With the AI Act, the European Union has created the world's first comprehensive legislation regulating the use and development of artificial intelligence. The regulation adopts a risk-based approach: the greater the risk of the AI system to the safety or fundamental rights of citizens, the stricter the rules. But what does this mean in practice for organizations that build AI (providers) and organizations that deploy AI (users)?
The Four Risk Categories
The core of the AI Act, anchored around Article 5 and beyond (to be verified), divides AI systems into four clear levels:
- Unacceptable risk (Prohibited AI): Systems that pose a clear threat to the safety and rights of people. Think of social scoring by governments, or AI systems that subliminally manipulate human behavior. These are strictly prohibited.
- High risk: AI deployed in critical infrastructure, education, recruitment and selection, and law enforcement (Annex III (to be verified)). These systems are subject to strict compliance requirements, including risk management, high data quality, logging, and human oversight.
- Limited risk: This mainly concerns AI systems where users need to know they are interacting with a machine. Think of chatbots, deepfakes, or generative AI content. Here, transparency obligations primarily apply.
- Minimal risk: Applications such as spam filters or AI support in video games. No specific legal obligations under the AI Act apply to these systems, although the EU encourages voluntary codes of conduct.
Transparency Requirements and General Purpose AI (GPAI)
For creators of General Purpose AI (general-purpose models, such as large language models that generate text and images), the law introduces specific rules (Article 50 (to be verified)). They must maintain technical documentation, respect copyright laws, and publish summaries of the training data.
For users of limited-risk systems (such as organizations deploying a customer service chatbot or publishing AI-generated images), transparency is key. Users of your services must be unambiguously informed that they are not communicating with a human, or that audiovisual content has been artificially generated or manipulated.
Timeline of Entry into Force (Overview)
The AI Act entered into force on August 1, 2024, but the obligations are being rolled out in phases to give the market time to prepare.
| Date | Phase / Obligation |
|---|---|
| February 2025 (to be verified) | Ban on AI systems with an unacceptable risk takes effect. Introduction of the AI literacy obligation. |
| August 2025 (to be verified) | Requirements for general-purpose AI models (GPAI) and associated transparency requirements take effect. |
| August 2026 - End of 2027 (to be verified) | Phased entry into force of the strict obligations for high-risk AI systems (depending on specific annexes). |
Preparing for the Future
Whether your organization builds or consumes, mapping your current AI use is step one. Determine which risk category your systems fall into and start setting up transparency and governance in a timely manner.
Would you like to delve deeper into how you can deploy AI strategically and responsibly within your organization? Read more on our knowledge base and guide environment for practical roadmaps and policy development.