The European Union's Artificial Intelligence Act (EU AI Act) establishes a risk-based framework for regulating artificial intelligence systems within the EU market. Adopted in 2024, the regulation classifies AI applications into four tiers - unacceptable, high, limited, and minimal risk - with corresponding obligations that scale with the potential harm to health, safety, and fundamental rights. This tiered approach aims to foster innovation while ensuring trustworthy deployment of Artificial intelligence technologies.
The Act applies to providers, deployers, importers, and distributors of AI systems operating in the EU, regardless of where they are based, if their outputs are used within the Union. It also covers general-purpose AI models, including Large language models, which are subject to transparency and copyright requirements.
Unacceptable Risk Tier
The highest tier prohibits AI practices that pose an unacceptable risk to EU values and fundamental rights. These include social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces (with narrow law enforcement exceptions), manipulative techniques exploiting vulnerabilities (e.g., age or disability), and predictive policing based solely on profiling. Systems in this category are banned outright, with limited derogations for national security and certain law enforcement scenarios, subject to judicial authorization.
High-Risk Tier
High-risk AI systems face the most extensive obligations. These include AI used in critical infrastructure (e.g., transport, energy), education and vocational training, employment and worker management, essential private and public services (e.g., credit scoring, healthcare), law enforcement, migration and asylum, and democratic processes. Providers must implement a risk management system, use high-quality training data, maintain technical documentation, enable human oversight, and ensure robustness and cybersecurity. They must also register in an EU database and undergo conformity assessment, often involving third-party evaluation for certain applications.
Deployers of high-risk systems must use them according to instructions, monitor for incidents, and conduct fundamental rights impact assessments when used in public sectors. High-risk systems must also be designed to work with human oversight, allowing operators to intervene or override outputs.
Limited Risk Tier
Limited risk applies to AI systems that interact with humans, such as chatbots, deepfakes, and emotion recognition systems. These are subject to transparency obligations: users must be informed they are interacting with an AI, and deepfakes must be labeled as artificially generated. This tier aims to prevent deception and ensure informed consent, without additional substantive requirements.
Minimal Risk Tier
Most AI applications, such as spam filters, video game AI, or inventory management, fall into the minimal risk tier. They are not subject to specific obligations under the Act, though voluntary codes of conduct are encouraged. This tier reflects the EU's intention to avoid over-regulating low-impact uses, allowing innovation to proceed with minimal bureaucratic burden.
General-Purpose AI Models
The Act introduces a separate regime for general-purpose AI (GPAI) models, which include foundation models like those from OpenAI, Anthropic, and Google DeepMind. All GPAI models must provide technical documentation and comply with copyright law. Models with systemic risk (trained with over 10^25 FLOPs) face additional obligations, including adversarial testing, incident reporting, and cybersecurity measures. The European Commission, in consultation with an AI Office, designates systemic-risk models.
Governance and Enforcement
The Act establishes a European Artificial Intelligence Board, composed of national supervisory authorities, to ensure consistent application. Each EU member state designates a national authority for market surveillance. Fines for non-compliance are tiered: up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for most other violations, and €7.5 million or 1.5% for supplying incorrect information. Small and medium-sized enterprises receive reduced fines and simplified documentation.
Timeline and Implementation
The Act entered into force on August 1, 2024, with a phased rollout. Prohibitions on unacceptable risk apply from February 2, 2025. GPAI obligations take effect from August 2, 2025. High-risk requirements for products already covered by EU product safety legislation apply from August 2, 2026, and for other high-risk systems from August 2, 2027. Member states must establish national authorities by August 2, 2025.
Impact and Criticism
The EU AI Act is the world's first comprehensive AI regulation, influencing global standards. Supporters argue it protects citizens and builds trust, while critics contend that high-risk obligations may stifle innovation, particularly for startups and open-source developers. The Act's extraterritorial reach means non-EU companies, including major tech firms like Google Cloud and Amazon Web Services, must comply if they serve EU customers. As of 2025, implementation guidance is still being developed, and the practical impact on emerging technologies like Generative AI remains to be seen.