
A practical, plain-language guide to the world's first comprehensive AI regulation. Understand what the EU AI Act means for your organisation, your AI systems, and your compliance obligations.
What is the EU AI Act? The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world's first horizontal, legally binding regulation on artificial intelligence. It establishes a risk-based approach to regulating AI systems across the European Union.
The EU AI Act is built on a simple but powerful idea: the stricter the risk an AI system poses to people's rights and safety, the stricter the rules. This is called a "risk-based approach." Instead of treating all AI the same, the law sorts AI systems into categories based on how much harm they could cause.
The European Union recognised that AI technology was spreading rapidly across every industry, but without consistent rules to protect people. The goals of the AI Act are:
AI systems are classified by risk level. Higher risk means stricter compliance requirements, more documentation, and stronger oversight.
People must remain in control. High-risk AI systems require meaningful human oversight, not just rubber-stamp approval.
People must know when they are interacting with AI. Clear disclosures are required for chatbots, deepfakes, and biometric systems.
Clear roles are defined (providers, deployers, distributors). Each has specific obligations. Documentation and record-keeping are mandatory.
The AI Act applies to any AI system that affects people in the EU, regardless of where the company is based. A US tech company, a Chinese startup, or an Indian SaaS provider, if their AI system is used in the EU, they must comply. This extraterritorial reach makes the AI Act a de facto global standard.
The AI Act has broad scope. It applies to a wide range of organisations and individuals involved in the AI lifecycle. Understanding whether you fall within scope is the first step to compliance.
The AI Act applies to:
AI providers based outside the EU who place AI systems on the EU market. Deployers established in the EU. Providers and deployers in third countries where the AI output is used in the EU.
AI developed for personal non-professional use. Military, defence, and national security purposes. Third-country public authorities in international law enforcement agreements. Open-source AI (with exceptions for GPAI and high-risk).
If you are a company based in the United States, United Kingdom, Switzerland, or anywhere outside the EU, and your AI system is used by EU residents or businesses, you must comply with the AI Act. This includes SaaS platforms, APIs, mobile apps, and embedded AI features.
The AI Act organizes AI systems into four main risk tiers. Think of it as a traffic light system with an additional "red zone" for banned practices. Every organisation must classify their AI systems to know which rules apply.
AI systems that pose a clear threat to fundamental rights and safety. Banned entirely.
AI systems that can significantly impact safety, health, or fundamental rights. Strict compliance required.
AI systems interacting with humans. Transparency obligations only.
Most AI applications fall here. No mandatory requirements, but voluntary codes encouraged.
Foundation models with broad capabilities. Special rules apply, stricter for systemic risk.
These AI systems are considered to pose an unacceptable risk to fundamental rights and are banned from use in the EU entirely. No exemptions, no compliance pathway, they are simply prohibited.
AI systems that deploy subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective to materially distort behaviour and cause significant harm. This includes dark pattern designs that exploit vulnerabilities to distort decision-making.
AI systems that exploit any of the vulnerabilities of a person or a specific group of persons due to their age, disability, or specific social or economic situation, to materially distort behaviour in a manner that causes significant harm.
AI systems used by public authorities for social scoring, evaluating or classifying the trustworthiness of natural persons over a certain period of time based on their social behaviour or known, inferred or predicted personal characteristics, leading to detrimental treatment.
The use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes is prohibited, with strictly limited exceptions: searching for victims of crime, preventing imminent threats to life or terrorist attacks, and locating suspects of serious crimes.
Using AI to categorise individuals based on biometric data to deduce race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation. Also, using AI for emotion recognition in workplaces and educational institutions (with limited exceptions for medical or safety reasons).
The untargeted scraping of facial images from the internet or CCTV footage to create or expand facial recognition databases. This practice is considered a grave threat to privacy and fundamental rights.
AI systems used to assess the risk of a natural person committing a criminal offence, based solely on profiling or personality traits. This does not include systems that assess risk based on concrete, verifiable facts directly related to criminal activity.
Violating the prohibited AI practices carries the highest penalties under the AI Act: up to €35 million or 7% of global annual turnover, whichever is higher. These rules have been enforceable since 2 February 2025.
High-risk AI systems face the most extensive compliance obligations. These systems require a full risk management system, rigorous data governance, transparency measures, human oversight, and robust documentation before they can be placed on the EU market.
High-risk AI falls into two categories:
Biometric identification, critical infrastructure, education, employment, access to essential services, law enforcement, migration/asylum/border control, administration of justice.
AI systems that are safety components of products already regulated under EU harmonisation legislation (toys, medical devices, vehicles, lifts, etc.).
Establish a continuous risk management system throughout the AI lifecycle. Identify, evaluate, and mitigate risks iteratively.
Training, validation, and testing datasets must be relevant, representative, free of errors, and complete. Examine possible biases.
Maintain comprehensive documentation proving compliance, including system architecture, design choices, and performance metrics.
Automatic logging of events during operation. Retain logs for a period appropriate to the system's purpose (typically 6 months).
Provide clear instructions for use, capabilities, limitations, and expected performance. Make this available to deployers.
Design systems so natural persons can effectively oversee operation. Include override mechanisms and alert systems.
Achieve appropriate accuracy, robustness, and cybersecurity. Regular testing and validation against defined metrics.
Before placing on the market, undergo conformity assessment (internal or third-party, depending on the system type).
Deployers of high-risk AI systems (except certain financial institutions) must conduct a Fundamental Rights Impact Assessment (FRIA) before first use. This assesses how the AI system might affect fundamental rights and what measures are needed to mitigate risks. This is similar to a DPIA under GDPR and the two can often be combined.
General-Purpose AI models, often called foundation models, are AI systems trained on broad data at scale, designed for generality of output, and adaptable to a wide range of downstream tasks. The AI Act creates a two-tier system for GPAI.
Every provider of a GPAI model must comply with the following:
GPAI models classified as having "systemic risk" (currently defined as models trained with computational effort greater than 10^25 FLOPs) face additional requirements:
GPAI models released under free and open-source licences are exempt from most GPAI obligations, unless they are designated as having systemic risk or are provided as a closed API service. The exception does not apply to prohibited or high-risk AI systems.
Even if your AI system is not high-risk, you may still need to comply with transparency requirements. The AI Act requires that people know when they are interacting with AI, and that AI-generated content is clearly identifiable.
When interacting with a chatbot, users must be informed that they are communicating with an AI, unless this is obvious from the context.
When emotion recognition or biometric categorisation systems are used, affected persons must be informed and the operator must comply with GDPR.
AI-generated or manipulated images, audio, or video that resembles real people (deepfakes) must be clearly labelled as artificially generated.
Text published to inform the public on matters of public interest that is AI-generated must be labelled, unless it has undergone human review or editorial control.
Providers of generative AI systems must ensure their outputs are marked in a machine-readable format, so they can be detected as artificially generated. Technical standards for watermarking are being developed by the European standards bodies (CEN-CENELEC).
The AI Act defines specific roles across the AI value chain, each with distinct obligations. Understanding which role(s) your organisation plays is critical to knowing what you must do.
If your organisation uses (deploys) high-risk AI systems, you must:
Getting ready for the AI Act does not happen overnight. We recommend a structured, phased approach that builds compliance capability progressively while minimising disruption to your operations.
Catalogue every AI system in use across your organisation, including third-party tools, embedded features, and experimental projects.
Map each AI system to the AI Act risk categories. Determine which are prohibited, high-risk, limited risk, or minimal risk.
Determine whether your organisation is a provider, deployer, distributor, or importer for each system. This defines your obligations.
Assess your current state against AI Act requirements. Identify missing documentation, processes, controls, and governance.
Implement a risk management system for high-risk AI. Establish risk registers, assessment protocols, and mitigation procedures.
Review training data for bias and representativeness. Implement data quality controls and documentation standards.
Compile or create technical documentation for each high-risk AI system. Include system architecture, performance metrics, and testing results.
Design and implement meaningful human oversight mechanisms. Train staff on override procedures and escalation paths.
Conduct Fundamental Rights Impact Assessments for high-risk AI deployments. Align with existing GDPR Data Protection Impact Assessments where possible.
Establish AI governance policies, assign ownership, create review committees, and define decision-making authority.
Regularly monitor AI system performance, risk indicators, and incident reports. Update risk assessments as systems evolve.
Establish protocols for detecting, documenting, and reporting serious incidents to relevant authorities within required timeframes.
Keep logs, documentation, and evidence up to date. Maintain version control and audit trails for all compliance materials.
Monitor regulatory updates, guidance from the AI Office, and evolving standards. Adjust compliance posture as the framework matures.
Organisations using Microsoft 365 can leverage their existing infrastructure for AI Act compliance. SharePoint serves as an evidence vault, Microsoft Lists tracks AI inventories and risk registers, Purview manages sensitivity labels and audit logs, and Copilot Studio automates compliance workflows. This "compliance in place" approach avoids adding yet another platform to your stack.
The AI Act enters into force progressively. Different provisions apply at different dates. Missing these deadlines can expose your organisation to significant penalties.
The regulation was published in the Official Journal of the European Union, starting the countdown for all subsequent deadlines.
Ban on unacceptable risk AI systems becomes effective. National authorities can begin enforcement actions against prohibited practices.
The AI Office must have codes of practice ready for General-Purpose AI models. GPAI providers should prepare for compliance.
All General-Purpose AI model obligations become enforceable, including systemic risk obligations. Penalties for non-compliance apply.
Full compliance required for high-risk AI systems under Annex III. All risk management, documentation, conformity assessment, and registration requirements apply.
High-risk AI systems that are safety components of regulated products (Annex II) must comply. This covers medical devices, vehicles, toys, and other products.
AI systems already on the market before August 2026 that undergo significant changes must be brought into compliance. Certain systems have until 2030.
The AI Act establishes a tiered penalty structure. Fines are calculated based on the severity of the violation and the size of the organisation. The amounts are substantial and designed to ensure serious compliance efforts.
| Violation Type | Maximum Fine | Applies To |
|---|---|---|
| Prohibited AI Practices | €35 million or 7% of global annual turnover | Use of banned AI systems, violation of fundamental rights prohibitions |
| High-Risk AI Non-Compliance | €15 million or 3% of global annual turnover | Failure to meet high-risk AI requirements, provider/deployer obligations |
| Incorrect Information | €7.5 million or 1% of global annual turnover | Supplying incorrect information to authorities, failing to cooperate |
| GPAI Model Violations | €15 million or 3% of global annual turnover | Failure to comply with GPAI model obligations, including systemic risk rules |
When determining the actual fine amount, supervisory authorities will consider:
For small and medium enterprises (SMEs) and start-ups, the AI Act requires that fines be proportionate. While the maximum percentages remain the same, the absolute amounts and enforcement approach take into account the organisation's size and resources. However, SMEs are not exempt and must still fully comply.
The AI Act uses specific terminology that may be unfamiliar. Here are the most important terms you need to understand, in plain language.
Executive Shield Partners helps organisations become demonstrably ready for the EU AI Act with a remote-first governance model built on Microsoft 365, Copilot Studio, and Purview.
This guide is for informational purposes only and does not constitute legal advice.
Regulation (EU) 2024/1689 of the European Parliament and of the Council
© 2025 Executive Shield Partners. AI Governance • EU AI Act • Microsoft 365