EU AI Act

The EU law that bans a few AI uses and adds heavier duties as an AI system's role and risk increase.

the European AI lawEU rules for AI productsis our AI feature high riskthe law banning some AI usesdo we need permission to ship AI in EuropeAI Act complianceis our chatbot regulated in the EUEU AI Acct

What it is

The EU AI Act is Regulation (EU) 2024/1689, a law that assigns duties according to an AI system's use, risk, and the organization's role. It prohibits a limited set of practices, social scoring and untargeted scraping of facial images to build recognition databases among them, places extensive requirements on high-risk systems, requires transparency for certain human-facing and synthetic-content uses, and creates a separate regime for general-purpose AI models. Providers and deployers carry different duties.

Reach for an assessment when an AI system or model is put on the EU market, used in the EU, or produces output used there. Inventory each actual use case, decide whether you are a provider, deployer, importer, or distributor, then test prohibited-practice, high-risk, transparency, and general-purpose-model rules. High-risk classification depends on purpose and context, not simply on how impressive the model is.

Gotcha: classifying the foundation model once does not classify every product built with it. A harmless writing assistant and a tool used to rank job applicants can use the same API but land in very different risk categories. Reassess when the intended purpose, users, data, geography, or decision power changes, and keep evidence for why the chosen category fits.

Ask AI for it

Create an EU AI Act readiness register for every AI feature described below. Map each system to Regulation (EU) 2024/1689, recording intended purpose, geography, provider or deployer role, model supplier, affected people, decision impact, and evidence. Test prohibited practices in Article 5, high-risk classification under Article 6 and Annex III, AI-literacy duties under Article 4, transparency duties under Article 50, and the general-purpose AI model rules. For any high-risk candidate, add owners and gaps for risk management, data governance, technical documentation, logs, human oversight, accuracy, robustness, cybersecurity, registration, and post-market monitoring. Add reassessment triggers and do not classify a use case from the model name alone.

You might have meant

gdprprivacy by designlawful basispersonal data piidata processing agreement