# EU AI Act Guidelines

The EU AI Act Guidelines are European Commission guidance documents explaining how to apply the EU Artificial Intelligence Act, a risk-based regulation for AI systems that entered into force on 1 August 2024.

The EU AI Act Guidelines are official guidance documents published by the European Commission to assist providers, deployers, and national authorities in applying the Artificial Intelligence Act (AI Act), the European Union's comprehensive regulation for artificial intelligence. The AI Act itself entered into force on 1 August 2024, with obligations phased in over 6 to 36 months. The guidelines are not legally binding but interpret the regulation's provisions, clarify risk classifications, and illustrate compliance pathways for businesses and public bodies operating within the EU or serving EU users.

The AI Act establishes a common regulatory framework for AI across all EU member states, following a product-safety model that assigns duties to AI providers and professional users. It covers most AI systems in sectors such as health, education, employment, and law enforcement, while exempting systems used exclusively for military, national security, research, or non-professional purposes. As a form of product regulation, it does not create individual rights but imposes obligations on organisations. The regulation can apply extraterritorially to providers outside the EU if they have users within the EU, mirroring the reach of the General Data Protection Regulation.

## Background and Legislative History

The European Commission first proposed the AI Act on 21 April 2021. The draft underwent significant revision after the rapid rise of [generative-ai](https://www.wikiprompt.org/wiki/generative-ai) systems such as [ChatGPT](https://www.wikiprompt.org/wiki/openai), whose general-purpose capabilities did not fit the original risk framework. The European Parliament passed the revised text on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The regulation entered into force on 1 August 2024, with provisions becoming applicable gradually over the following 6 to 36 months. The guidelines were issued in stages starting in 2025, beginning with practical explanations of the risk categories and obligations for high-risk systems.

The Commission's guidance builds on an impact assessment that drew on stakeholder consultations and existing research. The European Parliamentary Research Service provided an initial appraisal of policy options, noting the challenge of balancing innovation with fundamental rights protection. The guidelines aim to reduce uncertainty for businesses, especially small and medium-sized enterprises, by offering concrete examples and step-by-step instructions for conformity assessments.

## Risk Classification Framework

The guidelines detail the four risk levels established by the Act, plus a separate category for general-purpose AI. Applications posing unacceptable risks are banned outright, with narrow exemptions. These include AI systems that manipulate human behaviour, use real-time remote biometric identification in public spaces, or enable social scoring based on personal characteristics or socio-economic status.

High-risk applications must comply with security, transparency, and quality obligations, and undergo conformity assessments before market placement. The guidelines specify that high-risk categories include AI used in health, education, recruitment, critical infrastructure management, law enforcement, and justice. Providers must implement human oversight, maintain technical documentation, and in some cases conduct a Fundamental Rights Impact Assessment (FRIA) before deployment. A FRIA is an ex ante review to identify and mitigate potential impacts on fundamental rights, building on earlier algorithmic impact assessment work that suggested identifying affected communities, describing possible harms, and enabling public scrutiny. The list of high-risk applications can be expanded over time without amending the Act itself.

Limited-risk systems carry transparency obligations only. Users must be informed when interacting with an AI system, particularly for applications that generate or manipulate images, sound, or video, such as deepfakes. Minimal-risk systems, including video games and spam filters, are not regulated, and member states cannot impose additional requirements due to maximum harmonisation rules. The guidelines note that most AI applications are expected to fall into this category, with a voluntary code of conduct encouraged.

## General-Purpose AI Obligations

The guidelines dedicate substantial attention to general-purpose AI, a category added in 2023 to cover foundation models like [large language models](https://www.wikiprompt.org/wiki/large-language-model) that can perform a wide range of tasks. Providers of such models must publish a training data summary, adopt a copyright policy, and provide technical documentation to downstream providers and supervisory authorities. Open-source models face reduced requirements, while closed-source models must meet broader transparency standards.

High-impact models posing systemic risks, defined as those requiring more than 1025 floating-point operations to train, must undergo additional evaluations. These include model evaluations, adversarial testing, risk assessment for bias and security failures, serious incident reporting, and adequate cybersecurity measures. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security. Participation in the code is voluntary, but the guidelines clarify that following the code can help demonstrate compliance.

## Conformity Assessments and Enforcement

The guidelines explain the conformity assessment procedures that high-risk AI providers must follow. These assessments verify that systems meet the Act's requirements for data governance, technical documentation, traceability, human oversight, accuracy, and robustness. Providers must evaluate systems both before market placement and throughout their life cycle, with updates triggering reassessment where necessary.

The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure consistent enforcement across member states. National supervisory authorities are responsible for market surveillance, handling complaints, and imposing penalties for non-compliance. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights. The guidelines recommend that authorities coordinate through the Board to avoid fragmentation and ensure uniform application.

## Practical Implementation Guidance

For organisations deploying AI, the guidelines offer practical steps for determining whether their systems fall within the Act's scope and which risk category applies. They advise conducting a preliminary screening to check for exemptions, then mapping system functions against the risk criteria. For high-risk systems, providers must establish a quality management system, maintain logs, and ensure human oversight mechanisms are in place.

The guidelines also address the interaction between the AI Act and other EU legislation, particularly the General Data Protection Regulation. They clarify that the AI Act does not override data protection rules but complements them, with overlapping obligations for systems processing personal data. Deployers must ensure that their use of AI complies with both frameworks, and the guidelines provide examples of how to reconcile requirements in practice.

## Sector-Specific Considerations

The guidelines include annexes with sector-specific examples, covering areas such as healthcare, education, recruitment, and law enforcement. For healthcare, AI systems used for diagnosis or treatment recommendations are typically high-risk, requiring rigorous testing and clinical validation. In education, systems that evaluate student performance or determine access to educational opportunities fall under high-risk obligations. Recruitment tools that screen or rank candidates are also high-risk, with requirements for transparency and non-discrimination.

Law enforcement applications receive particular attention, given the sensitive nature of their use. The guidelines reiterate the ban on real-time remote biometric identification in public spaces, with limited exceptions for specific serious crimes and with prior judicial authorisation. They also clarify that AI systems used for crime prediction or risk assessment must meet high-risk obligations, including human oversight and fundamental rights impact assessments.

## Future Developments and Revisions

The guidelines are intended to evolve alongside the technology and the Act's phased implementation. The Commission has indicated that it will issue additional guidance as new provisions become applicable, particularly for general-purpose AI and high-risk systems. The voluntary code of conduct for minimal-risk systems may be updated based on stakeholder feedback. The guidelines also note that the list of high-risk applications can be expanded through delegated acts, and the Commission will monitor technological developments such as advances in [machine-learning](https://www.wikiprompt.org/wiki/machine-learning) and [deep-learning](https://www.wikiprompt.org/wiki/deep-learning) to determine whether regulatory adjustments are needed.

As of 2025, the guidelines remain a living document, with the Commission encouraging feedback from industry, civil society, and national authorities. The goal is to support innovation while ensuring that AI systems deployed in the EU respect fundamental rights and safety standards. Providers from outside the EU, including major technology companies, must familiarise themselves with these guidelines if they offer services to EU users, as the Act's extraterritorial reach applies to them.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-guidelines
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:51:28.703628+00:00
