EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
The EU Artificial Intelligence Act is a comprehensive regulatory framework designed to ensure that AI systems used within the European Union are safe, transparent, and respect fundamental rights. It establishes a risk-based approach, imposing stricter obligations on AI systems that pose higher risks to health, safety, or civil liberties.
Who it applies to
- Providers who develop AI systems and place them on the EU market or put them into service.
- Deployers (users) of AI systems who operate those systems under their authority within the EU.
- Importers of AI systems from non-EU countries into the European Union.
- Distributors who make AI systems available on the EU market.
- Non-EU entities whose AI system's output is used within the European Union.
How it works
The Act categorizes AI systems into four levels of risk: Unacceptable, High, Limited, and Minimal. Systems deemed an "unacceptable risk"—such as those utilizing social scoring or certain biometric surveillance—are prohibited. Most AI applications fall into the "minimal" category and face no mandatory requirements, while "limited risk" systems (like chatbots) must meet basic transparency obligations to ensure users know they are interacting with AI.
High-risk AI systems are subject to the most stringent requirements. These include implementing a robust risk management system, ensuring high-quality training data to prevent bias, maintaining detailed technical documentation, and establishing human oversight mechanisms.
Compliance for high-risk systems is verified through conformity assessments. Depending on the specific category of AI, this may be a self-assessment by the provider or a mandatory audit conducted by a third-party "notified body." Once compliant, providers affix a CE marking to indicate that the system meets all EU regulatory requirements before it enters the market.
Getting started
- Create an inventory of all AI systems currently developed, deployed, or procured by your organization.
- Map each identified system to one of the Act's four risk categories based on its intended purpose and use case.
- Perform a gap analysis for any "high-risk" or "limited-risk" systems to identify missing documentation or transparency measures.
- Establish an internal AI governance policy that defines roles, responsibilities, and oversight procedures.
- Review contracts with third-party AI vendors to ensure they provide the necessary technical documentation required for your compliance as a deployer.
Controls & requirements
- The risk-based approach: four risk tiers
- Art. 5 Prohibited AI practices
- Art. 6 & Annex III What makes an AI system high-risk
- Art. 9 The risk management system
- Art. 10 Data and data governance
- Arts. 11–12 Technical documentation and record-keeping
- Art. 13 Transparency and instructions for use
- Art. 14 Human oversight
- Art. 15 Accuracy, robustness and cybersecurity
- Art. 43 Conformity assessment and CE marking
- Ch. V General-purpose AI model obligations
- Art. 50 Chatbot and deepfake transparency obligations
- Art. 4 AI literacy
- Application timeline and penalties
Common misconceptions
- It only applies to companies headquartered in the EU; in reality, it has extraterritorial reach and applies to any entity whose AI output is used within the EU.
- All AI systems are considered "high-risk" and require certification, whereas most commercial applications actually fall into the minimal or limited risk categories.
- Compliance is a one-time event at launch; however, high-risk systems require continuous post-market monitoring and updated documentation throughout their lifecycle.