European Union

The EU AI Act

The first comprehensive, horizontal AI statute from a major regulator — risk-tiered, phased in over several years, and already shaping how other jurisdictions draft their own AI laws.

Phasing inEffective August 1, 2024
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash
Governome Editorial Team3 min readHow we source and review this content.

The EU AI Act entered into force on August 1, 2024, but "in force" and "fully applicable" are different things for this law — its obligations phase in over roughly three years, and a system that's out of scope today can come into scope as later provisions activate. Treat this page as the status summary, not a substitute for the classification work your specific system needs.

The risk-tier structure

The Act sorts AI systems into four tiers, and the obligations attach to the tier, not to the technology:

  • Unacceptable risk — practices banned outright: social scoring by public authorities, certain forms of manipulative AI, untargeted scraping of facial images for recognition databases, among others. These prohibitions were among the first provisions to take effect.
  • High-risk — systems subject to the Act's most substantial obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, and defined accuracy/robustness/cybersecurity standards. Classification runs through Article 6 — see our full breakdown of how that test actually works.
  • Limited risk — systems (like most chatbots) that face specific transparency obligations, such as disclosing that a user is interacting with AI, without the full high-risk compliance burden.
  • Minimal risk — the majority of AI applications, largely unregulated by the Act itself beyond voluntary codes of conduct.

What's actually in force right now

  • Prohibited practices and AI-literacy obligations — applicable since February 2025.
  • General-purpose AI (GPAI) model obligations — transparency and, for the most capable models, systemic-risk obligations — applicable since August 2025.
  • High-risk system obligations — phasing in on the longest timeline, with the bulk of Annex III high-risk requirements reaching applicability around August 2026, and certain Annex I product-safety-linked high-risk systems on an even longer runway extending into 2027.

Check the effective-date field on this page rather than assuming — we update it when the underlying schedule or guidance changes, and enforcement bodies have signaled some willingness to phase in practical enforcement gradually even after formal applicability dates pass.

Who the Act actually applies to

The Act applies extraterritorially, similarly to the GDPR: providers and deployers outside the EU are in scope if the AI system's output is used within the EU. A U.S. or UK company with no EU office can still fall within scope if it sells or deploys a system that affects people in the EU — this is the single most commonly missed scope question in early compliance planning.

Penalties

Penalties are tiered by violation type, with the most severe reserved for violations of the prohibited-practices provisions — up to the higher of a fixed amount in the tens of millions of euros or a percentage of global annual turnover, a structure that mirrors GDPR's own penalty tiers.

Where to go next

If you're trying to determine whether a specific system is high-risk, our Article 6 classification breakdown walks through the actual two-track test. For how EU AI Act obligations compare with what's expected under ISO/IEC 42001, see our ISO 42001 coverage — the standard is increasingly used as a practical route to demonstrating EU AI Act conformity.

Sources & references

  1. Official source
  2. Regulation (EU) 2024/1689 (full text, EUR-Lex)
  3. European Commission — AI Act overview
Compliance and legal professionals reviewing AI system documentation together
Photo: Amina Atar via Unsplash
Article 6 of the EU AI Act classifies a system as high-risk through a combination of Annex I product-safety overlap and Annex III use-case categories. Here's how the two-step test actually applies, with the exemption most teams get wrong.
Governome Editorial Team · 3 min read
Auditor reviewing AI management system documentation for certification
Photo: Zulfugar Karimov via Unsplash

frameworks

ISO/IEC 42001

ISO/IEC 42001 is a certifiable AI management system standard. Unlike the NIST AI RMF, an accredited body can actually audit you against it and issue a certificate.
Governome Editorial Team · 2 min read