The European Union’s Artificial Intelligence Act (EU AI Act) establishes the first comprehensive legal framework for artificial intelligence. Its risk-based structure places AI systems into four broad categories, with regulatory obligations increasing in line with the potential harm a system may cause.
Organizations that develop, provide, deploy, import, or distribute AI systems in the European Union should assess their systems against this framework and implement the obligations that apply to their risk category.
Prohibited AI Systems Pose Unacceptable Risks
High-Risk AI Systems Face Extensive Compliance Obligations
Limited-Risk AI Systems Require Transparency
Minimal Risk AI - No Additional Obligations
This obligation means that organizations must ensure prohibited AI systems are not placed on the market, put into service, or used within EU territory. The ban applies regardless of where the system was developed.
Practical Example
A multinational corporation cannot deploy emotion recognition technology to assess employee engagement, motivation, or dissatisfaction in its EU offices, even if the same system operates legally in non-EU locations.
Violations of these obligations may result in significant financial penalties, including fines of up to €35 million. The severity of these sanctions highlights the importance of identifying prohibited AI practices before deployment and maintaining effective compliance controls throughout the system’s lifecycle.
High-risk AI systems face the most extensive regulatory requirements under the EU AI Act. There are two pathways to classifying an AI system as high-risk.
The first pathway includes products covered by harmonization regulation of the European Union, including medical devices, elevators and aviation equipments. The AI system could be a standalone system or a safety component of the product.
The second pathway includes AI systems for specific applications listed in Annex III. These use cases include:
If the AI systems falls under the high-risk category, extensive obligations apply. The compliance obligations include requirements to implement risk management system, setting up data governance, drafting technical documentation and many more. (See full obligations)
Obligations fall primarily on providers, i.e. those placing systems on the market or putting them into service. Deployers face specific requirements including human oversight implementation, input data monitoring, use according to instructions, and registration duties.
Practical Examples
Recruitment AI: An organization uses AI to screen CVs and recommend hiring decisions. This qualifies as high-risk employment AI requiring comprehensive documentation, risk management, and human oversight.
Medical device AI: A healthcare provider implements AI software analyzing real-time patient conversations to assess depression or anxiety severity. The system likely falls under both EU AI Act high-risk requirements and Medical Device Regulation obligations, requiring dual compliance.
Violations of these obligations can result in significant financial penalties, including fines of up to 15 million € or 3 % of global annual turnover, whichever is higher. Non-compliance may also lead to regulatory scrutiny, operational disruption, and reputational damage.
Limited-risk AI systems trigger primarily transparency obligations. While not explicitly defined as a risk category, these systems typically involve human interaction or synthetic content generation.
Under Article 50, providers must inform people when they are interacting with an AI system, unless this is obvious from the context. Providers of generative AI must mark synthetic audio, images, video, and text in a machine-readable format where technically feasible.
Deployers must inform individuals when they use emotion-recognition or biometric-categorization systems. They must also clearly disclose AI-generated or manipulated deepfakes, including images, video, and audio, as well as public-interest text that has not undergone meaningful human review or editorial control.
Practical Example
AI Chatbot: government agency implements an AI chatbot on its public website to help citizens navigate services and locate information. The chatbot must clearly disclose to users that they are interacting with an AI system rather than a human agent.
Transparency obligations may also arise under other regulations, particularly GDPR Article 13-14 (information to data subjects) and Article 22 (automated decision-making). Organizations should ensure coordinated compliance across applicable frameworks.
Minimal-risk AI systems are not subject to specific obligations under the EU AI Act because they pose little or no risk to safety, health, or fundamental rights. The Act encourages organizations to adopt voluntary codes of conduct, which can demonstrate responsible AI practices and support broader governance goals.
Practical Examples
Spam filtering: Email systems using AI to detect and categorize spam messages
Video enhancement: Creative software applying AI for color correction, resolution enhancement, or editing assistance
While the EU AI Act imposes no specific requirements, minimal-risk AI remains subject to other applicable regulation. GDPR requirements apply where personal data processing occurs. Sector-specific rules may impose additional obligations depending on the application context.
Organizations developing or deploying AI systems in the EU should prioritize three steps:
System inventory: Document every AI system in use or development, including its purpose, data sources, and deployment context.
Risk classification: Apply the EU AI Act’s risk-based framework to each system.
Implementation planning: Establish timelines and allocate the resources needed to achieve compliance.
Classification is not always straightforward, particularly for general-purpose AI systems, AI components within larger products, or systems with multiple functions. Organizations facing classification uncertainty benefit from legal assessment early in development or deployment planning.