The EU AI Act Proposal 2021 is a landmark regulatory initiative by the European Commission to govern the development and use of artificial intelligence within the European Union. Proposed on 21 April 2021, it aims to establish a common legal framework for AI, classifying systems by risk and imposing corresponding obligations on providers and deployers. The regulation entered into force on 1 August 2024, with provisions phased in over the following 6 to 36 months, and applies extraterritorially to providers outside the EU with users within the bloc.
The proposal underwent significant revision to address the rise of Generative AI systems such as ChatGPT, whose general-purpose capabilities did not fit the original risk categories. It passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024.
Risk-Based Classification
The Act adopts a product-safety model, assigning regulatory duties that increase with potential harm. It defines four primary risk levels plus a separate category for general-purpose AI:
- Unacceptable risk: Banned applications include those that manipulate human behavior, use real-time remote biometric identification in public spaces, or enable social scoring. Narrow exemptions apply for specific cases.
- High risk: Systems in health, education, recruitment, critical infrastructure, law enforcement, or justice must meet quality, transparency, human oversight, and safety obligations. Some require a Fundamental Rights Impact Assessment before deployment, and citizens can submit complaints or request explanations for decisions affecting their rights.
- Limited risk: Transparency obligations apply, such as informing users they are interacting with AI or that content like deepfakes is AI-generated.
- Minimal risk: Unregulated systems, such as video games or spam filters, fall here. Member states cannot impose additional rules due to maximum harmonisation, though a voluntary code of conduct is suggested.
The list of high-risk applications can be expanded without amending the Act itself. The European Parliamentary Research Service noted that the Commission's impact assessment drew on stakeholder consultations and existing research when designing this framework.
General-Purpose AI Provisions
Added in 2023, this category covers foundation models like large language models that perform a wide range of tasks. Open-source models must publish a training data summary and copyright policy; closed-source models face broader transparency requirements. High-impact models requiring more than 10^25 floating-point operations to train are designated as posing systemic risk and must undergo model evaluations, adversarial testing, risk mitigation for bias and security failures, incident reporting, and adequate cybersecurity measures.
A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation is voluntary.
Exemptions and Scope
Articles 2.3 and 2.6 exempt AI systems used exclusively for military, defence, or national security purposes, as well as pure scientific research and development. The Act does not create individual rights but places duties on professional providers and deployers. It covers most sectors, with non-professional personal use also excluded.
Institutional Framework
The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the General Data Protection Regulation, it can apply to providers outside the EU if they have users within the bloc, extending its regulatory reach globally.
The phased implementation means obligations will come into operation gradually over 6 to 36 months from August 2024, allowing stakeholders time to adapt. The framework is designed to balance innovation with protection of health, safety, and fundamental rights, reflecting a precautionary approach to AI governance.