ai act hub

AI Act Hub: your resource center on the EU AI Regulation

Everything you need to comply with EU Regulation 2024/1689: application timeline, risk categories, obligations by role, glossary, comparison with GDPR and specialized consulting services.

AI Act · EU Regulation 2024/1689 · Compliance · Startups · Representative Art. 22

We classify your AI system and guide you through the entire conformity process.

TL;DR — The essentials of the AI Act

The AI Act (EU Regulation 2024/1689) is the first comprehensive legal framework on artificial intelligence. It classifies AI systems into four risk levels —unacceptable (prohibited), high (strict obligations), limited (transparency) and minimal (no specific obligations)— and applies to any AI system with effects in the EU, regardless of where the provider is established. Application is phased between February 2025 and August 2028. Sanctions can reach €35 million or 7% of global turnover.

Application timeline

The AI Act is applied progressively. These are the key dates:

2 Feb 2025 Prohibitions (unacceptable risk) and AI literacy obligations
2 Aug 2025 GPAI models, governance and sanctions
2 Aug 2026 General application (transparency, Art. 50). National authorities operational
2 Dec 2026 NCII and CSAM prohibition. Marking for pre-existing systems
2 Dec 2027 High-risk systems under Annex III
2 Aug 2028 High-risk systems under Annex I (regulated products)

For full details on each date, see the AI Act summary.

Risk categories

The AI Act classifies AI systems into four levels. Obligations are proportional to risk:

Unacceptable risk

Prohibited. Cannot be placed on the EU market.

Examples: Social scoring, subliminal manipulation, real-time biometric ID in public spaces (without exceptions)

High risk risk

Conformity assessment, technical documentation, EU database registration.

Examples: Biometrics, critical infrastructure, employment, education, credit, justice

Limited risk risk

Transparency obligations.

Examples: Chatbots, deepfakes, synthetic content generation

Minimal risk risk

No specific obligations. Voluntary codes of conduct.

Examples: Spam filters, AI in video games, low-impact recommendations

AI Act resources

Explore our specialized resources on the EU AI Regulation:

Sector AI Act guides

Vertical-specific analyses with use cases, risk classification, article-by-article obligations and compliance checklist:

Related articles

Frequently asked questions

What is the AI Act and who does it apply to?

The AI Act (EU Regulation 2024/1689) is the first comprehensive legal framework on artificial intelligence. It applies to providers, deployers (professional users), importers and distributors of AI systems that are placed on the market or used in the EU, regardless of where the provider is established. It has extraterritorial effect: any AI system whose outputs are used in the EU is subject to the Regulation.

When does the AI Act start applying?

Application is phased in: prohibitions on unacceptable-risk practices entered into force on 2 February 2025; obligations on GPAI models, governance and sanctions on 2 August 2025; general application (transparency, Art. 50) on 2 August 2026; high-risk systems under Annex III on 2 December 2027; and under Annex I on 2 August 2028.

How do I know if my AI system is high-risk?

A system is high-risk if it is listed in Annexes I or III of the Regulation (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and justice) or if it is a safety component of regulated products. It requires conformity assessment, technical documentation, EU database registration, data governance and human oversight.

What sanctions does the AI Act provide?

Maximum sanctions are: up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for non-compliance with high-risk system obligations; and up to €7.5 million or 1.5% for providing incorrect information to authorities. For SMEs and startups, the lower absolute amount applies.

Do I need an EU representative if my company is not in Europe?

Yes. Article 22 of the AI Act requires providers of AI systems not established in the EU to appoint an authorized representative in a Member State before placing their systems on the European market. The representative acts before national supervisory authorities and is responsible for compliance with the Regulation's obligations.

How does the AI Act relate to the GDPR?

The AI Act regulates AI systems (the product), while the GDPR regulates the processing of personal data (the rights). Their scopes overlap: most AI systems process personal data, and the GDPR applies to that processing. AI Act compliance does not exempt from GDPR compliance. Both frameworks require impact assessments (conformity assessment and DPIA respectively) that can be integrated.

What is a GPAI model and what obligations does it have?

A general-purpose AI model (GPAI) is a model trained on broad data through large-scale self-supervised learning, capable of performing a wide range of tasks (e.g. GPT-4, Gemini, Claude). Since August 2025, GPAI providers must comply with obligations on documentation, acceptable use policy and training data summary. GPAI models with systemic risk (>10²⁵ FLOPs) have additional obligations on risk assessment and incident reporting.

Which authority supervises the AI Act in Spain?

In Spain, the competent authority is the AESIA (Spanish Agency for the Supervision of Artificial Intelligence), operational since 2024. At European level, the European AI Office coordinates enforcement among Member States and directly supervises GPAI models with systemic risk.

Shall we talk?

Tell us about your project and we will help you find the best legal solution for your company.

Let's talk
Contact us