Skip to content
// Artificial intelligence

The EU AI Act

Regulation (EU) 2024/1689 (CELEX 32024R1689) · In force since 1 Aug 2024 — applies in stages 2025–2027

The AI Act is the world's first comprehensive AI law. It regulates AI based on risk: the greater the risk an AI system poses to health, safety or fundamental rights, the stricter the requirements. It applies in stages between 2025 and 2027.

// In brief

  • Regulation (EU) 2024/1689, adopted 13 June 2024, in force since 1 August 2024.
  • Risk-based: unacceptable risk (prohibited), high risk, limited risk (transparency) and minimal risk.
  • Prohibited AI practices and AI literacy requirements have applied since 2 February 2025.
  • Rules for general-purpose AI (GPAI) models have applied since 2 August 2025; the high-risk rules apply in full from 2 August 2026.
  • Fines of up to €35 million or 7% of global turnover for prohibited AI; lower tiers for other infringements.

The risk-based approach

  • Unacceptable risk (prohibited): e.g. social scoring, manipulative AI that exploits vulnerabilities, and unlawful real-time remote biometric identification in publicly accessible spaces.
  • High risk (Annex III): AI used in areas such as recruitment, credit scoring, critical infrastructure, education, medical devices and law enforcement — permitted, but subject to strict requirements.
  • Limited risk: transparency obligations — users must know they are interacting with AI, and AI-generated content (deepfakes) must be labelled.
  • Minimal risk: most AI — e.g. spam filters and recommendation systems — with no specific obligations.

Requirements for high-risk AI

Providers of high-risk AI must, among other things, operate a risk-management system, ensure data quality, produce technical documentation and logging, guarantee transparency and human oversight, and achieve robustness and cybersecurity. Before placing a system on the market, a conformity assessment and CE marking are required.

General-purpose AI (GPAI) models

Models such as ChatGPT-like systems are subject to specific transparency and documentation obligations. Models posing systemic risk face additional obligations around evaluation, incident reporting and cybersecurity.

Timeline

  • 1 Aug 2024: the regulation enters into force.
  • 2 Feb 2025: prohibited AI practices + AI literacy requirements.
  • 2 Aug 2025: rules for GPAI models and governance.
  • 2 Aug 2026: the bulk of the rules, including high-risk under Annex III.
  • 2 Aug 2027: high-risk AI embedded in regulated products.

How ZORC helps

We build AI solutions that are useful and responsible: clear transparency, a human in the loop, data quality and documentation. Talk to us about responsible AI →

This page is informational and fact-checked against the primary source, but it does not constitute legal advice. For a binding assessment of your specific organisation — talk to us or your legal counsel.

Frequently asked questions

What is the EU AI Act in simple terms?

The AI Act is the EU regulation that governs artificial intelligence based on risk. Dangerous uses are banned, high-risk AI faces strict requirements, and everyday AI gets transparency obligations or no specific obligations at all.

When does the AI Act apply?

It entered into force on 1 August 2024 and applies in stages: prohibited practices from 2 February 2025, GPAI rules from 2 August 2025, and the bulk of the rules — including high-risk — from 2 August 2026.

What counts as high-risk AI?

AI systems used in sensitive areas such as recruitment, credit scoring, critical infrastructure, education, medical devices and law enforcement — listed in Annex III. They are permitted but require risk management, documentation and human oversight, among other things.

What are the fines under the AI Act?

Up to €35 million or 7% of global annual turnover for prohibited AI, up to €15 million or 3% for other infringements, and up to €7.5 million or 1.5% for supplying incorrect information to authorities.

Do we have to label AI-generated content?

Yes. The AI Act requires transparency — users must know when they are interacting with AI, and AI-generated or manipulated content (such as deepfakes) must be labelled.

// Primary sources

Last fact-checked: 2026-06-02.

Need help complying with AI Act?

We build secure, compliant solutions and help you map exactly what applies to your organisation.