The EU AI Act is a European Union regulation establishing a harmonized legal framework for artificial intelligence across its member states, widely described as the first comprehensive AI-specific law adopted by a major regulatory body. Proposed by the European Commission in 2021, it was formally adopted in 2024 and entered into force on August 1, 2024, with most obligations phased in over the following two to three years.
Structure
The Act classifies AI systems into risk tiers rather than regulating the technology uniformly. Systems deemed to pose "unacceptable risk," such as social scoring by governments and certain forms of biometric surveillance, are banned outright. "High-risk" systems, including many uses in employment, credit scoring, law enforcement, and critical infrastructure, face requirements around risk management, data quality, documentation, human oversight, and conformity assessment before deployment. Lower-risk systems face lighter transparency obligations, such as disclosing when a user is interacting with a Chatbot or viewing a Deepfake. A later addition addressed general-purpose AI models directly, including extra obligations for the most capable systems classified as posing "systemic risk," a category shaped by ongoing debate over how to define frontier models.
Development and debate
The legislative process ran alongside the rapid rise of large language models following the launch of ChatGPT in late 2022, which prompted lawmakers to add provisions specifically targeting general-purpose models partway through negotiation. Industry groups, including major labs such as OpenAI and companies represented by Mistral AI on behalf of European interests, lobbied over the scope and stringency of rules for general-purpose models, with concerns raised that compliance costs could disadvantage smaller European developers relative to larger US and Chinese competitors. Civil society and AI ethics researchers generally supported binding rules but disagreed over whether the risk-tier approach adequately addressed harms like algorithmic bias documented in earlier automated decision systems.
Impact
The Act positioned the European Union as a first mover in binding AI regulation, in contrast to the more fragmented, sector-specific approach taken in the United States and the lighter-touch stance associated with jurisdictions competing to attract AI investment. Its phased rollout through 2025, 2026, and 2027 meant that its practical effects on model development and deployment continued to unfold gradually, and it became a frequent reference point in broader international discussions of AI governance, including at forums following the Bletchley Park AI Safety Summit.