AI Act | Overview
Regulation: EU 2024/1689 Effective: August 2, 2026 (for high-risk AI) Scope: Artificial Intelligence
What is the AI Act?
The AI Act is the world’s first comprehensive regulation of artificial intelligence. It classifies AI systems by risk level and establishes corresponding obligations.
Risk Classification
| Category | Obligation | Examples |
|---|---|---|
| PROHIBITED (Art. 5) | STOP — do not use | Real-time biometric ID without consent, Emotion recognition of children, Subliminal manipulation, Social scoring |
| HIGH-RISK (Art. 6, Annex III) | Full obligations | Credit scoring, Employment decisions, Health diagnostics, Law enforcement, Education access |
| MEDIUM-RISK (Art. 52) | Transparency | Chatbots (must be labeled as AI), Deepfakes (must be labeled), Emotion recognition (outside prohibited) |
| LOW-RISK | Minimal obligations | Spam filters, Recommendation systems (no rights impact), Analytics (anonymous) |
Key Obligations
For HIGH-RISK AI Systems
| Obligation | Description | Deadline |
|---|---|---|
| Risk Management | Documented risk management process | Before deployment |
| Data Governance | Training data quality, bias testing | Ongoing |
| Technical Documentation | Model card, training info, limitations | Before deployment |
| Record Keeping | Audit log, min. 5 years | Ongoing |
| Transparency | User information about AI | Before deployment |
| Human Oversight | Human-in-the-loop capability | Always |
| Accuracy & Robustness | Testing, monitoring, drift detection | Ongoing |
For GPAI (General-Purpose AI)
If using Claude, GPT-4, Gemini, or other GPAI:
- ✅ Audit Terms of Service
- ✅ DPA (Data Processing Agreement)
- ✅ Know limitations (hallucinations, bias, knowledge cutoff)
- ✅ Monitoring: log prompts + outputs
- ✅ NEVER send PII/health/financial data to GPAI without encryption
Your Role
| Role | Definition | Example |
|---|---|---|
| Provider | Developed/trains AI | Own ML models |
| Deployer | Deploys AI for end-users | Uses Claude in product |
| Importer | Imports AI from non-EU | Import US AI system |
| Distributor | Distributes AI to third parties | Reselling AI solutions |
Timeline
Penalties
| Violation | Penalty |
|---|---|
| Prohibited practices | up to €35M or 7% global annual turnover |
| High-risk violations | up to €15M or 3% global annual turnover |
| Other violations | up to €10M or 2% global annual turnover |
| Providing false information | up to €7.5M or 1% global annual turnover |
Example: Company with €100M global annual turnover = max penalty €7M for high-risk violation.