What it is
The EU AI Act — Regulation (EU) 2024/1689, in force since 1 August 2024 — is
the world's first horizontal AI law. It classifies AI systems by risk level and imposes
obligations proportionate to that level, with phased application running through 2026 and 2027.
Risk-based classification
- Prohibited. Social scoring by public authorities, certain biometric-categorisation
uses, manipulative or predatory-vulnerability AI.
- High-risk. AI used in critical infrastructure, education, employment, access to
essential services (including credit-scoring), law enforcement, migration and others.
Annex III explicitly lists fraud detection in financial services as high-risk.
- Limited-risk. Subject to transparency obligations (e.g. chatbots, deepfakes).
- Minimal-risk. No specific obligations.
Obligations for high-risk systems
- Risk-management system for the AI system's lifecycle.
- Data governance and quality requirements on training, validation and testing data.
- Technical documentation and logging.
- Transparency and provision of information to users
(Article 13).
- Human oversight (Article 14) — design requirements that allow a human to monitor,
intervene and override.
- Accuracy, robustness and cybersecurity.