EU AI Regulations

The EU AI Act is the most comprehensive AI-specific law in force anywhere, phasing in on a multi-year schedule — here's where it actually stands today.

The European Union's AI Act is the reference point every other jurisdiction gets compared to, for good reason: it's the first comprehensive, horizontal AI statute from a major regulator, and its risk-tiered structure (unacceptable, high-risk, limited-risk, minimal-risk) has already shaped how other jurisdictions are drafting their own laws.

The Act doesn't apply all at once. Prohibited practices and AI-literacy obligations came into force first; general-purpose AI model obligations followed; the bulk of the high-risk system requirements phase in on a longer timeline still. A system that's out of scope today can come into scope as later provisions activate — this is the single most common planning mistake we see.

Recently updated

European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 3 min read

Frequently asked questions

What makes an AI system "high-risk" under the EU AI Act?
Two independent tracks: the system is a safety component of a product already covered by existing EU product-safety law, or it falls into one of the specific use-case categories listed in Annex III (employment decisions, creditworthiness, access to essential services, biometric categorization, and others). See our full breakdown of Article 6 classification for how the test actually applies.
Does the EU AI Act apply to companies outside the EU?
Yes, when the system's output is used within the EU — the Act applies extraterritorially in the same way the GDPR does. A U.S. company selling an AI-powered hiring tool to an EU-based employer is generally in scope even without any EU presence.
What happens if a company doesn't comply?
The Act sets tiered penalties, with the highest tier reserved for violations of the prohibited-practices provisions and running into the tens of millions of euros or a percentage of global annual turnover, whichever is higher — structured similarly to GDPR penalty tiers.

Related topics