Updated Aug 20, 2026

EU AI Act

The European Union's comprehensive AI law — the first of its kind, and a de facto global standard through reach.

Share

What it means

The AI Act regulates by risk tier rather than by technology. A narrow set of uses is prohibited outright — including social scoring and certain biometric categorization. A larger high-risk tier, covering employment, education, credit, essential services and critical infrastructure, carries substantial obligations: risk management, data governance, technical documentation, logging, human oversight and conformity assessment. Limited-risk uses carry transparency duties, such as disclosing that a user is interacting with an AI. Most applications fall outside these tiers entirely.

General-purpose model providers have their own obligations, scaled up for models above a compute threshold deemed to carry systemic risk.

The implementation timeline has been amended since the original text, and the deadlines for high-risk obligations moved. Do not cite a schedule from memory or from older coverage — check the current consolidated text, since this is exactly the kind of date that gets restated confidently long after it changed.

Why it matters

Extraterritorial scope means it binds non-EU companies whose systems are used in the EU, so it functions as a global compliance floor much as GDPR did. Penalties are turnover-based and substantial. Most importantly, the obligations attach to the *use case*, not the technology — the same model is unregulated in one product and high-risk in another.

In practice

Classify by use case first; most deployments are not high-risk and the distinction is where compliance effort should be spent. If you are high-risk, documentation and meaningful human oversight are the load-bearing requirements. Verify current dates against the official text.

Related terms