What the EU AI Act Covers
The EU AI Act regulates AI systems placed on or put into service in the EU market, and AI systems whose outputs are used in the EU. The risk-based framework assigns obligations by risk tier:
Prohibited AI (effective 2 February 2025): Social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), AI that exploits vulnerabilities, subliminal manipulation, and emotion-recognition systems in workplaces and educational institutions.
High-Risk AI (effective 2 August 2026): Annex III systems including AI used in critical infrastructure, education/vocational training, employment, essential private/public services, law enforcement, migration/asylum, and administration of justice. These systems require conformity assessments, technical documentation, human oversight, and registration in the EU AI database.
GPAI Models (effective 2 August 2025): General-purpose AI models with training compute above 10²³ FLOPs face systemic-risk designation and enhanced obligations including adversarial testing, incident reporting, and cybersecurity measures.
Limited-Risk AI: Chatbots and deepfakes require transparency disclosures — users must be informed they are interacting with AI.
Who Must Comply
The following entities are subject to EU AI Act Compliance Hub obligations:
- →Providers placing AI systems on the EU market (regardless of domicile)
- →Deployers using AI systems in the EU for professional purposes
- →Importers bringing non-EU-origin AI systems into the EU market
- →Distributors making AI systems available in the EU market
- →GPAI model providers training models with compute above 10²³ FLOPs
- →High-risk AI providers in Annex III categories (HR, finance, healthcare, law enforcement)
- →Operators of AI in critical infrastructure (energy, water, transport, financial services)
- →Providers of AI used in education, employment screening, or credit/insurance decisions
Penalties and Enforcement History
The EU AI Act imposes a three-tier penalty structure calibrated to violation severity. Prohibited AI violations carry the highest penalties: up to €35M or 7% of global annual turnover (whichever is higher). Non-compliance with high-risk AI obligations triggers penalties up to €15M or 3% of turnover. Provision of incorrect, incomplete, or misleading information to authorities is penalised up to €7.5M or 1% of turnover. SMEs and startups benefit from proportionate assessment — penalties reflect company size and market access. National market surveillance authorities (NCAs) enforce the Act within their jurisdictions, with the European AI Office holding overarching supervisory authority for GPAI models.
Enforcement Timeline
Regulatory Comparison
| Dimension | EU AI Act | NIST AI RMF | ISO 42001 |
|---|---|---|---|
| Applicability | Mandatory — EU market | Voluntary — U.S. framework | Voluntary — global standard |
| Max Fine | €35M or 7% turnover | None (voluntary) | None (certification) |
| Enforcement Body | European AI Office + NCAs | N/A (NIST guidance) | ISO certification bodies |
| GPAI Rules | Yes — systemic risk designation | Partial — foundation model guidance | Limited |
| Timeline | 2024–2027 phased rollout | Published Jan 2023 | 2023 standard (ongoing) |
| Extraterritorial | Yes — EU market access trigger | No | No |
Mitigation Strategy
Map all AI systems your organisation provides, deploys, or imports to the EU AI Act risk tiers. Classify each system using Annex III categories and the Commission's classification guidance. High-risk systems require immediate action: conformity assessment, technical documentation, and registration in the EU AI database before deployment. Document the classification rationale — regulators may request it as evidence of good-faith compliance.
For each high-risk AI system, prepare Annex IV technical documentation covering: system description, development methodology, training data characteristics, accuracy and robustness metrics, human oversight measures, and cybersecurity controls. Conduct a conformity assessment — self-assessment applies to most Annex III systems; third-party assessment is required for biometric identification and critical infrastructure AI. Affix CE marking and register in the EU AI Office database before placing the system on the market.
Deploy post-market monitoring for all high-risk AI to detect performance degradation, bias drift, and serious incidents. GPAI model providers must implement adversarial testing (red-teaming) and report serious incidents to the European AI Office within prescribed timeframes. Designate a responsible person for AI compliance, maintain audit logs for at least 6 months, and integrate EU AI Act obligations into procurement, vendor management, and M&A due diligence processes.
Frequently Asked Questions
A: Yes, if you place AI systems on the EU market, put AI into service in the EU, or your AI's outputs are used in the EU. The Act has extraterritorial reach similar to GDPR. A US company providing an AI-powered HR screening tool to an EU employer is a "provider" subject to full compliance obligations, regardless of where the AI is developed or hosted. Establish EU point-of-contact arrangements and review all products reaching EU customers.
A: Annex III lists eight categories: (1) biometric identification and categorisation; (2) critical infrastructure management; (3) education and vocational training; (4) employment and worker management; (5) access to essential private/public services; (6) law enforcement; (7) migration, asylum, and border control; (8) administration of justice. AI systems in these categories require conformity assessment, technical documentation, and EU AI database registration before market placement.
A: GPAI model obligations (Chapter V) apply from 2 August 2025 to providers of general-purpose AI models, including models made available via API. The systemic-risk designation applies to models trained with more than 10²³ FLOPs of compute. Systemic-risk GPAI providers face enhanced obligations: adversarial testing (red-teaming), incident reporting to the European AI Office, cybersecurity measures, and energy consumption transparency. Providers below the threshold have lighter transparency and copyright compliance obligations.
A: The highest penalty tier applies to prohibited AI practices: up to €35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and startups, the penalty is capped at the lower of the two figures. National market surveillance authorities enforce these penalties within their jurisdictions, with the European AI Office holding overarching authority for GPAI-related violations and cross-border cases.
A: The EU AI Act and GDPR operate in parallel — compliance with one does not satisfy the other. GDPR governs all personal data processing (including data used to train or run AI systems), while the EU AI Act governs the AI system itself. A high-risk AI system processing personal data must satisfy both regimes: an Article 35 GDPR Data Protection Impact Assessment (DPIA) and an EU AI Act Annex IV conformity assessment. The AI Act also imposes specific data governance obligations for high-risk AI training datasets.
EU AI Act Compliance Guide → Risk tier classification, Annex III categories, GPAI model obligations, conformity assessment checklist, and 2025–2026 implementation timeline.
This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.