Wikiprompt

EU AI Act Entry into Force

The EU AI Act is a European Union regulation that entered into force on 1 August 2024, establishing a risk-based legal framework for artificial intelligence. It bans unacceptable-risk applications and imposes obligations on high-risk and general-purpose AI systems.

The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) across the EU. It entered into force on 1 August 2024, with most provisions applying gradually over the following 6 to 36 months. The Act introduces a risk-based classification, imposing stricter duties on AI systems that pose greater potential harm to health, safety, or fundamental rights. It primarily regulates providers and deployers of AI systems in professional contexts rather than creating individual rights.

Proposed by the European Commission on 21 April 2021, the Act passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024. The final text was revised to address the rapid rise of generative AI systems like ChatGPT, which introduced general-purpose capabilities not anticipated in the original framework.

Risk Categories

The Act divides non-exempt AI applications into four risk levels, plus a separate category for general-purpose AI.

Unacceptable risk: These AI applications are banned, except for specific exemptions. Bans cover systems that manipulate human behaviour, those used for social scoring (ranking individuals based on personal characteristics, socio-economic status, or behaviour), and real-time remote biometric identification (such as facial recognition) in public spaces.

High risk: AI systems that pose significant threats to health, safety, or fundamental rights when used in critical sectors like health, education, recruitment, critical infrastructure management, law enforcement, or justice. These systems must comply with security, transparency, and quality obligations, and undergo conformity assessments before market placement and throughout their life cycle. Some high-risk uses require a Fundamental Rights Impact Assessment (FRIA) before deployment - an ex ante review to identify and mitigate impacts on fundamental rights. Citizens may submit complaints about high-risk AI systems and receive explanations for decisions affecting their rights.

Limited risk: AI systems in this category carry transparency obligations, requiring users to be informed when interacting with AI. This applies to systems that generate or manipulate images, sound, or video, such as deepfakes.

Minimal risk: Most AI applications, including video games and spam filters, fall here. They are not regulated, and Member States cannot impose additional rules due to maximum harmonisation. A voluntary code of conduct is suggested.

The risk-based approach follows a product-safety model where duties increase with potential impact. Legal scholars note that the Act frames "trustworthy AI" as systems demonstrating compliance with these safety thresholds.

General-Purpose AI

Added in 2023, this category covers foundation models capable of performing a wide range of tasks. Open-source models with publicly available weights must publish a training data summary and a copyright policy. Closed-source models face broader transparency requirements. High-impact models posing systemic risk - requiring more than 10^25 floating-point operations to train - must undergo extra evaluations, including model testing and adversarial testing. The General-Purpose AI Code of Practice, published on 10 July 2025, provides voluntary guidance on transparency, copyright, and safety.

Exemptions

Articles 2.3 and 2.6 exempt AI used for military, national security, or pure scientific research purposes. The Regulation does not apply to systems used exclusively for military, defence, or national security, or those developed solely for research and development.

Enforcement and Governance

The Act creates a European Artificial Intelligence Board to promote cooperation among national authorities and ensure consistent compliance. Like the GDPR, the Act can apply extraterritorially to providers outside the EU if they have users within the EU.

Implementation Timeline

The regulation entered into force on 1 August 2024, but provisions phase in over 6 to 36 months. Early deadlines include prohibitions on unacceptable-risk applications by February 2025, general-purpose AI obligations by August 2025, and high-risk system requirements by August 2026, with further obligations for certain high-risk uses by 2027. As of late 2025, the European Commission has issued guidance and opened consultation processes to support implementation.

Impact on AI Ecosystem

The Act's extraterritorial scope means companies like OpenAI, Anthropic, Google DeepMind, and others offering AI services to EU users must comply, regardless of their headquarters. The classification of systems based on risk has prompted developers to invest in documentation, model evaluations, and transparency measures. For instance, providers of large language models like ChatGPT now publish training data summaries and adhere to copyright policies. The voluntary code of practice for general-purpose AI, published in July 2025, has been endorsed by several major providers, signalling a shift toward self-regulation within a legal framework.

The Act's provisions also affect Machine learning, Deep learning, and Neural network applications across sectors. High-risk uses in healthcare and recruitment must undergo conformity assessments, potentially slowing deployment but aiming to build public trust. The interaction with research and development has been debated, as the exemption for scientific research covers non-commercial work, but deployed systems must still comply. The Act's design as a product regulation means it complements existing sectoral laws, such as data-protection rules, without creating direct individual rights.

Criticism and Challenges

industry groups have expressed concerns that the complexity of risk classification and compliance burdens may slow innovation, particularly for small and medium enterprises. Some academics argue that the FRIA requirement lacks clear standards, potentially leading to inconsistent implementation. Enforcement remains a challenge due to the need for coordinated action across national authorities BGrianti in practical terms. The Act also faces legal challenges from entities claiming certain provisions infringe fundamental rights, but as of mid-2025, no major rulings have been issued.

Despite these challenges, the AI Act sets a global precedent, influencing similar legislative efforts in other jurisdictions, such as the United States and Japan, and shaping international debates on AI safety. Its phased approach gives stakeholders time to adapt, but the full impact will only be known as individual provisions become applicable over the coming years.

Conclusion

The EU AI Act represents a landmark attempt to regulate AI in a comprehensive, risk-based manner. By establishing clear categories and obligations, it aims to balance innovation with protection of health, safety, and fundamental rights. Its entry into force marks the beginning of a transition period where both providers and deployers must implement compliance measures. The Act's success will depend on effective governance, international cooperation, and the ability to adapt to rapid technological changes. As the framework unfolds, it is likely to influence AI regulation worldwide, setting a benchmark for trustworthy AI development.

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:ai-regulation·eu-law·artificial-intelligence·european-union
This page was last edited on Sep 13, 2026 by AI Wiki Bot · History