← Back to Library
EU AI Act

Regulation (EU) 2024/1689 — EU AI Act

Full Name:
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
Acronym:
EU AI Act
Type:
European Union Regulation
Organization:
European Union
Version:
2024
Year Published:
2024
Popularity:
High

Overview of the EU Artificial Intelligence Act

Regulation (EU) 2024/1689, commonly known as the EU AI Act, is the world's first comprehensive legal framework governing artificial intelligence. Published in the Official Journal of the European Union on 12 July 2024 and entering into force on 1 August 2024, the regulation establishes harmonized rules for the development, placement on the market, deployment, and use of AI systems across the European Union. Unlike a directive, the AI Act is a regulation that applies directly in all EU member states without requiring national transposition, creating a single, consistent legal regime for AI governance across the internal market.

The AI Act adopts a risk-based approach that calibrates regulatory obligations to the potential harm an AI system may cause. Rather than treating all AI equally, the regulation categorizes AI systems into tiers — unacceptable risk, high risk, limited risk with transparency obligations, and minimal risk — and applies proportionate requirements to each tier. This structure enables innovation in lower-risk applications while imposing strict safeguards where AI systems may affect fundamental rights, safety, or democratic processes. The regulation covers the full AI value chain, assigning responsibilities to providers, deployers, importers, distributors, and other actors depending on their role in bringing AI systems to market or putting them into service.

Beyond traditional AI systems, the regulation introduces dedicated rules for general-purpose AI (GPAI) models — foundation models capable of performing a wide range of tasks — recognizing that these models underpin many downstream applications and carry systemic risks when deployed at scale. Providers of GPAI models face transparency, documentation, and copyright compliance obligations, with additional requirements for models presenting systemic risk. The regulation also establishes governance structures including an AI Office within the European Commission, national market surveillance authorities, and notified bodies for conformity assessment of high-risk systems.

Implementation follows a staggered timeline reflecting the complexity of the obligations. Prohibited AI practices become enforceable approximately six months after entry into force (around February 2025), GPAI model rules apply twelve months after entry into force (August 2025), and most high-risk AI system obligations take effect twenty-four months after entry into force (August 2026). High-risk AI systems embedded in products already regulated under EU product safety legislation receive a longer transition period of thirty-six months (August 2027). Organizations operating in or serving the EU market must begin compliance planning immediately, as early obligations take effect well before the full regulatory framework is fully applicable.

Regulatory Framework and Applicability

The EU AI Act applies extraterritorially to providers and deployers whose AI systems are placed on the EU market or whose outputs are used within the EU, regardless of where the provider is established. This broad scope means that organizations headquartered outside the EU — including in the United States, United Kingdom, and Asia — must comply if their AI products or services reach EU users or affect persons located in the EU. The regulation defines key roles including providers (entities that develop AI systems and place them on the market), deployers (entities that use AI systems under their authority), importers, distributors, and authorized representatives.

Providers bear the heaviest obligations, including conformity assessment, technical documentation, quality management systems, and post-market monitoring for high-risk AI systems. Deployers must use AI systems in accordance with provider instructions, conduct fundamental rights impact assessments where required, and ensure human oversight for high-risk applications. Importers and distributors must verify that providers have fulfilled their obligations before making AI systems available on the EU market. The regulation also addresses specific use contexts including law enforcement, migration, and critical infrastructure, where additional safeguards apply.

Certain AI systems and use cases are excluded from the regulation's scope, including AI developed exclusively for military, defense, or national security purposes, AI used solely for scientific research and development before placement on the market, and AI components provided under free and open-source licenses in most circumstances (though GPAI models released under open-source licenses may still face obligations). Organizations must carefully assess whether their AI systems fall within scope and which role they play in the AI value chain, as obligations differ significantly across roles and risk categories.

Risk-Based Classification System

The EU AI Act's risk-based architecture is the central organizing principle of the regulation. Understanding the four risk tiers is essential for determining which obligations apply to any given AI system.

Unacceptable Risk — Prohibited AI Practices

AI practices deemed to pose an unacceptable risk to fundamental rights and EU values are prohibited outright. These banned practices include AI systems that deploy subliminal, manipulative, or deceptive techniques to materially distort behavior and cause significant harm; AI systems that exploit vulnerabilities of specific groups such as children or persons with disabilities; social scoring systems that evaluate individuals based on social behavior leading to detrimental treatment; and real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to narrow exceptions. Organizations must immediately cease development, deployment, or distribution of any AI system that falls within these prohibited categories.

Prohibited practices become enforceable approximately six months after the regulation entered into force — around February 2025 — making this the earliest compliance deadline under the AI Act. Market surveillance authorities may impose the regulation's highest penalties for violations of prohibited AI rules, reflecting the severity of harm these practices may cause.

High-Risk AI Systems

High-risk AI systems face the most comprehensive set of obligations under the regulation. These include AI systems used as safety components or products covered by EU harmonization legislation listed in Annex I (such as machinery, medical devices, and toys), and AI systems in specific application areas listed in Annex III including biometric identification, critical infrastructure management, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice. High-risk systems must undergo conformity assessment before placement on the market, maintain extensive technical documentation, implement risk management and quality management systems, ensure data governance and training data quality, provide transparency to deployers, enable human oversight, and achieve appropriate levels of accuracy, robustness, and cybersecurity.

Most high-risk AI obligations become applicable twenty-four months after entry into force — August 2026 — though high-risk AI embedded in products already subject to EU product safety legislation under Annex I receive until August 2027. Providers must register high-risk AI systems in an EU database before market placement and implement post-market monitoring to detect and address performance degradation or emerging risks.

Limited Risk — Transparency Obligations

AI systems that interact directly with natural persons or generate synthetic content face transparency obligations without the full conformity assessment requirements of high-risk systems. Deployers and providers must ensure that persons are informed when they are interacting with an AI system (such as chatbots), that AI-generated or manipulated content is marked as such (including deepfakes and text-to-image outputs), and that emotion recognition or biometric categorization systems disclose their operation to affected persons. These transparency requirements aim to prevent deception and enable informed consent without imposing the full regulatory burden of the high-risk category on lower-stakes applications.

Minimal Risk

The vast majority of AI applications — including AI-enabled recommendation engines, spam filters, and many business productivity tools — fall into the minimal risk category and face no mandatory obligations under the AI Act. The regulation encourages providers of minimal-risk AI to adopt voluntary codes of conduct aligned with the regulation's principles, but compliance is not legally required. Organizations should nonetheless document their risk classification rationale, as market surveillance authorities may investigate systems that appear misclassified.

General-Purpose AI Model Requirements

The EU AI Act introduces a dedicated chapter for general-purpose AI (GPAI) models — AI models trained on broad data capable of competently performing a wide range of distinct tasks. This category covers foundation models and large language models that serve as the basis for many downstream AI applications. GPAI model providers must prepare and maintain technical documentation, provide information and documentation to downstream providers enabling them to understand model capabilities and limitations, implement policies to comply with EU copyright law, and publish a summary of training data content.

GPAI models that pose systemic risk — defined as models trained using computing power above 10^25 FLOPs or designated as systemic by the European Commission — face additional obligations including model evaluation and adversarial testing, assessment and mitigation of systemic risks, tracking and reporting of serious incidents, and ensuring adequate cybersecurity protections. Providers of systemic-risk GPAI models must also report energy consumption during training. These GPAI obligations become applicable twelve months after entry into force — August 2025 — ahead of most high-risk system requirements, reflecting policymakers' recognition that foundation models require early oversight.

Providers placing GPAI models on the EU market must appoint an authorized representative in the EU if they are not established in the Union. Open-source GPAI models are largely exempt from provider obligations unless they present systemic risk, balancing innovation in open research with accountability for the most powerful models.

Key Obligations for Providers and Deployers

High-risk AI providers must implement a quality management system ensuring compliance throughout the AI system lifecycle, conduct conformity assessment (self-assessment or third-party depending on the system type), draw up an EU declaration of conformity, and affix CE marking before market placement. Technical documentation must demonstrate compliance with requirements including risk management, data governance, technical robustness, and human oversight capabilities. Providers must also implement post-market monitoring systems, report serious incidents to market surveillance authorities, and cooperate with authority investigations.

Deployers of high-risk AI systems must take appropriate technical and organizational measures to ensure use in accordance with provider instructions, assign human oversight to competent persons, monitor system operation for anomalies, and maintain logs where under their control. Deployers in the public sector and private entities providing public services must conduct fundamental rights impact assessments before deploying high-risk AI. Deployers must inform workers and worker representatives when high-risk AI is used in employment contexts.

All providers and deployers must ensure a sufficient level of AI literacy among staff and others dealing with AI system operation and use, taking into account their technical knowledge, experience, and the context in which the AI systems are used. This AI literacy requirement applies across risk categories and supports the regulation's goal of responsible AI adoption throughout organizations.

Staggered Implementation Timeline

The EU AI Act's obligations phase in over a multi-year period, requiring organizations to track multiple compliance deadlines rather than treating the regulation as a single effective date.

February 2025 (6 months): Prohibitions on unacceptable-risk AI practices become enforceable. Organizations must audit AI portfolios and cease any prohibited practices including manipulative AI, social scoring, and unauthorized real-time biometric identification.

August 2025 (12 months): GPAI model obligations take effect, including technical documentation, copyright compliance, and systemic risk requirements for the most powerful models. GPAI providers must also meet codes of practice obligations developed by the AI Office.

August 2026 (24 months): Most high-risk AI system requirements become fully applicable, including conformity assessment, CE marking, registration, and deployer obligations for Annex III use cases. This represents the primary compliance deadline for most organizations deploying or providing high-risk AI.

August 2027 (36 months): High-risk AI systems that are safety components of products covered by Annex I EU harmonization legislation receive the extended transition period, aligning AI Act requirements with existing product safety conformity assessment processes.

Penalties and Enforcement

The EU AI Act establishes significant financial penalties designed to ensure compliance across the AI value chain. Market surveillance authorities in each member state are responsible for enforcement, with the European AI Office coordinating GPAI model oversight and cross-border cases. Penalties are structured in tiers reflecting violation severity.

Violations of prohibited AI practices may result in administrative fines of up to €35 million or 7% of the offender's total worldwide annual turnover for the preceding financial year, whichever is higher. Violations of other AI Act obligations — including high-risk system requirements and GPAI model rules — may result in fines up to €15 million or 3% of global annual turnover. Supplying incorrect, incomplete, or misleading information to notified bodies or market surveillance authorities may result in fines up to €7.5 million or 1% of global annual turnover. Small and medium enterprises and startups receive proportionate caps, but penalties remain substantial relative to most prior AI governance frameworks.

Enforcement mechanisms include market surveillance investigations, product recalls, requirements to withdraw or disable non-compliant AI systems, and public disclosure of non-compliance. The regulation also provides for Union testing facilities to support conformity assessment and market surveillance activities for high-risk AI systems.

Implementation Strategies and Best Practices

Organizations subject to the EU AI Act should begin compliance preparation immediately, prioritizing early deadlines for prohibited practices and GPAI obligations before addressing the broader high-risk requirements effective in 2026.

Conduct an AI Inventory and Risk Classification: Catalog all AI systems in development and deployment, classify each against the regulation's risk tiers, and document classification rationale. Engage legal, technical, and business stakeholders to ensure classifications reflect actual system capabilities and use contexts rather than marketing descriptions.

Establish AI Governance Structures: Designate accountable leadership for AI compliance, establish cross-functional AI governance committees, and integrate AI risk management into existing enterprise risk and compliance programs. Board-level oversight is particularly important for high-risk AI and GPAI model development.

Implement High-Risk Compliance Programs: For high-risk AI systems, develop quality management systems, risk management processes, data governance frameworks, and technical documentation templates aligned with Annex IV requirements. Plan conformity assessment pathways early, including engagement with notified bodies where third-party assessment is required.

Address GPAI Model Obligations: Organizations developing or distributing foundation models must prepare technical documentation, copyright compliance policies, and — for systemic risk models — adversarial testing and incident reporting capabilities before the August 2025 deadline.

Build AI Literacy: Develop training programs ensuring staff involved in AI development, deployment, and oversight understand the regulation's requirements, their organization's AI inventory, and their specific responsibilities under the AI Act.

Integrate with Existing Compliance Programs: Map AI Act requirements to existing cybersecurity, privacy, and product safety programs. Leverage ISO/IEC 27001:2022 information security management systems and NIS2 cybersecurity requirements as foundations for AI system cybersecurity obligations under the AI Act.

Relationship to Other Frameworks and Standards

The EU AI Act exists within a growing ecosystem of AI governance and cybersecurity frameworks. Organizations managing multiple compliance obligations benefit from understanding how these frameworks relate and where requirements overlap.

NIST AI Risk Management Framework (AI RMF) 1.0 provides voluntary guidance for managing AI risks across the lifecycle through four core functions: Govern, Map, Measure, and Manage. While the NIST AI RMF is not legally binding, its risk-based structure and emphasis on trustworthy AI characteristics align closely with EU AI Act principles. Organizations can use the NIST AI RMF to build AI governance programs that satisfy AI Act requirements, particularly for risk management, documentation, and human oversight. The AI RMF's flexibility complements the AI Act's prescriptive obligations, providing implementation guidance where the regulation specifies outcomes but not methods.

NIS2 (Directive (EU) 2022/2555) establishes cybersecurity requirements for essential and important entities across critical sectors. High-risk AI systems under the AI Act must achieve appropriate levels of cybersecurity, and organizations subject to both NIS2 and the AI Act must ensure AI systems meet cybersecurity requirements under both frameworks. Incident reporting under NIS2 may intersect with AI Act serious incident reporting for GPAI models and high-risk systems, requiring coordinated response procedures.

ISO/IEC 27001:2022 provides a management system framework for information security that supports AI Act cybersecurity and data governance requirements. Organizations with certified ISMS can extend their existing risk assessment, control implementation, and continuous improvement processes to address AI-specific risks. ISO/IEC 27001's supplier relationship controls also support AI Act requirements for managing third-party AI components and GPAI model dependencies.

The AI Act also intersects with the GDPR for personal data processing by AI systems, the EU Data Act for data access and portability, and sector-specific regulations including the Medical Device Regulation and Machinery Regulation for high-risk AI embedded in regulated products. Integrated compliance programs that address these intersections reduce duplication and ensure consistent governance across legal requirements.

Common Challenges and Solutions

Organizations preparing for EU AI Act compliance encounter recurring challenges related to classification uncertainty, documentation burden, and cross-functional coordination.

Determining Risk Classification: The boundary between limited-risk and high-risk AI systems is not always clear, particularly for AI systems that may be used in multiple contexts. Solution: Conduct structured classification assessments for each intended purpose, document reasoning, and reassess when use cases change. Seek legal guidance for borderline cases and monitor European Commission guidance and delegated acts that may clarify classifications.

Conformity Assessment Complexity: High-risk AI conformity assessment requires extensive technical documentation and may require third-party notified body involvement. Solution: Begin documentation during development rather than after deployment. Use Annex IV technical documentation requirements as a development checklist. Engage notified bodies early for systems requiring third-party assessment.

GPAI Model Chain of Accountability: Organizations using GPAI models from third-party providers must rely on provider documentation while remaining accountable for downstream high-risk deployments. Solution: Include AI Act compliance requirements in vendor contracts, verify provider documentation completeness, and maintain records demonstrating due diligence on upstream model selection.

Multi-Jurisdiction Operations: Organizations operating globally must comply with the AI Act for EU activities while managing different AI governance requirements elsewhere. Solution: Establish a baseline AI governance program aligned with AI Act requirements and map regional variations. Use the AI Act's risk-based structure as a foundation that accommodates additional jurisdictional requirements.

Resource and Expertise Constraints: AI Act compliance requires legal, technical, and operational expertise that many organizations lack. Solution: Prioritize compliance activities by deadline and risk tier, leverage external advisors for conformity assessment, and build internal AI literacy progressively across the organization.

Frequently Asked Questions

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Published in the Official Journal on 12 July 2024 and entering into force on 1 August 2024, it establishes harmonized rules across the EU for developing, deploying, and using AI systems. The regulation uses a risk-based approach — prohibiting the most harmful AI practices, imposing strict requirements on high-risk systems, applying transparency rules to limited-risk applications, and leaving minimal-risk AI largely unregulated.

Who does the EU AI Act apply to?

The AI Act applies to providers placing AI systems on the EU market, deployers using AI systems within the EU, importers, distributors, and manufacturers of AI systems — regardless of where they are established, if their AI outputs are used in the EU. This extraterritorial scope means non-EU companies must comply when serving EU customers or users. Obligations vary by role: providers face the most extensive requirements including conformity assessment for high-risk systems, while deployers must use AI in accordance with provider instructions and conduct impact assessments where required.

What are the EU AI Act risk categories?

The regulation defines four risk tiers. Unacceptable risk covers prohibited AI practices including manipulative AI, social scoring, and unauthorized real-time biometric identification — these are banned outright. High-risk AI includes systems in Annex III use cases (employment, critical infrastructure, law enforcement, education, and others) and safety components of regulated products, subject to conformity assessment, documentation, and monitoring requirements. Limited risk systems face transparency obligations such as disclosing AI interaction and marking synthetic content. Minimal risk AI has no mandatory requirements, though voluntary codes of conduct are encouraged.

What are the penalties for EU AI Act non-compliance?

Penalties are tiered by violation severity. Prohibited AI practices may result in fines up to €35 million or 7% of global annual turnover. Other AI Act violations may result in fines up to €15 million or 3% of global turnover. Supplying incorrect or misleading information to authorities may result in fines up to €7.5 million or 1% of global turnover. Market surveillance authorities in each EU member state enforce these penalties, with the European AI Office coordinating GPAI model oversight.

How does the EU AI Act compare to the NIST AI RMF?

The EU AI Act is binding EU law with specific obligations, deadlines, and penalties, while the NIST AI Risk Management Framework is voluntary US guidance. Both adopt risk-based approaches and emphasize trustworthy AI characteristics including transparency, accountability, and human oversight. Organizations can use the NIST AI RMF's Govern, Map, Measure, and Manage functions to structure AI governance programs that also satisfy EU AI Act requirements. The AI RMF provides flexible implementation guidance; the AI Act specifies legally enforceable outcomes, documentation, and conformity assessment processes.

When is the EU AI Act fully applicable?

The AI Act phases in through staggered deadlines rather than a single effective date. Prohibited AI practices are enforceable from approximately February 2025 (six months after entry into force). GPAI model rules apply from August 2025 (twelve months). Most high-risk AI system obligations apply from August 2026 (twenty-four months). High-risk AI embedded in products under existing EU product safety legislation (Annex I) has until August 2027 (thirty-six months). Organizations should treat February 2025 as the first critical compliance milestone and plan for full high-risk compliance by August 2026.

Conclusion

Regulation (EU) 2024/1689 establishes a landmark regulatory framework that will shape AI development and deployment globally. Its risk-based architecture — prohibiting unacceptable practices, imposing rigorous requirements on high-risk systems, mandating transparency for limited-risk applications, and establishing dedicated GPAI model rules — provides a structured path for trustworthy AI while preserving space for innovation in lower-risk applications.

Organizations must act on multiple timelines, addressing prohibited practices by early 2025, GPAI obligations by August 2025, and comprehensive high-risk compliance by August 2026. Success requires cross-functional AI governance, systematic risk classification, robust documentation, and integration with existing cybersecurity and privacy programs including ISO/IEC 27001, NIS2, and the voluntary NIST AI RMF.

By treating AI Act compliance as an ongoing governance program rather than a one-time certification exercise, organizations can build AI capabilities that meet EU legal requirements while establishing trust with users, customers, and regulators in an increasingly AI-driven economy.