The EU AI Act in 60 Seconds
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive law regulating artificial intelligence. It takes a risk-based approach: the higher the risk an AI system poses, the stricter the requirements. It entered into force on 1 August 2024 with a phased implementation through 2028.
The Risk Pyramid
4 Risk Levels
🔴 Unacceptable Risk (Prohibited) — Article 5
- Social scoring by governments
- Real-time remote biometric identification in public spaces (with exceptions for law enforcement)
- Subliminal manipulation or exploitation of vulnerabilities
- Emotion recognition in workplaces and education (with exceptions)
- Predictive policing based solely on profiling
- Untargeted scraping of facial images for recognition databases
🟠 High Risk — Annex III
- Biometric identification and categorisation
- Critical infrastructure management (energy, water, transport)
- Education and vocational training (scoring, admissions)
- Employment (recruitment, HR decisions, task allocation)
- Essential services access (credit scoring, insurance pricing)
- Law enforcement
- Migration, asylum, and border control
- Administration of justice
🟡 Limited Risk (Transparency obligations)
- Chatbots — must disclose they are AI
- Deepfakes — must be labelled as AI-generated
- Emotion recognition — must inform the person
🟢 Minimal Risk
- AI-enabled video games, spam filters, inventory management
- No specific requirements (voluntary codes of conduct encouraged)
High-Risk AI Requirements
If your AI system is classified as high-risk, you must implement:
- Risk management system — Continuous, iterative risk identification and mitigation
- Data governance — Training, validation, and testing datasets must be relevant, representative, and free of errors
- Technical documentation — Detailed documentation of the AI system's design, development, and capabilities
- Record-keeping — Automatic logging of the AI system's operations for traceability
- Transparency — Clear instructions for use, including capabilities and limitations
- Human oversight — Designed to be effectively overseen by humans
- Accuracy, robustness, cybersecurity — Appropriate levels throughout the lifecycle
- Conformity assessment — Before placing on the market or putting into service
- EU database registration — High-risk systems registered in the EU public database
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →General-Purpose AI (GPAI) Models
The EU AI Act also regulates foundation models and general-purpose AI:
- All GPAI models: Technical documentation, copyright compliance, transparency about training data
- GPAI with systemic risk (>10^25 FLOPs training compute): Additional obligations including model evaluation, adversarial testing, incident reporting, and cybersecurity measures
Key Deadlines
- 2 February 2025: Prohibited AI practices apply (Article 5)
- 2 August 2025: GPAI model obligations apply
- 2 December 2027: High-risk AI system requirements for Annex III use cases apply (main compliance deadline, postponed from 2 August 2026 by the EU's 2026 Digital Omnibus)
- 2 August 2028: High-risk systems in Annex I (specific product safety legislation) — extended deadline, postponed from 2 August 2027
Technical Troubleshooting
Diagnostics, networks, and customer-facing problem resolution. In collaboration with Starweaver.
Start on Coursera →Penalties
- Prohibited AI practices: Up to €35,000,000 or 7% of total worldwide annual turnover
- High-risk non-compliance: Up to €15,000,000 or 3% of worldwide annual turnover
- Incorrect information to authorities: Up to €7,500,000 or 1% of worldwide annual turnover
- SME/startup adjustment: Lower caps for smaller entities
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
