The EU Artificial Intelligence Act (Regulation 2024/1689)

The EU Artificial Intelligence Act (AI Act), formally Regulation (EU) 2024/1689, is the world’s first comprehensive horizontal regulatory framework for artificial intelligence. Adopted on 13 June 2024 after extensive trilogue negotiations, the AI Act establishes a risk-based approach to AI regulation, categorising AI systems according to the level of risk they pose to health, safety, and fundamental rights. The Regulation applies to providers, deployers, importers, distributors, and product manufacturers of AI systems placed on the market or put into service in the European Union, regardless of whether the provider is established within the EU or in a third country, reflecting the same territorial scope model established by the GDPR.

Risk-Based Classification

The AI Act adopts a risk-based pyramid that determines the regulatory obligations applicable to each AI system. Four risk categories exist: unacceptable risk (prohibited), high risk (subject to conformity assessment and compliance obligations), limited risk (transparency obligations), and minimal risk (no additional obligations beyond existing law). The classification is determined by the intended purpose of the AI system and the sector in which it operates, not by the technology itself. This approach allows the Regulation to remain technologically neutral while targeting regulatory intervention where the potential for harm is greatest.

Prohibited AI Practices

Article 5 of the AI Act prohibits AI practices that present unacceptable risks to Union values and fundamental rights. Prohibited practices include: AI systems deploying subliminal techniques to materially distort behaviour in a manner causing harm; systems exploiting vulnerabilities of persons due to age, disability, or socio-economic situation; social scoring by public authorities; real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to narrow exceptions for specific serious crimes with prior judicial authorisation; and systems that create or expand facial recognition databases through untargeted scraping of images. The prohibition on real-time biometric identification was among the most contested provisions, with the European Parliament advocating for a complete ban and Member States seeking law enforcement derogations.

High-Risk AI Systems

The majority of regulatory obligations under the AI Act attach to high-risk AI systems, classified under Annex I (systems that are safety components of regulated products or subject to EU harmonisation legislation) and Annex II (standalone AI systems in specified use cases including biometric categorisation, critical infrastructure management, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice). High-risk systems must comply with mandatory requirements covering: risk management systems, data governance and training data quality, technical documentation and record-keeping, transparency and provision of information to deployers, human oversight mechanisms, and accuracy, robustness, and cybersecurity standards.

Providers of high-risk AI systems must implement a risk management system (Article 9) throughout the entire lifecycle of the system, comprising iterative processes of identification, analysis, evaluation, and mitigation of known and foreseeable risks. Training, validation, and testing datasets must be relevant, representative, and free from errors and biases to the extent possible. Technical documentation must demonstrate compliance and be maintained for the lifetime of the system plus 10 years. High-risk systems must undergo conformity assessment — either internal control (for most systems) or assessment by a notified body (for systems used in biometrics, law enforcement, and access to essential services, where fundamental rights risks are greatest).

Transparency Obligations for Limited Risk Systems

AI systems that interact with natural persons must be transparent about their AI nature. Users must be informed when they are interacting with an AI system, unless this is obvious from the circumstances. Deployers of emotion recognition systems or biometric categorisation systems must inform natural persons of the system’s operation. Deep fakes — AI-generated or manipulated content resembling existing persons, objects, or events — must be labelled as artificially generated. Providers of general-purpose AI models, including foundation models and generative AI, must publish a summary of training data and comply with copyright-relevant requirements.

Governance and the European AI Board

The AI Act establishes a multi-level governance structure. Each Member State must designate one or more notifying authorities and a single market surveillance authority responsible for supervision and enforcement. The European Artificial Intelligence Board (Article 65) is composed of representatives of Member States and the Commission, responsible for facilitating consistent application, issuing opinions and recommendations, and advising the Commission on AI policy. A scientific panel of independent experts advises on enforcement, particularly regarding general-purpose AI models.

Enforcement, Fines, and Penalties

The AI Act imposes substantial penalties for non-compliance. Violations of prohibited AI practices attract administrative fines of up to 7 per cent of annual worldwide turnover or €35 million, whichever is higher. Non-compliance with obligations applicable to high-risk AI systems attracts fines of up to 3 per cent of annual worldwide turnover or €15 million. Provision of incorrect information to notified bodies or competent authorities attracts fines of up to 1.5 per cent of annual worldwide turnover or €7.5 million. For SMEs and start-ups, the Regulation provides that fines should be proportionate and considers the legal form and economic capacity of the undertaking, though no specific exemption exists.

Relationship with Existing Legislation

The AI Act operates alongside existing EU sectoral legislation, including the GDPR, the Digital Services Act, the Product Liability Directive, and sector-specific harmonisation legislation. Where conflicts arise with the GDPR, the more specific provisions of the AI Act apply to AI-related matters, though data protection authorities retain their existing competences under the GDPR. The Regulation includes a fundamental rights impact assessment requirement for deployers that are public authorities or private operators providing public services, ensuring that AI deployment does not disproportionately impact fundamental rights.