The EU AI Act is the European Union's horizontal regulation of artificial intelligence systems, adopted in 2024 and entering force across phased deadlines. It classifies AI systems by risk – unacceptable, high, limited, and minimal – and imposes obligations on providers and deployers, with the heaviest requirements falling on high-risk systems and general-purpose models carrying systemic risk.
- The EU's horizontal AI regulation, adopted 2024, enforced in phases
- Four risk classes: unacceptable, high, limited, and minimal
- Obligations fall on both providers and deployers, not developers alone
- Penalties for prohibited practices reach €35 million or 7% of turnover
Why is the EU AI Act important?
The EU AI Act matters because it is the first major comprehensive AI law and it has shaped regulatory drafting in other jurisdictions. Organizations building compliance programs against it are frequently building the substrate for obligations that have not arrived yet elsewhere.
Enforcement is phased rather than switched on. It began in February 2025 with the Article 5 prohibitions on unacceptable-risk systems. General-purpose AI obligations took effect in August 2025. Broader high-risk obligations follow on the timeline set out in Article 113 of Regulation (EU) 2024/1689, and that timeline has been amended since adoption – which is reason enough to check the current position rather than rely on a date quoted in an older briefing.
The penalties are what focus attention. Prohibited practices carry fines reaching €35 million or 7% of worldwide annual turnover under Article 99. Enterprises with EU exposure are consequently mapping AI inventories and post-market monitoring against the Act's high-risk requirements.
What is the EU AI Act?
The EU AI Act is a horizontal regulation, meaning it applies across sectors rather than to one industry. It regulates AI systems by the risk they present rather than by the technology used, and it reaches organizations outside the EU whose systems are placed on or affect the EU market.
Obligations attach to roles. A provider develops an AI system or places it on the market. A deployer uses one under its own authority. Most enterprises are deployers of third-party AI and providers of anything they build themselves, which means both sets of duties usually apply somewhere in the organization.
For high-risk systems the requirements are substantive: a risk management system, data governance, technical documentation, record-keeping, transparency to users, human oversight, and accuracy and robustness measures, with conformity assessment before market placement and monitoring afterward.
General-purpose AI models carry their own obligations around documentation, copyright policy, and training-data transparency, with additional duties where a model is deemed to present systemic risk.
Types of EU AI Act risk classifications
The Act's four risk classes determine everything else, so classification is the first compliance task.
Unacceptable-risk systems are prohibited outright under Article 5. The category covers practices such as social scoring by public authorities, certain biometric categorization, and manipulative techniques exploiting vulnerability. These prohibitions have been enforceable since February 2025.
High-risk systems are permitted with substantial obligations. The Act reaches them two ways: systems used in listed areas such as employment, education, essential services, and law enforcement, and AI functioning as a safety component in products already regulated under EU product law.
Limited-risk systems carry transparency duties rather than full obligations – users must know they are interacting with AI, and synthetic content must be marked.
Minimal-risk systems, which is most AI in commercial use, carry no specific obligations beyond existing law.
General-purpose AI models sit across this structure with their own separate regime.
EU AI Act & Onyx
Onyx maps inventory, posture, governance, and runtime evidence to the EU AI Act's high-risk system requirements, so security and compliance teams can produce auditable artifacts on demand rather than assembling them when a request arrives.
The mapping follows the Act's own requirements. Record-keeping is served by the decision log, which captures what an AI system did, under what authorization, and what policy was evaluated. Human oversight under Article 14 is served by escalation, where actions crossing a defined threshold route to a person rather than completing autonomously. Risk management under Article 9 is served by continuous posture assessment and adversarial testing. Data governance is served by inline inspection of what enters and leaves a model. AI Governance is where those artifacts are produced.


