Update cookies preferences

EU AI Act

Updated:
 
August 12, 2026
Overview

The EU AI Act is the European Union's horizontal regulation of artificial intelligence systems, adopted in 2024 and entering force across phased deadlines. It classifies AI systems by risk – unacceptable, high, limited, and minimal – and imposes obligations on providers and deployers, with the heaviest requirements falling on high-risk systems and general-purpose models carrying systemic risk.

  • The EU's horizontal AI regulation, adopted 2024, enforced in phases
  • Four risk classes: unacceptable, high, limited, and minimal
  • Obligations fall on both providers and deployers, not developers alone
  • Penalties for prohibited practices reach €35 million or 7% of turnover

Why is the EU AI Act important?

The EU AI Act matters because it is the first major comprehensive AI law and it has shaped regulatory drafting in other jurisdictions. Organizations building compliance programs against it are frequently building the substrate for obligations that have not arrived yet elsewhere.

Enforcement is phased rather than switched on. It began in February 2025 with the Article 5 prohibitions on unacceptable-risk systems. General-purpose AI obligations took effect in August 2025. Broader high-risk obligations follow on the timeline set out in Article 113 of Regulation (EU) 2024/1689, and that timeline has been amended since adoption – which is reason enough to check the current position rather than rely on a date quoted in an older briefing.

The penalties are what focus attention. Prohibited practices carry fines reaching €35 million or 7% of worldwide annual turnover under Article 99. Enterprises with EU exposure are consequently mapping AI inventories and post-market monitoring against the Act's high-risk requirements.

What is the EU AI Act?

The EU AI Act is a horizontal regulation, meaning it applies across sectors rather than to one industry. It regulates AI systems by the risk they present rather than by the technology used, and it reaches organizations outside the EU whose systems are placed on or affect the EU market.

Obligations attach to roles. A provider develops an AI system or places it on the market. A deployer uses one under its own authority. Most enterprises are deployers of third-party AI and providers of anything they build themselves, which means both sets of duties usually apply somewhere in the organization.

For high-risk systems the requirements are substantive: a risk management system, data governance, technical documentation, record-keeping, transparency to users, human oversight, and accuracy and robustness measures, with conformity assessment before market placement and monitoring afterward.

General-purpose AI models carry their own obligations around documentation, copyright policy, and training-data transparency, with additional duties where a model is deemed to present systemic risk.

Types of EU AI Act risk classifications

The Act's four risk classes determine everything else, so classification is the first compliance task.

Unacceptable-risk systems are prohibited outright under Article 5. The category covers practices such as social scoring by public authorities, certain biometric categorization, and manipulative techniques exploiting vulnerability. These prohibitions have been enforceable since February 2025.

High-risk systems are permitted with substantial obligations. The Act reaches them two ways: systems used in listed areas such as employment, education, essential services, and law enforcement, and AI functioning as a safety component in products already regulated under EU product law.

Limited-risk systems carry transparency duties rather than full obligations – users must know they are interacting with AI, and synthetic content must be marked.

Minimal-risk systems, which is most AI in commercial use, carry no specific obligations beyond existing law.

General-purpose AI models sit across this structure with their own separate regime.

EU AI Act & Onyx

Onyx maps inventory, posture, governance, and runtime evidence to the EU AI Act's high-risk system requirements, so security and compliance teams can produce auditable artifacts on demand rather than assembling them when a request arrives.

The mapping follows the Act's own requirements. Record-keeping is served by the decision log, which captures what an AI system did, under what authorization, and what policy was evaluated. Human oversight under Article 14 is served by escalation, where actions crossing a defined threshold route to a person rather than completing autonomously. Risk management under Article 9 is served by continuous posture assessment and adversarial testing. Data governance is served by inline inspection of what enters and leaves a model. AI Governance is where those artifacts are produced.

Frequently Asked Questions

Does the EU AI Act apply to a company outside the EU?
Yes, where its AI systems are placed on the EU market or their output is used in the EU. Territorial reach follows market effect rather than corporate domicile, which is why non-EU enterprises with European customers are in scope.
Are we a provider or a deployer?
Usually both. You are a deployer of third-party AI used under your own authority, and a provider of anything you build and place on the market. The two roles carry different obligations, so the classification has to be made system by system.
When do the high-risk obligations actually apply?
On the timeline in Article 113, which has been amended since the Act was adopted. Any specific date quoted in secondary sources should be checked against the current consolidated text rather than trusted, since the deadlines have moved.
What are the penalties?
Up to €35 million or 7% of worldwide annual turnover for prohibited practices under Article 99, with lower ceilings for other infringements. Fines scale with turnover, so the percentage matters more than the absolute figure for large organizations.
How do AI agents fit into the Act's classifications?
By use rather than by architecture. An agent operating in a listed high-risk area carries high-risk obligations; the same technology in a minimal-risk use does not. The Commission's overview is the starting point, and human oversight duties are usually the hardest for autonomous agents to satisfy.
Related terms:
Table of Contents