Skip to main content

StrategyWiz

🎉 NAKS Digital Consulting is now StrategyWiz Consulting • Same Team • Same Expertise • Same Commitment • Welcome to Our New Website 🎉 NAKS Digital Consulting is now StrategyWiz Consulting • Same Team • Same Expertise • Same Commitment • Welcome to Our New Website 🎉 NAKS Digital Consulting is now StrategyWiz Consulting • Same Team • Same Expertise • Same Commitment • Welcome to Our New Website
EU AI Act: Law Meets Intelligent Technology

EU AI Act: Understanding Regulation (EU) 2024/1689

The European Union Artificial Intelligence Act (EU AI Act) establishes a comprehensive, risk-based framework for the development, deployment and use of artificial intelligence. It aims to promote trustworthy and human-centric AI while protecting health, safety, fundamental rights and democratic values.
The EU AI Act, formally known as Regulation (EU) 2024/1689, is the European Union’s landmark legislation governing artificial intelligence. It establishes common rules for AI systems and assigns different obligations according to the level of risk an AI system presents.
The regulation applies not only to organisations based in the EU, but in certain circumstances also to organisations outside the EU whose AI systems or outputs are placed on or used in the EU market. This makes the regulation relevant to a wide range of global businesses developing, providing or deploying AI technologies.

What is the EU AI Act?

The EU AI Act takes a risk-based approach to AI regulation. Rather than applying identical requirements to every AI application, it categorises AI systems according to the potential risks they pose.
The framework broadly distinguishes between:
  • Prohibited or unacceptable-risk AI practices
  • High-risk AI systems
  • AI systems subject to transparency requirements
  • Minimal or limited-risk AI applications
This approach allows the EU to impose stricter requirements on AI applications that could significantly affect people’s safety or fundamental rights, while allowing lower-risk applications to operate with fewer regulatory requirements.

1. Prohibited AI Practices

The AI Act prohibits certain AI practices considered unacceptable because of their potential to cause serious harm or undermine fundamental rights.
These include certain uses involving:
  • Manipulative or deceptive techniques that materially distort people’s behaviour and may cause significant harm
  • Exploitation of vulnerabilities associated with factors such as age, disability or specific social or economic circumstances Certain forms of social scoring
  • Certain prohibited biometric categorisation and identification practices
  • Other AI applications that create unacceptable risks to people’s safety or fundamental rights
The regulation’s prohibited practices are set out primarily in Article 5.
The prohibition rules and AI literacy requirements have already applied since 2 February 2025.

2. High-Risk AI Systems

High-risk AI systems are subject to the most extensive compliance requirements under the Act.
These systems can include AI used in areas such as:
  • Employment and recruitment Education and vocational training
  • Critical infrastructure
  • Certain biometric applications
  • Access to essential services
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice and democratic processes
The classification depends on the specific AI system and how it is used; not every AI application within these sectors is automatically high-risk.
High-risk AI providers may need to address requirements including:
  • Risk management
  • Data and data governance
  • Technical documentation
  • Record-keeping and logging
  • Transparency and instructions for use
  • Human oversight
  • Accuracy, robustness and cybersecurity
  • Quality management
  • Post-market monitoring
  • Conformity assessment
Providers and deployers also have responsibilities around human oversight, monitoring and reporting of serious incidents.

Current implementation timeline

The original AI Act established a broader 2026 application date for many provisions. However, following the AI Omnibus, which entered into force on 27 July 2026, some high-risk requirements now have extended implementation dates.
The current timeline provides that:
  • High-risk systems in areas such as biometrics, critical infrastructure, education, employment, migration, asylum and border control are scheduled for application from 2 December 2027.
  • High-risk AI embedded in regulated products such as certain machinery, toys and lifts is scheduled for application from 2 August 2028.

3. Transparency Requirements

The AI Act also introduces transparency obligations for certain AI systems.
From 2 August 2026, applicable transparency requirements include measures designed to help people understand when they are interacting with AI and when certain content has been generated or manipulated by AI.
For example:

AI interaction

Certain AI systems that directly interact with people, such as chatbots and AI agents, must inform users that they are interacting with an AI system.

AI-generated content

Providers of applicable generative AI systems must implement mechanisms for machine-readable marking or detection of AI-generated or manipulated content.
Additional disclosure requirements can apply to certain deepfakes and AI-generated or manipulated content relating to matters of public interest.<>br< These requirements are intended to improve transparency and reduce the risk of deception and manipulation.

4. General-Purpose AI Models

The AI Act also establishes specific obligations for General-Purpose AI (GPAI) models.
These are AI models capable of performing a broad range of tasks and that may serve as the foundation for different AI applications.
Providers of GPAI models are subject to requirements relating to areas such as:
  • Technical documentation
  • Information sharing across the AI value chain
  • Copyright compliance Transparency
  • Model evaluation and risk management in applicable cases
Additional requirements apply to GPAI models that may pose systemic risks because of their capabilities or scale. These providers must take appropriate measures to identify, assess and mitigate systemic risks.
The GPAI obligations became applicable from 2 August 2025, with enforcement of the relevant obligations continuing from August 2026

5. AI Literacy

The AI Act recognises that responsible AI use is not only a technology issue but also an organisational responsibility.
Providers and deployers are expected to take measures to ensure an appropriate level of AI literacy among employees and other people operating or using AI systems on their behalf. This should take into account their technical knowledge, experience, education and training, as well as the context in which the AI system is used.
For businesses, this means AI governance should include appropriate awareness, training and responsible-use practices rather than focusing exclusively on technical controls.

6. Who Does the EU AI Act Apply To?

The regulation can apply to a broad range of organisations, including:
  • AI developers and providers
  • Businesses deploying AI systems
  • Importers and distributors
  • Public authorities
  • Organisations developing or using AI in the EU
  • Certain organisations established outside the EU
Importantly, being located outside the EU does not automatically place an organisation outside the scope of the Act. The regulation can apply where an AI system is placed on the EU market, put into service or used in the EU, and in certain circumstances where the output of an AI system is used in the EU.

7. What Does the EU AI Act Mean for Businesses?

For organisations developing or deploying AI, compliance begins with understanding what AI systems are being used, who is responsible for them and what risks they create.
Businesses should consider establishing an AI governance framework that includes:
AI inventory
Identify the AI tools, models and systems being developed, purchased or used across the organisation.
Risk classification
Determine whether each use case falls into a prohibited, high-risk, transparency-related or lower-risk category.
Governance and accountability
Define who is responsible for AI systems, their oversight and compliance.
Data and security controls
Ensure appropriate data governance, cybersecurity and risk-management measures are in place.
Human oversight
Ensure people can appropriately understand, monitor and intervene in AI-supported processes where required.
Transparency
Inform users when applicable AI transparency requirements apply.
AI literacy and training
Provide employees with appropriate training and guidance for responsible AI use.

8. Enforcement and Penalties

The EU AI Act provides for significant administrative penalties.
Violations of the prohibited AI practices can result in fines of up to €35 million or 7% of a company’s total worldwide annual turnover for the preceding financial year, whichever is higher. Other categories of non-compliance can result in fines of up to €15 million or 3% of worldwide annual turnover, while providing incorrect, incomplete or misleading information to authorities can result in fines of up to €7.5 million or 1% of worldwide annual turnover.
The regulation also provides for proportional treatment of SMEs, including start-ups, in determining applicable fines.

9. A Phased Approach to AI Regulation

The EU AI Act is being implemented progressively rather than through a single compliance deadline.
Key milestones include:
DateKey development
1 August 2024AI Act entered into force
2 February 2025Prohibited AI practices and AI literacy provisions began applying
2 August 2025GPAI obligations and governance provisions began applying
2 August 2026Main AI Act application date and applicable transparency requirements
2 December 2027Current scheduled application date for certain high-risk AI systems
2 August 2028Current scheduled application date for certain high-risk AI systems embedded in regulated products
The implementation schedule has evolved following the 2026 AI Omnibus, so organisations should monitor official EU guidance and subsequent legislative updates rather than relying on older AI Act timelines.

Building Trustworthy AI

The EU AI Act represents a shift toward risk-based AI governance, where organisations are expected to understand the systems they develop or use and manage the risks associated with them.
For businesses, compliance is not simply about restricting AI adoption. It is about creating the governance, transparency, security and accountability needed to use AI responsibly while continuing to benefit from its capabilities.
Organisations that begin by establishing an inventory of AI use cases, assessing their risk levels, implementing appropriate controls and building AI literacy across their workforce will be better positioned to adapt to the evolving regulatory landscape.
The EU AI Act therefore represents both a compliance requirement and an opportunity for organisations to build more trustworthy, transparent and resilient AI practices.

Official source

The complete regulation is available through EUR-Lex – Regulation (EU) 2024/1689
For current implementation guidance, the European Commission’s AI Act policy page is also a useful reference.

Please fill the form