The EU AI Act is the world's first comprehensive horizontal AI regulation. It establishes a risk-based framework that classifies AI systems into four tiers — unacceptable (prohibited), high (regulated), limited (transparency obligations), and minimal (no obligations) — and imposes progressively stricter requirements as risk increases. The Act applies to any AI system placed on the market or whose output is used in the EU, regardless of where the provider is established.
The Act's extraterritorial scope means US-based AI developers are directly affected. A company in Silicon Valley that deploys an AI system whose outputs are used by anyone in the EU must comply — including designating an EU authorised representative, undergoing conformity assessments for high-risk systems, and maintaining technical documentation for general-purpose AI models. The Act also establishes the AI Office within the European Commission as the central governance body for general-purpose AI models, with the European Artificial Intelligence Board coordinating national authorities.
For AI developers, the Act creates a layered compliance architecture: prohibited practices (Art 5) that cannot be deployed at all, high-risk requirements (Art 8-15) that gate market access through conformity assessments, transparency obligations (Art 50) for limited-risk systems, and a separate regime for general-purpose AI models (Art 51-56) that applies to foundation model providers. The penalties — up to €35M or 7% of global turnover — exceed GDPR fines.
The following AI practices are prohibited:
(a) Subliminal/manipulative techniques: AI systems deploying subliminal techniques beyond a person's consciousness or purposefully manipulative/deceptive techniques with the objective or effect of materially distorting behaviour, causing significant harm.
(b) Exploitation of vulnerabilities: AI systems exploiting vulnerabilities due to age, disability, or social/economic situation to materially distort behaviour causing significant harm.
(c) Social scoring: AI systems for evaluating or classifying persons over time based on social behaviour or personal characteristics, leading to detrimental treatment in unrelated contexts or treatment disproportionate to behaviour.
(d) Predictive policing (solely profiling): AI systems for risk assessment of criminal offending based solely on profiling or personality traits. Does not apply to systems supporting human assessment based on objective, verifiable facts.
(e) Untargeted facial scraping: AI systems creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV.
(f) Emotion inference in workplace/education: AI systems inferring emotions in workplace and education institutions, except for medical or safety reasons.
(g) Biometric categorisation for protected attributes: AI systems categorising persons based on biometric data to deduce race, political opinions, trade union membership, religious/philosophical beliefs, sex life, or sexual orientation.
(h) Real-time remote biometric identification (RBI) in public spaces: Prohibited except for narrow law enforcement purposes (victim search, imminent threat prevention, criminal investigation) subject to prior judicial authorisation and strict safeguards.
The prohibited list draws a hard line that eliminates entire AI product categories. Social scoring systems (like those deployed in parts of China) are categorically banned. Emotion recognition in workplaces is banned — eliminating a product category that several companies have been developing. Untargeted facial scraping criminalises the methodology that many facial recognition companies used to build their training datasets.
The manipulation prohibition (5a) is broad and vaguely defined. "Purposefully manipulative or deceptive techniques" that "materially distort behaviour" could capture recommendation algorithms, targeted advertising, and AI chatbots designed to influence user behaviour. The "significant harm" qualifier provides some limiting effect, but the subjective nature of "manipulation" creates compliance uncertainty. AI developers must assess whether their systems could be characterised as "manipulative" — a term that is not defined in the regulation.
The line between prohibited and high-risk is where the compliance burden concentrates. Many AI use cases that are close to prohibited (e.g., biometric identification not in real-time, emotion recognition outside workplace/education) fall into the high-risk tier instead — where they are legal but subject to extensive requirements. Companies must carefully classify their systems to avoid accidentally crossing into prohibited territory.
An AI system is classified as high-risk under two pathways:
Pathway 1 (Art 6(1)): The AI system is a safety component of a product (or is itself a product) covered by Union harmonisation legislation listed in Annex I (e.g., machinery, medical devices, automotive), and that product is required to undergo third-party conformity assessment. In this case, the AI system's requirements are integrated into the existing product conformity assessment.
Pathway 2 (Art 6(2)): The AI system falls under one of the use cases listed in Annex III, which includes: (1) biometrics (remote identification, biometric categorisation, emotion recognition); (2) critical infrastructure (safety components in water, gas, electricity, road/rail traffic); (3) education and vocational training (admissions, exam scoring, student evaluation); (4) employment and worker management (recruitment, performance evaluation, task allocation); (5) essential services (creditworthiness, credit scoring, insurance pricing, benefits eligibility); (6) law enforcement (polygraphs, evidence reliability assessment, profiling); (7) migration and border management (lie detection, document verification, risk assessment); (8) justice and democratic processes (legal research, case facts evaluation, democratic process influence).
Derogation (Art 6(3)): An Annex III system is not high-risk if it: performs a narrow procedural task; improves the result of a previously completed human activity; detects decision-making patterns without replacing human assessment; or performs a preparatory task. However, systems performing profiling are always high-risk.
Article 7 empowers the Commission to amend Annex III via delegated acts, adding new high-risk use cases based on criteria including intended purpose, data processed, autonomy level, harm potential, power asymmetry, and reversibility of outcomes.
The risk-tier system gates AI development at the classification stage. Whether your AI system is classified as "minimal," "limited," or "high-risk" determines whether you face no obligations, transparency obligations, or the full weight of the Act's requirements (risk management, data governance, logging, transparency, human oversight, accuracy, conformity assessment, registration, post-market monitoring). Getting classification wrong — classifying a high-risk system as minimal — exposes the provider to penalties up to €15M or 3% of global turnover.
Annex III's use case list is the regulatory net. The eight categories capture the most commercially significant AI applications: hiring/recruitment, credit scoring, insurance, education, law enforcement, critical infrastructure. Any company building AI products in these domains faces the full high-risk compliance regime. The Commission's power to expand Annex III via delegated acts (Art 7) means the net can widen without legislative action — creating regulatory uncertainty for AI developers whose products are currently outside the high-risk tier.
The derogation (Art 6(3)) is narrow and easily lost. AI systems that "perform a narrow procedural task" or "improve a previously completed human activity" can escape high-risk classification — but only if they don't perform profiling. Since many modern AI systems inherently profile users, the derogation's practical value is limited. The "narrow procedural task" language also conflicts with the reality that AI systems are often deployed precisely because they handle complex, non-procedural tasks.
Art 8 — Compliance. High-risk AI systems must comply with all requirements in this Section, taking into account their intended purpose and the state of the art.
Art 9 — Risk management system. A continuous, iterative risk management process must be established, implemented, documented, and maintained throughout the AI system's lifecycle. It must identify and analyse known and reasonably foreseeable risks, estimate and evaluate risks under intended use and foreseeable misuse, evaluate risks from post-market monitoring, and adopt targeted risk management measures. Residual risk must be judged acceptable.
Art 10 — Data and data governance. Training, validation, and testing datasets must meet quality criteria: relevant design choices, documented data collection processes and origins, data preparation operations (annotation, labelling, cleaning), bias examination and mitigation, identification of data gaps. Datasets must be relevant, sufficiently representative, free of errors to the best extent possible, and have appropriate statistical properties — including for specific persons or groups. Special category data may be processed strictly for bias detection and correction, subject to appropriate safeguards.
Art 13 — Transparency to deployers. High-risk AI systems must be sufficiently transparent to enable deployers to interpret outputs and use them appropriately. Instructions for use must include: provider identity, system capabilities and limitations (accuracy metrics, robustness, cybersecurity), known risk circumstances, training data specifications, and human oversight measures.
Art 14 — Human oversight. Systems must be designed to be effectively overseen by natural persons during use. Oversight measures must enable: understanding of system capacities and limitations, awareness of automation bias, correct interpretation of outputs, ability to disregard/override/reverse outputs, and ability to intervene via a "stop" button or similar procedure.
Art 15 — Accuracy, robustness, and cybersecurity. Systems must achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle. Accuracy levels must be declared in instructions for use. Systems must be resilient against errors, faults, and inconsistencies. For systems that continue learning post-deployment, feedback loop risks must be addressed. Cybersecurity measures must protect against data poisoning, model poisoning, adversarial examples, model evasion, and confidentiality attacks.
The data governance requirements (Art 10) create a documentation burden that favours companies with established data pipelines. AI developers must document: data collection processes, data origins, original purpose of collection for personal data, annotation and labelling procedures, bias examination methodologies, and data gap identification. For companies that built their training datasets through web scraping with minimal documentation, retroactively creating this documentation is infeasible. Only companies that designed their data pipelines with provenance tracking from the start can comply efficiently.
The bias detection requirement (Art 10(2)(f-g)) is the Act's most technically demanding provision. AI developers must examine datasets for biases "likely to affect health and safety of persons, have a negative impact on fundamental rights, or lead to discrimination prohibited under Union law" — and implement measures to "detect, prevent and mitigate possible biases." This requires: (1) defining what bias means in the system's context, (2) measuring it across protected attributes, (3) implementing mitigation strategies (reweighting, augmentation, adversarial debiasing), and (4) documenting the process. For large language models, bias detection across all possible use cases is an open research problem.
Human oversight (Art 14) with a "stop" button requirement creates an architecture mandate. High-risk AI systems must include a mechanism for human operators to halt the system — a "stop button or similar procedure." This is a design requirement, not a policy requirement. AI systems that operate autonomously or in real-time pipelines (e.g., automated trading, content moderation at scale) may need fundamental architectural changes to incorporate a meaningful stop mechanism.
The cybersecurity requirements (Art 15(5)) specifically address AI-specific attack vectors. Data poisoning, model poisoning, adversarial examples, and model evasion are called out by name. This means AI developers must implement and document defenses against these attacks — which is an active research area, not a solved problem. For many AI companies, the state of the art in adversarial robustness lags far behind what Art 15 appears to expect.
For Annex III point 1 systems (biometrics): Providers may choose between (a) internal control based on Annex VI, or (b) assessment of the quality management system and technical documentation with involvement of a notified body (Annex VII). The notified body route is mandatory where harmonised standards or common specifications are not applied or are only partially applied.
For Annex III points 2-8 (all other high-risk use cases): Providers follow the internal control conformity assessment procedure (Annex VI) — no notified body involvement required.
For Annex I systems (product safety components): The provider follows the relevant conformity assessment procedure required under the applicable product harmonisation legislation, with AI Act requirements integrated into that assessment.
Where a notified body is involved, the provider may choose any notified body. For law enforcement, immigration, or asylum systems, the market surveillance authority acts as the notified body. The EU declaration of conformity (Art 47) must be drawn up and kept for 10 years. CE marking (Art 48) must be affixed.
The conformity assessment system favors large companies by design. For most high-risk AI systems (Annex III points 2-8), the assessment is based on "internal control" — meaning the provider self-assesses and self-certifies compliance. This appears to reduce burden, but the self-assessment must be backed by technical documentation, a quality management system, and post-market monitoring that must withstand regulatory inspection. Only companies with dedicated compliance teams, legal counsel, and quality management infrastructure can produce documentation that will survive scrutiny. A startup building an AI hiring tool faces the same documentation requirements as a multinational — but without the personnel to produce it.
Notified body involvement creates a bottleneck for biometric AI. Biometric systems (Annex III point 1) may require third-party assessment by a notified body. The number of notified bodies qualified to assess AI systems is extremely limited. The assessment process is time-consuming and expensive — creating a de facto gate that slows time-to-market for biometric AI products. Large companies with existing regulatory affairs teams (e.g., companies already in medical device conformity assessment) have a structural advantage.
The CE marking creates consumer trust signaling that benefits incumbents. CE marking signals compliance to procurers and consumers. Companies that can afford the conformity assessment process and achieve CE marking early will have a market advantage — the compliance cost becomes a barrier to entry for new competitors. This is the "regulatory moat" effect: compliance costs that large companies can absorb become competitive advantages against smaller entrants.
Self-assessment with regulatory inspection creates enforcement asymmetry. The internal control procedure means providers self-certify — but regulators can inspect documentation post-market. Large companies with legal teams can prepare documentation that withstands inspection. Smaller companies may produce technically compliant but legally vulnerable documentation. The enforcement risk falls disproportionately on those without regulatory affairs expertise.
Art 50 — Transparency obligations (limited risk tier). Providers must ensure AI systems interacting directly with natural persons inform them they are interacting with an AI system (unless obvious from context). Providers of AI systems generating synthetic audio, image, video, or text must mark outputs as artificially generated in a machine-readable format. Deployers of emotion recognition or biometric categorisation systems must inform exposed persons. Deployers of deepfake AI must disclose that content was artificially generated.
Art 51 — GPAI with systemic risk. A general-purpose AI model is presumed to have systemic risk if it has high-impact capabilities based on technical criteria (training compute, parameters, dataset size, benchmarks) or if the Commission designates it. The Commission considers: number of parameters, quality/size of training dataset, compute used for training, input/output modalities, benchmark evaluations, market reach (presumed at 10,000+ registered business users), and number of end-users.
Art 53 — Obligations for all GPAI providers. Providers must: maintain technical documentation (Annex XI); provide documentation to downstream AI system providers (Annex XII); implement a copyright compliance policy; publish a sufficiently detailed summary of training content. Open-source models are exempt from Art 53(1)(a) and (b) unless they present systemic risk.
Art 55 — Additional obligations for GPAI with systemic risk. Providers must: perform adversarial testing; assess and mitigate systemic risks at Union level; report serious incidents; ensure adequate cybersecurity for the model and physical infrastructure.
Art 56 — Codes of practice. The AI Office facilitates codes of practice at Union level. Providers may demonstrate compliance through adherence to approved codes until harmonised standards are published.
Governance structure: The European Artificial Intelligence Board (EAIB) coordinates national authorities. The AI Office (within the Commission) is the central governance body for GPAI models. Each Member State designates at least one notifying authority and one market surveillance authority (Art 70). An EU database (Art 71) registers high-risk AI systems. Providers must report serious incidents to market surveillance authorities within 15 days (Art 73).
The GPAI regime (Art 51-55) is the world's first binding regulation of foundation models. Every provider of a general-purpose AI model — including OpenAI, Anthropic, Google, Meta, Mistral, and any company placing a foundation model on the EU market — must comply with Art 53: maintain technical documentation, provide downstream documentation, implement copyright policy, and publish a training content summary. For models with systemic risk, additional obligations include adversarial testing, systemic risk assessment, and incident reporting. This is the regulatory layer that directly governs the frontier AI industry.
The training content summary requirement (Art 53(1)(d)) forces transparency about training data. GPAI providers must publish "a sufficiently detailed summary about the content used for training" using a template provided by the AI Office. This requirement directly addresses the opacity of training datasets — and creates a disclosure obligation that copyright holders and privacy advocates can use to assess whether their works or personal data were used. The level of detail in the AI Office's template will determine whether this is a meaningful transparency mechanism or a box-ticking exercise.
The systemic risk classification (Art 51) creates a two-tier GPAI regime. Models above the compute/parameter/reach thresholds face additional obligations. The 10,000 registered business users presumption (Art 51 criteria) means any commercially successful GPAI model will likely cross the threshold. The Commission can also designate models ex officio or based on scientific panel alerts — meaning the AI Office has discretionary power to escalate any model to the systemic risk tier. This creates regulatory uncertainty: a model that is below thresholds today could be designated tomorrow.
The open-source exemption (Art 53(2)) is significant but limited. Open-source GPAI models that publish their weights, architecture, and usage information are exempt from the documentation obligations — unless they present systemic risk. This creates a regulatory incentive for open-weight releases, but the systemic risk exception means that the most capable open-source models (e.g., Llama-class models) may still face full obligations. The boundary between "open source" and "systemic risk" will be one of the most contested regulatory questions in AI governance.
The AI Office is the GPAI regulator — and it has no US equivalent. The AI Office within the European Commission has direct authority over GPAI model providers, including those in third countries (via the authorised representative requirement, Art 54). US AI companies must appoint an EU-based authorised representative who maintains technical documentation and cooperates with the AI Office. This is the extraterritorial enforcement mechanism — see the next section for its full implications.
Art 2(1) — Scope. The Act applies to: (a) providers placing AI systems or GPAI models on the EU market, irrespective of whether those providers are established within the Union or in a third country; (b) deployers established or located within the Union; (c) providers and deployers in a third country where the output produced by the AI system is used in the Union; (d) importers and distributors; (e) product manufacturers; (f) authorised representatives of non-EU providers; (g) affected persons located in the Union.
Art 54 — Authorised representatives for third-country GPAI providers. Before placing a GPAI model on the Union market, providers established in third countries must appoint an authorised representative established in the Union. The representative must: verify technical documentation has been drawn up; maintain a copy for 10 years; provide information to the AI Office on request; cooperate with authorities. The representative must terminate the mandate if the provider acts contrary to its obligations. Open-source models without systemic risk are exempt.
Art 99 — Penalties. Non-compliance with prohibited practices (Art 5): fines up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. Non-compliance with high-risk obligations (Art 16, 22-26, etc.): fines up to €15,000,000 or 3% of worldwide turnover. Supply of incorrect/misleading information: fines up to €7,500,000 or 1% of worldwide turnover. For SMEs and start-ups, fines are capped at the lower of the percentage or the fixed amount.
When determining fines, authorities consider: nature, gravity, and duration of infringement; prior fines for the same infringement; fines under other Union/national law for the same activity; intentional or negligent character; action to mitigate harm; prior infringements; degree of cooperation; financial situation.
The extraterritorial reach is the Act's most significant feature for US AI developers. Art 2(1)(c) extends the Act to providers in third countries whose AI system output is used in the EU. This means a US-based AI company whose API is called by a user in the EU — or whose model output is embedded in a product used in the EU — is subject to the Act. The "output" criterion is broad: it could capture a US company's AI model used by a European customer through an API, a US model fine-tuned by a European deployer, or even a US model whose outputs are consumed indirectly through a downstream product.
The authorised representative requirement (Art 54) creates a physical EU presence obligation. Third-country GPAI providers must appoint an EU-based representative who can be served by authorities and who maintains documentation. This is not a paper formality — the representative must verify compliance, maintain records for 10 years, and must terminate the relationship (and inform the AI Office) if the provider acts contrary to obligations. This creates a regulatory foothold in the EU for enforcement against non-EU companies.
Penalties exceed GDPR — and GDPR enforcement was significant. The €35M/7% cap for prohibited practice violations exceeds GDPR's €20M/4% maximum. For a company with €50B global revenue, the maximum AI Act fine is €3.5B vs. GDPR's €2B. The 7% figure is deliberately designed to be painful even for the largest tech companies. The SME cap (lower of percentage or fixed amount) provides some protection for startups, but does not exempt them from compliance — only from the most devastating fine levels.
The practical effect on US AI developers: Any US AI company with EU users must: (1) classify its AI systems under the risk tiers; (2) for high-risk systems, implement the Art 8-15 requirements and undergo conformity assessment; (3) for GPAI models, comply with Art 53-55 documentation and transparency obligations; (4) appoint an EU authorised representative for GPAI models; (5) implement post-market monitoring and incident reporting. Companies that ignore the Act face fines that scale with global revenue — not EU revenue. The Act uses worldwide turnover as the fine base, meaning a US company's entire global revenue is the penalty denominator.
Contrast with the US approach. While the EU regulates AI through binding legislation with extraterritorial reach, the US approach under EO 14409 uses "voluntary" frameworks, classified benchmarks, and procurement-mediated compliance. The EU's model creates legal obligations enforceable by fines; the US model creates structural pressure enforceable by market access. AI developers operating in both jurisdictions face the dual challenge of EU legal compliance and US structural compliance — see our GDPR analysis for the underlying data protection layer that intersects with both.
Related frameworks: GDPR (Regulation 2016/679) (data protection layer — AI Act Art 2(7) preserves GDPR obligations; Art 10(5) allows special category data processing for bias detection under GDPR conditions) · EO 14409 (US AI governance — voluntary frameworks vs. EU's binding regulation; classified benchmarks vs. risk-tier classification)
Key interactions: AI Act Art 22 GDPR automated decisions map to AI Act Annex III high-risk categories · AI Act Art 27 (fundamental rights impact assessment) parallels GDPR Art 35 (DPIA) · AI Act Art 50 transparency obligations build on GDPR Art 13-14 information requirements · AI Act penalties (Art 99) exceed GDPR penalties (Art 83) · AI Act Art 2(7) explicitly preserves GDPR — both apply simultaneously where personal data is processed