EU AI Act

EU AI Act AI Act EU AI Regulation

Glossary

The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, often called the AI Regulation. It sets uniform rules for developing, placing on the market and using AI systems in the European Union. Its basic idea: the technology itself is not regulated, the purpose it is put to is. The greater the potential harm to people, the stricter the duties.

The regulation entered into force in August 2024, but it does not apply all at once. Its obligations arrive in stages across several years. This entry gives an overview of the structure and is no substitute for legal advice.

The approach: risk instead of technology

The regulation sorts applications into four tiers. What counts is always the specific purpose. The same model can fall under the strictest tier in one application and the loosest in another.

TierWhat falls under itConsequence
Prohibited practicesAmong others social scoring by authorities, manipulative techniques that cause significant harm, and certain forms of biometric evaluationNot permitted
High riskSystems in sensitive areas such as recruitment, credit decisions, education, critical infrastructure, or acting as a safety component in already regulated productsExtensive duties before and after deployment
Limited riskSystems interacting directly with people or producing generated content, such as chatbots and image or text generatorsTransparency obligations
Minimal riskThe large remainder, such as spam filters, shop recommendations, spelling assistanceNo specific duties

For most companies, day-to-day work sits in the lower two tiers. The point where it tips over is rarely the technology and almost always the decision that hangs on the output. A model pre-sorting job applications therefore stands in a different place from one drafting product descriptions.

General-purpose AI models, meaning the big large language models, have their own track with duties for the providers. These include technical documentation, information for the companies building on top, and details about copyright in the training data.

The timetable

The staggering is why the regulation appears in discussions both as “it has applied for ages” and as “it is still coming”. Both are true, depending on which part you mean.

The obligation that already applies

Since February 2025, Article 4 has required providers and deployers to ensure a sufficient level of AI literacy among the people operating AI systems on their behalf. That affects more organisations than most assume: it is enough for employees to use AI tools in a work context, and the company counts as a deployer.

There is no prescribed curriculum. What is required is a level of knowledge that fits the use. How does the tool work, where are its limits, which data may go into it, how do you recognise a wrong output. In practice this mostly means keeping a record: who was trained on what, and when.

The prohibited practices have likewise been banned since February 2025.

The transparency obligations

Article 50 has applied since 2 August 2026. It requires that people can tell when they are talking to an AI system, and that artificially generated or altered content is disclosed as such and marked in a machine-readable way. Deepfakes and AI-generated text on matters of public interest carry their own disclosure duties.

For websites this is the part with the widest reach. An assistant in support, an automatically generated product description, a generated image in a blog post: all of it sits in the territory this article addresses.

What comes later

For high-risk systems embedded as safety components in products already assessed under other EU legislation, the transition period runs longer, into 2027. The regulation’s timetable also remains politically in motion, so for a concrete project it is worth checking the current state of play.

Provider or deployer

The regulation distinguishes several roles. Two matter most in practice.

  • Provider is whoever develops an AI system and makes it available under their own name. The heavy duties sit here: risk management, data quality, technical documentation, logging, human oversight, conformity assessment for high-risk systems.
  • Deployer is whoever uses an AI system under their own authority. The duties are slimmer but real: use as intended, oversight by suitable people, informing the people affected, retaining logs.

The role can change. Adapt a bought-in model far enough and offer it under your own name, and it becomes your own system, which moves you into the provider role. This is one of the points that makes projects expensive when nobody clarifies it early.

Infringements carry fines that are staggered and, at the upper end, measured against worldwide annual turnover. The range is highest for the prohibited practices.

What this means in practice for software and websites

Most of the work is stocktaking, not technology.

  1. Build an inventory. Which AI functions are in use in the organisation, in your own software as well as in bought-in tools. The list is usually longer than expected.
  2. Classify the purpose. What hangs on the output? A decision about a person lands in a different tier from a text suggestion somebody edits.
  3. Settle the role. Provider or deployer, per application.
  4. Implement transparency. Disclosure wherever people talk to a system or see generated content.
  5. Organise oversight. Who reviews outputs, who may switch it off, where is that documented.
  6. Evidence competence. Record training sessions and participants.

Data protection is untouched by all this. The GDPR applies in parallel, and both bodies of rules ask partly the same questions of the same projects.

Frequently asked questions about the EU AI Act

Does the regulation apply to small companies too? Yes, though in graduated form. Article 4 applies regardless of company size. The heavy duties hang on the risk tier, not on headcount. For small and medium enterprises the regulation provides for eased documentation requirements.

Does the AI Act apply to providers outside the EU? It bites when a system is placed on the market in the EU or when its output is used here. The provider’s registered office alone does not decide the question.

Do I have to label every AI-generated text on my website? The transparency duties do not attach to every use of a tool, but to generated content that could pass as authentic and to text on matters of public interest. Content edited under human responsibility is treated differently from fully automated publishing. Where the line runs in an individual case belongs in front of a lawyer.

Is a chatbot automatically a high-risk system? No. An assistant that provides information normally falls under the transparency obligations. It becomes high risk when a decision about people hangs on the output, for instance in pre-screening job applications.

Conclusion

The EU AI Act is less a catalogue of bans than a sorting exercise. Anyone who knows which AI functions are running in the organisation, what they are used for and who answers for them has done the larger part. The rest is documentation and, for the transparency duties, a manageable change to the interface. How we build software with logging and human oversight designed in from the start is described on our page about custom software development. For an assessment from project practice, see the article AI in software development. What cannot be settled on paper is the literacy duty in Article 4, because that one needs people who understand what they are working with, and that is what our AI training for companies is for. If you want to know what this means for a specific plan, raise it in a free consultation.

← Back to glossary
HOMEGLOSSARYEU-AI-ACT