TL;DR — The essentials of the AI Act
The AI Act (EU Regulation 2024/1689) is the first comprehensive legal framework on artificial intelligence. It classifies AI systems into four risk levels —unacceptable (prohibited), high (strict obligations), limited (transparency) and minimal (no specific obligations)— and applies to any AI system with effects in the EU, regardless of where the provider is established. Application is phased between February 2025 and August 2028. Sanctions can reach €35 million or 7% of global turnover.
Application timeline
The AI Act is applied progressively. These are the key dates:
For full details on each date, see the AI Act summary.
Risk categories
The AI Act classifies AI systems into four levels. Obligations are proportional to risk:
Unacceptable risk
Prohibited. Cannot be placed on the EU market.
Examples: Social scoring, subliminal manipulation, real-time biometric ID in public spaces (without exceptions)
High risk risk
Conformity assessment, technical documentation, EU database registration.
Examples: Biometrics, critical infrastructure, employment, education, credit, justice
Limited risk risk
Transparency obligations.
Examples: Chatbots, deepfakes, synthetic content generation
Minimal risk risk
No specific obligations. Voluntary codes of conduct.
Examples: Spam filters, AI in video games, low-impact recommendations
AI Act resources
Explore our specialized resources on the EU AI Regulation:
AI Act Summary
Complete guide to the Regulation: scope, risk categories, timeline, obligations by role and sanctions.
AI Act vs GDPR
Comparative table of both frameworks: scope, obligations, sanctions and intersection points.
AI Act Glossary
30+ key terms from EU Regulation 2024/1689 with article references.
AI Act Guide for Startups
Complete compliance guide for tech startups: classification, deadlines and requirements.
EU AI Act Representative for Non-EU Companies
Authorized representative service (Art. 22) for companies placing AI on the EU market.
AI Regulation & Data Service
Comprehensive advisory on AI Act, GDPR and data governance.
Sector AI Act guides
Vertical-specific analyses with use cases, risk classification, article-by-article obligations and compliance checklist:
AI Act for Fintech
Credit scoring as high-risk (Annex III 5b), Art. 27 FRIA, fraud exclusion and fines.
AI Act for SaaS
Intended-use classification, Art. 50 transparency, GPAI models and dark patterns.
AI Act for Healthtech
Medical devices (MDR/IVDR + Annex I), Art. 9 GDPR health data and healthcare DPIA.
AI Act for Edtech
Annex III point 3 (assessment, proctoring), emotion prohibition (Art. 5(1)(f)) and children's data.
AI Act for E-commerce
Recommendation engines, chatbots, Art. 50 transparency and manipulation prohibition (Art. 5).
Related articles
AI Act timeline for startups: key dates and how to prepare
Detailed analysis of the EU AI Act implementation timeline for tech startups. Deadlines, phase-by-phase obligations, and progressive compliance strategy.
How much does AI Act compliance cost: a guide for startups
Realistic breakdown of AI Act compliance costs by risk category. Indicative budgets, cost factors, and strategies to optimise investment for AI startups.
AI Regulation: system classification and compliance requirements
Practical guide to classify AI systems according to risk level and determine the transparency, documentation and governance requirements applicable to each category.
Frequently asked questions
What is the AI Act and who does it apply to?
The AI Act (EU Regulation 2024/1689) is the first comprehensive legal framework on artificial intelligence. It applies to providers, deployers (professional users), importers and distributors of AI systems that are placed on the market or used in the EU, regardless of where the provider is established. It has extraterritorial effect: any AI system whose outputs are used in the EU is subject to the Regulation.
When does the AI Act start applying?
Application is phased in: prohibitions on unacceptable-risk practices entered into force on 2 February 2025; obligations on GPAI models, governance and sanctions on 2 August 2025; general application (transparency, Art. 50) on 2 August 2026; high-risk systems under Annex III on 2 December 2027; and under Annex I on 2 August 2028.
How do I know if my AI system is high-risk?
A system is high-risk if it is listed in Annexes I or III of the Regulation (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and justice) or if it is a safety component of regulated products. It requires conformity assessment, technical documentation, EU database registration, data governance and human oversight.
What sanctions does the AI Act provide?
Maximum sanctions are: up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for non-compliance with high-risk system obligations; and up to €7.5 million or 1.5% for providing incorrect information to authorities. For SMEs and startups, the lower absolute amount applies.
Do I need an EU representative if my company is not in Europe?
Yes. Article 22 of the AI Act requires providers of AI systems not established in the EU to appoint an authorized representative in a Member State before placing their systems on the European market. The representative acts before national supervisory authorities and is responsible for compliance with the Regulation's obligations.
How does the AI Act relate to the GDPR?
The AI Act regulates AI systems (the product), while the GDPR regulates the processing of personal data (the rights). Their scopes overlap: most AI systems process personal data, and the GDPR applies to that processing. AI Act compliance does not exempt from GDPR compliance. Both frameworks require impact assessments (conformity assessment and DPIA respectively) that can be integrated.
What is a GPAI model and what obligations does it have?
A general-purpose AI model (GPAI) is a model trained on broad data through large-scale self-supervised learning, capable of performing a wide range of tasks (e.g. GPT-4, Gemini, Claude). Since August 2025, GPAI providers must comply with obligations on documentation, acceptable use policy and training data summary. GPAI models with systemic risk (>10²⁵ FLOPs) have additional obligations on risk assessment and incident reporting.
Which authority supervises the AI Act in Spain?
In Spain, the competent authority is the AESIA (Spanish Agency for the Supervision of Artificial Intelligence), operational since 2024. At European level, the European AI Office coordinates enforcement among Member States and directly supervises GPAI models with systemic risk.