Glossary Terms

EU AI Act

The European Union regulation establishing risk-based rules for placing, providing and using AI systems in the EU.
On this page

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, a European Union law establishing harmonised rules for the development, placement on the market and use of artificial intelligence. It uses a risk-based approach and creates obligations for different actors, including providers, deployers, importers, distributors and parties involved with general-purpose AI models.

The regulation applies according to role, system, location and effect. Organisations outside the EU may be covered in certain circumstances when they place AI systems or models in the EU market or when outputs are used in the EU. The official text is available through EUR-Lex.

How does the risk-based framework work?

The Act prohibits certain AI practices, imposes extensive requirements on defined high-risk systems and creates transparency duties for particular uses. It also regulates general-purpose AI models, with additional obligations for models that may present systemic risk. Systems outside these categories may still be affected by other laws and voluntary governance standards.

Classification depends on intended purpose and context, not merely the technical model. A general tool may become part of a high-risk system when integrated into a regulated decision process.

What do high-risk requirements cover?

Requirements can include risk management, data and data-governance practices, technical documentation, logging, transparency to deployers, human oversight, accuracy, robustness, cybersecurity, quality management and post-market monitoring. Providers and deployers have different responsibilities, and contractual allocation does not necessarily change the legal role.

Organisations need an inventory and role analysis to identify systems, providers, models, intended purposes and affected markets. Evidence should be connected to real operational controls rather than created only at the end of development.

How should organisations prepare?

Preparation includes identifying AI systems, classifying risk, mapping organisational roles, assigning owners and establishing review workflows. Procurement should request evidence from vendors, while product and engineering teams should maintain documentation, testing and change records. Training and AI-literacy measures should be aligned with employees’ responsibilities.

The Act has phased application dates and may be supplemented by standards, codes and regulatory guidance. Organisations should monitor official developments and obtain legal advice for specific scope decisions.

Frequently asked questions

Does the EU AI Act ban artificial intelligence?

No. It prohibits defined practices and regulates other systems according to risk. Most AI uses are not banned, but other laws may still apply.

What is a high-risk AI system?

It is a system that meets specific criteria in the Act, including certain safety components and uses in listed areas such as employment or essential services.

Does the Act apply to generative AI?

Yes. Certain transparency rules and general-purpose AI model obligations can apply, depending on the model and use.

Is a deployer the same as a user?

A deployer is generally an organisation or authority using an AI system under its authority, excluding purely personal non-professional use.

Can compliance be handled only by the legal team?

No. Implementation requires product, engineering, data, security, procurement, risk, privacy, operations and leadership participation.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.