What is the EU AI Act?

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legislation for artificial intelligence. It entered into force on 1 August 2024 and will be applied in stages until 2027. The aim is to ensure that AI systems used within the EU aresafe, transparent and respects fundamental rights.

For Swedish companies, this means new requirements — regardless of whether you develop your own AI solutions or use third-party services such as ChatGPT, Copilot or other AI tools.

Risk classes – This is how the EU categorizes your AI

The EU AI Act divides AI systems into four risk levels:

1. Unacceptable risk (prohibited)

  • Social scoring of citizens
  • Real-time monitoring with biometrics in public places (with exceptions)
  • Manipulation of behavior through subliminal techniques

2. High risk

  • AI in recruitment and HR decisions
  • Credit assessment and insurance pricing
  • AI in education and degree grades
  • AI in healthcare diagnostics
  • Biometric identification

Companies using high-risk AI must meet requirements forrisk management, data quality, transparency, human oversight and documentation.

3. Limited risk

  • Chatbots and AI-generated content
  • Requirements toinform the userthat they interact with AI
  • Deepfakes must be clearly labeled

4. Minimal risk

  • Spam filters, AI in games, recommendation algorithms
  • No specific requirements, but good principles are recommended

EU AI Act and GDPR - How they are connected

The EU AI Act and the GDPR (data protection regulation) complement each other. GDPR protects personal data, while the AI ​​Act regulates the AI ​​system itself. Here are the main connections:

Data Protection Impact Assessment (DPIA)

If your AI system processes personal data on a large scale, a DPIA is already required under the GDPR. AI Actextends this requirementwith specific AI risk assessment.

Transparency and information

The GDPR requires you to inform about automated decisions (Article 22). The AI ​​Act further tightens the requirements — you must clearly communicate:

  • That AI is used
  • What kind of AI system
  • How decisions are made
  • What rights the person concerned has

The right to human review

Both the GDPR and the AI ​​Act give individuals the right tonot be subjected to fully automated decisionswith legal effect. Companies must ensure that a human can review and review AI decisions.

Data minimization and quality

GDPR's data minimization principle still applies. The AI ​​Act adds requirements thattraining data must be relevant, representative and free of bias.

What Swedish companies need to do now

Although full implementation is phased in, there are steps you should take today:

1. Map your AI systems

Take inventory of all the AI ​​tools and systems you use — including third-party solutions like ChatGPT, Midjourney, automated analytics tools, and more.

2. Classify risk levels

Assess which risk class each system falls under. High-risk systems require extensive documentation and compliance.

3. Update your GDPR procedures

Ensure that your existing data protection processes cover AI-specific requirements. Update impact assessments, index lists and information texts.

4. Train the staff

Make sure employees working with AI understand the new requirements.AI skillsbecomes a statutory obligation for certain personnel.

5. Establish AI policy

Document how your company uses AI, which guidelines apply and who is responsible for compliance.

6. Secure supplier agreements

If you use AI services from third parties, ensure that the agreements regulate liability, data processing and compliance with the EU AI Act.

Timeline – As for what?

Date what's happening
August 1, 2024 AI Act comes into force
February 2, 2025 Prohibition of unacceptable risk is applied
August 2, 2025 General Purpose AI (GPAI) requirements apply
August 2, 2026 Most regulations are fully enforced
August 2, 2027 Requirements for high-risk AI in existing systems

Sanctions in case of violation of the AI ​​Act

Just like the GDPR, the AI ​​Act hasheavy penalty fees:

  • Up to EUR 35 millionor 7% of global turnover for banned AI systems
  • Up to 15 million eurosor 3% for other violations
  • Up to 7.5 million eurosor 1.5% for incorrect information to authorities

For Swedish SME companies and startups there are lower ceilings, but the risks are still significant.

How ZORC can help

We at ZORC build AI solutions that aredesigned with regulatory compliance in mind. Whether you need:

  • An AI-powered website or app that complies with transparency requirements
  • Automated systems with built-in human supervision
  • Help map and classify your AI systems
  • An AI policy adapted for your company

Contact usfor a free consultation on how the EU AI Act affects your company in particular.


This article was last updated in April 2026 and is based on the published text of Regulation (EU) 2024/1689. We recommend always consulting legal expertise for company-specific advice.