Breaking Down the EU’s AI Act

Breaking Down the EU’s AI Act: The First Regulation on AI

Ronan Grobler

Head of GRC

Linkedin

TL;DR: EU AI Act

  • The EU AI Act is the world’s first comprehensive AI regulation, introducing a risk-based framework for governing artificial intelligence.
  • AI systems are classified into four risk categories, with stricter compliance requirements applying to higher-risk applications.
  • Organizations must understand key obligations, compliance deadlines, and potential penalties to prepare for the Act’s phased rollout.
  • Frameworks such as ISO 42001 and the NIST AI Risk Management Framework help organizations build responsible AI governance programs.
  • AI GRC platforms like Scytale simplify EU AI Act compliance with automation, continuous monitoring, and multi-framework support.

Artificial intelligence is rapidly transforming the way organizations operate, making it essential to balance innovation with transparency, accountability, and responsible use. As AI adoption continues to grow, regulators are introducing new requirements to help ensure these systems are developed and used safely. 

In this article, we’ll explore what the EU AI Act is, who it applies to, how it classifies AI systems, key compliance requirements, and what organizations need to do to prepare.

The EU AI Act is the world’s first comprehensive legal framework for regulating artificial intelligence, using a risk-based approach to promote the safe, transparent, and responsible use of AI across the European Union. 

Categorizing AI Systems: The EU’s Risk-Based Approach

The EU AI Act classifies AI systems according to the level of risk they pose to people’s rights, safety, and well-being. As the level of risk increases, so do the compliance requirements, with higher-risk systems subject to stricter obligations and oversight. Here are the four EU AI Act risk categories:

Minimal risk

Minimal-risk AI systems pose little or no risk and are not subject to mandatory compliance requirements under the EU AI Act. Common examples include spam filters, AI-powered video games, and recommendation engines, although organizations are encouraged to follow voluntary best practices for responsible AI use.

Limited risk

Limited-risk AI systems are subject to transparency requirements to ensure users understand when they are interacting with AI or viewing AI-generated content. Examples include chatbots, AI assistants, and deepfakes, where users must be clearly informed that AI is being used.

High risk

High-risk AI systems are used in areas where AI decisions could significantly affect people’s rights, safety, or access to essential services, such as healthcare, education, employment, transportation, and critical infrastructure. These systems must meet strict requirements, including risk management, high-quality data governance, technical documentation, human oversight, and continuous monitoring before they can be placed on the EU market.

Unacceptable risk

AI systems classified as posing an unacceptable risk are prohibited under the EU AI Act because they threaten people’s rights or safety. Examples include government social scoring systems and certain forms of real-time biometric surveillance and emotion recognition, which are banned except in very limited circumstances defined by the regulation.

EU AI Act risk categories overview 

Risk levelTypical examplesWhat it means
MinimalSpam filters, recommendation enginesNo mandatory compliance requirements.
LimitedChatbots, AI assistants, deepfakesTransparency obligations apply.
HighHealthcare, HR, education, transportationStrict compliance requirements and ongoing oversight.
UnacceptableGovernment social scoring, certain biometric surveillanceProhibited under the EU AI Act.
Overview of the EU AI Act risk categories

Streamline GRC workflows with seamless automation.

Scytale G2 badge

EU AI Act requirements for trustworthy AI 

The EU AI Act establishes requirements for organizations developing and deploying AI systems to help ensure AI is safe, transparent, and used responsibly. Its core requirements include: 

1. Ensure safety and fairness

High-risk AI systems must undergo risk management processes and use high-quality data to help reduce bias and improve reliability. Organizations are also required to continuously monitor these systems to ensure they remain safe and effective throughout their lifecycle.

2. Promote transparency and human oversight

Organizations must clearly inform users when they are interacting with AI or viewing AI-generated content where required. High-risk AI systems must also include appropriate human oversight to ensure important decisions can be reviewed and, where necessary, overridden.

3. Support responsible innovation

The EU AI Act encourages innovation by introducing regulatory sandboxes where organizations can develop and test AI systems in a controlled environment. This allows businesses to innovate responsibly while meeting regulatory requirements and building trust in their AI systems.

The impact of the EU AI Act on AI innovation 

The EU AI Act aims to promote responsible AI innovation while protecting people from the risks of artificial intelligence. Here are some of the key ways the regulation is shaping the future of AI

Concerns about innovation

Some organizations are concerned that additional compliance requirements could increase development costs, slow product launches, and make it harder for companies to innovate. Others argue that stricter regulation could place European businesses at a competitive disadvantage compared to regions with less restrictive AI policies.

Building trustworthy AI

The EU believes that clear rules will increase confidence in AI and encourage wider adoption across industries. By requiring risk management, transparency, human oversight, and accountability, the Act aims to help organizations identify potential risks early while building more trustworthy AI systems.

The future of AI regulation

The EU AI Act establishes a foundation for AI governance, but it is unlikely to be the final word on AI regulation. As AI technologies continue to evolve, organizations should expect additional guidance and updates, making continuous AI governance, cybersecurity, and compliance increasingly important for long-term success.

EU AI Act timeline: Key compliance deadlines

The EU AI Act is being introduced in phases, with different requirements taking effect over several years. Understanding these milestones helps organizations prepare for upcoming obligations, maintain continuous compliance, and prioritize their compliance efforts. Below are the key dates to know. 

DateMilestone
August 1, 2024The EU AI Act enters into force.
February 2, 2025Rules prohibiting unacceptable-risk AI systems become enforceable.
August 2, 2025Obligations for general-purpose AI (GPAI) models begin to apply.
August 2, 2026Most requirements for high-risk AI systems become enforceable.
August 2, 2027Additional requirements apply to certain AI systems regulated under Annex II legislation, such as medical devices.
EU AI Act timeline

EU AI Act penalties and fines

Organizations that fail to comply with the EU AI Act can face substantial fines depending on the severity of the violation. The highest penalties, for prohibited AI practices, can reach €35 million or 7% of global annual turnover, whichever is higher. Violations of governance, transparency, or technical documentation requirements can result in fines of up to €15 million or 3% of global annual turnover. Providing incorrect or misleading information to regulators may lead to penalties of up to €7.5 million or 1% of global annual turnover. 

Beyond financial penalties, non-compliance can damage customer trust, delay market entry, and increase regulatory scrutiny. Establishing a strong AI compliance program early helps organizations reduce risk, maintain compliance, and prepare for future regulatory changes.

Simplify EU AI Act compliance with Scytale

Scytale helps organizations prepare for the EU AI Act with an AI GRC platform that simplifies AI compliance. AI-powered automation streamlines evidence collection, continuous monitoring, risk assessments, and multi-framework compliance across standards such as SOC 2, ISO 27001, GDPR, HIPAA, and SOX ITGC.

The platform reduces duplicate work with built-in cross-mapping, while dedicated GRC experts provide practical support as AI regulations evolve. This helps organizations simplify audits, respond to new requirements faster, and stay continuously compliant.

FAQs about EU AI Act

  1. What is the EU AI Act?

    The EU AI Act is the world’s first comprehensive legal framework for regulating artificial intelligence. It uses a risk-based approach to classify AI systems and establishes requirements to promote the safe, transparent, and responsible use of AI across the European Union.

  2. When did the EU AI Act come into force?

    The EU AI Act entered into force on August 1, 2024, with its requirements being introduced in phases over several years. Different obligations apply from 2025 through 2027, giving organizations time to prepare for compliance based on the type of AI systems they develop or use.

  3. Does the EU AI Act apply to the UK?

    The EU AI Act does not apply directly to organizations operating only in the UK. However, UK businesses that place AI systems on the EU market or whose AI outputs are used within the EU must comply with the Act’s requirements.

  4. How much are the fines under the EU AI Act?

    The highest fines under the EU AI Act are up to €35 million or 7% of global annual turnover, whichever is higher. Companies can also face lower penalties for breaches of governance, transparency, or documentation requirements, making ongoing compliance and AI governance essential. Scytale’s AI GRC platform helps organizations simplify these requirements through continuous monitoring, automated evidence collection, and AI-powered compliance management.

  5. What is the EU AI Act compliance timeline?

    The EU AI Act compliance timeline is being introduced in stages between 2024 and 2027, with different obligations taking effect at different times. Key milestones include the enforcement of prohibited AI practices in 2025, high-risk AI system requirements in 2026, and additional obligations for certain regulated products in 2027.

  6. Who does the EU AI Act apply to?

    The EU AI Act applies to providers, deployers, importers, and distributors of AI systems that are placed on the EU market or whose outputs are used within the EU. This includes organizations both inside and outside the European Union, making it important for global businesses to understand their obligations. Scytale helps companies manage EU AI Act requirements alongside frameworks such as SOC 2, ISO 27001, GDPR, and SOX ITGC through a single AI GRC platform.

Ronan Grobler

Ronan Grobler

As Head of GRC at Scytale, Ronan Grobler leads a team of experts helping companies meet top security and privacy standards like ISO 27001, ISO 9001, ISO 42001, SOC 1, SOC 2, GDPR, HIPAA, CCPA, and DORA. With over four years of experience in governance, risk, and compliance, Ronan has supported businesses of all sizes - from fast-growing... Read more