The EU AI Act at a glance
The EU's AI Regulation (Regulation (EU) 2024/1689) is the world's first comprehensive law for artificial intelligence. It does not regulate AI across the board, but according to the risk of its use, and it affects virtually every company that uses AI.
What is the EU AI Act about?
The EU AI Act entered into force on 1 August 2024 and, as an EU Regulation, applies directly in all member states, without the need for national implementing legislation. Its goal is a trustworthy, safe and fundamental-rights-compliant use of AI in the European single market. The Regulation follows a risk-based approach: the higher the risk an AI application poses to people and society, the stricter the requirements.
Importantly, the EU AI Act has extraterritorial reach. Even providers outside the EU fall under it as soon as their AI systems are placed on the market in the EU or their outputs are used there. The obligations also do not take effect all at once, but gradually, a full timeline is available on our deadlines page.
The risk-based approach: four risk classes
At the heart of the EU AI Act is the classification of AI systems into four risk classes. The class determines the specific obligations:
Unacceptable risk
Prohibited practices, e.g. social scoring by public authorities or manipulative systems. Banned since 2 February 2025.
High risk
AI in sensitive areas (e.g. recruitment, credit scoring, critical infrastructure). Strict requirements for risk management, data quality and human oversight.
Limited risk
Transparency obligations, users must know, for example, that they are talking to a chatbot or that content is AI-generated.
Minimal risk
The majority of today's applications (e.g. spam filters, AI in video games). No special obligations.
Most companies use AI in the minimal or limited risk category. Even so, one fundamental obligation applies regardless of risk class, the AI literacy of employees.
GPAI: general-purpose AI models
A special role is played by GPAI models (General Purpose AI), large, versatile AI models that power modern chatbots and text or image generators. Since 2 August 2025, they are subject to their own obligations, including requirements for technical documentation, transparency towards downstream providers and compliance with copyright law. For particularly capable models with potential systemic risks, additional requirements apply.
Who is affected? Providers, deployers and more
The EU AI Act distinguishes several roles — each with different levels of obligation:
- Providers: develop AI systems or place them on the market under their own name. They carry the most extensive obligations.
- Deployers: use AI in the course of their professional activities, this applies to most companies.
- Importers & distributors: import or distribute AI systems in the EU market and must verify their conformity.
Crucially, even those who "merely" use AI — acting as deployers — are bound by obligations, particularly regarding the AI literacy of their staff. The misconception that "we don't develop AI so it doesn't apply to us" is one of the most common mistakes.
What obligations apply and from when?
The EU AI Act takes effect in stages. The key dates at a glance:
- 1 August 2024: The Regulation enters into force.
- 2 February 2025: Prohibited practices (Art. 5) and the AI literacy obligation (Art. 4) apply.
- 2 August 2025: Obligations for GPAI models, the governance structure and the penalty provisions take effect.
- 2 August 2026: The majority of the rules for high-risk AI systems become applicable.
- 2 August 2027: The last transitional periods for certain high-risk systems expire.
All details and exceptions are explained on our deadlines page.
EU AI Act and GDPR: not either-or
The EU AI Act does not replace the General Data Protection Regulation, both apply in parallel. While the GDPR governs the handling of personal data, the EU AI Act addresses the AI system itself and its risks. Where an AI application processes personal data, companies must comply with both frameworks simultaneously. Sound AI literacy helps employees recognise exactly these interfaces in everyday work.
Penalties for infringements
Infringements of the EU AI Act can trigger substantial fines. The Regulation scales them by severity:
- Up to €35 million or 7% of global annual turnover, only for prohibited practices under Article 5.
- Up to €15 million or 3%, for infringements of other obligations, including the AI literacy obligation under Art. 4.
- Up to €7.5 million or 1.5%, for false or misleading statements to authorities.
For small and medium-sized enterprises and start-ups, the lower of the two amounts serves as the cap. More on the fines page.
What does this mean in practice for your company?
- Get an overview of where AI is used in your company.
- Ensure that employees have sufficient AI literacy under Article 4.
- Complete an EU AI Act training course and document it verifiably, as proof towards the authorities.
- Keep the EU AI Act deadlines in view, in particular 2 August 2026, when the rules for many high-risk AI systems take effect.
Frequently asked questions about the EU AI Act
Does the EU AI Act apply to small businesses too?
Yes. The AI literacy obligation under Article 4 applies to everyone who uses AI professionally, regardless of company size. For fines, however, SMEs bear a lower burden.
Do I need to register my AI systems somewhere?
A registration requirement exists primarily for certain high-risk systems. If you only use AI in the minimal or limited risk category, the AI literacy of your staff is the primary concern. Further answers can be found on our FAQ page.
Train your team now View the fines
Note: this overview is for information only and does not constitute legal advice.