The EU AI Act: Europe's Risk-Tiered AI Law

The EU AI Act is the world's first comprehensive AI law, published in the EU Official Journal on 12 July 2024 and entering into force 1 August 2024, with obligations phasing in through August 2027.

Created 2026-09-19 Last reviewed 2026-09-19

What it is

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the European Union’s binding legal framework for AI, and the first comprehensive AI-specific law adopted by a major regulatory power. It does not regulate AI as a single category. Instead it sorts AI systems into four risk tiers — unacceptable, high, limited, and minimal — and attaches different obligations to each. Systems judged an “unacceptable risk,” such as social-scoring systems and certain manipulative or exploitative AI, are banned outright. High-risk systems — those used in contexts like hiring, credit scoring, law enforcement, healthcare, and education — must meet requirements before they can enter the market: documented risk management, human oversight, technical documentation, and in some cases third-party conformity assessment. Limited-risk systems, including most chatbots and AI-generated media, face lighter transparency duties, chiefly that users must be told they are interacting with AI or with synthetic content. Minimal-risk systems, such as spam filters or video-game AI, carry no mandatory obligations.

A separate track applies to “general-purpose AI” (GPAI) models — the large foundation models that underpin many downstream products. All GPAI providers face baseline transparency and copyright-related duties. Models that cross a systemic-risk threshold, set by the Act at a training-compute level of roughly 10^25 floating-point operations, face additional obligations: model evaluation, adversarial testing, and incident reporting to the European Commission’s AI Office. Providers can obtain a presumption of compliance with the matching obligations by signing the voluntary GPAI Code of Practice, which covers transparency and copyright for all providers and adds safety and security commitments for systemic-risk models.

The law was published in the EU’s Official Journal on 12 July 2024 and entered into force on 1 August 2024. Like most EU regulations, it does not take effect all at once. Prohibited-practice bans applied from 2 February 2025. Obligations on general-purpose AI models began applying 2 August 2025. The Commission’s enforcement and penalty powers over GPAI providers — including fines up to 3% of global annual turnover or €15 million, whichever is higher — became exercisable from 2 August 2026. The bulk of the remaining provisions, including most high-risk system obligations, become applicable 2 August 2026, with the most stringent high-risk requirements delayed until 2 August 2027 to give providers time to comply.

Why it matters for AI governance and narratives

The Act is frequently cited as evidence for competing framings of AI governance. In Brussels and among European civil-society and consumer-protection groups, it is presented as proof that binding, risk-tiered regulation is workable and that AI can be governed without halting innovation. In parts of the US tech press and among some industry voices, it is more often framed as a cautionary tale — a heavy compliance burden that could push AI development and deployment elsewhere, or as regulation written faster than the technology it targets, leaving gaps the market outpaces. Chinese coverage has at times used the Act’s gaps — such as behaviors that fall outside any defined regulatory category — to argue that rule-based frameworks lag practice, framing this as evidence for a taxonomy problem rather than an enforcement one. Because the Act is the most concrete, binding AI law any major jurisdiction has actually implemented, it functions as a reference point that every ecosystem — regulators, builders, capital, civil society — cites selectively to support its preferred narrative about whether AI governance is working, overreaching, or falling behind.

Key facts and dates

The European Commission’s AI Office, established to oversee GPAI compliance, and national market-surveillance authorities in each member state share enforcement responsibility, with GPAI enforcement centralized at the EU level and other provisions enforced nationally.

Where to learn more

Sources

Official European Commission service desk documenting the Act's legal entry-into-force and phased-applicability dates.
Hosts the full text of Regulation (EU) 2024/1689 with article-level navigation, the primary legal source.
Widely cited structured summary of the four-tier risk classification and GPAI obligations, maintained by the same project tracking official implementation.
Reputable international law firm analysis confirming the August 2025 GPAI obligations and August 2026 enforcement-power activation.
Referenced in: Editorial No. 329