The EU AI Act (Regulation (EU) 2024/1689) is the European Union's first comprehensive law on artificial intelligence — and the first piece of comprehensive AI legislation anywhere in the world. It entered into force on 1 August 2024 and applies in stages through to 2028. At its core, the Act treats AI in the same way the EU treats consumer products: the higher the potential for harm, the heavier the obligations on the people who build and use it.
That risk-based logic is the spine of the Regulation. Every AI system in scope falls into one of four tiers. Unacceptable risk — practices like social scoring by public authorities, untargeted facial-image scraping, real-time biometric identification in public spaces, and emotion recognition in workplaces or schools — is banned outright and has been since February 2025. High risk covers systems used in eight sensitive areas listed in Annex III, from biometrics and critical infrastructure to employment, credit scoring, and the administration of justice. These face the heaviest compliance stack. Limited risk systems, including chatbots and AI that generates synthetic content, must disclose their AI nature under Article 50. The fourth tier, minimal risk, covers the vast majority of commercial AI — spam filters, recommendation engines, inventory tools — and faces no AI-specific duties at all.
