# EU AI Act Adoption

The EU AI Act is a European Union regulation establishing a comprehensive legal framework for artificial intelligence, entering into force on 1 August 2024. It classifies AI applications by risk level, imposing obligations on providers and users while banning certain uses.

The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) within the EU. It entered into force on 1 August 2024, with provisions phased in gradually over the following 6 to 36 months. The Act covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or non-professional use. As a form of product regulation, it does not create individual rights but places duties on AI providers and organisations using AI in a professional context.

The Act classifies non-exempt AI applications by their risk of causing harm, with four levels - unacceptable, high, limited, and minimal - plus an additional category for general-purpose AI. Applications with unacceptable risks are banned, while high-risk applications must comply with security, transparency, and quality obligations and undergo conformity assessments. Limited-risk applications have transparency obligations, and minimal-risk applications are not regulated. For general-purpose AI, transparency requirements are imposed, with reduced requirements for open-source models and additional evaluations for high-capability models.

## Legislative History

The European Commission proposed the AI Act on 21 April 2021. The draft was revised to address the rise in popularity of generative AI systems, such as those developed by [OpenAI](https://www.wikiprompt.org/wiki/openai) and [Anthropic](https://www.wikiprompt.org/wiki/anthropic), whose general-purpose capabilities did not fit the main framework. The European Parliament passed the Act on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The regulation entered into force on 1 August 2024.

The Act also creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.

## Risk Categories

The risk-based scheme follows a product-safety model where regulatory duties are assigned to providers and deployers of AI systems, becoming more demanding as potential impact on health, safety, or fundamental rights increases. This structure ensures oversight focuses on systems likely to create significant risks while allowing lighter approaches for less sensitive uses.

Unacceptable risk applications are banned, except for specific exemptions. This includes AI that manipulates human behaviour, real-time remote biometric identification (such as facial recognition) in public spaces, and social scoring that ranks individuals based on personal characteristics or behaviour.

High-risk applications are those expected to pose significant threats to health, safety, or fundamental rights. This includes AI used in health, education, recruitment, critical infrastructure management, law enforcement, or justice. These systems must meet quality, transparency, human oversight, and safety obligations, and in some cases require a Fundamental Rights Impact Assessment before deployment. Citizens have the right to submit complaints about AI systems and receive explanations of decisions made by high-risk AI affecting their rights.

Limited-risk systems have transparency obligations, ensuring users know they are interacting with AI and can make informed choices. This includes applications that generate or manipulate images, sound, or videos, such as deepfakes. Minimal-risk systems, including video games or spam filters, are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules.

## General-Purpose AI

Added in 2023, the general-purpose AI category includes foundation models that can perform a wide range of tasks, such as [large language models](https://www.wikiprompt.org/wiki/large-language-model). If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy. Closed-source models must meet broader transparency requirements. High-impact models posing systemic risks, requiring more than 10^25 floating-point operations to train, must undergo extra evaluation.

A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation in the code is voluntary. Providers of general-purpose AI models must publish a summary of training data, adopt a copyright compliance policy, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations, adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure adequate cybersecurity.

## Exemptions and Enforcement

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for those reasons.

The Act's extraterritorial reach means providers from outside the EU, including major technology companies like [Google DeepMind](https://www.wikiprompt.org/wiki/google-deepmind) and [Amazon Web Services](https://www.wikiprompt.org/wiki/amazon-web-services), must comply if they have users within the EU. The European Artificial Intelligence Board facilitates national cooperation and ensures consistent application across member states. The list of high-risk applications can be expanded over time without modifying the AI Act itself, allowing the framework to adapt to emerging AI capabilities and applications.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-2024
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-09T02:01:30.205579+00:00
