The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) within the EU. It entered into force on 1 August 2024, with provisions becoming applicable gradually over the following 6 to 36 months. The Act classifies non-exempt AI applications by their risk of causing harm, with four levels – unacceptable, high, limited, and minimal – plus an additional category for general-purpose AI. It covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context.
The Act was proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. The draft was revised to address the rise of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework. The Act also creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.
Risk Categories
The risk-based scheme follows a product-safety model in which regulatory duties are assigned to the providers and deployers of AI systems, and these duties become more demanding as the potential impact on health, safety, or fundamental rights increases. This structure ensures that oversight focuses on systems likely to create significant risks while allowing lighter approaches for less sensitive uses. According to an initial appraisal by the European Parliamentary Research Service, the Commission's impact assessment drew on stakeholder consultations and a wide range of existing research when comparing policy options.
Unacceptable Risk
AI applications in this category are banned, except for specific exemptions. When no exemption applies, this includes AI applications that manipulate human behaviour, those that use real-time remote biometric identification (such as facial recognition) in public spaces, and those used for social scoring (ranking individuals based on personal characteristics, socio-economic status, or behaviour).
High-Risk
High-risk applications are those expected to pose significant threats to health, safety, or the fundamental rights of persons. Notably, AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice fall under this category. They are subject to quality, transparency, human oversight, and safety obligations, and in some cases require a Fundamental Rights Impact Assessment (FRIA) before deployment. A FRIA is an ex ante review to identify and mitigate potential impacts on fundamental rights. Earlier work on algorithmic impact assessments has suggested that such tools should identify which individuals and communities are affected by an automated system, describe possible harms, and provide a basis for public and institutional scrutiny. High-risk systems must be evaluated both before they are placed on the market and throughout their life cycle. The list of high-risk applications can be expanded over time without modifying the AI Act itself. Citizens have a right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.
Limited Risk
Limited-risk AI systems have transparency obligations, ensuring users are informed that they are interacting with an AI system and allowing them to make informed choices. This category includes, for example, AI applications that generate or manipulate images, sound, or videos (like deepfakes).
Minimal Risk
Minimal-risk systems include AI used for video games or spam filters. Most AI applications are expected to fall into this category. These systems are not regulated, and Member States cannot impose additional regulations due to maximum harmonisation rules. Existing national laws regarding the design or use of such systems are overridden. However, a voluntary code of conduct is suggested.
General-Purpose AI
Added in 2023, the general-purpose AI category includes foundation models (for example, generative AI models) that can perform a wide range of tasks. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks (requiring more than 10^25 floating-point operations to train) must undergo extra evaluation. A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation in the code is voluntary.
Beyond basic transparency duties, the Act sets a common list of obligations for providers of general-purpose AI models. They must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity.
Exemptions
Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. In particular, the Regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for scientific research. Additionally, AI used for non-professional personal activities is exempt.
Implementation Timeline
The AI Act entered into force on 1 August 2024, but its provisions apply in phases. The prohibitions on unacceptable-risk systems became applicable six months later, around February 2025. Obligations for general-purpose AI models apply from August 2025, and most high-risk system requirements apply from August 2026, with some provisions extending to 2027. This phased approach allows providers and deployers time to adapt.
Enforcement and Governance
The Act establishes the European Artificial Intelligence Board, composed of representatives from Member States and the Commission, to facilitate consistent application and cooperation. National supervisory authorities are responsible for enforcing the regulation, with penalties for non-compliance. The Act can apply extraterritorially to providers outside the EU if their AI systems are used within the EU, similar to the GDPR. This ensures that the risk-based framework has global reach for AI products and services targeting EU users.
Impact and Criticism
Legal scholars have noted that the Act frames "trustworthy AI" as systems that can show compliance with safety and risk thresholds. The risk-based approach has been praised for focusing on high-impact applications, but some critics argue that the classification of high-risk systems may be overly broad or that the exemptions for military and research uses could create gaps. Others point to the challenge of keeping pace with rapid developments in machine learning and deep learning, particularly as AI capabilities evolve. The Act's emphasis on transparency and human oversight is seen as a model for other jurisdictions, though its effectiveness remains to be seen as implementation unfolds.
References
- European Commission proposal, 21 April 2021
- European Parliament passage, 13 March 2024
- EU Council approval, 21 May 2024
- Entry into force, 1 August 2024
- General-Purpose AI Code of Practice, 10 July 2025