Skip to main content
Category: EU AI Act & GPAI

EU AI Act

Also known as: AI Act, Artificial Intelligence Act, EU Artificial Intelligence Act
Simply put

The EU AI Act is a European Union law that sets rules for how artificial intelligence systems can be developed and used, sorting them into different categories based on how much risk they pose. It aims to encourage innovation while protecting people's health, safety, and fundamental rights. It is often described as the first comprehensive AI regulation from a major regulator.

Formal definition

The EU AI Act is a regulation of the European Union that establishes a common regulatory and legal framework for AI systems within the EU, adopting a risk-based approach that classifies AI systems by risk level and attaches corresponding obligations to how organizations develop and deploy them. According to the evidence, the regulation entered into force on 1 August 2024; specific phased application dates and detailed obligations are not fully specified in the evidence provided and should be verified against the official text. As an EU regulation it is binding law within the EU's jurisdiction and should not be treated as interchangeable with voluntary standards (such as ISO/IEC 42001), non-binding frameworks (such as the NIST AI Risk Management Framework), or supervisory guidance regimes (such as SR 11-7) that address model risk in other contexts. The Act's scope centers on AI system definition, risk classification, and provider/deployer obligations; the precise thresholds, tiers, and enforcement mechanics are out of scope for this core definition and are governed by the regulation's operative provisions.

Why it matters

The EU AI Act is significant because it is commonly described as the first comprehensive AI regulation from a major regulator, establishing a common regulatory and legal framework for AI systems within the European Union. As binding law within the EU's jurisdiction, it carries a different weight than voluntary standards or non-binding frameworks: organizations that develop or deploy AI systems touching the EU market face legal obligations rather than optional best practices. This distinction matters for compliance planning, because the Act cannot be treated as interchangeable with instruments such as ISO/IEC 42001, the NIST AI Risk Management Framework, or supervisory guidance regimes like SR 11-7 that address model risk in other contexts.

The Act's risk-based structure — classifying AI systems by risk level and attaching corresponding obligations — means that the same organizational AI governance program may face materially different requirements depending on how a given system is categorized. For compliance officers and legal professionals, this creates a need to map internal AI inventories against the regulation's classification scheme before assuming a uniform control set will suffice. Because the regulation entered into force on 1 August 2024, organizations within its scope have a defined starting point for legal effect, though the specific phased application dates and detailed obligations are not fully specified in the evidence provided here and should be verified against the official text.

It is worth stressing what the Act does and does not do. It sets rules intended to promote innovation while protecting health, safety, and fundamental rights, but adherence to its obligations reduces and manages regulatory and rights-related risk rather than eliminating it. Professionals should also avoid over-reading the core framework: the precise thresholds, tiers, and enforcement mechanics are governed by the regulation's operative provisions and are out of scope for a high-level definition.

Who it's relevant to

Compliance officers and legal professionals
Those responsible for regulatory adherence need to understand the Act as binding EU law rather than optional guidance, and to map their organization's AI systems against its risk-based classification. Because detailed obligations and application dates are not fully captured in this summary, they should confirm specifics against the official text before committing to a compliance posture.
AI governance and policy specialists
Professionals designing organizational structures, policies, and oversight for AI systems will find the Act relevant as a regulatory anchor that shapes governance programs for entities within its jurisdiction. They should treat it as distinct from voluntary frameworks such as ISO/IEC 42001 or the NIST AI Risk Management Framework, integrating the Act's binding obligations without collapsing the difference between law and voluntary standards.
Providers and deployers of AI systems
Organizations that develop AI systems (providers) and those that put them into use (deployers) face obligations that differ according to their role and the risk classification of the system. Determining which category an organization falls into for a given system is a prerequisite to identifying the applicable requirements under the Act's operative provisions.
Model risk managers and auditors
While the Act addresses AI governance obligations rather than functioning as a model risk management guidance regime, professionals in these roles benefit from recognizing where AI governance requirements intersect with existing model risk controls. The Act should not be treated as interchangeable with supervisory guidance such as SR 11-7, which addresses model risk in other contexts, though both may apply to overlapping systems within an organization.

Inside AI Act

Risk-based tiering
The EU AI Act, adopted by the European Union, is commonly described as taking a risk-based approach that categorizes AI systems into tiers such as prohibited practices, high-risk systems, and lower-risk systems subject to lighter obligations. Obligations scale with the assigned risk category rather than applying uniformly to all AI systems.
Prohibited practices
The Act sets out certain AI uses that are banned outright. These represent uses considered to pose unacceptable risk under the framework, and are distinct from high-risk uses, which are permitted subject to conditions rather than forbidden.
High-risk system obligations
For systems classified as high-risk, the Act typically imposes obligations that may include risk management processes, data governance, technical documentation, human oversight, and accuracy and robustness measures. The specific obligations attach to the high-risk classification and are more demanding than those for lower-risk systems.
Transparency obligations
Certain systems are subject to transparency-related duties, such as informing individuals that they are interacting with or affected by an AI system in defined circumstances. These obligations can apply independently of, or in addition to, high-risk classification.
Governance and enforcement structure
The Act contemplates oversight and enforcement mechanisms at the EU and member-state level. As a legal instrument of the European Union, it establishes obligations on providers and deployers of AI systems within its jurisdictional scope rather than functioning as voluntary guidance.

Common questions

Answers to the questions practitioners most commonly ask about AI Act.

Does the EU AI Act apply globally, like a universal standard for AI?
No. The EU AI Act is legislation issued by the European Union and is scoped to its own jurisdictional reach, not a universal or worldwide standard. As commonly understood, it can affect providers and deployers outside the EU where their AI systems are placed on the EU market or their outputs are used within the EU, but this extraterritorial effect is not the same as the Act governing all AI everywhere. It should not be treated as interchangeable with voluntary frameworks such as the NIST AI Risk Management Framework or ISO/IEC 42001, or with sector-specific supervisory guidance.
Is the EU AI Act the same kind of instrument as the NIST AI RMF or ISO/IEC 42001?
No, these should not be conflated. The EU AI Act is EU legislation, whereas the NIST AI Risk Management Framework is a voluntary framework and ISO/IEC 42001 is a voluntary management-system standard. They differ in their issuing bodies and in their nature. Organizations sometimes use voluntary frameworks and standards to help structure compliance efforts, but adopting them does not by itself demonstrate conformity with the Act, and the Act's obligations are distinct from those instruments.
How does an organization determine which obligations under the Act apply to a given AI system?
In the Act's design, obligations are typically tied to how a system is categorized and to the role the organization plays, such as provider or deployer. Determining applicable obligations generally begins with assessing the system's use and risk categorization and confirming whether the organization's activities and market reach fall within scope. Because categorization drives obligations, this classification step is usually treated as foundational. Organizations should confirm specific classification criteria and role definitions against the current legal text and any official guidance rather than relying on general summaries.
How does compliance with the EU AI Act relate to existing model risk management practices?
AI governance and model risk management remain distinct even where they support Act compliance. Model risk management—the identification, measurement, monitoring, and control of risks arising from model use—can supply tools such as validation, monitoring, and documentation that help address certain expectations. AI governance provides the organizational structures, policies, and accountability for oversight. Neither substitutes for confirming the Act's specific legal requirements, and existing practices may need to be mapped to, and supplemented for, those requirements rather than assumed to satisfy them.
What kinds of documentation and oversight are commonly associated with preparing for the Act?
In many governance approaches, preparation involves documentation of system purpose and use, records supporting risk assessment, and defined accountability for oversight across roles. These measures are intended to help manage and reduce risk and to support demonstrable compliance; they do not eliminate risk. The precise documentation and oversight obligations depend on how a system is classified and the organization's role, so specifics should be confirmed against the current legal text and official guidance rather than generalized checklists.
How should organizations approach timing and phased applicability when implementing the Act?
Legislation of this kind is often applied in phases, with different provisions becoming applicable at different times. Because effective dates and transitional arrangements determine when specific obligations take effect, organizations should verify the current, official timelines rather than assume all requirements apply at once. Treating proposed or not-yet-applicable provisions as already binding, or assuming an implementation is final before verifying applicable dates, are common errors to avoid.

Common misconceptions

The EU AI Act is interchangeable with the NIST AI Risk Management Framework or ISO/IEC 42001.
The EU AI Act is a legal instrument of the European Union with binding force within its jurisdiction, whereas the NIST AI RMF is a voluntary framework issued by a U.S. body and ISO/IEC 42001 is a voluntary international standard. They are not equivalent, not issued by the same body, and cannot be substituted for one another for compliance purposes.
The EU AI Act applies universally to all AI systems in the same way.
The Act uses a risk-based tiering approach, so obligations differ substantially by risk category, and its application is scoped to its jurisdiction and to defined roles such as providers and deployers. It does not impose a single uniform set of requirements on every AI system everywhere.
The EU AI Act is the same thing as model risk management or governs banking models under SR 11-7-style expectations.
The EU AI Act is an AI governance and regulatory instrument focused on obligations for AI systems within the EU, and is distinct from model risk management as historically framed by supervisory guidance such as SR 11-7 in the U.S. banking context. The two may overlap where an AI system is also a model subject to risk management, but they are separate frameworks with different origins and scope.

Best practices

Determine whether your organization's role falls within the Act's jurisdictional scope and identify whether you act as a provider, deployer, or another defined role, since obligations differ by role.
Classify each AI system against the Act's risk tiers before assuming obligations, distinguishing prohibited, high-risk, and lower-risk categories rather than applying a single control set to all systems.
For systems classified as high-risk, map the applicable obligations such as risk management, data governance, documentation, human oversight, and robustness measures to concrete internal controls.
Treat EU AI Act compliance as distinct from voluntary frameworks like the NIST AI RMF or ISO/IEC 42001, using those frameworks as complementary tools rather than substitutes for legal obligations.
Where an AI system also functions as a model subject to model risk management, coordinate governance and model risk workstreams while keeping the distinct requirements of each framework clearly documented.
Track evolving regulatory treatment and defer to authoritative legal texts and qualified counsel for specific clause references, effective dates, and scope, rather than relying on generalized summaries.