The EU AI Act, Explained

The EU AI Act doesn't regulate "AI" as one thing. It sorts AI systems into risk tiers and attaches different obligations to each and it can reach your business even if you're based outside the EU.

9+ Years of Compliance Expertise
Saudi Arabia
Oman
Bahrain
End-to-End Execution
Europe
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive AI law in a major jurisdiction. It sorts AI systems into four risk tiers - unacceptable, high, limited, minimal and attaches different obligations to each, plus a separate horizontal layer of rules for general-purpose AI models. It applies to providers and deployers inside the EU, and to many outside it, based on where the AI system's output is actually used.
  • What the AI Act Actually Regulates
    The Act defines an "AI system" broadly (Article 3(1)): a machine-based system designed to operate with varying levels of autonomy, that may adapt after deployment, and that infers from input how to generate outputs — predictions, content, recommendations, or decisions — that can influence physical or virtual environments. This definition is technology-neutral: it covers everything from a simple recommendation engine to a large language model, and does not depend on whether the system uses machine learning specifically.
Who Has to Comply
  • The Act applies to (Article 2)
    Providers placing AI systems or GPAI models on the EU market regardless of where they're established; deployers located in the EU; importers and distributors into the EU; and product manufacturers integrating AI under their own name.
  • It also reaches outside the EU
    A provider or deployer in a third country - including the UAE - must comply if the AI system's output is used in the EU, or the system is placed on the EU market for first use there. This is the same output-based logic that makes GDPR relevant to non-EU companies.
  • Excluded from scope
    Military/national-security use, pre-market R&D, free and open-source AI (unless deployed as high-risk), personal non-professional use, and AI used exclusively for scientific research.
  • The Risk Pyramid
    Unacceptable risk - banned outright (Article 5). Eight prohibited
    practices: manipulative or subliminal techniques causing harm; exploiting
    vulnerabilities of children, disabled people, or economically
    disadvantaged groups; social scoring; predicting criminal risk based
    solely on profiling or personality traits; untargeted facial-image
    scraping for recognition databases; emotion recognition in workplaces or
    schools; biometric categorization inferring race, political opinion,
    religion, sexual orientation, or union membership; and real-time remote
    biometric identification in public spaces by law enforcement (narrow,
    judicially-authorized exceptions).

    High risk - heavily regulated, not banned. Employment, credit scoring,
    critical infrastructure, law enforcement, migration, essential services.
    Detailed obligations: risk management, data governance, technical
    documentation, human oversight, accuracy/robustness testing, conformity
    assessment before market placement. Full detail on the dedicated
    High-Risk AI Systems page.

    Limited risk - transparency obligations (Article 50). Disclose AI
    interaction (unless obvious); label AI-generated content as such, in
    machine-readable form; inform people exposed to emotion-recognition or
    biometric-categorization systems; disclose deepfakes and AI-generated
    text on matters of public interest (exceptions for clearly
    artistic/satirical work and editorially-reviewed content). In effect
    from 2 August 2026.

    Minimal risk - no obligations under the Act. Most ordinary commercial AI
    use falls here, though other law (data protection in particular) can
    still apply.
  • General-Purpose AI: A Separate, Horizontal Layer
    General-purpose AI (GPAI) models aren't a fifth risk tier — they sit alongside the pyramid with their own obligations (technical documentation, training-content summaries, copyright-compliance measures, extra duties for models carrying "systemic risk") regardless of what a downstream deployer builds on top of them. Covered in full on our GPAI Obligations page, since most businesses meet this layer through a vendor rather than directly.
  • Who Enforces It
    Enforcement runs on two levels. The AI Office, established within the European Commission, handles EU-level coordination and oversight — particularly for GPAI models — advised by the European Artificial Intelligence Board (representing Member States), an independent Scientific Panel, and an Advisory Forum of stakeholders. Each Member State designated its own national market surveillance authority by 2 August 2025, responsible for day-to-day supervision and enforcing the prohibitions and high-risk rules within its territory. Authorities protecting specific fundamental rights (data protection, non-discrimination) also have powers to investigate AI Act violations that intersect with their existing mandates.
  • Penalties
    Three tiers under Article 99, scaled to severity: up to €35 million or 7% of global annual turnover for violations of the banned practices in Article 5; up to €15 million or 3% of turnover for violations of most other obligations, including the high-risk-system rules and GPAI provider duties; up to €7.5 million or 1% of turnover for supplying incorrect, incomplete, or misleading information to regulators. The higher of the fixed amount or the percentage applies — the same structure as GDPR fines.
  • Timeline: What's In Force Now
    The Act's provisions did not all take effect on one date, and a mid-2026 amendment changed some of the deadlines that follow. Rather than repeat dates here that will go stale, we keep a single up-to-date timeline on a dedicated page: see the EU AI Act Timeline.
What's Included

Classification of your AI systems against the Act's four risk tiers, and against the separate GPAI layer where relevant

Gap assessment against the obligations that follow from that classification (risk management, data governance, technical documentation, human oversight, transparency disclosures)
Drafting or reviewing the compliance documentation a classification requires — technical files, transparency notices, DPIA-adjacent risk assessments
Ongoing monitoring as amendments (such as the 2026 Digital Omnibus) shift deadlines or scope

Frequently Asked Questions

Related

Need help mapping which EU AI Act applies to your systems?
By submitting this form, I acknowledge that I have read and agree to the Privacy Policy, and I consent to the processing of my personal data.


Please note: We do not provide any personalized investment advice, token selection guidance, or transaction recommendations. AMLzone is a compliance consultancy and project management services provider, not a Virtual Asset Advisor.