The European Union Artificial Intelligence Act (AI Act) represents the world's first comprehensive legal framework for artificial intelligence. By establishing obligations proportional to the level of risk posed by an AI system, the EU aims to foster innovation while ensuring safety and fundamental rights.
Risk Categories Defined
The Act categorizes AI systems into four distinct risk levels, each bearing specific regulatory consequences:
1. Unacceptable Risk
Systems falling into this category are strictly prohibited. This includes:
- Cognitive behavioral manipulation of vulnerable groups or specific individuals (e.g., voice-activated toys encouraging dangerous behavior).
- Social scoring systems evaluating individuals based on social behavior or personal traits.
- Real-time biometric identification systems in publicly accessible spaces by law enforcement (with narrow exceptions).
- Biometric categorization systems inferring political opinions, religious beliefs, or sexual orientation.
2. High Risk
High-risk systems are permitted but subject to stringent compliance obligations before entering the market. These include systems used in:
- Critical infrastructure management (e.g., transport, water, gas).
- Educational or vocational training (e.g., scoring exams).
- Employment and worker management (e.g., CV sorting algorithms).
- Essential private and public services (e.g., credit scoring).
- Law enforcement, migration, and border control.
Obligations for High-Risk Providers: Establish a risk management system, ensure data governance, draft technical documentation, maintain automated record-keeping (logs), guarantee transparency, enable human oversight, and ensure robustness and cybersecurity.
3. Limited Risk
These systems (e.g., chatbots, deepfakes, emotion recognition systems) must comply with minimal transparency obligations. Users must be made aware they are interacting with an AI system unless it is obvious from the context.
4. Minimal or No Risk
The vast majority of AI systems (e.g., AI-enabled video games, spam filters) fall into this category. The AI Act imposes no mandatory obligations on these systems, though voluntary codes of conduct are encouraged.
General Purpose AI (GPAI) Models
The Act introduces specific rules for General Purpose AI models (e.g., large language models). All GPAI models must maintain technical documentation, comply with EU copyright law, and publish detailed summaries of training data. Models posing systemic risk (defined by computing power exceeding $10^{25}$ FLOPs) face additional obligations, including model evaluation, adversarial testing, and incident reporting.
Timeline and Implementation
The AI Act follows a phased implementation approach following its entry into force:
- 6 Months: Prohibitions on unacceptable risk systems take effect.
- 12 Months: Rules for General Purpose AI models apply.
- 24 Months: Obligations for high-risk systems under Annex III become applicable.
- 36 Months: Obligations for high-risk systems requiring external conformity assessments apply.
Penalties for Non-Compliance
Fines under the AI Act are severe, scaling with the size of the offending company:
- Prohibited Practices: Up to €35 million or 7% of global annual turnover.
- High-Risk Obligations: Up to €15 million or 3% of global annual turnover.
- Incorrect Information Supplied: Up to €7.5 million or 1.5% of global annual turnover.
For SMEs and start-ups, the fines are subject to the lower of the two amounts.
Next Steps for Enterprises
Organizations must immediately audit their AI portfolios to map existing systems against the new risk categories. Delaying compliance efforts until the implementation deadlines will likely result in strategic bottlenecks and potential enforcement action.