Skip to content
Thursday 2026-07-30 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

Definition

EU AI Act: The World’s First Comprehensive AI Law Explained

Updated

What the EU AI Act Is

Think of the EU AI Act as a building code for artificial intelligence. A building code does not tell an architect what to design — it sets minimum safety standards so that the finished structure does not collapse, catch fire, or poison its occupants. The AI Act works the same way: it does not dictate what AI systems companies can build, but it defines the safety, transparency, and accountability requirements those systems must meet before they can be sold or deployed on the EU market.

The law — formally Regulation (EU) 2024/1689 — was published on June 13, 2024 and entered into force on August 1, 2024. It is administered by the European AI Office within the European Commission for general-purpose AI models, and by national competent authorities in each EU member state for other AI systems.

How the Risk Categories Work

The Act does not regulate all AI the same way. Instead, it sorts AI systems into four risk levels, and the obligations scale with the potential for harm.

Unacceptable risk systems are banned outright. This includes AI that uses subliminal manipulation to distort behavior and cause harm, social scoring systems that evaluate people based on social behavior or personality traits, and real-time remote biometric identification in publicly accessible spaces by law enforcement (with narrow, court-authorized exceptions). Emotion recognition in workplaces and schools is also prohibited in most circumstances.

High-risk systems are permitted but subject to the Act’s strictest requirements. This category covers AI used in critical infrastructure, education, employment, law enforcement, migration management, and justice. Providers of high-risk systems must implement a risk management system, maintain technical documentation, ensure data governance, provide transparency to deployers, build in human oversight mechanisms, and meet accuracy, robustness, and cybersecurity standards. These systems require a conformity assessment before they can be placed on the market.

Transparency risk systems face lighter obligations focused on disclosure. If you are interacting with a chatbot, viewing AI-generated content, or encountering an emotion-recognition system, the Act requires that you be informed. The goal is simple: you have a right to know when you are dealing with a machine.

Minimal or no risk systems — spam filters, recommendation algorithms, most consumer applications — face no additional regulatory requirements under the Act.

Extraterritorial Reach

The Act does not stop at EU borders. Any provider or deployer that places an AI system on the EU market, or whose AI outputs are used within the EU, must comply — regardless of where the company is headquartered. A San Francisco startup selling AI-powered hiring tools to German companies is subject to the same rules as a Berlin-based firm. This extraterritorial scope is similar to how the GDPR reached global companies through their EU user base.

A Worked Example: AI Hiring Software

Consider a company that sells AI software to screen job applicants. The software reviews resumes, scores candidates, and recommends who should advance to interviews. Under the Act, this is a high-risk system because it is used in employment — one of the Annex III high-risk domains.

The provider must now: conduct a conformity assessment proving the system meets safety and performance standards; maintain a risk management system that identifies and mitigates potential harms (such as bias against protected groups); provide technical documentation so deployers understand how the system works; ensure a human can override or review the AI’s recommendations before they affect a candidate’s application; and register the system in the EU’s public database of high-risk AI systems.

If the same company also sells a simple chatbot for its careers page that answers basic questions about open positions, that chatbot falls under transparency risk — it must disclose that the user is interacting with AI, but it does not face the full high-risk compliance burden.

General-Purpose AI Obligations

The Act includes specific rules for general-purpose AI (GPAI) model providers — the companies behind large foundation models like those powering AI agents. These obligations, which took effect on August 2, 2025, require providers to share technical documentation with downstream deployers, comply with EU copyright law, and publish summaries of training data content.

Models classified as posing systemic risk — defined by a compute threshold of more than 10^25 floating-point operations during training — face additional obligations: conducting model evaluations, performing adversarial testing, reporting serious incidents to the AI Office, and implementing cybersecurity protections. The AI Office has exclusive competence for supervising and enforcing these GPAI rules.

Penalties

The enforcement teeth are real. Article 99 sets three penalty tiers:

  • Prohibited practices: Up to €35 million or 7 percent of total worldwide annual turnover, whichever is higher.
  • Other violations (high-risk obligations, transparency rules): Up to €15 million or 3 percent of turnover.
  • Misleading information to authorities: Up to €7.5 million or 1 percent of turnover.

For small and medium-sized enterprises and startups, the lower of the fixed amount or the percentage applies. Member states set the actual penalty amounts within these maximums and designate national authorities to enforce them.

The Enforcement Timeline

The Act rolls out in phases, with one significant adjustment made after publication:

  • February 2, 2025: Prohibited AI practices and AI literacy obligations became applicable.
  • August 2, 2025: Governance rules and general-purpose AI model obligations became applicable.
  • August 2, 2026: Transparency obligations and full applicability for most provisions. Member states must also establish regulatory sandboxes — controlled testing environments where companies can develop and validate AI systems under supervisory authority oversight.
  • December 2, 2027: High-risk AI systems in Annex III domains (employment, law enforcement, education, etc.) face full compliance obligations. This deadline was extended from August 2, 2026 by the Digital Omnibus regulation, adopted by the EU Council on June 29, 2026.
  • August 2, 2028: High-risk AI systems embedded in regulated products under Annex I (such as medical devices, lifts, and toys) face full compliance obligations.

Common Questions

Does the EU AI Act apply to companies outside Europe?

Yes. The Act has extraterritorial reach. If your AI system is placed on the EU market or its outputs are used within the EU, you must comply — regardless of where your company is based. This is the same jurisdictional logic the GDPR uses.

What counts as a “high-risk” AI system?

The Act identifies eight domains in Annex III: biometric identification, critical infrastructure management, education and vocational training, employment and worker management, access to essential services (including credit scoring), law enforcement, migration and border control, and justice and democratic processes. AI systems used in these areas are high-risk by default, unless they pose limited risk in the specific context.

Is the EU AI Act already in effect?

Partially. The prohibition on banned AI practices and AI literacy requirements took effect on February 2, 2025. General-purpose AI obligations began on August 2, 2025. Most remaining provisions — including the high-risk compliance framework — are phasing in through 2027 and 2028. The Act is being enforced now, but not all obligations are active yet.

How does this affect AI agents and agent compliance?

AI agents that operate autonomously — making decisions, executing transactions, or interacting with humans on behalf of users — may fall into multiple risk categories depending on their function. An agent that screens job applicants is high-risk. An agent that answers customer service questions has transparency obligations. The Act’s compliance framework requires deployers to assess which category their agent falls into and meet the corresponding obligations. For a deeper look, see the agent compliance explainer and the AI agent security glossary entry.

Maintained by Theodore Wren · updated Jul 19, 2026