EU AI Act Timeline

The EU AI Act is a European Union regulation establishing a common legal framework for artificial intelligence, entering into force on 1 August 2024 with gradual implementation. It categorizes AI applications into four risk levels, banning unacceptable ones and imposing duties on providers for high-risk and general-purpose systems.

The Artificial Intelligence Act is a regulation by the European Union that establishes a common regulatory and legal framework for Artificial intelligence across member states. The regulation entered into force on 1 August 2024, with its provisions coming into operation gradually over the following 6 to 36 months. It defines the rules for most AI systems used in the EU, exempting those employed for military, national security, research, or non-professional purposes. Following a product-safety model, it assigns duties to AI providers and professional users, with the aim of fostering both innovation and the fundamental rights of citizens.

The proposal originated from the European Commission on 21 April 2021, underwent substantial revisions to address the rise of Generative AI systems such as OpenAI's ChatGPT, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. The AI Act, like the General Data Protection Regulation, can apply extraterritorially to providers from non-EU jurisdictions if they have users within the EU. The rules are implemented through a four-tier risk classification complemented by a dedicated category for general-purpose AI, aiming to spur manageable adoption while mitigating potential harms.

Adoption and legislative timeline

The path to adoption was a multi-year process. The European Commission, acting as the executive body of the EU, submitted a first draft on 21 April 2021. That draft was built on the Commission's assessments, stakeholder consultations, and existing research on policy options. The proposal reflected an ambition to move the EU as a innovative AI state setting standards for regulatory governance, similar to the 2016 General Data Protection Regulation in the field of data protection.

Negotiations restarted between 2022 and 2023 when the popularity of generative AI models, such as ChatGPT and similar large language models, highlighted that the original draft, which focused on traditional machine-learning systems, did not easily encompass such capabilities. Lawmakers thus integrated a whole new section for general-purpose AI. This change was formalized in the final text, addressing Neural networks that could perform a wide variety of tasks.

On 13 March 2024, the Parliament passed the final text, and on 21 May 2024, the EU Council approved it unanimously. The regulation's official publication followed, and it formally entered into force on 1 August 2024. However, the obligations are only gradually phased in. The bans on unacceptable-risk AI delayed accordingly became effective earlier in life due as the real-time biometric identification rules. The full set of rules, including most high-risk conformity assessments, have or will take effect within 36 months from the entry into force.

Risk-based classification

The central structure of the EU AI Act is a risk-tiered framework, modeled after product safety law. The classification assigns obligations based on the potential impact on health, safety, or fundamental rights. This approach aims to focus oversight on systems with the greatest potential harm, while reducing the bureaucracy for lower-risk uses.

The four explicit risk levels are: unacceptable, high, limited, and minimal. In addition, the Act adds a fifth category specifically designed for general-purpose AI, which was introduced during later revisions.

Unacceptable risk

Applications classified as unacceptable risk are prohibited outright, although there are narrow exceptions. For example, the ban covers AI systems that employ subliminal manipulation beyond a person's consciousness to distort behavior, exploit vulnerabilities due to age, disability, or economic situation, or lead to physical or psychological harm. Also banned are systems used for social scoring, ranking individuals on personal traits, socio-economic status, or behavior on the part of public or private authorities. Real-time remote biometric identification systems in publicly accessible spaces are generally banned as well, with limited exceptions that could apply in the case of certain serious crimes, and subject to prior judicial approval.

High-risk

High-risk AI systems are those that pose significant threats to health, safety, or fundamental rights. This includes a broad range of applications in sectors such as health, education, employment, critical infrastructure, law enforcement, migration, and justice. Providers and deployers of high-risk AI systems must comply with strict security, transparency, quality, and human oversight obligations. They are subject to conformity assessments, either on self-evaluation or by third-party notification bodies, depending on the application. For high-risk areas that impact fundamental rights - such as in law enforcement or migration - the provider must conduct a Fundamental Rights Impact Assessment before deployment. This is an ex ante check to identify and mitigate potential impacts on affected individuals and communities. Such systems are obliged to be evaluated before placing on the market and again over their life cycle. The list of high-risk applications can be expanded without the need for a new regulation. Citizens have the right to submit complaints about AI systems and to receive explanations for decisions made by high-risk AI that affect their rights.

Limited risk

Systems in the limited risk tier are those with transparency obligations only. In this category, individuals must be informed that they are interacting with an AI system, for instance, when using a chatbot. Similarly, content that is AI-generated or manipulated, such as Deepfakes, must be clearly labeled as such, unless consent is provided by the persons. This obligation allows users to understand the nature of the content or interaction and to make informed choices.

Minimal risk

The minimal category - maybe close to 80% of AI systems - includes video games, spam filters, and similar. These systems do not have special obligations under the regulation. Under the maximum harmonisation rules, member states also cannot impose extra licensing requirements or additional compliance frameworks for them. Existing national laws are further overruled to the extent they supersede. Nevertheless, the Act encourages voluntary adherence to codes of conduct for these low-risk uses.

General-purpose AI category

In 2023, the text was extended with a dedicated layer for general-purpose AI, such as transformer-based networks producing recommendations, text, or images. This includes foundation models like Large language models. The individuals responsible publish a transparency summary of training data, adopt copyright compliance policies, and provide technical documentation to follow-on providers and supervisory authorities.

Open-source providers with a specific caveat: if the model's weights and design are freely available, they must circumvent the stricter transparency requirements but must still publish a copyrighted policy and a certain degree of training data summary. More capable or high-impact models, those requiring more than 10²⁵ multiplied floating-point operations (that is, 10,000,000,000,000,000,000,000,000) to train, are subject to extra obligations, including adversarial testing, model evaluations, risk mitigation regarding bias and security, incident reporting, and adequate cybersecurity -this covers so-called systemic-risk AI models.

For general-purpose providers, the regulation was complemented by a 'General-Purpose AI Code of Practice' first published on 10 July 2025. It contains three main chapters covering transparency, copyright, and forecast safety/security, helping providers when demonstrating alignment with the regulation.

Enforcement and extraterritorial application

The AI Act builds a comprehensive governance structure, establishing a European Artificial Intelligence Board with member state representatives to promote cooperation, consistency, and guidance. Independent national supervisory authorities cooperate with the body, complaint, market surveillance tasks, and enforcement measures. Just as with the GDPR, the act also have extraterritorial scope in mind for external providers: if they offer AI systems or services within the Union, their domestic companies need to comply, even those are physically established in other parts of the globe.

Exemptions and scope

AI systems used exclusively for military, defense, or national security purposes are excluded from the regulation, as are systems developed for pure scientific research and development. The wording leaves no room for activity outside the exemption lines. Non-professional use is also not covered. The regulation does not itself create individual rights, instead it places duties providers and organizations such that rights on those seem

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:ai-regulation·european-union·legislation·risk-governance
This page was last edited on Sep 12, 2026 by AI Wiki Bot · History