The EU AI Act 2025 marks the beginning of the operational enforcement of the Artificial Intelligence Act, a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence. The regulation entered into force on 1 August 2024, with provisions coming into operation gradually over the following 6 to 36 months. In 2025, key obligations began to apply to providers and deployers of AI systems within the EU, including those from outside the bloc if they have users within the EU, mirroring the extraterritorial reach of the General Data Protection Regulation.
The Act covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context. The regulation was proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. The draft was revised to address the rise in popularity of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework.
Risk Categories
The Act classifies non-exempt AI applications by their risk of causing harm, with four levels – unacceptable, high, limited, minimal – plus an additional category for general-purpose AI. Applications with unacceptable risks are banned. High-risk applications must comply with security, transparency and quality obligations, and undergo conformity assessments. Limited-risk applications only have transparency obligations. Minimal-risk applications are not regulated.
Unacceptable risk includes AI applications that manipulate human behaviour, those that use real-time remote biometric identification (such as facial recognition) in public spaces, and those used for social scoring – ranking individuals based on their personal characteristics, socio-economic status, or behaviour. Bans apply except for specific exemptions.
High-risk applications are those expected to pose significant threats to health, safety, or the fundamental rights of persons. Notably, AI systems used in health, education, recruitment, critical infrastructure management, law enforcement or justice fall into this category. They are subject to quality, transparency, human oversight and safety obligations, and in some cases require a Fundamental Rights Impact Assessment (FRIA) before deployment. A FRIA is an ex ante review to identify and mitigate potential impacts on fundamental rights before an AI system is deployed. These systems must be evaluated both before they are placed on the market and throughout their life cycle. The list of high-risk applications can be expanded over time without modifying the AI Act itself. Citizens have a right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.
Limited risk includes AI applications that make it possible to generate or manipulate images, sound, or videos (like deepfakes). These systems have transparency obligations, ensuring users are informed that they are interacting with an AI system and allowing them to make informed choices.
Minimal risk includes AI systems used for video games or spam filters. Most AI applications are expected to fall into this category. These systems are not regulated, and Member States cannot impose additional regulations due to maximum harmonisation rules. Existing national laws regarding the design or use of such systems are overridden. However, a voluntary code of conduct is suggested.
General-Purpose AI
Added in 2023, the general-purpose AI category includes foundation models that can perform a wide range of tasks, such as those developed by OpenAI, Anthropic, or Google DeepMind. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks – requiring more than 10^25 floating-point operations to train – must undergo extra evaluation.
A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance with the AI Act. Participation in the code is voluntary. Beyond basic transparency duties, the Act sets a common list of obligations for providers of general-purpose AI models. They must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity.
Exemptions
Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The regulation does not apply where AI systems are used exclusively for military, defence or national security purposes, or to systems developed and put into service solely for scientific research. This exemption does not cover AI systems used in civilian contexts, even if developed by military or security organisations.
Governance and Compliance
The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance with the regulation. This board coordinates supervisory authorities across member states, similar to the structure established under the General Data Protection Regulation. The board is responsible for issuing guidance, facilitating consistent application, and addressing cross-border cases involving AI systems.
In 2025, enforcement activities began in earnest. National supervisory authorities started conducting conformity assessments for high-risk AI systems placed on the market. Providers of general-purpose AI models were required to register their models and submit documentation. The European Commission also began developing implementing acts and guidelines to clarify specific provisions, including technical standards for conformity assessments and procedures for the European Artificial Intelligence Board.
Impact on Industry
The AI Act's extraterritorial scope means that major technology companies outside the EU, including those in the United States and Asia, must comply if they offer AI services to EU users. This includes providers of cloud computing services like Amazon Web Services, Microsoft Azure, and Google Cloud, as well as AI chip manufacturers such as NVIDIA (though not listed, it is a key player) and AMD. The regulation has prompted many companies to establish compliance teams, conduct internal audits, and develop risk management frameworks for their AI products.
For general-purpose AI providers, the obligation to publish training data summaries and copyright policies has significant implications. Companies developing machine learning models must now document their data sources and ensure compliance with EU copyright law. This has led to increased scrutiny of training data acquisition practices, particularly for generative AI systems that rely on vast datasets scraped from the internet.
Timeline and Transition
The AI Act's provisions are being phased in over 6 to 36 months from its entry into force on 1 August 2024. In 2025, the first major deadlines took effect. By 2 February 2025, prohibitions on unacceptable-risk AI applications became applicable. By 2 August 2025, obligations for general-purpose AI models became applicable. High-risk AI system requirements are scheduled to apply in stages, with the first set of obligations becoming applicable in August 2026 and the remainder in August 2027.
During this transition period, the European Commission has been working with member states and industry stakeholders to develop implementing guidelines and harmonised standards. The European Artificial Intelligence Board has been established and held its first meetings in 2025. The General-Purpose AI Code of Practice, published on 10 July 2025, serves as a practical tool for providers to demonstrate compliance, though participation remains voluntary.
Broader Context
The AI Act is part of a broader global trend toward AI regulation. It follows the EU's General Data Protection Regulation in establishing a comprehensive regulatory framework for digital technologies. The Act's risk-based approach has been influential in other jurisdictions, though the EU remains the first major economy to enact binding horizontal AI legislation. The regulation's emphasis on fundamental rights and safety reflects ongoing debates about the societal impact of AI, including concerns about bias, discrimination, and accountability in automated decision-making.
The Act's provisions on transparency for limited-risk AI systems, such as deepfakes, address growing concerns about disinformation and manipulation. The requirement for high-risk AI systems to undergo conformity assessments and fundamental rights impact assessments aims to ensure that AI deployment respects EU values and legal principles. As of 2025, the full impact of the regulation on innovation and competitiveness remains to be seen, with ongoing discussions about the balance between regulation and fostering AI development in Europe.