Know the Facts: EU Artificial Intelligence Act
Official Source Link: Read Here
Status & Jurisdiction: Enacted - European Union & Ireland
Target Organisations: AI Software Developers, Enterprise Deployers of Generative AI, Tech Vendors & Public Sector Tech Officers
Compliance Ranking: 🔴 Level 3 (see here)
1. Key Takeaways
Risk-Based Tiering: Categorises AI systems into ‘Unacceptable’ (Banned), ‘High-Risk’ (Strict Compliance), ‘Specific Transparency’ (GPAI/Deepfakes) and ‘Low Risk’.
Fundamental Rights Assessments: Requires deployers of high-risk AI to assess impacts on rights, data governance, human oversight and cyber resilience.
Severe Financial Sanctions: Fines reach up to €35M or 7% of global annual turnover for prohibited AI practices.
2. What is the EU AI Act?
It is the world’s first comprehensive horizontal legal framework for artificial intelligence. Its objective is to ensure that AI systems placed on the EU market are safe, transparent, non-discriminatory and respectful of fundamental rights while fostering innovation.
The regulation applies extra-territorially to both EU-based and non-EU providers if the output produced by the AI system is used within the European Union.
3. Regulatory & Financial Impact on Businesses
Direct Obligations: Providers of high-risk AI platforms must establish risk-management systems, maintain continuous data quality logging, obtain CE-marking and register in the EU database. Deployers must ensure human oversight and monitor operational drift.
Indirect Supply Chain Pressures: Downstream software vendors and enterprise buyers will demand conformity certificates and contractual guarantees from ‘upstream’ AI foundation model providers.
Penalties for Non-Compliance: Infringements on prohibited AI practices trigger fines up to €35 million or 7% of global turnover. Non-compliance with general high-risk provisions incurs up to €15 million or 3% of turnover.
4. Implementation Timeline & Key Dates
1 August 2024 – Entry into Force
The EU AI Act officially enters into force across all EU Member States.
2 February 2025 – Prohibited AI Practices & Literacy
Ban on ‘Unacceptable Risk’ AI practices (e.g. social scoring, cognitive behavioural manipulation, facial recognition scraping) becomes fully enforceable.
Mandatory AI literacy obligations take effect for deployers and providers.
2 August 2025 – General Purpose AI (GPAI) Governance
Rules on General Purpose AI (GPAI) models and systemic risk governance take effect for new models entering the market.
Governance enforceability and AI Office supervisory/investigative powers become active.
2 August 2026 – Transparency Obligations & Systemic GPAI Rules
Article 50 Transparency Rules Take Effect: Mandatory disclosure for AI chatbots, synthetic content and deepfake labeling (with a four-month transition window to 2 December 2026 for synthetic content tools placed on the market prior to August 2026).
New bans on AI-generated non-consensual deepfakes ("nudifiers") and CSAM start to apply.
2 August 2027 – Regulatory Sandboxes & Legacy GPAI
EU Member States must have at least one operational AI Regulatory Sandbox in place.
Legacy General Purpose AI (GPAI) models placed on the market before 2 August 2025 must achieve full compliance.
2 December 2027 – Stand-Alone High-Risk AI Systems (Annex III)
Full rules and compliance obligations for stand-alone high-risk AI systems (Annex III, e.g. biometrics, critical infrastructure, employment, credit scoring, education) take effect. (Deferred from August 2026 under the Digital Omnibus package).
2 August 2028 – Embedded High-Risk AI Systems (Annex I)
Compliance rules apply for high-risk AI embedded in ‘safety-critical’, regulated products that are subject to existing EU product safety legislation (Annex I, e.g. medical devices, machinery, aviation, automotive).