What Is the EU AI Act?

Also called: AI Act, Artificial Intelligence Act, EU Artificial Intelligence Act

Related problems: We sell or use AI in the EU and don't know which rules apply to us; An EU customer is asking whether our AI features are high-risk; Not sure whether we count as an AI provider or just a user; Staff using AI for hiring or credit decisions about people in the EU

The EU AI Act is a European Union regulation that sets common rules for artificial intelligence based on risk. It bans a short list of AI practices, sets strict requirements for high-risk uses such as AI in hiring, credit decisions or critical infrastructure, adds transparency duties for things like chatbots and AI-generated content, and places separate obligations on providers of general-purpose AI models. Duties depend on whether you develop AI (a provider), use it (a deployer) or import or distribute it. Its rules are phased in from 2025 onward, and the timeline has been amended, so check current dates. This entry is an overview for buyers, not legal advice.

At a glance

  • An EU regulation (Regulation (EU) 2024/1689) that applies directly across member states.
  • It sets out several rule sets that can overlap: prohibited practices, high-risk systems, transparency obligations and separate obligations for general-purpose AI models.
  • Obligations differ by role; providers of high-risk systems carry the most, and deployers have their own, lighter duties.
  • It can reach organizations outside the EU whose AI is placed on the EU market or whose output is used there.
  • Application is phased from 2025 onward, and 2026 amendments pushed back high-risk deadlines; confirm current timelines with the European Commission and counsel.

What problem it solves

AI increasingly shapes decisions about people, such as who gets interviewed or who gets credit. Before the AI Act, EU data protection, product safety and anti-discrimination law covered parts of this, but nothing set common requirements for AI systems themselves.

The AI Act creates one rulebook across the EU so that higher-risk AI meets baseline requirements for data quality, documentation, human oversight and robustness, while most everyday AI, such as spam filters, is left largely alone. For mid-market buyers, it matters mainly in two ways: if you use AI in a high-risk way in the EU, you have duties as a deployer; and your AI vendors will be working out their own obligations, which shows up in contracts and documentation.

How it works

Work out which rules apply. The Act is not a single ladder of tiers: its rule sets for prohibited practices, high-risk systems, transparency and general-purpose AI models can overlap, so a high-risk system can also carry transparency duties. Whether a system is high-risk depends mainly on its intended use, not the underlying technology: the regulation defines high-risk systems either as safety components of products already regulated in the EU or as listed use cases such as employment, education, credit and access to essential services. Systems outside the prohibited and high-risk rules may still have transparency or other obligations.

Identify your role. Providers develop and place AI on the market; deployers use it under their own authority; importers and distributors bring it into the EU or pass it on. A deployer can become a provider, for example by substantially modifying a high-risk system or putting its own name on one.

Meet the obligations. Providers of high-risk systems run risk management, use appropriate training data, keep technical documentation and logs, design for human oversight, go through the conformity assessment route the regulation sets for their type of system and register certain systems in an EU database. Deployers use systems according to instructions, assign human oversight, monitor operation and, in some cases, assess impacts on people’s rights. Transparency duties require telling people when they interact with AI and labelling certain AI-generated content.

Enforcement. National market surveillance authorities supervise most rules, and the European Commission’s AI Office oversees general-purpose AI models.

Rule sets and risk categories

The rows below are rule sets that may apply to an AI system or model, not exclusive tiers: a system can fall under more than one. “Limited risk” and “minimal risk” are informal shorthand the European Commission uses to explain the Act, not formal categories in it.

Rule set What triggers it What’s required Typical evidence
Prohibited practices Practices listed as banned, such as social scoring and certain manipulative or biometric uses Not allowed on the EU market Internal review confirming no prohibited use
High-risk AI used as a safety component of regulated products, or in listed areas such as hiring, credit, education and critical infrastructure Providers: risk management, documentation, logging, human oversight design, conformity assessment by the route the regulation sets (confirm whether a third-party body is involved for your system), registration. Deployers: use per instructions, oversight, monitoring, sometimes a rights impact assessment Conformity declaration, CE marking, instructions for use, deployer oversight records
Transparency obligations (informally “limited risk”) Systems that interact with people, generate content or perform certain recognition tasks, including some high-risk systems Disclose AI interaction; mark or label certain AI-generated content User notices, content labelling
No specific AI Act obligations (informally “minimal risk”) Much everyday AI, such as spam filters, that falls outside the rule sets above No AI Act-specific requirements beyond general provisions; voluntary codes encouraged; other laws still apply Usually none specific to the AI Act
General-purpose AI model Providers of models that can be used for many tasks Technical documentation, information for downstream providers, copyright policy, training-content summary Model documentation, code of practice adherence
General-purpose AI model with systemic risk The most capable models, based on criteria in the regulation Above, plus model evaluation, risk mitigation, incident reporting and cybersecurity Evaluation and incident records shared with the AI Office

When it matters for buyers

  • When you use AI to make decisions about people in the EU. Hiring, worker management and credit are listed high-risk areas, and deployers have duties there.
  • When you sell products or services with AI features into the EU. You may be a provider and need to classify what you offer.
  • When choosing AI vendors. Ask how they classify their system and what documentation they provide to deployers.
  • When you are expanding into Europe. Fold the AI Act into your AI governance and GRC program alongside privacy work.

Our governance, risk and compliance and artificial intelligence overviews cover providers that help with AI compliance programs.

Questions to ask vendors

  • How do you classify your AI features under the EU AI Act, and for which intended uses?
  • Are you the provider of the AI system, or do you build on another company’s general-purpose model?
  • What instructions for use and documentation will you give us as a deployer?
  • What human oversight features, logs and monitoring does the product support?
  • How will you tell us about serious incidents or substantial changes to the system?
  • How do contract terms allocate AI Act responsibilities between us?

How it differs from GDPR

The General Data Protection Regulation (GDPR) governs personal data: how it is collected, used, shared and protected, whatever the technology. The AI Act governs AI systems and models: how they are designed, documented, overseen and used, whether or not they process personal data. They often apply together, for example to an AI hiring tool that processes applicant data. The voluntary NIST AI Risk Management Framework (AI RMF) is not a law, but it can help structure the risk management work both expect.

Frequently Asked Questions

Does the EU AI Act apply to companies outside the EU?
It can. It can reach providers placing AI systems or models on the EU market, and in some cases providers and deployers outside the EU whose AI output is used in the EU. Whether it applies to you depends on your role and how your AI is used, so check with counsel. This is not legal advice.
When does the EU AI Act apply?
In phases from 2025 onward. Prohibited practices and general-purpose AI model rules came first, and amendments adopted in 2026 pushed back the main high-risk obligations into 2027 and 2028. Timelines have changed before, so check the European Commission's current guidance.
What is the difference between a provider and a deployer?
A provider develops an AI system or model, or has one developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system in its own work. Most mid-market companies are deployers of AI they buy, which carries lighter but real duties, especially for high-risk uses.
Are AI chatbots high-risk under the AI Act?
Not automatically. Chatbots generally carry transparency duties, such as telling people they are interacting with AI, and the general-purpose AI models behind many of them carry separate obligations for their providers. A chatbot can also be high-risk if it is used for a listed purpose, such as screening job applicants, and then several rule sets apply at once.
Does the AI Act replace GDPR?
No. GDPR continues to apply whenever personal data is processed, including by AI systems. The AI Act adds rules about the AI systems themselves, so many uses need to meet both.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.