What Is the EU AI Act and Why Should You Care?
The EU AI Act is now law. It entered into force on 1 August 2024, making it the world's first binding regulation specifically for AI systems. If your business develops, sells, or uses AI that touches the EU market — regardless of where you are headquartered — this law applies to you.
The risk-based approach
The AI Act does not treat all AI the same. It classifies systems into five categories — prohibited, high-risk, limited-risk, minimal-risk, and out-of-scope — and assigns obligations accordingly. The most common mistake? Assuming you are minimal-risk when you are actually high-risk. If your AI is involved in recruitment, credit scoring, insurance, medical diagnosis, or law enforcement, you are almost certainly in the high-risk category.
Provider vs deployer
Your obligations depend on your role. Providers (who develop AI systems) carry the heaviest burden. Deployers (who use third-party AI in a professional context) have a lighter but still significant set of duties. Most businesses are deployers.
The timeline is already moving
AI literacy training and prohibited-practice rules are already enforceable since February 2025. Full high-risk obligations take effect on 2 August 2026. Fines can reach up to 35 million euros or 7% of global turnover.
Already GDPR-compliant?
You have a head start — but GDPR compliance alone is not enough. The AI Act adds new requirements around AI literacy, system monitoring, log retention, and fundamental rights impact assessments.
Three questions to start with
What is my role? What is my risk classification? What are my specific obligations? Our full implementation guide answers all three.
Read the Full Chapter
Read the complete Chapter 1 with detailed explanations, self-assessment tools, and the enforcement timeline.
Read the Full ChapterCheck Your AI Risk Level — Free