# EU AI Act Council Approval

The Council of the EU unanimously approved the Artificial Intelligence Act on 21 May 2024, establishing the world's first comprehensive legal framework for AI, with risk-based rules and transparency obligations.

The Council of the European Union gave its final approval to the Artificial Intelligence Act (AI Act) on 21 May 2024, concluding a legislative process that began with the European Commission's proposal on 21 April 2021. The unanimous vote by member states' ministers marked the last major hurdle before the regulation could enter into force, setting the stage for the world's first comprehensive legal framework governing [artificial-intelligence](https://www.wikiprompt.org/wiki/artificial-intelligence). The Act had previously passed the European Parliament on 13 March 2024, and its final text incorporated significant revisions made in response to the rapid rise of [generative-ai](https://www.wikiprompt.org/wiki/generative-ai) systems such as [openai](https://www.wikiprompt.org/wiki/openai)'s ChatGPT, whose general-purpose capabilities did not fit the original risk-based framework.

The regulation formally entered into force on 1 August 2024, with provisions scheduled to become applicable gradually over the following 6 to 36 months. This phased implementation was designed to give businesses, national authorities, and providers of AI systems adequate time to adapt to the new obligations. The AI Act establishes a common regulatory and legal framework for AI across all EU member states, covering most AI systems in a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or non-professional use. As a form of product regulation, it does not create individual rights but instead places duties on AI providers and on organisations that use AI in a professional context.

## Risk-Based Classification

The Act classifies non-exempt AI applications into four risk levels - unacceptable, high, limited, and minimal - plus an additional category for general-purpose AI. This risk-based scheme follows a product-safety model in which regulatory duties are assigned to providers and deployers, becoming more demanding as the potential impact on health, safety, or fundamental rights increases. The structure ensures that oversight focuses on systems likely to create significant risks while allowing lighter approaches for less sensitive uses.

Applications with unacceptable risks are banned outright, except for specific exemptions. This includes AI systems that manipulate human behaviour, those using real-time remote biometric identification (such as facial recognition) in public spaces, and social scoring systems that rank individuals based on personal characteristics, socio-economic status, or behaviour. High-risk applications must comply with security, transparency, and quality obligations, and undergo conformity assessments before deployment. These include AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice, which must also undergo a Fundamental Rights Impact Assessment (FRIA) in some cases - an ex ante review to identify and mitigate potential impacts on fundamental rights.

Limited-risk applications only have transparency obligations, ensuring users are informed that they are interacting with an AI system and allowing them to make informed choices. This category includes deepfake-generating tools and other systems that manipulate images, sound, or video. Minimal-risk applications, such as AI in video games or spam filters, are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules. Most AI applications are expected to fall into this category, with a voluntary code of conduct suggested for best practices.

## General-Purpose AI Provisions

Added in 2023, the general-purpose AI category addresses foundation models that can perform a wide range of tasks, including large language models and other [machine-learning](https://www.wikiprompt.org/wiki/machine-learning) systems. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks - defined as requiring more than 10^25 floating-point operations to train - must undergo extra evaluation, including model evaluations, adversarial testing, risk assessment for bias and security failures, serious incident reporting, and adequate cybersecurity measures.

Beyond basic transparency duties, providers of general-purpose AI models must publish a summary of training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation in the code is voluntary.

## Exemptions and Extraterritorial Reach

Articles 2.3 and 2.6 of the Act exempt AI systems used exclusively for military, defence, or national security purposes, as well as pure scientific research and development. The regulation also does not apply to systems developed and put into service solely for these purposes. Like the EU's General Data Protection Regulation, the AI Act can apply extraterritorially to providers from outside the EU if they have users within the EU, meaning companies such as [google-deepmind](https://www.wikiprompt.org/wiki/google-deepmind), [anthropic](https://www.wikiprompt.org/wiki/anthropic), or [amazon-web-services](https://www.wikiprompt.org/wiki/amazon-web-services) offering AI services to EU customers must comply regardless of their headquarters location.

## Governance and Enforcement

The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance with the regulation. This board coordinates supervisory authorities across member states, facilitating consistent application of the rules. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights. The list of high-risk applications can be expanded over time without modifying the AI Act itself, allowing the framework to adapt to emerging risks.

## Legislative Journey and Revisions

The European Commission's original proposal on 21 April 2021 drew on stakeholder consultations and a wide range of existing research, according to an initial appraisal by the European Parliamentary Research Service. The draft Act was revised during negotiations to address the rise in popularity of generative AI systems, whose general-purpose capabilities did not fit the main framework. The final text balanced innovation concerns with fundamental rights protections, incorporating input from various stakeholders including technology companies, civil society organisations, and academic institutions.

The unanimous approval by the EU Council on 21 May 2024 represented a significant political achievement, demonstrating cross-party and cross-national consensus on AI regulation. The phased implementation schedule means that different provisions become applicable at different times, with the most urgent bans and transparency requirements taking effect first, followed by obligations for high-risk systems and general-purpose AI models over the subsequent months.

## Implications for Industry

The AI Act's extraterritorial scope and comprehensive coverage mean that major technology companies worldwide must adjust their development and deployment practices. Providers of [large-language-model](https://www.wikiprompt.org/wiki/large-language-model) systems, [neural-network](https://www.wikiprompt.org/wiki/neural-network) based applications, and other AI tools must document their training data, implement copyright policies, and conduct risk assessments. The distinction between open-source and closed-source models creates different compliance burdens, potentially influencing how companies choose to release their AI systems. The Act's risk-based approach also affects sectors such as healthcare, education, and law enforcement, where high-risk AI applications face the most stringent requirements.

## Broader Context

The AI Act represents a landmark in technology regulation, following the EU's pattern of establishing global standards through comprehensive legislation. Its risk-based framework has been studied by regulators in other jurisdictions considering similar approaches. The Act's emphasis on transparency, human oversight, and fundamental rights protection reflects broader societal concerns about AI's impact on democracy, privacy, and individual autonomy. As the provisions come into operation gradually, the practical implementation will be closely watched by industry, civil society, and policymakers worldwide.

The regulation's success will depend on effective enforcement by national authorities and the European Artificial Intelligence Board, as well as cooperation from AI providers. The voluntary code of conduct for minimal-risk applications and the General-Purpose AI Code of Practice provide guidance for compliance, while the Act's flexibility allows for future updates as AI technology evolves. The Council's approval on 21 May 2024 thus marked not an end but a beginning - the start of a new era in which AI systems operating in the EU must demonstrate compliance with clear, enforceable rules designed to protect health, safety, and fundamental rights.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-council-approval
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:51:48.389602+00:00
