The EU AI Act: What Businesses Need to Know
The EU AI Act, which entered into force in August 2024 and will apply in stages through 2027, represents the world's first comprehensive legal framework specifically regulating artificial intelligence. For businesses operating in or serving customers in the European Union, understanding its requirements is now essential compliance work.
Risk-Based Structure
The Act classifies AI systems by risk level. Unacceptable risk systems (social scoring by governments, real-time biometric surveillance in public spaces for law enforcement) are outright prohibited. High-risk systems — including AI used in hiring, credit decisions, critical infrastructure, and certain medical applications — face strict requirements including mandatory risk assessments, human oversight, data quality standards, and registration in an EU database before deployment.
General Purpose AI Models
The Act includes specific provisions for general-purpose AI models (GPAIs) like large language models. Models with systemic risk — defined as training compute above 10^25 FLOPs — face additional obligations including adversarial testing, incident reporting to the EU AI Office, and cybersecurity measures. All GPAI providers must maintain technical documentation, comply with EU copyright law, and publish summaries of training data.
Compliance Timeline
Prohibited practices rules applied from February 2025. High-risk system requirements apply from August 2026. The GPAI model rules apply from August 2025. Businesses should conduct an inventory of their AI systems now to determine which risk categories apply and what compliance steps are needed before relevant deadlines.
Prohibited AI Practices
The AI Act outright bans several categories of AI application. These prohibitions, which took effect in February 2025, cover: AI systems that use subliminal techniques to manipulate behavior in harmful ways; systems that exploit vulnerabilities of specific groups; AI-based social scoring by public authorities; most real-time remote biometric identification in public spaces for law enforcement purposes; and AI used to infer emotions in workplace or educational settings. Violations of the prohibitions carry the highest fines: up to €35 million or 7% of worldwide annual turnover, whichever is higher.
High-Risk AI: Obligations in Practice
For businesses deploying high-risk AI, the practical compliance burden is substantial. You must implement a quality management system covering data governance, technical documentation, and record-keeping. The AI system must be registered in the EU database for high-risk AI before it is placed on the market or put into service. Users of high-risk AI (not just developers) have their own obligations — including implementation of human oversight measures and monitoring of system performance after deployment. Supply chain complexity is significant: businesses that deploy AI systems built on third-party foundation models need to understand how their supplier's compliance obligations interact with their own.
General Purpose AI and Foundation Models
The AI Act introduced specific obligations for providers of general-purpose AI (GPAI) models — the large language models and other foundation models that underpin many downstream AI applications. All GPAI providers must maintain technical documentation, comply with EU copyright law, and publish a summary of training data. Providers of GPAI models with systemic risk (defined by training compute thresholds) face additional requirements including adversarial testing, incident reporting to the European AI Office, and cybersecurity obligations. This affects providers like OpenAI, Google, Anthropic, and Meta offering models in the EU — and businesses that integrate these models into their products inherit some compliance obligations as downstream deployers.
The Risk-Based Tier System in Practice
The AI Act's four-tier framework — unacceptable risk (banned), high-risk, limited transparency obligations, and minimal risk — requires businesses to classify each AI system they develop, deploy, or use. Classification is not always straightforward: the same underlying AI model may be high-risk in one use case (medical diagnosis) and minimal-risk in another (content recommendation). Businesses should inventory their AI systems against Annexes II and III of the Act, which list the product categories and use cases that trigger high-risk classification. When classification is genuinely uncertain, the AI Office — the EU body responsible for Act oversight — will issue guidance, but organisations should not wait for guidance before beginning compliance work.
High-Risk AI: Core Compliance Requirements
For businesses that develop or deploy high-risk AI systems, the Act imposes eight categories of requirements: risk management systems, data and data governance documentation, technical documentation, record-keeping (logging), transparency and information to deployers, human oversight mechanisms, accuracy and robustness requirements, and cybersecurity standards. Each category has specific sub-obligations. For deployers (businesses using a vendor's high-risk AI rather than building their own), the obligations are lighter but non-trivial: they must ensure the system is used in accordance with instructions, monitor performance, and report serious incidents to national market surveillance authorities. The distinction between provider and deployer — and how it applies to fine-tuned or customised models — is a significant area of ongoing legal interpretation.
General-Purpose AI Models
The AI Act introduced a new regulatory category that did not exist in earlier drafts: general-purpose AI (GPAI) models — large foundation models trained on broad data that can be used for multiple tasks. All GPAI model providers must maintain technical documentation, comply with EU copyright law, and publish a sufficiently detailed summary of training data. GPAI models with systemic risk (trained with computational power exceeding 10^25 FLOPs — a threshold currently met by a small number of frontier models) face additional obligations including adversarial testing, cybersecurity reporting, and energy efficiency reporting. For businesses integrating third-party GPAI models into their products, the obligations cascade: their downstream system may be classified as high-risk based on its use case, even if the underlying model is not.
Compliance Timeline and Enforcement
The AI Act entered into force in August 2024. Prohibited AI practices became enforceable in February 2025. Obligations for GPAI models took effect in August 2025. High-risk AI system requirements apply from August 2026 (for systems not already regulated under existing sector-specific legislation) and from 2027 for systems covered by existing harmonised standards. National market surveillance authorities in each member state will enforce most provisions; the AI Office handles systemic-risk GPAI. Fines for violations can reach EUR 35 million or 7% of global annual turnover for the most serious breaches, and EUR 15 million or 3% for other violations — with lower caps for SMEs.
Related reading: EU AI Act Prohibited Practices (August 2026) · AI Liability and Algorithmic Harm