A first look at the EU's landmark framework for regulating artificial intelligence.
How is the European Union regulating artificial intelligence, and why is the EU AI Act significant?
Artificial intelligence is evolving at a rapid pace and is creating new opportunities. With such change in society, questions about safety and accountability have arisen. The EU AI Act is a dedicated framework for regulating AI across a wide range of different applications.
The EU AI Act is a European Union regulation that creates rules for the development, placing on the market and use of AI systems. The Act was proposed in 2021 originally, and on the 1st of August 2024 it went into force.1
Since then, various provisions have begun applying in stages. The most recent update came on the 2nd of August 2026, when new transparency requirements under Article 50 took effect. The high-risk obligations that were also originally due that date were postponed to the 2nd of December 2027 under the EU's Digital Omnibus, which entered into force just days earlier.2 This is an act being introduced, and adjusted, in multiple stages.
Its central feature is the risk-based approach. Rather than applying identical rules to every AI system, the Act divides AI uses according to their potential risk.
Under the act, certain practices are prohibited where the EU considers the risks unacceptable. High-risk AI systems are permitted but must meet requirements covering areas such as risk management, data governance, transparency, human oversight, accuracy and cybersecurity. The main approach of the law is: The greater the risk, the greater the regulation.
What makes this law unique is that it applies to different participants in the AI supply chain including providers, deployers, importers and distributors depending on their role.
Let's give a hypothetical example to explain this idea. Let's say Microsoft develops an AI recruitment system that analyses CVs to help identify suitable candidates. A law firm then uses that system to screen applicants for a training contract and uses such AI. In such case both the provider (Microsoft) and the deployer (Law firm) would be included under the act if something went wrong.
The scope of the law can even extend beyond the EU. Certain organisations based outside Europe can be covered where their AI systems are placed on the EU market, used in the EU, or where the output of an AI system is used within the EU. This means that the legislation is relevant not only to European companies but, in certain circumstances, to organisations developing and supplying AI internationally.
The Act also contains specific rules for General-Purpose AI models, models capable of performing a wide range of tasks and being used in different applications.
The most serious breaches can result in fines of up to €35 million or 7% of a company's worldwide annual turnover, whichever is higher. Other violations of the Act can result in fines of up to €15 million or 3% of worldwide annual turnover.3
The Act also treats SMEs differently, including start-ups, when calculating certain maximum fines. The scale of these penalties demonstrates that AI compliance is intended to be a legal responsibility, rather than simply an ethical consideration.
| Violation Type | Maximum Fine |
|---|---|
| Most serious breaches | €35 million or 7% of worldwide turnover |
| Other violations | €15 million or 3% of worldwide turnover |
No. The EU AI Act is still new, with its provisions being introduced in stages. As a result, there is currently limited case law interpreting the Act itself. Some parts of the legislation are already applicable, while others will apply later.
One of the key challenges is keeping regulation aligned with technological development. AI is changing at a pace that Usain Bolt can't keep up with. It took over 3 years to get the law passed in the first place and even longer to implement the legislation fully, so imagine now having to change the law every other week!
Another challenge with this piece of legislation is the accountability and responsibility can be complicated. An AI system may involve a model provider, an application developer and an organisation deploying the system. Establishing which party is responsible for a particular problem can therefore become a complex legal question.
These issues will become clearer as the Act is implemented and tested through regulatory enforcement and future cases.
The EU AI Act establishes a legal framework specifically designed for artificial intelligence, using the level of risk as the basis for determining regulatory requirements.
Its significance will depend not only on the text of the legislation, but on how companies, regulators and courts apply it in practice.
As AI continues to develop, the EU AI Act will provide an important case study in how the law attempts to regulate a rapidly changing technology.