Sistava

What is EU AI Act?

Also called Artificial Intelligence Act, Regulation (EU) 2024/1689.

The EU AI Act is the European Union's regulation on artificial intelligence, Regulation (EU) 2024/1689, which entered into force in August 2024. It classifies AI systems by risk and attaches obligations accordingly, from outright prohibition to transparency duties. It applies to providers and deployers placing systems on the European Union market regardless of where they are established.

The structure is risk-based with four broad tiers. A small set of practices is prohibited, including certain manipulative techniques, untargeted scraping of facial images to build recognition databases, and social scoring by public authorities. High-risk systems, listed by sector and use case, carry the heaviest obligations. Limited-risk systems mainly carry transparency duties, such as disclosing that a person is interacting with an AI system. Everything else is largely unregulated by the Act.

Obligations for high-risk systems center on demonstrable process rather than a specific technology. They include a risk management system, data governance, technical documentation, automatic record keeping, transparency toward deployers, effective human oversight, and appropriate accuracy, robustness, and cybersecurity. Providers and deployers hold different duties, so the same system generates different obligations depending on the role a company occupies.

A separate chapter addresses general purpose AI models, with documentation, copyright policy, and training data summary requirements, plus additional obligations where a model is deemed to present systemic risk. This is the part most directly relevant to organizations building on top of general models, since it shapes what information model providers must supply downstream.

Application is staged rather than immediate. Prohibitions and AI literacy provisions applied from February 2025, general purpose model obligations from August 2025, and most high-risk obligations were set to apply from August 2026, with certain product-embedded high-risk categories later. Timelines and some details have been subject to proposed amendments and ongoing guidance, so anyone assessing obligations should check the current position rather than rely on a summary. This is not legal advice.

Key points

In practice

A company outside the European Union sells a recruitment screening tool to employers in Europe. Employment-related screening falls within the high-risk categories, so the provider faces obligations including risk management, data governance, documentation, record keeping, and enabling human oversight, while the employer takes on deployer duties. Being established elsewhere does not remove the obligations, because the system is placed on the European Union market.

Related terms

Back to the AI Glossary