Strategy & governance

EU AI Act

Artificial Intelligence Act · Regulation (EU) 2024/1689

The European Union's law on artificial intelligence, which sets obligations according to risk: a few uses are banned, high-risk uses are strictly regulated, some require transparency, and most are left free.

Prohibited practicessocial scoring, manipulationHigh riskhiring, credit, education: strict obligationsTransparency obligationschatbots, deepfakes: disclosure and labellingMinimal riskmost applications: no added obligationsTIMETABLE · as of October 2026Feb 2025prohibitionsAug 2025general-purpose modelsAug 2026transparencyDec 2027high risk · Annex IIIAug 2028products · Annex IDuties follow the use and not the technology; companies outside the EU are covered when their systems are used in the EU.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/eu-ai-act

In plain terms

The Act treats AI the way product-safety law treats goods: the more harm a use can do, the more is demanded before it reaches the market. A spam filter carries no duties. A chatbot must tell people they are talking to a machine. A system that screens job applicants or scores creditworthiness must meet requirements on data, documentation, human oversight and accuracy. A short list of practices, such as social scoring and manipulative techniques, is forbidden.

Why it matters

It applies beyond the EU: a company in Türkiye, the United Kingdom or the United States is covered if it places an AI system on the EU market or if the system's output is used in the EU. Duties depend on the role: the provider that develops a system carries most of them, and the deployer that uses it carries fewer. For most companies the practical work is an inventory of AI uses, sorted by risk category. Fines for prohibited practices reach 35 million euros or 7% of worldwide annual turnover. The timetable has been amended once already, so dates should be checked against the current text.

Example

A Turkish software company sells a tool that ranks job applicants, and a third of its customers are in Germany and the Netherlands. Recruitment is on the Act's high-risk list, so the company is a provider of a high-risk system whatever its home country. It starts on risk management, data governance, technical documentation and a human-oversight design, and appoints an authorised representative in the EU. Its internal meeting-notes assistant is in the minimal-risk category and needs none of this.

Most often confused with

EU AI Act vs. GDPR

EU AI ActRegulates AI systems, by the risk of the use
GDPRRegulates personal data, whatever the technology

The two apply side by side. The GDPR governs any processing of personal data, with or without AI. The AI Act governs AI systems, with or without personal data. A recruitment tool that processes applicants' data must satisfy both, and compliance with one gives no exemption from the other.

Under the hood

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. Since 2 February 2025: the prohibitions and the AI literacy duty. Since 2 August 2025: obligations for providers of general-purpose AI models, with extra duties for models posing systemic risk, supported by a voluntary code of practice. Since 2 August 2026: the transparency duties of Article 50, covering disclosure of chatbots, labelling of deepfakes and marking of AI-generated content. An amending regulation of July 2026, known as the Digital Omnibus on AI (Regulation (EU) 2026/1744), moved the high-risk obligations: 2 December 2027 for the stand-alone uses listed in Annex III, such as employment, credit, education and essential services, and 2 August 2028 for AI built into regulated products. It also added prohibitions on systems that generate non-consensual intimate imagery, applying from 2 December 2026. High-risk requirements: risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness, and conformity assessment. Supervision lies with national authorities and, for general-purpose models, the Commission's AI Office. The position described is that of October 2026.

Written by Mehmet Erkek · Last updated: