contact us
A clear breakdown of the EU AI Act's risk tiers, obligations, and phased compliance deadlines.
The EU AI Act, Plain-English: What’s Actually Required and When

The EU AI Act, formally adopted in 2024, is the first comprehensive legal framework anywhere aimed specifically at AI systems rather than treating them under existing data-protection or product-safety law alone. Its central organizing idea is simple even though the compliance detail underneath it isn't: risk determines obligation. The more risk a system poses to safety or fundamental rights, the more it has to do to stay on the right side of the law.

The four risk tiers

Unacceptable risk systems are banned outright. This tier covers things like social scoring by governments and certain forms of manipulative or exploitative AI, along with real-time biometric identification in public spaces except under narrow, defined exceptions.

High-risk systems are legal but heavily regulated. This tier covers AI used in contexts like hiring, credit scoring, law enforcement, critical infrastructure, and medical devices. Places where a wrong or biased output can materially affect someone's rights or safety. High-risk systems carry the bulk of the Act's compliance burden: risk management systems, data governance requirements, technical documentation, human oversight, and conformity assessments before they can go to market.

Limited risk systems (chatbots, deepfake generators, and similar tools) carry primarily transparency obligations: people need to be told they're interacting with an AI system or looking at AI-generated content, rather than being deceived into thinking otherwise.

Minimal risk covers most other AI applications (spam filters, recommendation systems in low-stakes contexts) where the Act imposes essentially no additional obligations beyond existing law.

The separate track for general-purpose models

Layered on top of that risk-tier structure is a separate set of obligations specifically for general-purpose AI models, the kind of large foundation models that power many downstream products. These providers face baseline transparency requirements (technical documentation, disclosure of training data at a summary level, copyright-compliance measures) regardless of tier, with additional obligations kicking in for models classified as carrying "systemic risk" based on the compute used to train them.

The phased timeline

The Act didn't take effect all at once. Prohibited-practice bans came into force first, on a matter of months after formal adoption. Obligations for general-purpose AI model providers followed roughly a year in. The heaviest obligations (for high-risk systems) carry the longest runway, giving affected companies more time to build the required governance and documentation infrastructure before enforcement begins in earnest. That staggered approach was a deliberate response to industry concerns that a single hard deadline would be unworkable for companies with AI embedded across many products.

Why this matters outside the EU

Companies without any EU legal entity still pay attention to this law, for the same reason global companies pay attention to GDPR: if your product is used by people in the EU, EU law can reach you regardless of where you're headquartered. It's also functioning, as GDPR did before it, as something of a de facto global standard. Several other jurisdictions have drawn on the EU AI Act's risk-tier structure when drafting their own frameworks, a dynamic we cover in our comparison of how China, the UK, and the US are diverging on AI governance.

What it doesn't settle

The Act is a compliance framework, not a resolution of the harder open questions in AI policy. It doesn't settle the copyright disputes over training data (see our status check on AI copyright lawsuits) and it leaves significant interpretive work to guidance documents and national regulators that are still being finalized. For any company operating AI products that touch the EU market, the practical takeaway is straightforward even if the compliance work isn't: know which risk tier your system falls into, and build documentation practices now rather than when an obligation deadline is already close.

Share with