Regulation overview

The EU AI Act, in plain English

The world's first comprehensive AI law. It applies to anyone placing AI on the EU market or whose AI affects people in the EU — regardless of where your company is based.

Five risk classifications

Prohibited

Social scoring, manipulative practices, untargeted face scraping. Banned outright.

High-risk

Hiring, credit scoring, critical infrastructure, education, law enforcement. Full conformity assessment required.

Limited risk

Chatbots, deepfakes, emotion recognition. Transparency obligations.

Minimal risk

Spam filters, AI in video games. Voluntary codes of conduct.

General-purpose AI

Foundation models. Documentation, copyright policy, and (above thresholds) systemic risk controls.

Key dates

Feb 2, 2025
Prohibited-AI bans take effect; AI literacy obligations apply.
Aug 2, 2025
GPAI obligations and governance rules begin.
Aug 2, 2026
Most provisions become enforceable across the EU.
Aug 2, 2027
High-risk systems regulated under product-safety law deadline.

Provider vs deployer

Provider

You develop or place an AI system on the market under your name or trademark. You carry the heaviest documentation and conformity duties.

Deployer

You use an AI system in a professional capacity. You owe transparency to affected people, human oversight, and use-case monitoring.

Ready to find out where you stand?

Run a free classification of your AI system in minutes.

Start your assessment