What is the AI Act?
The EU AI Act is the world's first comprehensive artificial intelligence regulation. It establishes a legal framework for the development, marketing and use of AI systems in the European Union.
The AI Act's approach is based on risk classification: the higher the risk of the AI system, the stricter the obligations.
Key change: The AI Act establishes differentiated obligations depending on the type of system and the organization's role, including, where applicable, risk management, documentation, human oversight, registration and specific assessments.
Risk classification
In simplified terms, the AI Act's framework can be understood through different risk levels and categories:
- Unacceptable risk: Prohibited. Includes AI systems that manipulate human behavior, exploit vulnerabilities or use social scoring systems.
- High risk: Strict obligations. Includes AI in critical infrastructure, education, employment, access to essential services, immigration and administration of justice.
- Limited risk: Transparency obligations. Includes chatbots and content generation systems. Emotion recognition is prohibited in the workplace and educational settings (art. 5.1.f); outside those contexts, it is subject to transparency obligations (art. 50).
- Other AI systems: not subject, by that fact alone, to the specific obligations of high-risk systems, without prejudice to other obligations that may apply depending on the system, the organization's role and the context of use. Includes most current AI applications.
Obligations for high-risk systems
High-risk AI systems must comply with:
- Risk management system: Continuous process of identifying and mitigating risks.
- Training data: Relevant, representative and, as far as possible, complete and error-free data (art. 10).
- Technical documentation: Detailed record of the system and its operation.
- Human oversight: Human supervision and control mechanisms.
- Security and accuracy: Adequate levels of security, accuracy and robustness.
- Event logging: Automatic logging of events during operation.
Key deadlines
- August 1, 2024: AI Act entry into force.
- February 2, 2025: Application of article 4 (AI literacy). ⚠️ Already enforceable.
- August 2, 2025: Application of obligations for general-purpose AI systems (GPAI).
- July 27, 2026: The AI Digital Omnibus enters into force, postponing the high-risk timelines.
- August 2, 2026: Application of general transparency obligations (art. 50).
- December 2, 2026: Application of the new prohibition on certain systems generating non-consensual sexually explicit or intimate content or child sexual abuse material, and the end of the transitional period for the marking and detection obligations of article 50.2 for certain systems placed on the market before August 2, 2026.
- December 2, 2027: Application for Annex III high-risk AI systems (critical infrastructure, education, employment, etc.) — postponed from August 2026.
- August 2, 2028: Application for Annex I high-risk AI systems (regulated products) — postponed from August 2027.
⚠️ Updated: the AI Digital Omnibus (in force since July 27, 2026) postponed the application of Annex III high-risk obligations to December 2027 and Annex I to August 2028. The obligations on prohibited practices, AI literacy and GPAI remain in effect from their original dates.
Consequences of non-compliance
| Infringement |
Maximum fine |
| Prohibited practices (art. 5) |
€35M or 7% of global turnover |
| Other infringements (art. 99.4) |
€15M or 3% of global turnover |
| Incorrect or misleading information |
€7.5M or 1% of global turnover |
How can I help you with the AI Act?
AI Act Gap Analysis
We analyze your AI systems, classify them by risk and design a compliance roadmap based on the organization's role, the system's classification and applicable obligations.
View service →
ISO 42001 · AI Governance
We implement an AI Management System aligned with the AI Act and ISO 42001.
View service →
Impact Assessment
We carry out the impact assessments that are required or appropriate depending on the system, the organization's role and the context of use.
View service →
Do you need to prepare your company for the AI Act?
Request an assessment meeting →
20–30 minutes · No commitment · We review context, need and next steps.