European Union
The EU AI Act
The first comprehensive, horizontal AI statute from a major regulator — risk-tiered, phased in over several years, and already shaping how other jurisdictions draft their own AI laws.
The EU AI Act entered into force on August 1, 2024, but "in force" and "fully applicable" are different things for this law — its obligations phase in over roughly three years, and a system that's out of scope today can come into scope as later provisions activate. Treat this page as the status summary, not a substitute for the classification work your specific system needs.
The risk-tier structure
The Act sorts AI systems into four tiers, and the obligations attach to the tier, not to the technology:
- Unacceptable risk — practices banned outright: social scoring by public authorities, certain forms of manipulative AI, untargeted scraping of facial images for recognition databases, among others. These prohibitions were among the first provisions to take effect.
- High-risk — systems subject to the Act's most substantial obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, and defined accuracy/robustness/cybersecurity standards. Classification runs through Article 6 — see our full breakdown of how that test actually works.
- Limited risk — systems (like most chatbots) that face specific transparency obligations, such as disclosing that a user is interacting with AI, without the full high-risk compliance burden.
- Minimal risk — the majority of AI applications, largely unregulated by the Act itself beyond voluntary codes of conduct.
What's actually in force right now
- Prohibited practices and AI-literacy obligations — applicable since February 2025.
- General-purpose AI (GPAI) model obligations — transparency and, for the most capable models, systemic-risk obligations — applicable since August 2025.
- High-risk system obligations — phasing in on the longest timeline, with the bulk of Annex III high-risk requirements reaching applicability around August 2026, and certain Annex I product-safety-linked high-risk systems on an even longer runway extending into 2027.
Check the effective-date field on this page rather than assuming — we update it when the underlying schedule or guidance changes, and enforcement bodies have signaled some willingness to phase in practical enforcement gradually even after formal applicability dates pass.
Who the Act actually applies to
The Act applies extraterritorially, similarly to the GDPR: providers and deployers outside the EU are in scope if the AI system's output is used within the EU. A U.S. or UK company with no EU office can still fall within scope if it sells or deploys a system that affects people in the EU — this is the single most commonly missed scope question in early compliance planning.
Penalties
Penalties are tiered by violation type, with the most severe reserved for violations of the prohibited-practices provisions — up to the higher of a fixed amount in the tens of millions of euros or a percentage of global annual turnover, a structure that mirrors GDPR's own penalty tiers.
Where to go next
If you're trying to determine whether a specific system is high-risk, our Article 6 classification breakdown walks through the actual two-track test. For how EU AI Act obligations compare with what's expected under ISO/IEC 42001, see our ISO 42001 coverage — the standard is increasingly used as a practical route to demonstrating EU AI Act conformity.
Sources & references
Suggested next reading
frameworks