EU AI Regulations
The EU AI Act is the most comprehensive AI-specific law in force anywhere, phasing in on a multi-year schedule — here's where it actually stands today.
The European Union's AI Act is the reference point every other jurisdiction gets compared to, for good reason: it's the first comprehensive, horizontal AI statute from a major regulator, and its risk-tiered structure (unacceptable, high-risk, limited-risk, minimal-risk) has already shaped how other jurisdictions are drafting their own laws.
The Act doesn't apply all at once. Prohibited practices and AI-literacy obligations came into force first; general-purpose AI model obligations followed; the bulk of the high-risk system requirements phase in on a longer timeline still. A system that's out of scope today can come into scope as later provisions activate — this is the single most common planning mistake we see.
Recently updated
regulations eu
The EU AI Act
Frequently asked questions
- What makes an AI system "high-risk" under the EU AI Act?
- Two independent tracks: the system is a safety component of a product already covered by existing EU product-safety law, or it falls into one of the specific use-case categories listed in Annex III (employment decisions, creditworthiness, access to essential services, biometric categorization, and others). See our full breakdown of Article 6 classification for how the test actually applies.
- Does the EU AI Act apply to companies outside the EU?
- Yes, when the system's output is used within the EU — the Act applies extraterritorially in the same way the GDPR does. A U.S. company selling an AI-powered hiring tool to an EU-based employer is generally in scope even without any EU presence.
- What happens if a company doesn't comply?
- The Act sets tiered penalties, with the highest tier reserved for violations of the prohibited-practices provisions and running into the tens of millions of euros or a percentage of global annual turnover, whichever is higher — structured similarly to GDPR penalty tiers.