What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the European Union’s law on artificial intelligence. It takes a risk-based approach: it prohibits certain AI practices, sets strict requirements for high-risk systems, adds transparency duties for some uses, and creates obligations for general-purpose AI models.
Definition
The EU AI Act is a European Union regulation (Regulation (EU) 2024/1689) that governs the development, placing on the market, and use of artificial intelligence systems using a risk-based framework.
Background
The EU AI Act sorts AI by risk. A small set of practices deemed an unacceptable risk are prohibited. High-risk systems (for example, certain uses in employment, education, or critical infrastructure) must meet requirements such as risk management, data governance, technical documentation, human oversight, and accuracy and robustness. Some systems that interact with people carry transparency obligations. Separately, providers of general-purpose AI (GPAI) models have their own set of obligations. The regulation entered into force in 2024, with its obligations applying in stages over the following period.
Why it matters
The AI Act has extraterritorial reach: it can apply to providers and deployers outside the EU when their AI systems are used in the EU. For any company building or deploying AI that touches the EU market, it is becoming a core compliance consideration, with meaningful penalties for non-compliance.
Step by step
- Inventory the AI systems you build or use and where they are used.
- Classify each by the Act’s risk tiers (prohibited, high-risk, transparency, or minimal).
- For high-risk systems, implement the required controls (risk management, data governance, documentation, human oversight).
- Meet transparency duties where systems interact with people or generate content.
- Track the staged application dates that apply to your systems and obligations.
Examples
- A vendor whose AI is used by EU customers assesses whether any use is high-risk and prepares the required documentation and oversight.
- A provider of a general-purpose AI model reviews the GPAI obligations that apply to it.
Common mistakes
- Assuming it only applies to EU-based companies; it can reach providers and deployers outside the EU when AI is used in the EU.
- Treating all AI as high-risk; the Act is tiered, and most systems are not high-risk.
- Confusing the AI Act (law) with ISO 42001 (a voluntary certifiable standard).
FAQ
Does the EU AI Act apply to US companies?
It can. Like the GDPR, the AI Act has extraterritorial reach and may apply to providers and deployers outside the EU when their AI systems are placed on the EU market or used in the EU.
How does the EU AI Act relate to ISO 42001?
The AI Act is binding law; ISO/IEC 42001 is a voluntary management standard. Implementing an ISO 42001 AI management system can help you operationalize practices that support AI Act compliance, but it is not a substitute for meeting the law.
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free