The AI Act: regulatory framework for artificial intelligence
The EU Artificial Intelligence Regulation (AI Act) establishes the world’s first comprehensive legal framework for regulating AI systems. Its risk-based approach classifies systems into four categories, each with proportionate requirements.
Classification of AI systems by risk level
Unacceptable risk (prohibited)
- Social scoring systems
- Real-time remote biometric identification in public spaces (with exceptions)
- Subliminal manipulation or exploitation of vulnerabilities
- Emotion inference in workplaces and educational centers
High risk
- Personnel selection and employee evaluation systems
- Credit scoring and financial risk assessment
- AI-assisted medical diagnosis
- Critical infrastructure management systems
- Autonomous vehicles and safety components
Limited risk
- Chatbots and virtual assistants (transparency obligation)
- Content generation systems (deepfakes)
- Biometric categorization systems
Minimal risk
- Spam filters
- Video games with AI
- Inventory systems
Requirements for high-risk systems
- Risk management system — Continuous assessment throughout the lifecycle
- Data governance — Quality, representativeness, and absence of biases in training data
- Technical documentation — Detailed description of the system, its purpose, and limitations
- Activity logging — Traceability of system operations
- Transparency — Clear instructions for operators
- Human oversight — Effective human intervention mechanisms
- Accuracy, robustness, and cybersecurity — Verifiable technical standards
Application timeline
| Date | Milestone |
|---|---|
| August 2024 | Entry into force |
| February 2025 | Prohibitions on unacceptable-risk AI |
| August 2025 | Requirements for general-purpose AI models |
| August 2026 | General application of remaining provisions (transparency, Article 50) |
| December 2026 | New prohibition on NCII/CSAM AI; watermarking deadline for pre-August 2026 systems |
| December 2027 | Requirements for high-risk systems (Annex III, standalone) |
| August 2028 | Requirements for high-risk systems (Annex I, regulated products) |
How to prepare your company?
The first step is to correctly classify your AI systems. Not all require the same level of compliance. At A2 Estudio Legal we conduct classification assessments and design compliance roadmaps tailored to your product. Consult with our team.