resources

AI Act Summary — Practical Guide to the EU Artificial Intelligence Regulation

Practical and structured guide to the AI Act (EU Regulation 2024/1689): scope, application timeline, risk categories, obligations by role and penalties. Reference for technology companies and legal practitioners.

AI Act · EU Regulation 2024/1689 · Risk categories · Obligations · Penalties · GPAI

We help you classify your AI system, prepare technical documentation and meet all regulatory requirements.

The AI Act (EU Regulation 2024/1689 of the European Parliament and of the Council of 13 June 2024) is the world's first comprehensive legal framework for artificial intelligence. It establishes uniform rules for the development, commercialisation and use of AI systems in the European Union, with extraterritorial effect: it applies to any AI system that has effects in the EU, regardless of where its provider is established.

Scope of application

The AI Act applies to:

  • Providers that place AI systems on the market or put them into service in the EU (regardless of where they are established)
  • Deployers (professional users) that use AI systems in the EU
  • Importers and distributors of AI systems in the EU
  • Product manufacturers that incorporate AI systems

Outside scope: personal non-professional use, AI systems for defence and national security, basic scientific research.

Application timeline

2 Aug 2024 AI Act enters into force (EU Regulation 2024/1689)
2 Feb 2025 Prohibitions on unacceptable-risk systems and AI literacy obligations begin to apply
2 Aug 2025 Rules for general-purpose AI models (GPAI), governance and penalties apply. GPAI Code of Practice becomes operational
2 Aug 2026 General application of the remaining AI Act provisions (transparency, Article 50). National supervisory authorities operational
2 Dec 2026 New prohibition on AI generating non-consensual intimate imagery (NCII) and CSAM applies. Watermarking deadline for AI systems placed on the market before 2 Aug 2026
2 Dec 2027 Rules for high-risk AI systems classified under Annex III (standalone systems) apply
2 Aug 2027 GPAI models placed on the market before 2 Aug 2025 must be compliant. National AI regulatory sandboxes operational
2 Aug 2028 Rules for high-risk AI systems classified under Annex I (regulated products, e.g. medical devices, machinery) apply

Risk categories

The AI Act classifies AI systems into four risk levels. Obligations are proportionate to the assigned risk level.

Unacceptable risk

Examples: Social scoring systems, subliminal manipulation, exploitation of vulnerable groups, real-time remote biometric identification in public spaces (with exceptions), generation of non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM) (from December 2026).

Obligations: PROHIBITED. Placing on the market and putting into service banned in the EU.

High risk

Examples: AI in critical infrastructure, medical AI devices, biometric identification systems, AI in recruitment, educational AI, AI for access to essential services (credit, insurance), AI in administration of justice.

Obligations: Conformity assessment, full technical documentation, registration in EU AI database, mandatory human oversight, audits and serious incident notification.

Limited risk

Examples: Chatbots, deepfakes, synthetic content generation systems.

Obligations: Transparency obligations: users must be informed they are interacting with AI. Mandatory labelling of AI-generated content.

Minimal risk

Examples: Spam filters, AI in video games, recommendation assistants with limited impact.

Obligations: No specific obligations. Voluntary adoption of codes of conduct is encouraged.

General-purpose AI models (GPAI)

GPAI models (such as GPT-4, Gemini or Claude) have specific obligations from August 2025:

  • Detailed technical documentation and acceptable use policy
  • Summary of training data used (respecting copyright)
  • For GPAI models with high systemic impact (over 1025 FLOPs of training compute): systemic risk assessment, serious incident notification, adversarial testing
  • Compliance with the GPAI Code of Practice

Key obligations by role

Providers (AI system manufacturers)

  • Conformity assessment before market placement
  • Complete technical documentation of the system
  • Registration in EU AI Act Database (high-risk systems)
  • Human oversight integrated in the system
  • Notification of serious incidents within 15 days
  • Designate an EU representative if not established in Europe (Art. 22)

Deployers (professional users)

  • Active human oversight of the AI system in use
  • Fundamental rights impact assessment (public-sector systems)
  • Notification to authorities for public bodies or companies with over 50 staff
  • Registration in EU database for public bodies

Importers and distributors

  • Verify that the provider has carried out the conformity assessment
  • Verify that the CE marking is present
  • Retain technical documentation
  • Notify providers of any identified risks

Penalties

€35M or 7% turnover Prohibited practices (unacceptable-risk systems)
€15M or 3% turnover Non-compliance with high-risk system obligations or other obligations
€7.5M or 1.5% turnover Incorrect or incomplete information to supervisory authorities

Fines apply whichever amount is higher (absolute or percentage). For SMEs and startups, fines are capped at the lower absolute amount.

Governance and supervision

Each member state designates one or more national AI Act supervisory authorities. In Spain, the competent body is AESIA (Spanish Agency for the Supervision of Artificial Intelligence), operational since 2024. At European level, the EU AI Office coordinates enforcement, supervises GPAI models and can investigate providers directly.

Extraterritorial effect: non-European companies

The AI Act applies to any provider, regardless of where they are established, if their AI system has effects in the EU. Companies not established in the EU that market AI systems in Europe must:

  • Designate an authorised representative in the EU (Art. 22)
  • Comply with all Regulation obligations applicable to their system category

See our AI Act representation for Asian companies and AI Act representation for US/Canada/UK companies services.

Need to comply with the AI Act?

We classify your AI system by risk level, prepare the technical documentation and guide you through the full conformity process under the European AI regulation.

Request an assessment
Contact us