In plain terms
The Act treats AI the way product-safety law treats goods: the more harm a use can do, the more is demanded before it reaches the market. A spam filter carries no duties. A chatbot must tell people they are talking to a machine. A system that screens job applicants or scores creditworthiness must meet requirements on data, documentation, human oversight and accuracy. A short list of practices, such as social scoring and manipulative techniques, is forbidden.
Why it matters
It applies beyond the EU: a company in Türkiye, the United Kingdom or the United States is covered if it places an AI system on the EU market or if the system's output is used in the EU. Duties depend on the role: the provider that develops a system carries most of them, and the deployer that uses it carries fewer. For most companies the practical work is an inventory of AI uses, sorted by risk category. Fines for prohibited practices reach 35 million euros or 7% of worldwide annual turnover. The timetable has been amended once already, so dates should be checked against the current text.
Example
A Turkish software company sells a tool that ranks job applicants, and a third of its customers are in Germany and the Netherlands. Recruitment is on the Act's high-risk list, so the company is a provider of a high-risk system whatever its home country. It starts on risk management, data governance, technical documentation and a human-oversight design, and appoints an authorised representative in the EU. Its internal meeting-notes assistant is in the minimal-risk category and needs none of this.
Most often confused with
EU AI Act vs. GDPR
The two apply side by side. The GDPR governs any processing of personal data, with or without AI. The AI Act governs AI systems, with or without personal data. A recruitment tool that processes applicants' data must satisfy both, and compliance with one gives no exemption from the other.
Under the hood
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. Since 2 February 2025: the prohibitions and the AI literacy duty. Since 2 August 2025: obligations for providers of general-purpose AI models, with extra duties for models posing systemic risk, supported by a voluntary code of practice. Since 2 August 2026: the transparency duties of Article 50, covering disclosure of chatbots, labelling of deepfakes and marking of AI-generated content. An amending regulation of July 2026, known as the Digital Omnibus on AI (Regulation (EU) 2026/1744), moved the high-risk obligations: 2 December 2027 for the stand-alone uses listed in Annex III, such as employment, credit, education and essential services, and 2 August 2028 for AI built into regulated products. It also added prohibitions on systems that generate non-consensual intimate imagery, applying from 2 December 2026. High-risk requirements: risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness, and conformity assessment. Supervision lies with national authorities and, for general-purpose models, the Commission's AI Office. The position described is that of October 2026.