Comprehensive Resource

The Complete EU AI Act Guide

A practical, plain-language guide to the world's first comprehensive AI regulation. Understand what the EU AI Act means for your organisation, your AI systems, and your compliance obligations.

100+ Pages of Law
4 Risk Levels
27 EU States
€35M Max Fine

What is the EU AI Act? The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world's first horizontal, legally binding regulation on artificial intelligence. It establishes a risk-based approach to regulating AI systems across the European Union.

AI Act Basics & Key Concepts

The EU AI Act is built on a simple but powerful idea: the stricter the risk an AI system poses to people's rights and safety, the stricter the rules. This is called a "risk-based approach." Instead of treating all AI the same, the law sorts AI systems into categories based on how much harm they could cause.

Why Was the AI Act Created?

The European Union recognised that AI technology was spreading rapidly across every industry, but without consistent rules to protect people. The goals of the AI Act are:

  • Protect fundamental rights like privacy, non-discrimination, and freedom of expression
  • Ensure AI systems used in the EU are safe and trustworthy
  • Create legal certainty for companies developing or using AI
  • Support innovation while preventing harm
  • Set a global standard for AI governance (the "Brussels Effect")

Core Principles of the AI Act

Risk-Based Approach

AI systems are classified by risk level. Higher risk means stricter compliance requirements, more documentation, and stronger oversight.

Human Oversight

People must remain in control. High-risk AI systems require meaningful human oversight, not just rubber-stamp approval.

Transparency

People must know when they are interacting with AI. Clear disclosures are required for chatbots, deepfakes, and biometric systems.

Accountability

Clear roles are defined (providers, deployers, distributors). Each has specific obligations. Documentation and record-keeping are mandatory.

Key Insight

The AI Act applies to any AI system that affects people in the EU, regardless of where the company is based. A US tech company, a Chinese startup, or an Indian SaaS provider, if their AI system is used in the EU, they must comply. This extraterritorial reach makes the AI Act a de facto global standard.

Who Does the AI Act Apply To?

The AI Act has broad scope. It applies to a wide range of organisations and individuals involved in the AI lifecycle. Understanding whether you fall within scope is the first step to compliance.

Organisations Within Scope

  • Providers — Companies that develop AI systems or GPAI models and place them on the EU market
  • Deployers — Organisations that use AI systems in a professional capacity (previously called "users")
  • Distributors — Entities in the supply chain that make AI systems available on the EU market
  • Importers — Entities that place AI systems from third countries on the EU market
  • Product Manufacturers — Companies that integrate AI into products covered by EU harmonisation legislation
  • Authorised Representatives — Entities appointed by non-EU providers to act on their behalf in the EU

Extraterritorial Reach

The AI Act applies to:

Yes, It Applies

AI providers based outside the EU who place AI systems on the EU market. Deployers established in the EU. Providers and deployers in third countries where the AI output is used in the EU.

Exemptions

AI developed for personal non-professional use. Military, defence, and national security purposes. Third-country public authorities in international law enforcement agreements. Open-source AI (with exceptions for GPAI and high-risk).

Important for Non-EU Companies

If you are a company based in the United States, United Kingdom, Switzerland, or anywhere outside the EU, and your AI system is used by EU residents or businesses, you must comply with the AI Act. This includes SaaS platforms, APIs, mobile apps, and embedded AI features.

The Risk-Based Classification System

The AI Act organizes AI systems into four main risk tiers. Think of it as a traffic light system with an additional "red zone" for banned practices. Every organisation must classify their AI systems to know which rules apply.

Unacceptable Risk

AI systems that pose a clear threat to fundamental rights and safety. Banned entirely.

  • Social scoring by governments
  • Emotion recognition in workplaces/schools
  • Biometric categorisation (political, religious beliefs)
  • Predictive policing based on profiling
  • Real-time remote biometric ID in public (with narrow exceptions)

High Risk

AI systems that can significantly impact safety, health, or fundamental rights. Strict compliance required.

  • Recruitment & HR screening tools
  • Credit scoring & loan decisions
  • Medical devices & diagnostics
  • Educational grading & admissions
  • Law enforcement risk assessment
  • Critical infrastructure management

Limited Risk

AI systems interacting with humans. Transparency obligations only.

  • Chatbots & virtual assistants
  • AI-generated content (must be disclosed)
  • Deepfakes (must be labelled)
  • Emotion recognition systems (must inform users)

Minimal Risk

Most AI applications fall here. No mandatory requirements, but voluntary codes encouraged.

  • Spam filters
  • AI-enabled video games
  • Inventory management systems
  • Recommendation engines (non-critical)
  • Customer service routing (simple)

General-Purpose AI (GPAI)

Foundation models with broad capabilities. Special rules apply, stricter for systemic risk.

  • Large Language Models (GPT, Llama, etc.)
  • Multimodal foundation models
  • Generative AI for text, image, code
  • Models with >10^25 FLOPs training compute

Prohibited AI Practices

These AI systems are considered to pose an unacceptable risk to fundamental rights and are banned from use in the EU entirely. No exemptions, no compliance pathway, they are simply prohibited.

AI systems that deploy subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective to materially distort behaviour and cause significant harm. This includes dark pattern designs that exploit vulnerabilities to distort decision-making.

AI systems that exploit any of the vulnerabilities of a person or a specific group of persons due to their age, disability, or specific social or economic situation, to materially distort behaviour in a manner that causes significant harm.

AI systems used by public authorities for social scoring, evaluating or classifying the trustworthiness of natural persons over a certain period of time based on their social behaviour or known, inferred or predicted personal characteristics, leading to detrimental treatment.

The use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes is prohibited, with strictly limited exceptions: searching for victims of crime, preventing imminent threats to life or terrorist attacks, and locating suspects of serious crimes.

Using AI to categorise individuals based on biometric data to deduce race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation. Also, using AI for emotion recognition in workplaces and educational institutions (with limited exceptions for medical or safety reasons).

The untargeted scraping of facial images from the internet or CCTV footage to create or expand facial recognition databases. This practice is considered a grave threat to privacy and fundamental rights.

AI systems used to assess the risk of a natural person committing a criminal offence, based solely on profiling or personality traits. This does not include systems that assess risk based on concrete, verifiable facts directly related to criminal activity.

Enforcement Note

Violating the prohibited AI practices carries the highest penalties under the AI Act: up to €35 million or 7% of global annual turnover, whichever is higher. These rules have been enforceable since 2 February 2025.

High-Risk AI Requirements

High-risk AI systems face the most extensive compliance obligations. These systems require a full risk management system, rigorous data governance, transparency measures, human oversight, and robust documentation before they can be placed on the EU market.

Where High-Risk Applies

High-risk AI falls into two categories:

Annex III (Critical Uses)

Biometric identification, critical infrastructure, education, employment, access to essential services, law enforcement, migration/asylum/border control, administration of justice.

Annex II (Safety Components)

AI systems that are safety components of products already regulated under EU harmonisation legislation (toys, medical devices, vehicles, lifts, etc.).

Mandatory Requirements for High-Risk AI

Risk Management

Establish a continuous risk management system throughout the AI lifecycle. Identify, evaluate, and mitigate risks iteratively.

Data Governance

Training, validation, and testing datasets must be relevant, representative, free of errors, and complete. Examine possible biases.

Technical Documentation

Maintain comprehensive documentation proving compliance, including system architecture, design choices, and performance metrics.

Record-Keeping

Automatic logging of events during operation. Retain logs for a period appropriate to the system's purpose (typically 6 months).

Transparency

Provide clear instructions for use, capabilities, limitations, and expected performance. Make this available to deployers.

Human Oversight

Design systems so natural persons can effectively oversee operation. Include override mechanisms and alert systems.

Accuracy & Robustness

Achieve appropriate accuracy, robustness, and cybersecurity. Regular testing and validation against defined metrics.

Conformity Assessment

Before placing on the market, undergo conformity assessment (internal or third-party, depending on the system type).

Fundamental Rights Impact Assessment (FRIA)

Deployers of high-risk AI systems (except certain financial institutions) must conduct a Fundamental Rights Impact Assessment (FRIA) before first use. This assesses how the AI system might affect fundamental rights and what measures are needed to mitigate risks. This is similar to a DPIA under GDPR and the two can often be combined.

General-Purpose AI (GPAI) Rules

General-Purpose AI models, often called foundation models, are AI systems trained on broad data at scale, designed for generality of output, and adaptable to a wide range of downstream tasks. The AI Act creates a two-tier system for GPAI.

All GPAI Model Obligations

Every provider of a GPAI model must comply with the following:

  • Maintain technical documentation — Including training and testing processes and evaluation results
  • Provide information to downstream providers — Documentation to enable integrators to understand capabilities and limitations
  • Comply with EU copyright law — Implement a policy to respect Union copyright law, including identifying and respecting reservations of rights
  • Publish training content summary — A sufficiently detailed summary of the content used for training (using the AI Office template)

GPAI with Systemic Risk (Additional Obligations)

GPAI models classified as having "systemic risk" (currently defined as models trained with computational effort greater than 10^25 FLOPs) face additional requirements:

  • Model evaluation — Conduct adversarial testing and red-teaming with state-of-the-art protocols
  • Assess and mitigate systemic risk — Document and take action to reduce risks at the EU level
  • Track and report serious incidents — Notify the AI Office of serious incidents without undue delay
  • Ensure adequate cybersecurity — Physical infrastructure security and model weights protection
  • Commission model capability reports — Independent expert assessments of model capabilities and risks

Free and Open-Source Exception

GPAI models released under free and open-source licences are exempt from most GPAI obligations, unless they are designated as having systemic risk or are provided as a closed API service. The exception does not apply to prohibited or high-risk AI systems.

Transparency Obligations

Even if your AI system is not high-risk, you may still need to comply with transparency requirements. The AI Act requires that people know when they are interacting with AI, and that AI-generated content is clearly identifiable.

When Transparency Rules Apply

AI Chatbots

When interacting with a chatbot, users must be informed that they are communicating with an AI, unless this is obvious from the context.

Emotion Recognition

When emotion recognition or biometric categorisation systems are used, affected persons must be informed and the operator must comply with GDPR.

Deepfakes

AI-generated or manipulated images, audio, or video that resembles real people (deepfakes) must be clearly labelled as artificially generated.

Generated Text

Text published to inform the public on matters of public interest that is AI-generated must be labelled, unless it has undergone human review or editorial control.

Watermarking Requirement

Providers of generative AI systems must ensure their outputs are marked in a machine-readable format, so they can be detected as artificially generated. Technical standards for watermarking are being developed by the European standards bodies (CEN-CENELEC).

Roles & Responsibilities

The AI Act defines specific roles across the AI value chain, each with distinct obligations. Understanding which role(s) your organisation plays is critical to knowing what you must do.

Provider
A natural or legal person that develops an AI system or GPAI model, or has it developed, and places it on the market or puts it into service under their own name or trademark. Primary compliance responsibility.
Deployer
A natural or legal person that uses an AI system under its authority in a professional capacity. Does not include personal, non-professional use. Previously called "user" in draft versions.
Distributor
A natural or legal person in the supply chain, other than the provider or importer, that makes an AI system available on the Union market.
Importer
A natural or legal person located in the EU that places on the market an AI system bearing the name or trademark of a natural or legal person established in a third country.
Authorised Representative
A natural or legal person established in the EU who has received a written mandate from a non-EU provider to act on their behalf regarding compliance obligations.

Deployer Obligations for High-Risk AI

If your organisation uses (deploys) high-risk AI systems, you must:

  • Implement human oversight measures as specified by the provider
  • Monitor operation for risks and incidents, notify provider of serious incidents
  • Maintain logs automatically generated by the AI system
  • Conduct a Fundamental Rights Impact Assessment (FRIA) before first use
  • Inform workers' representatives and affected persons that they will be subject to high-risk AI
  • For public sector deployers: register the AI system in the EU database before first use

Your AI Act Compliance Roadmap

Getting ready for the AI Act does not happen overnight. We recommend a structured, phased approach that builds compliance capability progressively while minimising disruption to your operations.

Phase 1: Discover & Assess (Weeks 1-4)

Create an AI Inventory

Catalogue every AI system in use across your organisation, including third-party tools, embedded features, and experimental projects.

Classify Risk Levels

Map each AI system to the AI Act risk categories. Determine which are prohibited, high-risk, limited risk, or minimal risk.

Map Roles

Determine whether your organisation is a provider, deployer, distributor, or importer for each system. This defines your obligations.

Gap Analysis

Assess your current state against AI Act requirements. Identify missing documentation, processes, controls, and governance.

Phase 2: Build & Implement (Weeks 5-12)

Risk Management

Implement a risk management system for high-risk AI. Establish risk registers, assessment protocols, and mitigation procedures.

Data Governance

Review training data for bias and representativeness. Implement data quality controls and documentation standards.

Technical Documentation

Compile or create technical documentation for each high-risk AI system. Include system architecture, performance metrics, and testing results.

Human Oversight

Design and implement meaningful human oversight mechanisms. Train staff on override procedures and escalation paths.

FRIA & DPIA

Conduct Fundamental Rights Impact Assessments for high-risk AI deployments. Align with existing GDPR Data Protection Impact Assessments where possible.

Governance Framework

Establish AI governance policies, assign ownership, create review committees, and define decision-making authority.

Phase 3: Operate & Maintain (Ongoing)

Continuous Monitoring

Regularly monitor AI system performance, risk indicators, and incident reports. Update risk assessments as systems evolve.

Incident Reporting

Establish protocols for detecting, documenting, and reporting serious incidents to relevant authorities within required timeframes.

Record Maintenance

Keep logs, documentation, and evidence up to date. Maintain version control and audit trails for all compliance materials.

Stay Current

Monitor regulatory updates, guidance from the AI Office, and evolving standards. Adjust compliance posture as the framework matures.

Microsoft 365 Advantage

Organisations using Microsoft 365 can leverage their existing infrastructure for AI Act compliance. SharePoint serves as an evidence vault, Microsoft Lists tracks AI inventories and risk registers, Purview manages sensitivity labels and audit logs, and Copilot Studio automates compliance workflows. This "compliance in place" approach avoids adding yet another platform to your stack.

Enforcement Timeline

The AI Act enters into force progressively. Different provisions apply at different dates. Missing these deadlines can expose your organisation to significant penalties.

August 2024

AI Act Enters into Force

The regulation was published in the Official Journal of the European Union, starting the countdown for all subsequent deadlines.

2 February 2025

Prohibited AI Practices — ENFORCEABLE

Ban on unacceptable risk AI systems becomes effective. National authorities can begin enforcement actions against prohibited practices.

2 May 2025

Codes of Practice for GPAI

The AI Office must have codes of practice ready for General-Purpose AI models. GPAI providers should prepare for compliance.

2 August 2025

GPAI Rules & Penalties — ENFORCEABLE

All General-Purpose AI model obligations become enforceable, including systemic risk obligations. Penalties for non-compliance apply.

2 August 2026

High-Risk AI Systems — ENFORCEABLE

Full compliance required for high-risk AI systems under Annex III. All risk management, documentation, conformity assessment, and registration requirements apply.

2 August 2027

Annex II High-Risk AI — ENFORCEABLE

High-risk AI systems that are safety components of regulated products (Annex II) must comply. This covers medical devices, vehicles, toys, and other products.

2 August 2030

Transition for Existing AI

AI systems already on the market before August 2026 that undergo significant changes must be brought into compliance. Certain systems have until 2030.

Penalties & Fines

The AI Act establishes a tiered penalty structure. Fines are calculated based on the severity of the violation and the size of the organisation. The amounts are substantial and designed to ensure serious compliance efforts.

Violation Type Maximum Fine Applies To
Prohibited AI Practices €35 million or 7% of global annual turnover Use of banned AI systems, violation of fundamental rights prohibitions
High-Risk AI Non-Compliance €15 million or 3% of global annual turnover Failure to meet high-risk AI requirements, provider/deployer obligations
Incorrect Information €7.5 million or 1% of global annual turnover Supplying incorrect information to authorities, failing to cooperate
GPAI Model Violations €15 million or 3% of global annual turnover Failure to comply with GPAI model obligations, including systemic risk rules

Factors Affecting Penalties

When determining the actual fine amount, supervisory authorities will consider:

  • The nature, gravity, and duration of the infringement
  • Whether the infringement was intentional or negligent
  • Any action taken to mitigate damage
  • Degree of cooperation with the authority
  • Relevant previous infringements
  • Annual turnover and market size of the offender

Administrative Fines for SMEs

For small and medium enterprises (SMEs) and start-ups, the AI Act requires that fines be proportionate. While the maximum percentages remain the same, the absolute amounts and enforcement approach take into account the organisation's size and resources. However, SMEs are not exempt and must still fully comply.

Key Terms Glossary

The AI Act uses specific terminology that may be unfamiliar. Here are the most important terms you need to understand, in plain language.

AI System
A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from inputs how to generate outputs such as predictions, content, recommendations, or decisions.
Risk-Based Approach
The core regulatory methodology of the AI Act: different levels of regulatory requirements depending on the level of risk an AI system poses to health, safety, and fundamental rights.
Conformity Assessment
The process of demonstrating whether specified requirements relating to an AI system have been fulfilled. Can be internal (self-assessment) or third-party (notified body).
CE Marking
A marking by which the provider indicates that the AI system is in conformity with the AI Act requirements and other applicable EU harmonisation legislation.
FRIA
Fundamental Rights Impact Assessment. A process to identify, assess, and mitigate risks to fundamental rights before deploying a high-risk AI system.
Notified Body
An independent third-party conformity assessment body designated by an EU member state to assess high-risk AI systems in specific areas before market placement.
AI Office
The European Artificial Intelligence Office, established within the European Commission, responsible for overseeing the AI Act's implementation, especially for GPAI models.
Systemic Risk
Risk specific to GPAI models with high impact capabilities, which can have a significant impact on public health, safety, security, or fundamental rights across the EU.
FLOPs
Floating Point Operations. A measure of computational effort used to train AI models. The AI Act uses 10^25 FLOPs as the threshold for systemic risk GPAI models.
Biometric Identification
The automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing identity (e.g., facial recognition, fingerprint scanning).
Deepfake
AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or other entities, and would falsely appear to a person to be authentic.
Sandbox
A controlled environment established by a competent authority where innovative AI systems can be developed and tested under regulatory supervision before market placement.

Need Help with AI Act Compliance?

Executive Shield Partners helps organisations become demonstrably ready for the EU AI Act with a remote-first governance model built on Microsoft 365, Copilot Studio, and Purview.

This guide is for informational purposes only and does not constitute legal advice.

Regulation (EU) 2024/1689 of the European Parliament and of the Council

© 2025 Executive Shield Partners. AI Governance • EU AI Act • Microsoft 365