O que é o Regulamento de IA da UE?
O Regulamento da Inteligência Artificial da UE é o quadro jurídico horizontal da União Europeia para a inteligência artificial. Utiliza uma abordagem baseada no risco e cria diferentes obrigações para as organizações que desenvolvem, colocam no mercado, importam, distribuem ou utilizam sistemas de IA e modelos de IA de uso geral.
O Regulamento entrou em vigor em 1 de agosto de 2024. As suas disposições aplicam-se em fases, pelo que as organizações devem acompanhar tanto a categoria jurídica de cada sistema de IA como a data em que as obrigações relevantes se tornam exigíveis.
A quem se aplica o Regulamento de IA da UE?
O Regulamento pode ser aplicado a fornecedores, implementadores, importadores, distribuidores, fabricantes de produtos e fornecedores de modelos de IA de uso geral. Ele também pode alcançar organizações fora da UE quando estas disponibilizam um sistema ou modelo de IA no mercado da UE, ou quando o resultado produzido por um sistema de IA é utilizado na UE.
O papel de uma organização pode mudar de um sistema para outro. Uma empresa pode ser uma implementadora ao usar uma ferramenta de terceiros, uma fornecedora ao desenvolver ou modificar substancialmente um sistema, e uma fabricante de produtos ao integrar IA em um produto regulamentado. Portanto, a classificação de papéis deve ser realizada para cada caso de uso e documentada.
A estrutura de risco do Regulamento de IA
Práticas de IA proibidas
Certain uses are considered incompatible with EU values and are prohibited, subject to narrow exceptions. These include specified forms of harmful manipulation, exploitation of vulnerabilities, social scoring, certain predictive policing, untargeted facial-image scraping, emotion recognition in workplaces and schools in defined circumstances, certain biometric categorisation and some real-time remote biometric identification by law enforcement.
High-risk AI systems
High-risk systems include certain AI used as a safety component of regulated products and specified use cases in sensitive areas such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and the administration of justice. Whether a use case is high risk depends on the legal criteria and any applicable exclusions.
Transparency-risk systems
Specific transparency rules apply to systems that interact directly with people and to certain AI-generated or manipulated content. Depending on the context, people may need to be informed that they are interacting with AI, and synthetic content may need machine-readable marking or visible labelling.
Minimal or no risk
Most AI systems are not classified as high risk and do not receive mandatory system-specific requirements under the Act. Voluntary codes and responsible governance remain useful, particularly where other laws such as the GDPR, consumer law, employment law or sector regulation apply.
General-purpose AI models
Providers of general-purpose AI models have separate obligations concerning technical documentation, information for downstream providers, copyright compliance and a public summary of training content. Models with systemic risk face additional evaluation, risk-management, incident-reporting and cybersecurity requirements.
EU AI Act implementation timeline
- 2 February 2025: prohibited AI practices, definitions and AI literacy obligations began to apply.
- 2 August 2025: governance rules and obligations for providers of general-purpose AI models began to apply.
- 2 August 2026: the Act generally becomes applicable, including Article 50 transparency obligations and many other provisions.
- 2 December 2027: high-risk rules for specified sensitive-area systems in Annex III apply following the 2026 AI Omnibus changes.
- 2 August 2028: high-risk rules for AI embedded in regulated products listed in Annex I apply.
Timelines should be checked against the specific role, system and transitional provision. Existing systems, models already on the market and public-sector uses may have additional transition rules.
AI literacy and prohibited-practice controls
Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and other people operating AI systems on their behalf. Training should reflect technical knowledge, experience, education, the context of use and the people affected by the system.
Organisations should also implement controls to prevent prohibited uses. A policy alone is not enough: system inventory, approval gates, role-based access, procurement review, use-case screening and monitoring are needed to show that the prohibition is operationalised.
Core obligations for high-risk AI systems
Providers of high-risk systems generally need a documented risk-management system, appropriate data and data-governance practices, technical documentation, logging, instructions for use, human-oversight measures, accuracy, robustness and cybersecurity controls, a quality-management system, conformity assessment, registration and post-market monitoring.
Deployers have their own duties, including following instructions, assigning competent human oversight, monitoring operation, keeping relevant logs, reporting serious incidents and carrying out a fundamental-rights impact assessment in specified cases. Employers and public authorities may also have notification or registration duties.
Fundamental-rights impact assessments
Certain deployers of high-risk systems must assess the potential impact on fundamental rights before use. A fundamental-rights impact assessment should describe the process in which the AI is used, the affected people, risks, human oversight, mitigation and governance. Where personal data is involved, it may need to be coordinated with a GDPR Data Protection Impact Assessment rather than treated as a disconnected exercise.
Transparency obligations
From 2 August 2026, providers and deployers of certain AI systems must meet Article 50 transparency rules. Examples include informing people when they are directly interacting with AI, making AI-generated or manipulated content detectable, and visibly disclosing deepfakes or specified public-interest text where the legal conditions are met.
Transparency should be designed into the product and workflow. Notices should be timely, accessible and understandable, and records should show who assessed the obligation, what disclosure was selected and how it is maintained.
Governance and enforcement
National competent authorities supervise AI systems, while the European AI Office oversees general-purpose AI obligations and certain AI systems based on those models. The Act provides tiered administrative fines linked to the type of infringement and, for undertakings, worldwide annual turnover. Contractual, product, employment, privacy and reputational consequences may apply in addition to regulatory fines.
A practical EU AI Act checklist
- Create an inventory of internally developed, procured and shadow AI systems.
- Assign an owner and document each organisation's role in the AI value chain.
- Screen systems for prohibited practices, high-risk categories, transparency duties and GPAI obligations.
- Implement AI literacy training proportionate to roles and contexts.
- Document intended purpose, data, affected people, vendors and deployment context.
- Run risk, fundamental-rights, privacy and security assessments where required.
- Define human oversight, escalation, incident and change-management controls.
- Maintain technical documentation, logs, instructions, approvals and evidence.
- Review supplier contracts and obtain the information needed for downstream compliance.
- Monitor regulatory guidance, standards and material changes throughout the lifecycle.
How TrustWorks supports EU AI Act operations
TrustWorks helps organisations turn AI Act obligations into a connected governance programme across legal, privacy, risk, security, procurement, engineering and business teams.
- AI inventory and discovery: identify approved, third-party and shadow AI systems.
- Role and risk classification: document value-chain roles, intended purpose and regulatory category.
- Assessments: run AI risk, fundamental-rights, privacy, vendor and security reviews in structured workflows.
- Evidence management: maintain documentation, logs, training, approvals, incidents and remediation histories.
- Lifecycle monitoring: assign owners, trigger reviews and manage changes after deployment.
- Cross-functional collaboration: coordinate accountability across internal teams and external providers.
TrustWorks supports AI governance and EU AI Act compliance operations. It does not provide legal advice, and organisations should assess their specific obligations with qualified counsel and current European Commission guidance.









