, and testing data must meet specific quality criteria. Governance must cover data collection processes, data provenance, and measures to prevent and mitigate bias.

Technical documentation is a core requirement, covering system design specifications, capabilities, limitations, and regulatory compliance efforts. A quality management system must be in place. Postmarket monitoring plans must track system performance and continued compliance after deployment.

Specific transparency rules apply based on what the AI does. Systems that interact directly with individuals must inform users they are talking to an AI, unless context makes it obvious. Content generated or manipulated by AI must be marked as such in machine-readable format. This covers deepfakes, synthetic images, audio, and text published to inform the public on matters of public interest.

What high-risk AI deployers must do

Deployers have obligations that are easy to overlook because everyone focuses on providers. They must take appropriate technical and organizational measures to ensure they use high-risk AI systems according to the provider’s instructions. They must retain automatically generated logs, to the extent those logs are under their control, for a specified period.

For deployers providing certain essential services, including government bodies and private organizations delivering public services, a fundamental rights impact assessment must be conducted before using specific high-risk AI systems for the first time. This is a real operational requirement, not a box-checking exercise.

Rules for general-purpose AI models

General-purpose AI models are AI models that display significant generality, can competently perform a wide range of distinct tasks, and can be integrated into a variety of downstream applications. Foundation models like GPT-4, Claude, Llama, and Gemini are the most visible examples.

Providers of GPAI models must establish policies to respect EU copyright law and write publicly available detailed summaries of their training data sets. On July 18, 2025, the European Commission published draft guidelines clarifying the scope of these GPAI obligations and released a Code of Practice that offers voluntary compliance pathways for transparency, copyright, and safety requirements.

If a GPAI model poses systemic risk, the obligations increase. Systemic risk is defined as risk specific to the high-impact capabilities of GPAI models with significant impact on the EU market due to their reach or due to actual or reasonably foreseeable negative effects on public health, safety, fundamental rights, or society as a whole. The Act uses training compute as one criterion: if the cumulative computing power used to train a model exceeds 10^25 floating point operations (FLOPs), the model is presumed to have high-impact capabilities and pose systemic risk.

Providers of systemic-risk GPAI models must document and report serious incidents to the EU AI Office and relevant national regulators. They must implement adequate cybersecurity to protect the model and its physical infrastructure. These rules apply to both proprietary and open-source models.

EU AI Act penalties

The fines are structured in three tiers under Article 99 of the regulation. For violating prohibited AI practices, organizations face up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. For most other violations, including failure to meet high-risk AI system requirements, fines reach up to EUR 15 million or 3% of worldwide annual turnover. Supplying incorrect, incomplete, or misleading information to authorities carries a penalty of up to EUR 7.5 million or 1% of worldwide annual turnover.

For startups and small-to-medium enterprises, the fine is the lower of the two possible amounts. The Act also extends certain simplified regulatory requirements to small mid-caps, a change introduced through the AI omnibus simplification package.

These are not theoretical numbers. GDPR fines over the past seven years have reached hundreds of millions of euros against companies like Meta, TikTok, and Amazon. The EU AI Act creates penalty ceilings that are structurally similar.

When the EU AI Act takes effect

The Act entered into force on August 1, 2024. Different provisions phase in on different dates.

Prohibited AI practices and AI literacy obligations started applying on February 2, 2025. The governance rules and GPAI model obligations became applicable on August 2, 2025, for new models. Providers of GPAI models placed on the market before that date have until August 2, 2027, to comply.

Following the AI omnibus political agreement of May 2026, the timeline for high-risk AI systems was adjusted. Rules for high-risk AI systems used in areas such as biometrics, critical infrastructure, education, employment, and migration now apply from December 2, 2027. For AI systems integrated into regulated products, the rules apply from August 2, 2028. These adjustments give companies time to work with the technical standards and support instruments the European Commission is still developing.

What the EU AI Act means for organizations outside Europe

The extraterritorial reach is the part that catches non-European organizations off guard. The Act does not care where your servers are or where your headquarters is incorporated. If you sell AI into the EU, if your AI output is used within the EU, if an EU company sends you data and your AI processes it and sends results back, the Act applies to you.

This means a startup in Bangalore with a SaaS product that uses AI to score sales leads, and has two customers in Germany, has obligations under this law. A Canadian hospital using an AI diagnostic tool built by a vendor in Tel Aviv is affected if the tool’s output influences patient care decisions for EU citizens visiting that hospital.

The practical starting point is to identify whether your organization is a provider, deployer, or importer under the Act, and then map your AI systems to the risk categories. For most organizations, most AI systems will fall into the minimal risk bucket. The challenge is identifying the ones that do not and addressing them before the applicable compliance deadlines. Understanding AI compliance requirements across jurisdictions is the operational starting point.

How to prepare for EU AI Act compliance

Start with an inventory. You cannot classify what you have not catalogued. List every AI system your organization builds, buys, or uses. Note what it does, what data it touches, where it runs, and who its users are.

Map each system to a risk category. Is it on the prohibited list? If not, does it fall into a high-risk use case based on the Act’s designated areas? Is it a general-purpose AI model? Everything else is minimal risk.

For high-risk systems, the requirements are specific enough that most organizations will need to stand up a governance function. Risk management processes, data governance controls, technical documentation, and postmarket monitoring plans do not build themselves. Many organizations start by adopting established AI governance frameworks to structure their compliance approach. A fundamental rights impact assessment is not a form you can fill out in an afternoon.

For GPAI models, the transparency and copyright obligations require documentation of training data sources and a public summary. If your model crosses the 10^25 FLOPs threshold, systemic risk obligations kick in.

The European Commission’s AI Pact offers a voluntary path to start aligning with the Act before requirements become mandatory. The EU AI Office, AI Board, Scientific Panel, and Advisory Forum collectively steer governance and enforcement. National market surveillance authorities in each member state handle day-to-day oversight.

Several EU member states have begun setting up AI regulatory sandboxes, controlled environments where companies can test AI systems under regulatory supervision before full deployment. Each member state must have at least one sandbox operational by August 2, 2026.

The Act does not demand perfection on day one. But it does demand you start.

Frequently asked questions

What is the difference between the EU AI Act and GDPR?

The GDPR governs how organizations collect, process, and store personal data. The EU AI Act governs how AI systems are developed, placed on the market, and used. They overlap in practice. A high-risk AI system that processes personal data must comply with both laws. But the GDPR applies to all personal data processing, AI or not, while the AI Act only applies to AI systems.

What are the risk categories under the EU AI Act?

There are four: unacceptable risk (banned), high risk (strict obligations), limited risk (transparency requirements), and minimal risk (no additional rules). Most AI systems in use today fall into the minimal risk category.

Which AI practices are banned under the EU AI Act?

Subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, untargeted scraping of facial images, emotion recognition at work and school, biometric categorization based on protected characteristics, predictive policing based on profiling, real-time remote biometric identification by law enforcement, and, as of the May 2026 AI omnibus agreement, AI systems that generate non-consensual sexually explicit content.

What are the penalties for non-compliance?

Up to EUR 35 million or 7% of worldwide annual turnover for violating prohibited practices. Up to EUR 15 million or 3% for most other violations. Up to EUR 7.5 million or 1% for supplying incorrect information to authorities. Startups and SMEs pay the lower of the two amounts.

Does the EU AI Act apply to companies outside the EU?

Yes. If your AI system or its output is used in the EU, the Act applies regardless of where your company is incorporated. Non-EU providers must designate authorized representatives within the EU.

Next steps

Understanding the EU AI Act is one step. Figuring out how it maps to your specific AI systems is the next one. Start with an inventory. Classify each system by risk tier. Build a compliance roadmap that targets the earliest applicable deadline for your organization.

Continue Reading

Previous: What is an AI security graph?
Next: What is the NIST AI Risk Management Framework?

More in AI security

  • Guide

The agentic AI security checklist: 12 controls to verify before you deploy

Staff September 4, 2026
Twelve controls to verify before you deploy an AI agent, each mapped to an OWASP ASI risk...
Read more Read more about The agentic AI security checklist: 12 controls to verify before you deploy
LLM jailbreak defense: techniques that actually stop attacks Jailbreak defense
  • Cybersecurity

LLM jailbreak defense: techniques that actually stop attacks

Staff July 28, 2026
How do enterprises secure AI data pipelines at production scale? safety
  • Cybersecurity

How do enterprises secure AI data pipelines at production scale?

Staff July 28, 2026
How companies can defend against AI model extraction attacks
  • Guide

How companies can defend against AI model extraction attacks

Staff July 23, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026

Glossary

model router
  • LLMs

What is a model router for AI? A plain-English guide

Staff July 30, 2026
A model router for AI is a decision layer that picks which large language model answers each...
Read more Read more about What is a model router for AI? A plain-English guide
What is agentic SDLC?
  • Glossary

What is agentic SDLC?

Staff July 22, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026
LLM system prompt leakage: what it is, how it works, and how to stop it agentic ai
  • Glossary

LLM system prompt leakage: what it is, how it works, and how to stop it

Staff July 15, 2026
What is LLM supply chain security? (OWASP LLM03:2025 explained) llm supply chain
  • Glossary

What is LLM supply chain security? (OWASP LLM03:2025 explained)

Staff July 14, 2026

Guides

The agentic AI security checklist: 12 controls to verify before you deploy
  • Guide

The agentic AI security checklist: 12 controls to verify before you deploy

Staff September 4, 2026
LLM jailbreak defense: techniques that actually stop attacks Jailbreak defense
  • Cybersecurity

LLM jailbreak defense: techniques that actually stop attacks

Staff July 28, 2026
How do enterprises secure AI data pipelines at production scale? safety
  • Cybersecurity

How do enterprises secure AI data pipelines at production scale?

Staff July 28, 2026
How companies can defend against AI model extraction attacks
  • Guide

How companies can defend against AI model extraction attacks

Staff July 23, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026
How to prevent adversarial attacks on AI models
  • Guide

How to prevent adversarial attacks on AI models

Staff July 22, 2026
  • Home
  • What’s new in AI
  • Solutions
  • Cybersecurity
  • Learn
Copyright © All rights reserved. | by AF themes.