European Union
EU AI Act
The EU Artificial Intelligence Act is the world's first comprehensive AI law. It classifies AI systems by risk and sets obligations for providers and deployers of high-risk systems, from risk management and data governance to human oversight, transparency, and post-market monitoring.
19 articles
Subject matter
This Regulation lays down harmonised rules for the placing on the market, putting into service and use of artificial intelligence systems in the Union.
Scope
This Regulation applies to providers, deployers, importers, distributors and product manufacturers of AI systems in the Union.
Definitions
Key definitions including AI system, provider, deployer, high-risk AI system, and other terms used throughout the Regulation.
AI literacy
Providers and deployers of AI systems shall take measures to ensure AI literacy among their staff and other persons dealing with AI systems.
Prohibited AI practices
AI practices that are prohibited in the Union, including subliminal manipulation, social scoring, and certain biometric identification uses.
Classification rules for high-risk AI systems
AI systems are classified as high-risk based on their intended purpose and the risks they pose to health, safety and fundamental rights.
Risk management system
Providers of high-risk AI systems shall establish and implement a risk management system throughout the entire lifecycle.
Data and data governance
Training, validation and testing data sets shall be subject to appropriate data governance practices.
Transparency and provision of information to deployers
Providers shall design high-risk AI systems in a way that is sufficiently transparent for deployers to interpret the system's output and use it appropriately.
Human oversight
High-risk AI systems shall be designed to allow effective human oversight measures to reduce risks.
Accuracy, robustness and cybersecurity
High-risk AI systems shall be designed and developed to achieve an appropriate level of accuracy, robustness, and cybersecurity.
Obligations of deployers of high-risk AI systems
Deployers of high-risk AI systems shall use such systems in accordance with the instructions of use.
Fundamental rights impact assessment for high-risk AI systems
Deployers of high-risk AI systems shall carry out a fundamental rights impact assessment before putting the system into use.
Transparency obligations for providers and deployers of certain AI systems
Providers and deployers of certain AI systems shall ensure sufficient transparency to enable users to interpret and appropriately use the output.
Classification of general-purpose AI models as general-purpose AI models with systemic risk
A GPAI model is classified as having systemic risk if it has high-impact capabilities, presumed where the cumulative training compute exceeds 10^25 FLOPs.
Obligations for providers of general-purpose AI models
GPAI providers must keep technical documentation, provide information to downstream providers, put in place a copyright policy, and publish a summary of training content.
Obligations for providers of general-purpose AI models with systemic risk
Providers of GPAI models with systemic risk must perform model evaluation and adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity.
Penalties
Administrative fines for infringements of the AI Act, up to EUR 35 million or 7% of global annual turnover.
Entry into force and application
The AI Act entered into force on 1 August 2024, with different application dates for different provisions.
Turn EU AI Act into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial