The latest AI trends, brought to you by experts
Get curated insights on the most important—and intriguing—AI news. Subscribe to our weekly Think newsletter. See the IBM Privacy Statement.
The Artificial Intelligence Act of the European Union, also known as the EU Artificial Intelligence Act or AI Act, is a law that governs the development and/or use of artificial intelligence (AI) in the European Union (EU). Officially Regulation (EU) 2024/1689, the AI Act takes a risk-based approach to regulation, applying different rules to AI according to the risk they pose with the goal of establishing “safety, fundamental rights and human-centric AI.”
Widely considered the world’s first comprehensive regulatory framework for AI, the EU AI Act prohibits some AI uses outright and implements strict governance, risk management and transparency requirements for others. An advisory forum featuring members from civil society, academia and industry provides technical expertise and advice on standardization and implementation of the Act. Each EU member state must designate at least one market surveillance authority and at least one notifying authority. It must also designate one market surveillance authority as the single point of contact for the Act.
The act also creates rules for general-purpose artificial intelligence models, such as IBM’s Granite and Meta’s Llama 3 open-weight foundation model. The European Artificial Intelligence Board is responsible for advising member states on how to consistently and effectively apply the AI Act.
Penalties can range from EUR 7.5 million or 1% of worldwide annual turnover to EUR 35 million or 7% of worldwide annual turnover, depending on the type of noncompliance.
The AI Act is at the heart of the European Union’s efforts to achieve digital sovereignty, the ability to maintain control over technology systems, data, operations and AI in the face of change and disruption.. In turn, a business’s ability to comply with the AI Act is an important part of their own digital sovereignty—and AI sovereignty—should they do business in the EU.
In the same way that the EU’s General Data Protection Regulation (GDPR) can inspire other nations to adopt data privacy laws, experts anticipate the EU AI Act will spur the development of AI governance and ethics standards worldwide.
Get curated insights on the most important—and intriguing—AI news. Subscribe to our weekly Think newsletter. See the IBM Privacy Statement.
The EU AI Act applies to multiple operators in the AI value chain, such as providers, deployers, importers, distributors, product manufacturers and authorized representatives. Worthy of mention are the definitions of providers, deployers and importers under the EU AI Act.
Providers are people or organizations that develop an AI system or general-purpose AI (GPAI) model, or have it developed on their behalf, and who place it on the market or put the AI system into service under their name or trademark.
The act broadly defines an AI system as a system that can, with some level of autonomy, process inputs to infer how to generate outputs (for example, predictions, recommendation, decisions, content) that can influence physical or virtual environments. It defines GPAI as AI models that display significant generality, are capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream AI systems or applications. For example, a foundation model often qualifies as a GPAI; a chatbot or generative AI tool built on that model would be an AI system.
Deployers are people or organizations that use AI systems. For example, an organization that uses a third-party AI chatbot to handle customer service inquiries would be a deployer.
Importers are people and organizations located or established in the EU that bring AI systems of a person or company established outside of the EU to the EU market.
The EU AI Act also applies to providers and deployers established outside the EU when the output produced by their AI system is used in the EU. It also applies to providers outside the EU that place AI systems or GPAI models on the EU market. For example, suppose a company in the EU sends data to an AI provider outside the EU, who uses AI to process the data, and then sends the output back to the company in the EU for use. Because the output of the provider’s AI system is used in the EU, the provider is bound by the EU AI Act.
Certain providers outside the EU that offer AI services in the EU must designate authorized representatives in the EU to coordinate compliance efforts on their behalf.
While the act has a broad reach, some uses of AI are exempt. Purely personal uses of AI, and AI models and systems used only for scientific research and development, are examples of exempt uses of AI.
The EU AI Act regulates AI systems based on risk level. Risk here refers to the likelihood and severity of the potential harm. Some of the most important provisions include:
Risk categories include:
While “limited risk” is a commonly used explanatory label, it is not a defined category in the text of the act; rather, the act identifies particular transparency obligations. Similarly, AI systems that are not prohibited or classified as high-risk are often described as “minimal risk” systems and might still need to meet transparency obligations. The act encourages voluntary codes of conduct for AI systems at every risk level. Examples of minimal-risk systems can include email spam filters and video games. Many common AI uses today fall into this category.
Timelines for implementation of the EU AI Act are subject to change by statute. In July 2026 the EU enacted the AI Omnibus, which in addition to expanding compliance simplifications for some small businesses, introducing a bloc-wide regulatory sandbox and clarifying certain safety protections, postponed deadlines for some of the highest-risk AI systems until 2027 and 2028, depending on their application.
The EU AI Act explicitly lists certain prohibited AI practices that are deemed to pose an unacceptable level of risk. For example, developing or using an AI system that intentionally manipulates people into making harmful choices they otherwise wouldn’t make is deemed by the act to pose unacceptable risk to users, and is a prohibited AI practice.
What qualifies as a prohibited practice can be clarified through guidance, enforcement decisions and case law. Adding a new statutory prohibition would require an amendment to the applicable law. A partial list of Prohibited AI practices at the time this article was published include:
AI systems are considered high-risk under the EU AI Act if they are a product, or safety component of a product, regulated under specific EU laws referenced by the act, such as toy safety and in vitro diagnostic medical device laws.
The act also lists specific uses that are generally considered high-risk, including AI systems used:
For systems included in this list, an exception may be available if the AI system does not pose a significant threat to health, safety, or rights of individuals. The act specifies criteria, one or more of which must be fulfilled, before an exception can be triggered (for example, where the AI system is intended to perform a narrow procedural task). If relying on this exception, the provider must document its assessment that the system is not high-risk, and regulators can request to see that assessment. The exception is not available for AI systems that automatically process personal data to evaluate or predict some aspect of a person’s life, such as their product preferences (profiling), which are always considered high-risk.
High-risk AI systems must comply with specific requirements. Some examples include:
There are additional transparency obligations for specific types of AI. For example:
We highlight some obligations on key operators of high-risk AI systems in the AI value chain—providers and deployers—below.
Providers of high-risk AI systems must comply with requirements including:
Deployers of high-risk AI systems will have obligations including:
The EU AI Act creates separate rules for general-purpose AI models (GPAI). Providers of GPAI models will have obligations including the following:
If a GPAI model is classified as posing a systemic risk, providers will have additional obligations. Systemic risk is a risk specific to the high-impact capabilities of GPAI models that have a significant impact on the EU market due to their reach or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights or the society as a whole, that can be propagated at scale across the value chain. The act uses training resources as one of the criteria for identifying systemic risk—if the cumulative amount of computing power used to train a model is greater than 10^25 floating point operations (FLOPs), it is presumed to have high-impact capabilities and pose a systemic risk. The EU Commission can also classify a model as posing a systemic risk.
Providers of GPAI models that pose a systemic risk, including free, open-source models, must meet some additional obligations, for example:
The EU AI Act can support the European Union’s digital sovereignty by requiring companies that do business in the European Union to abide by the bloc’s regulations, strengthening its control over digital infrastructure.
It can further encourage digital sovereignty by supporting the growth and development of European AI firms that would reduce the bloc’s dependence on technology developed in countries with different regulatory requirements. It does not, however, require EU member countries to maintain complete control over their AI infrastructure, maintaining the flexibility that is also an element of digital sovereignty.
Additionally, the AI Act creates demands on firms doing business in the European Union who wish to maintain their own digital sovereignty. Businesses need to maintain greater visibility into AI systems to meet the Act’s requirements for transparency and human oversight. These requirements may increase demand for AI tools that provide extensive documentation, governance controls and auditability.
While the AI Act imposes compliance requirements for businesses outside the European Union as well as in member states, it also acts as a spur for digital sovereignty: Firms with strong AI governance capabilities may be better positioned to adapt to regulatory requirements and changes in the AI market.
For noncompliance, authorities can fine organizations up to EUR 35,000,000 or 7% of worldwide annual turnover, whichever is higher.
For most other violations, including noncompliance with the requirements for high-risk AI systems, organizations can be fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher.
The supply of incorrect, incomplete or misleading information to authorities can result in organizations being fined up to EUR 7,500,000 or 1% of worldwide annual turnover, whichever is higher.
Notably, the EU AI Act has different rules for fining start-ups and other small and medium-size enterprises (or SMEs, in the AI Act’s parlance). For these businesses, the fine can be up to the lower of the two possible amounts specified above.
The European Commission can impose fines on providers of GPAI models of up to 3% of their total worldwide turnover in the preceding financial year for certain infringements of the GPAI provisions.
The law entered into force on 1 August 2024, with different provisions of the law going into effect in stages. In July 2026 as part of the AI Omnibus the EU postponed the compliance deadline for most standalone high-risk AI systems, including those used in education, hiring, and law enforcement, to 2 December 2027. High-risk AI systems incorporated into regulated products, such as medical devices and machinery, will be subject to the AI Act from 2 August 2028.
The client is responsible for ensuring compliance with all applicable laws and regulations. IBM does not provide legal advice nor represent or warrant that its services or products will ensure that the client complies with any law or regulation.
The client is responsible for ensuring compliance with all applicable laws and regulations. IBM does not provide legal advice nor represent or warrant that its services or products will ensure that the client complies with any law or regulation.