What Is the EU AI Act? A Plain-English Guide for Legal and Business Professionals

May 27 / Lexstream
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's horizontal law governing artificial intelligence. Adopted in 2024 and entering into in August of the same year, it applies the same logic as the EU's product-safety regime: the more harm an AI system can cause, the heavier the obligations on the people who build and use it. Prohibited practices were banned from February 2025; transparency rules for deepfakes and general-purpose AI come into force in August 2026; most high-risk obligations now apply from late 2027 or 2028, following a deferral agreed in May 2026.

The EU AI Act (Regulation (EU) 2024/1689) is the European Union's first comprehensive law on artificial intelligence — and the first piece of comprehensive AI legislation anywhere in the world. It entered into force on 1 August 2024 and applies in stages through to 2028. At its core, the Act treats AI in the same way the EU treats consumer products: the higher the potential for harm, the heavier the obligations on the people who build and use it.

That risk-based logic is the spine of the Regulation. Every AI system in scope falls into one of four tiers. Unacceptable risk — practices like social scoring by public authorities, untargeted facial-image scraping, real-time biometric identification in public spaces, and emotion recognition in workplaces or schools — is banned outright and has been since February 2025. High risk covers systems used in eight sensitive areas listed in Annex III, from biometrics and critical infrastructure to employment, credit scoring, and the administration of justice. These face the heaviest compliance stack. Limited risk systems, including chatbots and AI that generates synthetic content, must disclose their AI nature under Article 50. The fourth tier, minimal risk, covers the vast majority of commercial AI — spam filters, recommendation engines, inventory tools — and faces no AI-specific duties at all.

Why this matters beyond the tech sector

The temptation is to read the AI Act as a law for AI labs. It isn't. If your organisation uses AI to screen CVs, score creditworthiness, triage customer support, generate marketing copy, or moderate content, you are almost certainly within scope. The Act applies extraterritorially: any AI system whose output is used in the EU is caught, regardless of where the provider is based.

Two things make the AI Act fundamentally different from the GDPR most legal teams already know. First, it regulates the technology, not just the data — so an AI system that processes no personal data is still in scope. Second, it puts duties on multiple parties: providers, deployers, importers, and distributors all have distinct obligations, with the heaviest falling on whoever places the system on the market under their own name. For most business and legal teams the practical question is not "does the Act apply to us?" but "which of our AI use cases falls into which tier, and what does each one require?" That second question is where the work begins — and where our companion post on who has to comply picks up.

Learn more about the EU AI Act on Lexstream's AI Law and Governance Series