EU regulation · Phasing in 2025–2027

The EU AI Act. The world's first AI law, explained.

Regulation (EU) 2024/1689 applies to almost every organisation that develops, sells or uses AI systems in the EU. The obligations phase in between February 2025 and August 2027 — and most companies are further in scope than they think.

The AI Act in 60 seconds

What it is
Regulation (EU) 2024/1689, directly applicable in all member states — no national transposition needed.
Who it applies to
Providers, deployers, importers and distributors of AI systems placed on or used in the EU market, including non-EU companies whose output is used in the EU.
The approach
Risk-based: prohibited practices, high-risk systems, transparency-risk systems and minimal risk, plus separate rules for general-purpose AI (GPAI) models.
Since when
In force 1 August 2024; obligations phase in between 2 February 2025 and 2 August 2027.
What it costs to ignore
Fines up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for most other infringements.

The risk pyramid

The AI Act does not regulate AI as a technology. It sorts uses into four levels of risk and attaches duties to each, with a separate track for general-purpose models. Working out which level your systems sit in is the first compliance task, not a formality.

Unacceptable risk — prohibited

Prohibited practices including social scoring, manipulative techniques and most real-time remote biometric identification. These are banned outright, and they carry the highest fines.

High risk

High-risk AI systems — the Annex III use cases such as recruitment, credit scoring and critical infrastructure, plus AI embedded in products already regulated under EU product legislation. This is where the substantive requirements live.

Transparency risk

Chatbots and deepfakes. The system is not restricted, but people must be told they are interacting with AI, and synthetic content must be disclosed as such.

Minimal risk

Everything else — the large majority of AI in ordinary business use. No specific obligations under the Act beyond the general rules that already apply to your organisation.

Key dates

  1. 1 August 2024

    The AI Act enters into force.

  2. 2 February 2025

    The prohibitions on unacceptable-risk practices and the AI literacy duty apply.

  3. 2 August 2025

    Obligations for general-purpose AI models and the governance rules apply.

  4. 2 August 2026

    Most remaining obligations apply, including the Annex III high-risk requirements.

  5. 2 August 2027

    High-risk AI embedded in products regulated under other EU legislation.

What high-risk actually requires

If a system is high risk, the provider obligations read like a product compliance programme: a documented process, evidence that it was followed, and a conformity assessment ending in CE marking — in some cases with a notified body involved. Deployers of certain Annex III systems may also need a fundamental rights impact assessment.

Risk management system

A continuous, documented process across the system's lifecycle, identifying and mitigating risks to health, safety and fundamental rights.

Data governance

Training, validation and testing data sets governed for relevance, representativeness and known bias.

Technical documentation

Documentation drawn up before the system is placed on the market and kept up to date, sufficient for authorities to assess conformity.

Logging

Automatic recording of events over the lifetime of the system, so its operation can be traced after the fact.

Transparency and instructions for use

Deployers must receive information that lets them understand and use the system correctly, including its capabilities and limitations.

Human oversight

Designed so that a person can understand, monitor, intervene in and, where needed, stop the system.

Accuracy, robustness and cybersecurity

An appropriate level of performance and resilience against errors, faults and attempts to manipulate the system.

Conformity assessment and CE marking

The system is assessed against the requirements and carries the CE marking before it is placed on the market.

Registration in the EU database

High-risk systems are registered in the EU database before being placed on the market or put into service.

Provider or deployer? Different duties

Most organisations are deployers of systems built by someone else — but the provider and deployer roles can shift. Put your own name on a system, or change its intended purpose, and the build-side duties become yours.

Simplified comparison of the two main roles for high-risk AI systems.
RoleWho it isCore duties
ProviderDevelops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.Risk management, data governance, technical documentation, logging, human oversight by design, accuracy and cybersecurity, conformity assessment, CE marking, registration.
DeployerUses an AI system under its own authority in a professional capacity.Use the system according to the instructions, assign competent human oversight, monitor operation, keep logs where applicable, inform affected people where required, and carry out a fundamental rights impact assessment where it applies.

GPAI models

General-purpose AI models sit on their own track. Because they are not built for one defined use, the Act regulates the model itself rather than a single application: providers of GPAI models must maintain technical documentation, provide information to downstream providers who build on the model, respect EU copyright law and publish a summary of the content used for training. Models judged to present systemic risk carry additional obligations. These rules apply from 2 August 2025.

If you build a product on top of a third-party model, you are normally a downstream provider or a deployer, not a GPAI provider — but you inherit the need for the model information the Act requires the upstream provider to give you.

AI Act and NIS2 overlap

High-risk AI systems must be robust and secure against attempts to manipulate them — a product-level cybersecurity duty attached to the system. NIS2 sits one level up: it is an organisational duty to manage cybersecurity risk across your operations, with the Article 21 measures and statutory incident reporting. Many organisations will be in scope of both: NIS2 for how the company manages security, the AI Act for how a specific system behaves.

The practical consequence is shared evidence. A risk register, supplier controls and incident procedures built for NIS2 cover part of what an AI Act audit trail asks for — but neither replaces the other.

Free: AI Act Applicability Checklist

Find out in 15 minutes whether the AI Act applies to you, and in which risk category.

Get the free AI Act checklist

AI Act document packages are available now.

They follow the same three layers as our NIS2 packages: an AI system inventory and risk classification, a governed process with a compliance calendar, and the required policies, procedures and technical documentation templates. Three tiers from 99 EUR, delivered instantly.

See the three tiers and what each one includes

Frequently asked questions