Skip to main content
← All posts·
Regulatory Compliance

What Is the EU AI Act? The World's First AI Law Explained [2026 Guide]

The EU AI Act explained clearly. Risk-based classification system, prohibited AI practices, high-risk requirements, GPAI model obligations, conformity assessments, penalties up to €35M or 7% of turnover, and key compliance deadlines through 2028.

Luca Berton11 min read

The EU AI Act in 60 Seconds

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive law regulating artificial intelligence. It takes a risk-based approach: the higher the risk an AI system poses, the stricter the requirements. It entered into force on 1 August 2024 with a phased implementation through 2028.

The Risk Pyramid

4 Risk Levels

🔴 Unacceptable Risk (Prohibited) — Article 5

  • Social scoring by governments
  • Real-time remote biometric identification in public spaces (with exceptions for law enforcement)
  • Subliminal manipulation or exploitation of vulnerabilities
  • Emotion recognition in workplaces and education (with exceptions)
  • Predictive policing based solely on profiling
  • Untargeted scraping of facial images for recognition databases

🟠 High Risk — Annex III

  • Biometric identification and categorisation
  • Critical infrastructure management (energy, water, transport)
  • Education and vocational training (scoring, admissions)
  • Employment (recruitment, HR decisions, task allocation)
  • Essential services access (credit scoring, insurance pricing)
  • Law enforcement
  • Migration, asylum, and border control
  • Administration of justice

🟡 Limited Risk (Transparency obligations)

  • Chatbots — must disclose they are AI
  • Deepfakes — must be labelled as AI-generated
  • Emotion recognition — must inform the person

🟢 Minimal Risk

  • AI-enabled video games, spam filters, inventory management
  • No specific requirements (voluntary codes of conduct encouraged)

High-Risk AI Requirements

If your AI system is classified as high-risk, you must implement:

  1. Risk management system — Continuous, iterative risk identification and mitigation
  2. Data governance — Training, validation, and testing datasets must be relevant, representative, and free of errors
  3. Technical documentation — Detailed documentation of the AI system's design, development, and capabilities
  4. Record-keeping — Automatic logging of the AI system's operations for traceability
  5. Transparency — Clear instructions for use, including capabilities and limitations
  6. Human oversight — Designed to be effectively overseen by humans
  7. Accuracy, robustness, cybersecurity — Appropriate levels throughout the lifecycle
  8. Conformity assessment — Before placing on the market or putting into service
  9. EU database registration — High-risk systems registered in the EU public database
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

General-Purpose AI (GPAI) Models

The EU AI Act also regulates foundation models and general-purpose AI:

  • All GPAI models: Technical documentation, copyright compliance, transparency about training data
  • GPAI with systemic risk (>10^25 FLOPs training compute): Additional obligations including model evaluation, adversarial testing, incident reporting, and cybersecurity measures

Key Deadlines

  • 2 February 2025: Prohibited AI practices apply (Article 5)
  • 2 August 2025: GPAI model obligations apply
  • 2 December 2027: High-risk AI system requirements for Annex III use cases apply (main compliance deadline, postponed from 2 August 2026 by the EU's 2026 Digital Omnibus)
  • 2 August 2028: High-risk systems in Annex I (specific product safety legislation) — extended deadline, postponed from 2 August 2027
🎓 Course with Starweaver

Technical Troubleshooting

Diagnostics, networks, and customer-facing problem resolution. In collaboration with Starweaver.

Start on Coursera →

Penalties

  • Prohibited AI practices: Up to €35,000,000 or 7% of total worldwide annual turnover
  • High-risk non-compliance: Up to €15,000,000 or 3% of worldwide annual turnover
  • Incorrect information to authorities: Up to €7,500,000 or 1% of worldwide annual turnover
  • SME/startup adjustment: Lower caps for smaller entities
EU AI Act
artificial intelligence
regulation
compliance
risk classification
explained
GPAI

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →