What is the EU AI Act?
The EU Artificial Intelligence Act is the European Union's horizontal legal framework for artificial intelligence. It uses a risk-based approach and creates different obligations for organisations that develop, place on the market, import, distribute or use AI systems and general-purpose AI models.
The Act entered into force on 1 August 2024. Its provisions apply in phases, so organisations should track both the legal category of each AI system and the date on which the relevant obligations become enforceable.
Who does the EU AI Act apply to?
The Act can apply to providers, deployers, importers, distributors, product manufacturers and providers of general-purpose AI models. It can also reach organisations outside the EU when they place an AI system or model on the EU market, or when the output produced by an AI system is used in the EU.
An organisation's role may change from one system to another. A business can be a deployer when using a third-party tool, a provider when developing or substantially modifying a system, and a product manufacturer when integrating AI into a regulated product. Role classification should therefore be completed for each use case and documented.
The AI Act risk framework
Prohibited AI practices
Certain uses are considered incompatible with EU values and are prohibited, subject to narrow exceptions. These include specified forms of harmful manipulation, exploitation of vulnerabilities, social scoring, certain predictive policing, untargeted facial-image scraping, emotion recognition in workplaces and schools in defined circumstances, certain biometric categorisation and some real-time remote biometric identification by law enforcement.
High-risk AI systems
High-risk systems include certain AI used as a safety component of regulated products and specified use cases in sensitive areas such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and the administration of justice. Whether a use case is high risk depends on the legal criteria and any applicable exclusions.
Transparency-risk systems
Specific transparency rules apply to systems that interact directly with people and to certain AI-generated or manipulated content. Depending on the context, people may need to be informed that they are interacting with AI, and synthetic content may need machine-readable marking or visible labelling.
Minimal or no risk
Most AI systems are not classified as high risk and do not receive mandatory system-specific requirements under the Act. Voluntary codes and responsible governance remain useful, particularly where other laws such as the GDPR, consumer law, employment law or sector regulation apply.
General-purpose AI models
Providers of general-purpose AI models have separate obligations concerning technical documentation, information for downstream providers, copyright compliance and a public summary of training content. Models with systemic risk face additional evaluation, risk-management, incident-reporting and cybersecurity requirements.
EU AI Act implementation timeline
- 2 February 2025: prohibited AI practices, definitions and AI literacy obligations began to apply.
- 2 August 2025: governance rules and obligations for providers of general-purpose AI models began to apply.
- 2 August 2026: the Act generally becomes applicable, including Article 50 transparency obligations and many other provisions.
- 2 December 2027: high-risk rules for specified sensitive-area systems in Annex III apply following the 2026 AI Omnibus changes.
- 2 August 2028: high-risk rules for AI embedded in regulated products listed in Annex I apply.
Timelines should be checked against the specific role, system and transitional provision. Existing systems, models already on the market and public-sector uses may have additional transition rules.
AI literacy and prohibited-practice controls
Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and other people operating AI systems on their behalf. Training should reflect technical knowledge, experience, education, the context of use and the people affected by the system.
Organisations should also implement controls to prevent prohibited uses. A policy alone is not enough: system inventory, approval gates, role-based access, procurement review, use-case screening and monitoring are needed to show that the prohibition is operationalised.
Core obligations for high-risk AI systems
Providers of high-risk systems generally need a documented risk-management system, appropriate data and data-governance practices, technical documentation, logging, instructions for use, human-oversight measures, accuracy, robustness and cybersecurity controls, a quality-management system, conformity assessment, registration and post-market monitoring.
Deployers have their own duties, including following instructions, assigning competent human oversight, monitoring operation, keeping relevant logs, reporting serious incidents and carrying out a fundamental-rights impact assessment in specified cases. Employers and public authorities may also have notification or registration duties.
Fundamental-rights impact assessments
Certain deployers of high-risk systems must assess the potential impact on fundamental rights before use. A fundamental-rights impact assessment should describe the process in which the AI is used, the affected people, risks, human oversight, mitigation and governance. Where personal data is involved, it may need to be coordinated with a GDPR Data Protection Impact Assessment rather than treated as a disconnected exercise.
Transparency obligations
From 2 August 2026, providers and deployers of certain AI systems must meet Article 50 transparency rules. Examples include informing people when they are directly interacting with AI, making AI-generated or manipulated content detectable, and visibly disclosing deepfakes or specified public-interest text where the legal conditions are met.
Transparency should be designed into the product and workflow. Notices should be timely, accessible and understandable, and records should show who assessed the obligation, what disclosure was selected and how it is maintained.
Governance and enforcement
National competent authorities supervise AI systems, while the European AI Office oversees general-purpose AI obligations and certain AI systems based on those models. The Act provides tiered administrative fines linked to the type of infringement and, for undertakings, worldwide annual turnover. Contractual, product, employment, privacy and reputational consequences may apply in addition to regulatory fines.
A practical EU AI Act checklist
- Create an inventory of internally developed, procured and shadow AI systems.
- Assign an owner and document each organisation's role in the AI value chain.
- Screen systems for prohibited practices, high-risk categories, transparency duties and GPAI obligations.
- Implement AI literacy training proportionate to roles and contexts.
- Document intended purpose, data, affected people, vendors and deployment context.
- Run risk, fundamental-rights, privacy and security assessments where required.
- Define human oversight, escalation, incident and change-management controls.
- Maintain technical documentation, logs, instructions, approvals and evidence.
- Review supplier contracts and obtain the information needed for downstream compliance.
- Monitor regulatory guidance, standards and material changes throughout the lifecycle.
How TrustWorks supports EU AI Act operations
TrustWorks helps organisations turn AI Act obligations into a connected governance programme across legal, privacy, risk, security, procurement, engineering and business teams.
- AI inventory and discovery: identify approved, third-party and shadow AI systems.
- Role and risk classification: document value-chain roles, intended purpose and regulatory category.
- Assessments: run AI risk, fundamental-rights, privacy, vendor and security reviews in structured workflows.
- Evidence management: maintain documentation, logs, training, approvals, incidents and remediation histories.
- Lifecycle monitoring: assign owners, trigger reviews and manage changes after deployment.
- Cross-functional collaboration: coordinate accountability across internal teams and external providers.
TrustWorks supports AI governance and EU AI Act compliance operations. It does not provide legal advice, and organisations should assess their specific obligations with qualified counsel and current European Commission guidance.










