The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) within the EU. It entered into force on 1 August 2024, with provisions that shall come into operation gradually over the following 6 to 36 months. The Act covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context.
The Act classifies non-exempt AI applications by their risk of causing harm. There are four levels β unacceptable, high, limited, minimal β plus an additional category for general-purpose AI. For general-purpose AI, transparency requirements are imposed, with reduced requirements for open source models, and additional evaluations for high-capability models. The Act also creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance with the regulation. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.
Legislative History
The European Commission proposed the AI Act on 21 April 2021. It passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024. The draft Act was revised to address the rise in popularity of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework. The general-purpose AI category was added in 2023, reflecting the rapid development of large language models and other generative AI systems.
Risk Categories
The Act adopts a risk-based approach, assigning regulatory duties to providers and deployers of AI systems. These duties become more demanding as the potential impact on health, safety, or fundamental rights increases. The categories are:
- Unacceptable risk β AI applications in this category are banned, except for specific exemptions. This includes AI applications that manipulate human behaviour, those that use real-time remote biometric identification (such as facial recognition) in public spaces, and those used for social scoring (ranking individuals based on their personal characteristics, socio-economic status, or behaviour).
- High-risk β AI applications expected to pose significant threats to health, safety, or fundamental rights. This includes AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice. They are subject to quality, transparency, human oversight, and safety obligations, and in some cases require a Fundamental Rights Impact Assessment before deployment. They must be evaluated both before they are placed on the market and throughout their life cycle. Citizens have a right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.
- Limited risk β AI systems in this category have transparency obligations, ensuring users are informed that they are interacting with an AI system. This includes AI applications that generate or manipulate images, sound, or videos (like deepfakes).
- Minimal risk β This includes AI systems used for video games or spam filters. Most AI applications are expected to fall into this category. These systems are not regulated, and Member States cannot impose additional regulations due to maximum harmonisation rules. Existing national laws regarding the design or use of such systems are overridden. A voluntary code of conduct is suggested.
The risk-based scheme follows a product-safety model, ensuring that oversight focuses on systems likely to create significant risks while allowing lighter approaches for uses considered less sensitive. Some legal scholars argue that, in practice, the Act frames "trustworthy AI" as systems that can show compliance with these safety and risk thresholds.
General-Purpose AI Obligations
The general-purpose AI category includes foundation models (for example, ChatGPT) that can perform a wide range of tasks. Providers of general-purpose AI models must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements.
High-impact models that pose systemic risks (require more than 10^25 floating-point operations to train) must undergo extra evaluation. These models must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity.
A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance with the AI Act. Participation in the code is voluntary.
Exemptions
Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The Regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for scientific research. Non-professional use is also exempt.
Enforcement and Extraterritoriality
The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance with the regulation. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU. This means that companies such as OpenAI, Anthropic, and Google DeepMind may be subject to the Act if they offer services to EU users.
Impact on AI Development
The AI Act's general-purpose AI provisions have significant implications for the development and deployment of AI systems. Providers must now consider transparency and copyright obligations from the design stage. The requirement to publish training data summaries may affect proprietary models, while open-source models face reduced requirements, potentially encouraging more open development. The systemic risk evaluations for high-capability models could influence the training of very large neural networks, as providers may need to allocate resources for safety testing.
The Act also interacts with broader trends in machine learning and deep learning. For example, the focus on transparency aligns with efforts to document training data and model behaviour, as seen in research on model pruning and data augmentation. The Act's requirements for technical documentation may push providers to adopt more rigorous practices, such as those used in transformer architectures and multi-head attention mechanisms.
Reception and Criticism
The AI Act has been met with mixed reactions. Some stakeholders welcome the regulatory clarity it provides, while others express concerns about compliance costs and potential stifling of innovation. The extraterritorial reach has been a particular point of debate, as it may affect global AI providers. The voluntary code of practice for minimal-risk systems is seen as a flexible approach, but some argue that the Act's risk categories are not always clear-cut, especially for general-purpose AI that can be used in multiple contexts.
As of 2025, the Act is in its gradual implementation phase, with provisions coming into operation over 6 to 36 months from August 2024. The full impact on the AI industry will become clearer as enforcement begins and case law develops.