The EU AI Act Explained: A General Guide to Europe’s Risk-Based AI Regulation

A practical introduction to the EU AI Act, explaining its risk-based framework, global reach, regulated actors, AI system classifications, phased implementation, governance and significant penalties for noncompliance.

The EU AI Act Explained: A General Guide to Europe’s Risk-Based AI Regulation
ChatGPT generated from image: The Sociable Telephone Game -- 1902 Players connected by a "telephone" - New-York Historical Society 

The European Union Artificial Intelligence Act (EU AI Act) establishes a comprehensive regulatory framework for artificial intelligence in the European Union. Rather than attempting to regulate AI as a technology in the abstract, the Act focuses primarily on how AI is developed, placed on the market, put into service and used.

Its basic logic is risk-based: the greater the potential risks associated with an AI system or its use, the more demanding the regulatory requirements become. Some AI practices are prohibited altogether; certain systems are classified as high-risk and subject to extensive requirements; other systems are primarily subject to transparency obligations; and many lower-risk systems face comparatively limited requirements. The Act also creates a separate regulatory framework for general-purpose AI (GPAI) models. 

This article provides a general introduction to the framework. More detailed articles address the individual categories, obligations and enforcement mechanisms separately.

What Is the EU AI Act?

The EU AI Act approaches artificial intelligence in significant part through the lens of product regulation and safety. At its core are requirements that must be satisfied before certain AI systems can be placed on the EU market or put into service.

This approach differs from the General Data Protection Regulation (GDPR). The GDPR regulates the processing of personal data. The AI Act regulates AI systems and certain AI models, and the information they process may include personal or non-personal data and content.

The two frameworks therefore complement one another. An organization using an AI system involving personal data may have obligations under both the GDPR and the AI Act. 


A useful way to understand the AI Act is that it generally seeks to regulate AI use cases and risks rather than AI technology itself.

The EU AI Act Has Potentially Global Reach

The AI Act is an EU law, but its significance is not limited to companies headquartered in Europe.

A provider does not necessarily have to be established in the EU for the Act to apply. Among other circumstances, the Act applies to providers placing AI systems or GPAI models on the EU market or putting AI systems into service in the EU. It also applies to deployers established or located in the EU.

Most importantly for organizations outside Europe, the Act can apply where a provider or deployer is outside the EU but the output produced by an AI system is used in the EU


The EU AI Act can affect organizations throughout an international AI supply chain.

When Does the EU AI Act Apply?

The AI Act entered into force on August 1, 2024, but its requirements become applicable progressively rather than all at once.

The result is a phased implementation structure. Determining whether a particular requirement applies therefore requires asking not only what kind of AI is involved, but also when it was placed on the market or put into service.

What Is an “AI System”?

The starting point is determining whether the technology is an AI system within the meaning of the Act.


Article 3(1) defines an AI system as a machine-based system designed to operate with varying levels of autonomy that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs—including predictions, content, recommendations or decisions—that can influence physical or virtual environments

Several characteristics are therefore important:

  • the system is machine-based;
  • it operates with some degree of autonomy;
  • it infers how to generate outputs from its inputs;
  • those outputs may include predictions, content, recommendations or decisions; and
  • the outputs can influence a physical or virtual environment.

There are two particularly important concepts for distinguishing AI from conventional software: autonomous operation and inference.

A system based solely on human-defined rules that automatically executes predetermined operations does not necessarily satisfy this concept of autonomy. By contrast, inference can involve machine-learning techniques as well as logic- or knowledge-based techniques.

This means the Act is not confined to machine learning or generative AI. Certain expert systems, for example, may qualify because knowledge-based systems can use inference algorithms to draw conclusions from a defined knowledge base. 

Adaptiveness after deployment—essentially, the capacity of a system to change its behavior during use—is relevant but not required for a system to qualify as an AI system.

AI Systems and AI Models Are Not the Same Thing

An important distinction under the Act is the difference between an AI system and an AI model.

As a general matter, AI models themselves are not regulated in the same manner as AI systems. The major exception is the special framework governing general-purpose AI models, or GPAI models.

A GPAI model is an AI model that:

  • displays significant generality;
  • can competently perform a wide range of distinct tasks; and
  • can be integrated into a variety of downstream systems or applications.

Large language models (LLMs) will typically be consider GPAI. GPAI models are also sometimes referred to as foundation models because they can serve as the basis for many downstream applications. 

A GPAI model should also be distinguished from a GPAI system. A GPAI system is an AI system based on a GPAI model that can itself serve a variety of purposes.

This distinction matters because the Act regulates AI systems through its general risk-based structure while imposing a separate set of requirements on GPAI models, with additional requirements for GPAI models presenting systemic risk. 

The Risk-Based Structure of the AI Act: AI Systems


One of the most important features of the EU AI Act is its risk-based regulatory architecture.

The framework for AI Systems can broadly be visualized as a pyramid. As risk increases, regulation becomes more demanding. The slides divide AI systems into four broad levels:

AI systems presenting unacceptable risks

At the top are certain uses considered sufficiently dangerous that they are prohibited under Article 5.

The prohibited practices include certain uses involving manipulation, exploitation of vulnerabilities, social scoring, predictive policing, facial-image scraping, emotion recognition, biometric categorization and real-time remote biometric identification.

The precise scope of those prohibitions—and their exceptions—is important and will be addressed separately. 

High-risk AI systems

Below prohibited systems are high-risk AI systems, which are permitted but subject to extensive regulatory requirements.

An AI system can generally become high-risk through one of two routes.

First, it may be an AI system used as a product or safety component of a product covered by specified EU product legislation.

Second, it may fall within one of the critical use cases listed in Annex III, including certain uses involving biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border management, or the administration of justice and democratic processes. 

High-risk systems are subject to requirements including risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity. 

AI systems subject to transparency requirements

Some AI systems are subject to particular transparency obligations regardless of whether they qualify as high-risk.

The basic purpose is to ensure that people are informed in specified circumstances that they are interacting with AI or encountering AI-generated or AI-manipulated content. These requirements differ from the more extensive transparency and explainability requirements applicable to high-risk systems. 

AI systems presenting minimal risk

At the bottom of the regulatory pyramid are AI systems presenting comparatively limited risks.

These systems are not generally subject to the extensive conformity requirements imposed on high-risk AI. Nevertheless, the broader framework remains relevant, including AI literacy under Article 4 and voluntary codes of conduct under Article 95.

Who Is Regulated? The AI Supply Chain

Another fundamental feature of the AI Act is that it does not regulate only the company that originally develops an AI system. Instead, it identifies different operators throughout the AI supply chain. The relevant roles include:

  • Providers develop an AI system or GPAI model, or have one developed, and place it on the market or put it into service under their own name or trademark.
  • Deployers use an AI system under their own authority. Commercial organizations and public authorities can therefore be deployers. Individuals using AI purely for personal, non-professional purposes are generally excluded from this role.
  • Importers are EU-established actors that place on the EU market an AI system bearing the name or trademark of a person established outside the EU.
  • Distributors make AI systems available on the EU market without being the provider or importer.
  • Product manufacturers can assume provider responsibilities where an AI system forms part of a regulated product or serves as its safety component in the circumstances specified by the Act.
  • Authorized representatives are EU-established persons appointed by non-EU providers to perform specified functions and interact with authorities on their behalf. 

These roles are not mutually exclusive. Depending on what an organization does, the same person or company can potentially occupy more than one role. The classification can also change . For example, someone who substantially modifies an AI system may assume the obligations of a provider. 

A Practical Way to Think About AI Act Compliance

The structure of the Act suggests a sequence of questions for analyzing an AI product or use case:

  1. Is the technology an AI system or GPAI model covered by the Act?
  2. Does an exclusion apply?
  3. Does the Act apply territorially?
  4. What role does each organization occupy—provider, deployer, importer, distributor, manufacturer or authorized representative?
  5. Is the AI practice prohibited?
  6. If permitted, is the system high-risk?
  7. Does it trigger specific transparency requirements?
  8. Is a GPAI model involved, and if so, what GPAI obligations apply?
  9. What operational, documentation, conformity, monitoring or other obligations follow from that classification?

The important point is that “Does the AI Act apply?” is only the beginning of the analysis. Once the answer is yes, the system's classification, intended purpose, operator roles and place in the supply chain determine the obligations that follow.

What Is Outside the AI Act?

The Act is broad, but it does contain exclusions.

The slides identify exclusions or special treatment for:

  • AI used for military, defense and national security purposes;
  • certain scientific research and R&D-only AI;
  • certain pre-market testing, other than real-world testing;
  • certain free and open-source AI, subject to important limitations;
  • certain high-risk products governed through other EU legislation; and
  • certain operators subject to limited exemptions.

The open-source exception is described as narrow. It does not simply mean that open-source AI is outside the Act in every circumstance. 

AI Literacy Is Part of the Framework

The AI Act is not concerned exclusively with technical system requirements.

It also introduces the concept of AI literacy: the skills, knowledge and understanding that allow providers, deployers and affected persons to make informed decisions concerning AI systems and understand their opportunities, risks and possible harms.

AI literacy therefore forms part of the broader governance structure surrounding the responsible deployment and use of AI. 

The AI Act Is More Than a List of AI Rules

The most useful way to understand the EU AI Act is not as a single checklist that applies equally to every AI product.

It is a classification and governance framework.

The Act first asks what the technology is, where and how it is being used, who is responsible for it and what risks the particular use creates. Those answers determine the regulatory consequences.

For businesses, this means that AI Act compliance begins with mapping AI systems, models, use cases and supply-chain roles. The same underlying technology can potentially produce very different legal consequences depending on its intended purpose, how it is deployed and who is using it.

The framework can therefore be summarized simply:

Identify the AI → determine whether the Act applies → identify the operators → classify the risk → determine the applicable obligations.

That structure provides the foundation for understanding the more detailed parts of the EU AI Act: prohibited AI practices, high-risk systems, transparency requirements, GPAI models, provider and deployer obligations, conformity assessments, AI literacy, governance and enforcement.

How Is the EU AI Act Enforced?

The AI Act combines national enforcement with EU-level governance and coordination.

This institutional structure matters because the text of the AI Act establishes the rules, while institutions determine how those rules are implemented, interpreted, updated and enforced in practice. 

At the EU level, the framework includes the European Commission and AI Office, together with other EU-level governance bodies. At Member State level, national competent and market-surveillance authorities play important enforcement roles. The Act also provides individuals with a mechanism to lodge complaints with national authorities. 

As with the GDPR, enforcement therefore involves interaction between EU institutions and national authorities rather than a single centralized regulator.


The financial consequences of noncompliance can be substantial.

Generally, the higher of the fixed monetary amount and percentage-based amount determines the potential ceiling, while different treatment applies to SMEs. 

The highest penalties therefore correspond to the practices the Act considers unacceptable risks.