What Is the EU AI Act?
The EU AI Act is the world\'s first comprehensive legal framework for artificial intelligence. Adopted in 2024 and entering force in stages through 2028, it establishes binding rules for any AI system used in the European Union — regardless of where the company that built it is located.
The Act classifies AI systems into four risk tiers and imposes requirements proportional to each tier\'s potential for harm. It is the most significant piece of AI regulation in history, and its effects will be felt globally as companies adjust their products to comply.
The EU AI Act is not just European regulation. It is the global standard that every AI company will have to meet.
The Four Risk Tiers
1. Unacceptable Risk (Banned)
AI systems that pose an unacceptable risk to fundamental rights are completely banned. This includes:
- Social scoring — Systems that rate citizens based on their social behavior (like China\'s social credit system)
- Real-time remote biometric identification — Facial recognition in public spaces, except for serious crimes
- Emotion recognition in workplaces and schools — AI that reads emotions to make decisions about employees or students
- Manipulation of vulnerable groups — AI that exploits the vulnerabilities of people due to age, disability, or social situation
- Predictive policing based on profiling — AI that predicts criminal behavior based on personal characteristics rather than specific evidence
2. High Risk (Strict Requirements)
AI systems used in critical areas face the most stringent requirements:
- Critical infrastructure — AI managing water, energy, or transport systems
- Education — AI used for student assessment or admission decisions
- Employment — AI used for hiring, promotion, or termination decisions
- Law enforcement — AI used for evidence evaluation or risk assessment
- Migration and border control — AI used for visa or asylum processing
- Justice and democracy — AI used to interpret or apply the law
High-risk AI must meet requirements including risk management, data governance, technical documentation, transparency, human oversight, accuracy, and cybersecurity.
3. Limited Risk (Transparency Requirements)
AI systems that interact with humans or generate content must disclose that they are AI:
- Chatbots — Must inform users they are talking to an AI
- Deepfakes — AI-generated content must be labeled
- Emotion recognition — Must inform subjects that the system is being used
- Biometric categorization — Must inform subjects of the system\'s purpose
4. Minimal Risk (No Requirements)
AI systems with minimal risk — such as spam filters, AI-enabled video games, or inventory management systems — face no specific requirements under the Act. Most AI systems fall into this category.
What Changed with the Digital Omnibus
In July 2026, the European Commission introduced the Digital Omnibus on AI, which modified several aspects of the original AI Act:
Timeline Shifts
The high-risk AI requirements, originally scheduled for August 2026, were delayed to December 2027. This gives companies more time to comply but also signals the difficulty of implementing comprehensive AI regulation in a rapidly evolving field.
Nudification Ban
The Omnibus added a specific prohibition under Article 5: AI systems that generate, distribute, or facilitate non-consensual intimate imagery (commonly called "nudification" or "deepfake pornography") are now explicitly banned. This was not explicitly addressed in the original Act and was added in response to the growing problem of AI-generated non-consensual intimate imagery.
Enforcement Centralization
The Omnibus established a centralized EU AI Office to coordinate enforcement across member states. Previously, enforcement was left to national authorities, creating inconsistency. The EU AI Office now has the power to investigate, fine, and order the withdrawal of non-compliant AI systems.
Standardization Support
The Omnibus accelerated the development of harmonized standards by mandating that European standardization organizations produce technical standards for high-risk AI systems within 12 months. These standards will define how companies can demonstrate compliance with the Act\'s requirements.
When Does Everything Apply?
| Date | Requirement |
|---|---|
| February 2025 | Prohibited AI practices take effect (social scoring, manipulation, etc.) |
| August 2025 | Transparency requirements for limited-risk AI (chatbots, deepfakes) |
| December 2027 | High-risk AI requirements take effect (delayed from August 2026) |
| 2028 | Full enforcement, including fines up to 7% of global annual turnover |
How It Affects Companies Outside the EU
The EU AI Act has extraterritorial reach — it applies to any company that places an AI system on the EU market or whose AI system\'s output is used in the EU. This means:
- US tech companies — OpenAI, Google, Meta, Microsoft, and others must comply if their AI systems are used by EU residents. This is already happening: ChatGPT and Gemini both have EU-specific features and disclosures.
- Chinese AI companies — Any Chinese AI company that sells to EU customers must comply. This is particularly relevant for companies like ByteTance (TikTok) and Baidu.
- Startups and SMEs — Small companies face the same requirements as large ones, though the Act includes some proportionality measures for SMEs.
The practical effect is that many companies are adopting EU-compliant practices globally, because maintaining separate compliance regimes for different regions is more expensive than meeting the strictest standard everywhere.
Enforcement and Penalties
The EU AI Act has significant enforcement teeth:
- Prohibited practices — Fines up to €35 million or 7% of global annual turnover (whichever is higher)
- High-risk violations — Fines up to €15 million or 3% of global annual turnover
- Transparency violations — Fines up to €7.5 million or 1% of global annual turnover
For context, a 7% fine on a company with €100 billion in revenue would be €7 billion — a potentially existential penalty. The severity of these fines is designed to ensure that companies take compliance seriously.
EU vs. US Approach
The EU and US have taken fundamentally different approaches to AI regulation:
EU: Comprehensive, Risk-Based
The EU AI Act applies to all AI systems, classifies them by risk, and imposes requirements proportional to that risk. It is prescriptive, detailed, and applies to the technology itself.
US: Sector-Specific, Voluntary
The US has no comprehensive federal AI law. Instead, AI is regulated through existing sector-specific laws (healthcare, finance, employment) and voluntary frameworks. The AI Executive Order (2023) established guidelines but did not create binding requirements. State-level laws (like California\'s AI transparency requirements) are emerging but remain fragmented.
Implications
For companies, the EU approach creates clarity but also complexity. The US approach creates flexibility but also uncertainty. Most companies are choosing to comply with the EU standard as a de facto global baseline, because the penalties for non-compliance are too severe to ignore.
The Nudification Ban in Detail
The AI nudification ban is worth examining separately because it addresses a specific, growing harm. AI tools that generate non-consensual intimate imagery — often called "deepfake pornography" — have become increasingly sophisticated and accessible. The ban prohibits:
- Generating non-consensual intimate imagery using AI
- Distributing such imagery
- Providing tools or services specifically designed to create such imagery
- Knowing or having reasonable grounds to know that the imagery is non-consensual
This ban is notable because it targets a specific use case rather than a category of technology. It represents a new approach to AI regulation: addressing specific harms as they emerge rather than waiting for comprehensive frameworks to catch up.
What Can You Do
- If you build AI products — Assess your products against the EU AI Act\'s risk tiers. If your product is high-risk, start building compliance infrastructure now. The December 2027 deadline is closer than it seems.
- If you use AI products — Ask your vendors about their EU AI Act compliance. Are they classifying their systems correctly? Do they have the required transparency disclosures? Are they preparing for high-risk requirements?
- If you are in the EU — Understand your rights under the Act. You have the right to know when AI is being used to make decisions about you, and you have the right to human oversight for high-risk AI decisions.
- If you are a policymaker — Study the EU approach as a model for your own jurisdiction. The Act is not perfect, but it represents the most comprehensive attempt to regulate AI to date. Learn from its strengths and weaknesses.
Sources
- European Commission, "Regulation (EU) 2024/1689 — Artificial Intelligence Act" — Official Journal of the European Union
- European Commission, "Digital Omnibus on AI" — legislative proposal, July 2026
- EU AI Office, "Guidelines for High-Risk AI Systems" — implementation guidance
- NIST, "AI Risk Management Framework" — US federal guidelines
- Bertelsmann Stiftung, "Global AI Regulation Tracker" — comparative analysis
- Future of Life Institute, "AI Safety Index" — company compliance assessment