European Union Regulation 2024/1689

The Complete Guide to the EU AI Act

The first comprehensive AI regulation. Understand the risk-based framework, compliance requirements, key deadlines, and penalties. Everything you need to prepare your organization for full compliance.

Aug 2024
Entry into Force
Feb 2025
Prohibited AI Ban
Aug 2026
High-Risk Deadline
35M EUR
Maximum Fine
Understanding the Regulation

What is the EU AI Act?

The EU Artificial Intelligence Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Published in the Official Journal on July 12, 2024 and entering into force on August 1, 2024, it establishes a risk-based approach to AI regulation.

The Act aims to ensure that AI systems placed on the EU market are safe, respect fundamental rights, and uphold EU values while promoting innovation and investment in AI technologies.

Unlike sector-specific regulations, the AI Act applies horizontally across all sectors and industries, with requirements varying based on the level of risk posed by specific AI applications.

Risk-Based
4 Risk Tiers
Global Reach
Extraterritorial

Core Principles

  • Human-centric approach to AI development and deployment
  • Protection of fundamental rights and EU values
  • Transparency and accountability in AI systems
  • Risk-proportionate regulatory requirements
  • Support for innovation through regulatory sandboxes
  • Harmonized rules across all EU member states
The Heart of the AI Act

Risk Classification System

The EU AI Act categorizes AI systems into four risk levels, each with different regulatory requirements. Higher risk means stricter obligations.

Unacceptable Risk

AI systems that pose a clear threat to people's safety, livelihoods, and rights are banned outright.

Prohibited
February 2, 2025

Examples of Unacceptable Risk AI Systems:

Social scoring systems by governments
Real-time remote biometric identification in public spaces (with limited exceptions)
Subliminal manipulation techniques causing harm
Exploitation of vulnerabilities (age, disability, social situation)
Emotion recognition in workplaces and educational institutions
Untargeted scraping of facial images for facial recognition databases
Predictive policing based solely on profiling

High Risk

AI systems that significantly impact people's health, safety, or fundamental rights. Subject to strict requirements before market placement.

Regulated
August 2, 2026

Examples of High Risk AI Systems:

Biometric identification and categorization
Critical infrastructure management (water, gas, electricity)
Education and vocational training (exam scoring, admissions)
Employment, worker management, recruitment
Access to essential services (credit scoring, insurance)
Law enforcement applications
Migration, asylum, and border control
Administration of justice and democratic processes

Limited Risk

AI systems with specific transparency obligations to ensure users know they are interacting with AI.

Transparency Required
August 2, 2025

Examples of Limited Risk AI Systems:

Chatbots and conversational AI
Emotion recognition systems (where permitted)
Biometric categorization systems
AI-generated or manipulated content (deepfakes)
AI systems that generate text for public information

Minimal Risk

The vast majority of AI systems fall into this category with no specific obligations, though voluntary codes of conduct are encouraged.

No Requirements

Examples of Minimal Risk AI Systems:

Spam filters
AI-enabled video games
Inventory management systems
AI-powered spell checkers
Recommendation algorithms (most)
Manufacturing optimization AI
Implementation Timeline

Key Compliance Dates

The EU AI Act follows a phased implementation approach. Mark these critical dates in your compliance calendar.

Completed

Published in the Official Journal

July 12, 2024

The AI Act (Regulation (EU) 2024/1689) was published in the EU Official Journal, entering into force on 1 August 2024. Parliament had adopted it on 13 March 2024.

Completed

Entry into Force

August 1, 2024

The AI Act entered into force 20 days after publication in the Official Journal.

Imminent

Prohibited AI Practices Ban

February 2, 2025

All prohibited AI practices become illegal. Organizations must cease usage.

Upcoming

GPAI Rules Apply

August 2, 2025

General-Purpose AI (GPAI) model requirements take effect, including transparency and systemic risk obligations.

Upcoming

High-Risk AI Requirements

August 2, 2026

Full compliance required for high-risk AI systems, including conformity assessments.

Upcoming

Additional High-Risk Categories

August 2, 2027

Extended high-risk requirements for certain AI systems in Annex I products.

Latest Update - November 2025

Digital Omnibus Proposal

The European Commission proposed the Digital Omnibus to simplify and streamline reporting obligations under the AI Act and other digital regulations.

Extended Deadlines

Potential 12-month extension for certain high-risk AI compliance requirements

Simplified Reporting

Consolidation of reporting requirements across Digital Services Act, AI Act, and Data Act

SME Relief

Reduced administrative burden for small and medium enterprises

Harmonized Definitions

Alignment of terminology across EU digital regulations

Under negotiation - Final text expected Q2 2026
Compliance Requirements

High-Risk AI Requirements

High-risk AI systems must meet stringent requirements across seven key areas before being placed on the market.

Risk Management

Article 9 of the EU AI Act

Establish and maintain a risk management system throughout AI lifecycle
Identify and analyze known and foreseeable risks
Implement risk mitigation measures
Continuous iterative process of risk identification and mitigation
Non-Compliance Consequences

Penalties & Fines

The EU AI Act includes significant penalties to ensure compliance. Fines are calculated as the higher of a fixed amount or percentage of global turnover.

Prohibited AI Practices

35 million EUR
or 7% of turnover

Deploying or placing on market AI systems with unacceptable risk

High-Risk Non-Compliance

15 million EUR
or 3% of turnover

Failing to meet high-risk AI requirements

Incorrect Information

7.5 million EUR
or 1.5% of turnover

Providing misleading information to authorities

SME Proportionality

For small and medium-sized enterprises, including startups, the maximum fines are capped to ensure proportionality. However, organizations of all sizes should prioritize compliance to avoid both financial penalties and reputational damage.

Professional Certification

Master EU AI Act Compliance

Our comprehensive training program covers all aspects of the EU AI Act, from risk classification to conformity assessment. Earn your certification and demonstrate compliance expertise.

113 Requirements Covered
Expert Instructors
Practical Exercises
Got Questions?

Frequently Asked Questions

Common questions about the EU AI Act and compliance requirements.

Ready to Start Your Compliance Journey?

Join thousands of organizations preparing for EU AI Act compliance with CSOAI.

Ask the Council assistant — the EU AI Act — obligations, timelines and getting compliant
Governed answer · AI governance & cybersecurity only · signed to Layer 0
Open the full AI OS →