# EU AI Act Text

The EU AI Act is a European Union regulation establishing a risk-based legal framework for artificial intelligence, entering into force on 1 August 2024. It classifies AI applications into unacceptable, high, limited, and minimal risk categories, with additional rules for general-purpose AI.

The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) within the EU. It entered into force on 1 August 2024, with provisions coming into operation gradually over the following 6 to 36 months. The Act covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context.

The Act classifies non-exempt AI applications by their risk of causing harm, with four levels – unacceptable, high, limited, minimal – plus an additional category for general-purpose AI. Applications with unacceptable risks are banned; high-risk applications must comply with security, transparency and quality obligations and undergo conformity assessments; limited-risk applications only have transparency obligations; minimal-risk applications are not regulated. For general-purpose AI, transparency requirements are imposed, with reduced requirements for open source models, and additional evaluations for high-capability models. The Act also creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.

## Legislative History

The European Commission proposed the AI Act on 21 April 2021. The draft was revised to address the rise in popularity of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework. The European Parliament passed the Act on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The final text was published in the Official Journal of the EU, and the regulation entered into force on 1 August 2024. The phased implementation means that certain provisions, such as bans on unacceptable-risk systems, apply earlier, while others, such as obligations for high-risk systems, apply later.

## Risk Categories

The AI Act establishes a risk-based scheme following a product-safety model. Regulatory duties are assigned to providers and deployers of AI systems, and these duties become more demanding as the potential impact on health, safety, or fundamental rights increases. This structure ensures that oversight focuses on systems likely to create significant risks while allowing lighter approaches for uses considered less sensitive. Some legal scholars argue that, in practice, the Act frames 'trustworthy AI' as systems that can show compliance with these safety and risk thresholds. According to an initial appraisal by the European Parliamentary Research Service, the Commission's impact assessment drew on stakeholder consultations and a wide range of existing research when comparing policy options for this risk-based framework.

### Unacceptable Risk

AI applications in this category are banned, except for specific exemptions. When no exemption applies, this includes AI applications that manipulate human behaviour, those that use real-time remote biometric identification (such as facial recognition) in public spaces, and those used for social scoring (ranking individuals based on their personal characteristics, socio-economic status, or behaviour).

### High-Risk

AI applications that are expected to pose significant threats to health, safety, or the fundamental rights of persons fall into this category. Notably, AI systems used in health, education, recruitment, critical infrastructure management, law enforcement or justice are included. They are subject to quality, transparency, human oversight and safety obligations, and in some cases require a Fundamental Rights Impact Assessment before deployment. A Fundamental Rights Impact Assessment (FRIA) is an ex ante review to identify and mitigate potential impacts on fundamental rights before an AI system is deployed. Earlier work on algorithmic impact assessments has suggested that such tools should identify which individuals and communities are affected by an automated system, describe possible harms, and provide a basis for public and institutional scrutiny of its use. High-risk systems must be evaluated both before they are placed on the market and throughout their life cycle. The list of high-risk applications can be expanded over time without modifying the AI Act itself. Citizens also have a right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.

### Limited Risk

AI systems in this category have transparency obligations, ensuring users are informed that they are interacting with an AI system and allowing them to make informed choices. This category includes, for example, AI applications that make it possible to generate or manipulate images, sound, or videos (like deepfakes).

### Minimal Risk

This category includes, for example, AI systems used for video games or spam filters. Most AI applications are expected to fall into this category. These systems are not regulated, and Member States cannot impose additional regulations due to maximum harmonisation rules. Existing national laws regarding the design or use of such systems are overridden. However, a voluntary code of conduct is suggested.

## General-Purpose AI

Added in 2023, the general-purpose AI category includes foundation models (for example, ChatGPT) that can perform a wide range of tasks. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks (require more than 10^25 floating-point operations to train) must undergo extra evaluation. A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance with the AI Act. Participation in the code is voluntary.

Beyond these basic transparency duties, the Act sets a common list of obligations for providers of general-purpose AI models. They must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. Models that are designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity.

## Exemptions

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. In particular, the Regulation does not apply where AI systems are used exclusively for military, defence or national security purposes, or to systems developed and put into service solely for scientific research. Additionally, AI used for non-professional personal activities is not covered.

## Enforcement and Governance

The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance with the regulation. Each Member State is expected to designate competent authorities for market surveillance and enforcement. The Act can apply extraterritorially to providers from outside the EU if they have users within the EU, similar to the GDPR. Penalties for non-compliance can be significant, though the specific amounts are not detailed in the source facts.

## Impact and Reception

The AI Act is considered a landmark piece of legislation, being the first comprehensive AI law in the world. It has been compared to the GDPR in its potential global influence, as companies outside the EU may choose to comply with its standards to access the EU market. The risk-based approach has been praised for focusing on actual harms, but some critics argue that the definition of high-risk is too broad or that the exemptions for military and security uses are too wide. The Act also aims to foster innovation by providing legal certainty for AI developers and users.

## Relation to Other AI Developments

The AI Act's general-purpose AI provisions were introduced in response to the rapid advancement of generative AI models, such as those developed by [openai](https://www.wikiprompt.org/wiki/openai), [anthropic](https://www.wikiprompt.org/wiki/anthropic), and [google-deepmind](https://www.wikiprompt.org/wiki/google-deepmind). These models, built on [transformer](https://www.wikiprompt.org/wiki/transformer) architectures and trained using [machine-learning](https://www.wikiprompt.org/wiki/machine-learning) techniques, have capabilities that span many domains, making them difficult to fit into traditional product categories. The Act's requirements for transparency and risk assessment are intended to complement technical safety measures like [model-pruning](https://www.wikiprompt.org/wiki/model-pruning) and [data-augmentation](https://www.wikiprompt.org/wiki/data-augmentation), though the Act itself does not prescribe specific technical methods.

## Future Outlook

As of 2025, the AI Act is in its early implementation phase. The European Commission is expected to issue further guidance and delegated acts to clarify certain provisions. The General-Purpose AI Code of Practice, published on 10 July 2025, is a key step in helping providers comply. The Act's long-term impact on AI innovation and deployment in the EU and beyond remains to be seen, but it is likely to shape the global conversation on AI governance for years to come.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-text
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:51:21.546692+00:00
