Jurisdiction
European Union (extraterritorial)
Authority
European AI Office + National Market Surveillance Authorities
Max Penalty
€35M or 7% of global annual turnover
Compliance Difficulty90/100
The EU AI Act (Regulation (EU) 2024/1689) became the world's first comprehensive AI law, entering into force on 1 August 2024. It applies a risk-based classification framework — prohibited, high-risk, limited-risk, and minimal-risk — and imposes proportionate obligations on providers, deployers, importers, and distributors across all sectors. GPAI model providers face transparency and systemic-risk obligations from 2 August 2025, with high-risk system requirements phased in through 2 August 2026. The Act has extraterritorial reach: any provider placing AI on the EU market or deployer operating in the EU must comply, regardless of domicile.

What the EU AI Act Covers

The EU AI Act regulates AI systems placed on or put into service in the EU market, and AI systems whose outputs are used in the EU. The risk-based framework assigns obligations by risk tier:

Prohibited AI (effective 2 February 2025): Social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), AI that exploits vulnerabilities, subliminal manipulation, and emotion-recognition systems in workplaces and educational institutions.

High-Risk AI (effective 2 August 2026): Annex III systems including AI used in critical infrastructure, education/vocational training, employment, essential private/public services, law enforcement, migration/asylum, and administration of justice. These systems require conformity assessments, technical documentation, human oversight, and registration in the EU AI database.

GPAI Models (effective 2 August 2025): General-purpose AI models with training compute above 10²³ FLOPs face systemic-risk designation and enhanced obligations including adversarial testing, incident reporting, and cybersecurity measures.

Limited-Risk AI: Chatbots and deepfakes require transparency disclosures — users must be informed they are interacting with AI.

Who Must Comply

The following entities are subject to EU AI Act Compliance Hub obligations:

  • Providers placing AI systems on the EU market (regardless of domicile)
  • Deployers using AI systems in the EU for professional purposes
  • Importers bringing non-EU-origin AI systems into the EU market
  • Distributors making AI systems available in the EU market
  • GPAI model providers training models with compute above 10²³ FLOPs
  • High-risk AI providers in Annex III categories (HR, finance, healthcare, law enforcement)
  • Operators of AI in critical infrastructure (energy, water, transport, financial services)
  • Providers of AI used in education, employment screening, or credit/insurance decisions

Penalties and Enforcement History

The EU AI Act imposes a three-tier penalty structure calibrated to violation severity. Prohibited AI violations carry the highest penalties: up to €35M or 7% of global annual turnover (whichever is higher). Non-compliance with high-risk AI obligations triggers penalties up to €15M or 3% of turnover. Provision of incorrect, incomplete, or misleading information to authorities is penalised up to €7.5M or 1% of turnover. SMEs and startups benefit from proportionate assessment — penalties reflect company size and market access. National market surveillance authorities (NCAs) enforce the Act within their jurisdictions, with the European AI Office holding overarching supervisory authority for GPAI models.

Enforcement Timeline

Aug 2024
EU AI Act Enters Into Force
Regulation (EU) 2024/1689 officially entered into force on 1 August 2024, starting the phased implementation clock.
Feb 2025
Prohibited AI Rules Apply
Chapter II prohibited AI practices (social scoring, real-time biometric identification, subliminal manipulation) became enforceable on 2 February 2025.
Aug 2025
GPAI Model Obligations Apply
Chapter V GPAI obligations and governance rules applicable to general-purpose AI model providers became enforceable on 2 August 2025.
Aug 2026
High-Risk AI Obligations Apply
Full Annex III high-risk AI system obligations — conformity assessments, technical documentation, human oversight, EU AI database registration — become mandatory.
Aug 2027
Annex I High-Risk AI
AI systems already under EU product safety legislation (Annex I: machinery, medical devices, vehicles) must additionally comply with EU AI Act requirements.

Regulatory Comparison

DimensionEU AI ActNIST AI RMFISO 42001
ApplicabilityMandatory — EU marketVoluntary — U.S. frameworkVoluntary — global standard
Max Fine€35M or 7% turnoverNone (voluntary)None (certification)
Enforcement BodyEuropean AI Office + NCAsN/A (NIST guidance)ISO certification bodies
GPAI RulesYes — systemic risk designationPartial — foundation model guidanceLimited
Timeline2024–2027 phased rolloutPublished Jan 20232023 standard (ongoing)
ExtraterritorialYes — EU market access triggerNoNo

Mitigation Strategy

01
Conduct an AI System Inventory and Risk Classification

Map all AI systems your organisation provides, deploys, or imports to the EU AI Act risk tiers. Classify each system using Annex III categories and the Commission's classification guidance. High-risk systems require immediate action: conformity assessment, technical documentation, and registration in the EU AI database before deployment. Document the classification rationale — regulators may request it as evidence of good-faith compliance.

02
Build Technical Documentation and Run Conformity Assessments

For each high-risk AI system, prepare Annex IV technical documentation covering: system description, development methodology, training data characteristics, accuracy and robustness metrics, human oversight measures, and cybersecurity controls. Conduct a conformity assessment — self-assessment applies to most Annex III systems; third-party assessment is required for biometric identification and critical infrastructure AI. Affix CE marking and register in the EU AI Office database before placing the system on the market.

03
Establish Ongoing Post-Market Monitoring and Incident Reporting

Deploy post-market monitoring for all high-risk AI to detect performance degradation, bias drift, and serious incidents. GPAI model providers must implement adversarial testing (red-teaming) and report serious incidents to the European AI Office within prescribed timeframes. Designate a responsible person for AI compliance, maintain audit logs for at least 6 months, and integrate EU AI Act obligations into procurement, vendor management, and M&A due diligence processes.

As of 2025, the European AI Office issued its first binding opinions on GPAI model providers under Article 52 of the EU AI Act, establishing that training compute above the 10²³ FLOP threshold triggers systemic-risk designation even for models not publicly released when deployed via API. The first formal investigations under prohibited AI rules were opened in Q2 2025 relating to emotion-recognition systems in EU workplace management software — the sector most affected by the February 2025 prohibited AI rollout.Enforcement Precedent

Frequently Asked Questions

Q: Does the EU AI Act apply to my US-based company?

A: Yes, if you place AI systems on the EU market, put AI into service in the EU, or your AI's outputs are used in the EU. The Act has extraterritorial reach similar to GDPR. A US company providing an AI-powered HR screening tool to an EU employer is a "provider" subject to full compliance obligations, regardless of where the AI is developed or hosted. Establish EU point-of-contact arrangements and review all products reaching EU customers.

Q: What are Annex III high-risk AI categories?

A: Annex III lists eight categories: (1) biometric identification and categorisation; (2) critical infrastructure management; (3) education and vocational training; (4) employment and worker management; (5) access to essential private/public services; (6) law enforcement; (7) migration, asylum, and border control; (8) administration of justice. AI systems in these categories require conformity assessment, technical documentation, and EU AI database registration before market placement.

Q: When do GPAI model obligations apply and who is affected?

A: GPAI model obligations (Chapter V) apply from 2 August 2025 to providers of general-purpose AI models, including models made available via API. The systemic-risk designation applies to models trained with more than 10²³ FLOPs of compute. Systemic-risk GPAI providers face enhanced obligations: adversarial testing (red-teaming), incident reporting to the European AI Office, cybersecurity measures, and energy consumption transparency. Providers below the threshold have lighter transparency and copyright compliance obligations.

Q: What is the EU AI Act penalty for a prohibited AI violation?

A: The highest penalty tier applies to prohibited AI practices: up to €35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and startups, the penalty is capped at the lower of the two figures. National market surveillance authorities enforce these penalties within their jurisdictions, with the European AI Office holding overarching authority for GPAI-related violations and cross-border cases.

Q: How does the EU AI Act interact with GDPR for AI systems processing personal data?

A: The EU AI Act and GDPR operate in parallel — compliance with one does not satisfy the other. GDPR governs all personal data processing (including data used to train or run AI systems), while the EU AI Act governs the AI system itself. A high-risk AI system processing personal data must satisfy both regimes: an Article 35 GDPR Data Protection Impact Assessment (DPIA) and an EU AI Act Annex IV conformity assessment. The AI Act also imposes specific data governance obligations for high-risk AI training datasets.

Deep Dive Guide

EU AI Act Compliance Guide → Risk tier classification, Annex III categories, GPAI model obligations, conformity assessment checklist, and 2025–2026 implementation timeline.

About the Author

This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.

LLB · LLM
International Commercial Law
20 Years
Active Legal Practice
Notary + Arbitrator
Commissioned & International
Jurisdictions
UAE · EU · US · UK · Singapore
Full credentials and methodology →