AI Act

The AI Act is the European regulation governing artificial intelligence by risk level. It prohibits a number of applications outright, imposes demanding requirements on high-risk systems, requires transparency where systems interact with people or generate content, and leaves minimal-risk systems free.

Legal basis

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. The prohibited practices have applied since 2 February 2025, the rules on general-purpose AI since 2 August 2025 and the transparency obligations of Article 50 since 2 August 2026. Regulation (EU) 2026/1744, known as the digital omnibus, postponed the high-risk regime: requirements for Annex III applications apply from 2 December 2027 and those for Annex I from 2 August 2028. Systems already in use before August 2026 have until December 2030. That postponement affects the high-risk regime only; the remaining obligations apply as normal.

How it works in practice

The first question is not which risk level applies but which role you occupy. Are you a provider, placing a system on the market under your own name, or a deployer? Different obligations attach to each. Anyone who adapts an existing model and offers it under their own brand becomes a provider. Classification follows: recruitment and selection, credit scoring, insurance and access to education all fall under Annex III. Whatever the risk level, since February 2025 there has been a duty to ensure sufficient AI literacy among staff working with these systems.

Where it goes wrong

The biggest misconception is that the postponement moved everything. Prohibited practices, transparency and the rules for general-purpose models already apply. A second error is the absence of an inventory: many organisations do not know what AI has already entered their processes through standard software. Third, the relationship with the GDPR is underestimated; a system that complies with the Act is still unlawful if there is no basis for the processing.

Related terms

The Act connects to the data protection impact assessment, to the data processing agreement with your AI supplier, and to copyright in relation to training data.

Would you like your AI applications assessed? Our IT law specialists map role, risk level and obligations.