Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: AI Governance

EU AI Act

Also known as: AI Act, Artificial Intelligence Act, EU Artificial Intelligence Act, the AI Act
Simply put

The EU AI Act is a European Union law that governs how artificial intelligence systems are developed and used within the EU. It is described as the first comprehensive legal framework on AI by a major regulator, and it aims to address the risks that AI systems can pose. As binding legislation rather than a voluntary standard, it creates enforceable obligations for those who fall within its scope.

Formal definition

The EU AI Act is a European Union regulation establishing a common regulatory and legal framework for artificial intelligence within the EU, which entered into force on 1 August 2024. It governs the development and use of AI systems, defining an AI system (per Article 3) as a machine-based system capable of operating autonomously and adapting after deployment to generate outputs such as predictions or decisions. As a regulation, it carries direct legal force and should be distinguished from voluntary standards or frameworks (for example, ISO/IEC standards) that apply only where adopted contractually or incorporated by law. The Act's provisions and defined terms are subject to amendment and staged application; readers should verify specific obligations, timelines, and definitions against the current official consolidated text, and note that certain interpretations and enforcement practices remain evolving. Application to particular circumstances requires professional judgment.

Why it matters

The EU AI Act represents the first comprehensive legal framework on artificial intelligence introduced by a major regulator, and its significance lies in this pioneering status. Unlike voluntary standards or frameworks that apply only where adopted contractually or incorporated by law, the AI Act is binding legislation carrying direct legal force. For organizations that develop or deploy AI systems touching the EU, this means enforceable obligations rather than optional best practices, and the Act positions Europe to play a leading role in shaping global expectations around AI governance.

The Act matters because it addresses the risks that AI systems can pose while establishing a common regulatory and legal framework across the European Union. Having entered into force on 1 August 2024, it introduces obligations that apply in stages, which means compliance is not a single event but an evolving process that organizations must track over time. Because certain interpretations and enforcement practices remain in development, affected parties should treat this as an area requiring ongoing attention rather than a settled body of requirements.

For compliance professionals, the practical importance is that obligations under the Act are fact-specific and depend on how a given AI system operates and is used within the EU. Determining whether and how the Act applies to a particular system or organization requires professional judgment and verification against the current official consolidated text, since provisions, timelines, and defined terms are subject to amendment.

Who it's relevant to

AI developers and providers
Organizations that develop AI systems intended for the EU market fall within the Act's scope and may be subject to enforceable obligations under the framework. Because the Act defines an AI system broadly — a machine-based system capable of operating autonomously and adapting after deployment — developers should assess whether their systems meet this definition and verify their specific obligations against the current official text.
Organizations deploying AI in the EU
Entities that use AI systems within the European Union, as distinct from those that build them, may also carry obligations under the Act. Whether and how the framework applies depends on the particular system and use, and application to specific circumstances requires professional judgment.
Compliance and legal professionals
Compliance officers, legal counsel, and related specialists advising on EU operations need to track this framework as binding law rather than a voluntary standard. Given that provisions apply in stages and that interpretations and enforcement practices remain evolving, these professionals should monitor developments and confirm requirements against the latest authoritative source.
Organizations outside the EU with EU-facing AI activity
Because the Act governs the development and use of AI within the European Union, organizations based elsewhere may be affected where their AI systems reach the EU. Such parties should evaluate their exposure carefully, as the applicability of the framework to a given situation is fact-specific and warrants professional review.

Inside AI Act

Risk-based classification
The EU AI Act structures obligations according to the level of risk an AI system poses, generally distinguishing categories such as prohibited (unacceptable-risk) practices, high-risk systems, and lower-risk systems subject to lighter or transparency-focused obligations. The intensity of compliance duties scales with the assigned risk tier rather than applying uniformly.
Prohibited practices
Certain AI uses deemed to pose unacceptable risk are banned outright. Readers should verify the precise list against the current official text, as the specific practices and their boundaries are subject to interpretation and potential amendment.
High-risk system obligations
Systems classified as high-risk are generally subject to more stringent requirements, which may include risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy or robustness measures. The exact obligations depend on the classification and should be confirmed against the enacted text.
Transparency requirements
For some AI systems, the Act generally imposes disclosure-type obligations so that people are made aware they are interacting with or affected by AI in specified circumstances. These duties are distinct from, and lighter than, the full high-risk regime.
Allocation of responsibilities across the AI value chain
The Act distinguishes among different actors in the AI supply chain (such as those who develop and those who deploy systems), assigning distinct obligations to each. These roles are not interchangeable, and the applicable duties depend on the actor's function.
Legal nature and jurisdictional scope
The EU AI Act is binding EU law, not a voluntary standard or framework. It governs the EU market and may reach organizations established outside the EU where their AI systems affect the EU market or persons within it. Application to a specific organization is fact-specific.

Common questions

Answers to the questions practitioners most commonly ask about AI Act.

Is the EU AI Act the same kind of instrument as a voluntary framework like the NIST AI Risk Management Framework?
No. The EU AI Act is binding law within its scope, carrying legal force and enforcement consequences, whereas frameworks such as the NIST AI Risk Management Framework are voluntary and become obligatory only where incorporated by contract or referenced by another legal requirement. Conflating the two can lead organizations to treat mandatory obligations as optional best practices. Readers should confirm the current status and text of the Act against the official published source.
Does the EU AI Act only apply to organizations physically established in the European Union?
Not necessarily. The Act is generally understood to have extraterritorial reach, meaning it may apply to providers and deployers located outside the EU in certain circumstances, such as where AI system outputs are used within the EU. Territorial establishment is therefore not the sole test for applicability. Because the precise triggers are fact-specific and interpretation continues to evolve, organizations should verify their exposure against the current official text and seek professional judgment for their particular situation.
How does the EU AI Act's risk-based structure affect which obligations apply to a given system?
The Act generally categorizes AI systems by risk level, and the applicable obligations differ accordingly, with more stringent requirements attaching to higher-risk uses. Determining the correct category for a specific system is a fact-specific exercise that depends on the system's purpose and context of use. This entry does not classify individual systems; organizations should assess each system against the current criteria in the official text and apply professional judgment.
How should an organization determine whether it is acting as a provider or a deployer under the Act?
The Act distinguishes between roles such as provider and deployer, and the obligations attaching to each differ. These roles are distinct and should not be conflated, since an organization's responsibilities depend on which role it occupies for a given system, and a single organization may occupy different roles across different systems. Role determination is fact-specific; organizations should map their activities against the definitions in the current official text and obtain professional advice where the position is unclear.
How does compliance with the EU AI Act relate to certification or conformity procedures?
Compliance and certification are related but distinct concepts. Meeting the Act's requirements is a matter of legal obligation, while any conformity or certification-related procedures serve as one means of demonstrating that certain requirements are met, in the cases where such procedures apply. The specific mechanisms, their scope, and their versions can change, so organizations should confirm what applies to their systems against the latest authoritative source rather than assuming a fixed process.
How does the EU AI Act interact with other obligations such as data protection requirements?
The EU AI Act addresses AI-specific requirements and does not replace separate obligations that may apply, such as data protection rules, which govern distinct concerns. Privacy and security, and AI-specific compliance, are separate matters that may apply concurrently to the same system. This entry does not cover those other regimes; organizations should evaluate all applicable obligations together and consult the relevant official texts and professional advisors for their circumstances.

Common misconceptions

The EU AI Act is a voluntary framework or best-practice standard, similar to ISO/IEC 27001 or the NIST frameworks.
The EU AI Act is binding legislation carrying legal force within its scope, not a voluntary or contractual standard. Voluntary standards may support compliance efforts, but they do not substitute for the legal obligations the Act imposes.
The Act applies uniformly to all AI systems, imposing the same requirements on every use case.
Obligations are generally tiered according to risk level, so requirements differ substantially between prohibited, high-risk, and lower-risk systems. Many systems face limited or transparency-focused duties rather than the full high-risk regime.
Because it is an EU law, the Act only affects organizations physically located within the EU.
The Act can have extraterritorial reach, potentially applying to organizations outside the EU where their AI systems affect the EU market or people within the EU. Whether it applies in a given case depends on specific facts and should be assessed against the current official text.

Best practices

Inventory and classify your AI systems by the Act's risk tiers, since the applicable obligations depend on whether a system falls into prohibited, high-risk, or lower-risk categories.
Identify your role in the AI value chain (for example, whether you develop or deploy a system), because the Act assigns distinct obligations to different actors that should not be conflated.
Verify the precise list of prohibited practices, high-risk criteria, and transparency duties against the current official text, as details are subject to interpretation and potential amendment.
Assess extraterritorial exposure if your organization is established outside the EU but your AI systems may affect the EU market or persons within it.
Maintain documentation and governance processes proportionate to the risk classification of each system, recognizing that high-risk systems generally attract more stringent requirements.
Monitor evolving guidance and enforcement practice, and engage qualified professional judgment before applying these definitions to specific circumstances, as this entry is informational and not legal advice.
Application Security Isn’t Optional Anymore.