What is AI Act?

The AI Act is the EU regulation that sets rules for the responsible development, deployment, and use of artificial intelligence systems.

Ce este AI Act regulament UE inteligență artificială

Table of content

For organizations asking what is AI Act, the regulation establishes a legal framework for the responsible development and use of artificial intelligence in the European Union.

The AI Act is the world’s first comprehensive legal framework dedicated to the regulation of artificial intelligence.

Adopted by the European Union in 2024 under the official name Regulation (EU) 2024/1689, it establishes harmonized rules for the development, use, and commercialization of artificial intelligence systems across the European market.

Its main objective is to promote an ecosystem of safe, ethical, and human-centric AI, based on respect for fundamental rights and a risk-based approach.

The regulation entered into force on 1 August 2024, and its requirements apply progressively, with deadlines extending until 2030.

Why Was the AI Act Created?

The European Union recognized that the rapid development of AI systems, combined with the growing use of advanced models, can create significant risks for safety, security, and fundamental rights. Key challenges include:

  • lack of transparency in AI-generated decisions;
  • potential discrimination in automated systems;
  • abusive or dangerous uses of advanced technologies;
  • vulnerabilities affecting critical services or essential infrastructure.

For this reason, the AI Act sets clear obligations for providers and users of AI systems, depending on the level of risk presented by each application. This unified approach supports public trust and the responsible adoption of artificial intelligence in Europe.

Who Does the AI Act Apply To?

The regulation has a very broad scope, covering both EU-based organizations and organizations outside the Union, where their AI systems affect users or individuals located in the EU. Under the regulation:

  • all entities that develop, place on the market, or use AI systems in the EU may fall within scope;
  • obligations vary depending on the role: provider, deployer, importer, distributor, or user;
  • the rules apply to both private companies and public institutions;
  • AI systems developed outside the Union must comply with the AI Act if they are used in the EU.

The AI Act also covers General Purpose AI models, including large language models and generative AI models, especially where they are considered to present “systemic risk”.

Four Risk Levels Under the AI Act

To understand what is AI Act, it is important to know that the regulation classifies AI models and applications based on the level of risk they may create for individuals or society. This classification determines the applicable requirements and obligations.

1. Unacceptable Risk – Prohibited Systems

AI systems that pose a threat to fundamental rights are prohibited, including:

  • governmental social scoring systems;
  • systems that exploit children’s vulnerabilities;
  • emotion recognition systems in schools or workplaces;
  • abusive forms of biometric surveillance.

2. High Risk – Strict Regulation

These systems may significantly affect people’s lives, for example in healthcare, employment, justice, education, or access to public services.
Obligations include:

  • detailed technical documentation;
  • conformity assessments;
  • transparency and accuracy;
  • appropriate human oversight.

3. Limited Risk – Transparency Requirements

This category includes systems that interact directly with users, such as chatbots or generative AI systems that can produce content. In such cases, users must be informed about the artificial nature of the system or content.

4. Minimal Risk – No Additional Obligations

Many AI applications fall into this category, such as spam filters or AI-enabled video games, and may be used freely without additional regulatory requirements.

What Obligations Does the AI Act Impose?

To better understand what AI Act means for organizations, the regulation establishes different obligations depending on the type of AI system and its level of risk.

Depending on the type of AI system and the organization’s role, companies may need to comply with requirements such as:

  • risk management and implementation of technical and organizational measures;
  • internal data governance, including the quality of training data;
  • documentation and records for audit purposes;
  • transparency toward users and authorities;
  • human oversight and the possibility of human intervention;
  • continuous monitoring of system performance;
  • reporting serious incidents related to AI use.

Entities that develop or deploy advanced generative models may have additional obligations related to security, usage limitations, and dataset documentation.

What Sanctions Does the AI Act Provide?

The regulation introduces one of the strictest sanctions regimes in European legislation. Fines may reach:

  • 7% of global annual turnover; or
  • up to EUR 35 million,
    depending on the category of infringement.

Sanctions depend on the seriousness of the infringement. The highest fines apply to the use of prohibited AI systems or failure to comply with requirements for models presenting systemic risk.

How Does the AI Act Affect Organizations?

The adoption of the AI Act has significant implications for both the public and private sectors:

  • the need to assess all AI systems in use;
  • adaptation of procurement and development processes;
  • introduction of governance and internal control mechanisms;
  • investment in documentation, audits, and risk management;
  • management accountability for the responsible use of AI.

The regulation positions Europe as a pioneer in AI regulation and sets international standards that may influence legislation in other regions.

The AI Act represents a decisive step toward the responsible integration of artificial intelligence into society. It creates a balance between innovation and the protection of individuals, establishing a clear framework for the safe and transparent adoption of AI technologies.

Organizations must adapt their processes, identify risks, and implement appropriate measures to comply with the new requirements.

By complying with the AI Act, organizations can contribute to building a trustworthy digital ecosystem capable of using the potential of artificial intelligence in an ethical and secure way.

For companies analyzing what is AI Act and how it affects their activity, the regulation introduces clear obligations regarding risk management and transparency for AI systems.

After understanding what is AI Act, companies should assess their AI systems, roles, risks, and internal governance processes.

If your organization uses artificial intelligence systems and needs to comply with the new European regulations, explore our AI governance and EU AI Act compliance services.

Related posts

  • NIS2 vs Cyber Resilience Act

    NIS2 vs Cyber Resilience Act explains the key differences between EU cybersecurity rules for organizations…

    View post
    nis2 vs cyber resilience act diferențe NIS2 vs Cyber Resilience Act
  • What is Data Act

    The Data Act sets EU rules for access, sharing, and use of data generated by…

    View post
    Ce este Data Act regulament UE acces date conformitate ai act
  • What is NIS2

    NIS2 is the EU cybersecurity directive that introduces mandatory risk management, incident reporting, and governance…

    View post
    What is NIS2