EU AI Act
Definition
EU AI Act
The EU AI Act is the world’s first horizontal law on artificial intelligence, which entered into force on 1 August 2024. It classifies AI systems by risk and imposes duties on providers, deployers, and importers that place AI on the European Union market.
The regulation, formally Regulation (EU) 2024/1689, applies extraterritorially. A vendor based in Manila, Bangalore, or Austin falls under it once its model, output, or hiring tool touches an EU user. Fines reach 7% of global turnover for banned use.
Compliance rolls out in stages. Prohibited practices bit on 2 February 2025, general-purpose AI rules on 2 August 2025, and high-risk obligations by 2 December 2027. Buyers, BPO vendors, and integrators share the paperwork. Missing a stage shifts liability.
Enforcement lands with the European AI Office plus national market surveillance authorities. The regulation sits alongside GDPR, the Data Act, and the Digital Services Act — a stack that now governs nearly every digital product sold into the EU bloc.
Key takeaways
- Applies to any AI system placed on the EU market, no matter where the vendor sits.
- Uses four risk tiers: unacceptable, high, limited/transparency, and minimal.
- Full high-risk obligations bind by 2 December 2027; prohibited uses already do.
- General-purpose AI providers file Article 53 documentation, including training-data summaries.
- Penalties reach €35 million or 7% of global turnover for banned practices.
How it works
The EU AI Act works by sorting every AI system into a risk tier, then attaching duties that scale with the tier. Higher risk means heavier documentation, testing, human oversight, and post-market monitoring; low risk stays lightly touched.
Providers self-assess against Annex III categories, register high-risk systems in the EU database, and keep technical files for ten years post-market. Deployers add risk management logs, human review, and worker-notification duties before rollout.
| Risk tier | Examples | Core duty |
|---|---|---|
| Unacceptable | Social scoring, predictive policing, workplace emotion recognition | Banned outright |
| High | CV screening, credit scoring, medical triage | Conformity assessment + registration |
| Limited (transparency) | Chatbot, deepfake, generative AI output | Disclosure and labelling |
| Minimal | Spam filters, AI in games | No specific rules |
General-purpose AI models sit under a separate Article 53 track. Providers publish training-data summaries, respect EU copyright opt-outs, and if the model exceeds 10^25 FLOPs of training compute, file systemic-risk assessments with the AI Office.
Documentation forms the spine. High-risk providers write a technical file, data governance plan, human oversight description, and cybersecurity assessment before CE marking. Authorities can demand the full stack within 30 days, so paperwork sits ready at all times.
Sandboxes offer a supervised runway. Every EU member state must run an AI regulatory sandbox by 2 August 2026, where small firms can test high-risk systems under supervision before full pre-market conformity assessment kicks in.
Deployer-side duties bite hardest at operational rollout. Workers using an AI system for HR, credit, or medical decisions must be told. Affected individuals get the right to a human review and an explanation before an adverse decision lands.
Examples
Real cases already show how the EU AI Act reshapes vendor decisions. Firms have paused product launches, redesigned features, and rewritten supplier contracts to fit the risk tiers before the December 2027 hard deadline for high-risk systems.
Apple delayed the EU launch of Apple Intelligence in June 2024 over AI Act obligations. Meta followed for its multimodal Llama models later that year, holding release outside the bloc. Both moves signalled how big-tech reads risk-tier ambiguity.
OpenAI committed to the EU General-Purpose AI Code of Practice in July 2025, publishing model documentation and copyright summaries under Article 53. Anthropic and Google DeepMind signed shortly after, marking the first coordinated industry move.
On the enforcement side, the European AI Office — housed within DG CNECT — became operational in February 2025 and now co-supervises GPAI models.
Spain’s AESIA took the lead among national supervisors, handling sandbox admission and post-market incident reports inside its borders.
The Council of Europe’s AI Convention, opened for signature in September 2024, parallels the EU AI Act on rights-based provisions. Signatories include the US, UK, Israel, and the EU — a signal that AI Act principles are becoming the global baseline.
Related terms
The EU AI Act sits inside a larger cluster of AI governance and outsourcing terms. Buyers reading this page usually also want the vocabulary sitting one layer up, one layer down, and beside it in the risk stack.
- Artificial Intelligence: the parent field the act regulates end-to-end.
- Machine Learning: the technique behind most high-risk systems the act covers.
- Generative AI: the general-purpose branch with its own Article 53 rules.
- Compliance: the operational function that owns AI Act filings inside a firm.
- Risk Management: the framework used to grade AI systems against the four tiers.
- Quality Assurance: the review layer that tests high-risk models before deployment.
FAQ
When did the EU AI Act take effect?
The AI Act entered into force on 1 August 2024. Its obligations phase in through 2027, with prohibited practices already binding since 2 February 2025 and general-purpose AI rules since 2 August 2025. Transparency duties join in August 2026.
Does the EU AI Act apply to companies outside Europe?
Yes. Any provider or deployer whose AI system’s output is used inside the EU falls within scope, no matter where the company sits. A Philippine BPO serving an EU client must still comply, and importers share the paperwork burden.
What counts as a high-risk AI system?
High-risk systems appear in Annex III and cover hiring, credit scoring, education grading, medical triage, and critical infrastructure. Each triggers conformity assessment, registration, and human oversight. Deployers log inference results for post-market audits.
How large are the penalties?
Fines reach €35 million or 7% of global annual turnover for prohibited practices, whichever is higher. Other breaches sit at €15 million or 3%, and misleading regulators carries €7.5 million or 1% of turnover.
How should outsourcing buyers respond?
Buyers should inventory every AI-touching supplier, request Annex III risk classification and any conformity assessment paperwork, and update MSAs with an AI Act warranty clause. Most BPO contracts signed pre-2024 do not carry it. Contract renewals help fold it in.
Do open-source models get an exemption?
Free and open-source models are largely exempt unless they qualify as general-purpose AI with systemic risk, in which case Article 53 still applies.
Want a neutral read on which outsourcing partners already operate AI Act-ready processes? Start with the Outsource Accelerator platform.







Independent




