Loading…
Loading…
The AI Act applies a risk-tiered regulatory architecture to AI systems and general-purpose AI (GPAI) models:
1. Prohibited practices (Article 5) — outright bans on social scoring by public authorities, untargeted scraping of facial images for biometric databases, real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), emotion recognition in workplaces / education, and certain manipulative or vulnerability-exploiting systems. Effective 2 February 2025.
2. High-risk AI systems (Annex III + product-safety annexes) — AI used in critical infrastructure, education, employment, access to essential services, law enforcement, migration / border control, and the administration of justice. Providers must implement a risk-management system, data-governance obligations, technical documentation, logging, transparency, human oversight, accuracy / robustness / cybersecurity standards, conformity assessment, and post-market monitoring. Bulk of obligations apply from 2 August 2026; product-embedded high-risk systems (medical devices, civil aviation, vehicles, etc.) from 2 August 2027.
3. General-purpose AI models (Articles 51–55) — transparency, technical documentation, EU-copyright-compliance policy, and training-data summary obligations on all GPAI providers. "Systemic-risk" GPAI models (training compute > 10^25 FLOP, or designated by the Commission) face additional model-evaluation, adversarial-testing, incident-reporting, and cybersecurity obligations. Effective 2 August 2025.
4. Limited-risk systems — transparency obligations (e.g., disclosing AI interaction, labelling deepfakes).
5. Minimal-risk systems — no obligations beyond voluntary codes of conduct.
Extraterritoriality (Article 2) — the Regulation binds any provider placing an AI system on the EU market or putting it into service in the EU, regardless of the provider's place of establishment; and any provider/deployer whose AI output is used in the EU. Foreign providers must designate an EU authorised representative.
Penalties (Article 99):
(whichever higher) for prohibited-practice violations.
misleading information.
Governance — a new European AI Office within DG CNECT (operational since June 2024) leads GPAI supervision. National market-surveillance authorities enforce vis-à-vis providers and deployers. The European Artificial Intelligence Board coordinates Member-State practice.
Anthropic, Google DeepMind, Microsoft, Meta, Mistral, Cohere must produce training-data summaries, document copyright- compliance policies, and (if classified systemic-risk) submit to model evaluation and adversarial testing under the AI Office. GPT-4-class and Claude-class models almost certainly cross the 10^25 FLOP threshold; Llama 3 405B is borderline.
Vertex AI, AMZN Bedrock, ORCL OCI Generative AI, SAP Joule, Salesforce Einstein) will pass-through high-risk obligations to EU customers and absorb provider-side documentation costs. EU competitors (SAP, Aleph Alpha, Mistral, ASML / IMEC for compute hardware) gain a relative compliance-familiarity advantage.
Eightfold), edtech (Pearson, Coursera), credit-scoring (Equifax, Experian, FICO), insurtech, biometrics (CLEAR, IDEMIA), healthcare AI (Tempus, Veracyte, Bayer / Recursion deals), and ADAS/AV providers face the heaviest conformity-assessment burdens from 2 August 2026.
open-source GPAI from some transparency duties (training-data summary still required), but the systemic-risk threshold catches open-weight frontier models too. Tilts the open-vs-closed release calculus for Meta Llama and Mistral OS releases.
with the GDPR (2018), Digital Services Act (2024), Digital Markets Act (2024), Data Act (2025), and the proposed AI-Liability Directive, the AI Act completes a four-pillar EU digital-sovereignty perimeter. Reinforces the broader thesis that the EU's primary geoeconomic instrument is regulatory rather than tariff or subsidy.
Innovation Package (January 2024), AI Continent Action Plan (April 2025), and AI Factories under EuroHPC. Regulation + subsidy together constitute the "Brussels Effect 2.0" playbook.
voluntarily vs litigate the systemic-risk designation?
application or "stop-the-clock" amendment, as some industry groups (DigitalEurope, CCIA) and Member States (FR, NL, DE) have requested through 2025–2026? Watch for Commission proposal text H1 2026.
(no horizontal law), the US Executive-Order rollback under Trump-2 (EO 14179 of January 2025 revoking Biden EO 14110), and the Korean AI Basic Act (effective 22 January 2026).
systemic-risk designations and first prohibited-practice enforcement cases will set the de-facto compliance bar.