T1#regulation#security
EU AI Act Adopted — The World's First Comprehensive AI Regulation

Metadata
- Date
- Decade
- 2020s
- Tier
- T1
- Sources
- 07
- Connections
- 00
- Tags
- #regulation#security
On 13 March 2024, the plenary of the European Parliament approved the Artificial Intelligence Act. The vote was 523 in favour, 46 against, 49 abstaining.
The European Commission calls it "the world's first comprehensive legal framework on AI"—enforceable by substantial fines and reaching operators outside the Union. But the plenary vote was not the end of the legislative process. Council adoption followed on 21 May, publication in the Official Journal on 12 July (Regulation (EU) 2024/1689), and entry into force twenty days later, on 1 August. Application then began provision by provision. Approved, adopted, in force and applicable are four different dates.
Risk Tiers
The Act's skeleton is a four-tier classification of AI systems.
1. Unacceptable risk — prohibited outright
- Social scoring—not limited to public authorities; private deployment is caught too
- Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrow exceptions
- Untargeted scraping of facial images from the internet or CCTV footage to build recognition databases
- Biometric categorisation that infers sensitive characteristics
- Predictive policing based solely on profiling a person's traits
- Systems that exploit human vulnerabilities (age, disability, etc.)
- Subliminal manipulation techniques
- Emotion recognition in workplaces and educational institutions
2. High risk — strict obligations
- Hiring, credit scoring, judicial decision-making, law enforcement, education, immigration, critical infrastructure, medical devices, and similar high-stakes domains
Such systems must implement risk management, data governance, transparency, human oversight, and demonstrated accuracy and robustness.
3. Limited risk — transparency obligations
- Chatbots, generative systems (deepfakes, etc.)
Users must be told they are interacting with AI or seeing AI-generated content.
4. Minimal risk — free
- Everything else (spam filters, game AI, …)
Special Regime for General-Purpose AI
General-purpose models like ChatGPT, Claude, and Gemini do not fit cleanly into the risk tiers. The Act creates a separate category, General-Purpose AI Model (GPAI), with a two-tier compute-based regulation.
- All GPAI: draw up technical documentation, comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training.
- GPAI with systemic risk: additionally, model evaluations, adversarial testing, cybersecurity hardening, and serious-incident reporting.
Article 51(2) sets the trigger as a presumption: a model "shall be presumed to have high impact capabilities" when "the cumulative amount of computation used for its training measured in floating point operations is greater than 10²⁵". Classification runs through provider notification to the AI Office, not through a published list of model names. Public estimates put GPT-4-class frontier models above the line.
For contrast, the reporting trigger in the US EO 14110 was 10²⁶ integer or floating-point operations—an order of magnitude apart, and measured differently.
Fines
Article 99's schedule exceeds the GDPR's ceiling (€20 million or 4%). In each band the fine is the higher of the two figures.
- Breach of the Article 5 prohibitions: up to €35 million, or 7% of total worldwide annual turnover for the preceding financial year
- Breach of other obligations, high-risk duties included: up to €15 million, or 3%
- Supplying incorrect, incomplete or misleading information: up to €7.5 million, or 1%
The "percentage of worldwide turnover" formulation has bite even for the largest firms.
Phased Application—and the 2026 Postponement
The Council of the EU adopted the Act on 21 May 2024. It appeared in the Official Journal on 12 July and entered into force twenty days later, on 1 August. Not all provisions begin together:
- 2 February 2025: the prohibitions and the AI-literacy duty apply.
- 2 August 2025: GPAI obligations apply; models already on the market before that date have until 2 August 2027.
- 2 August 2026: the general date of application, including the Article 50 transparency duties.
In July 2026 the timetable was rewritten. The Digital Omnibus on AI, proposed by the Commission on 19 November 2025, became Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force on 27 July—six days before the AI Act's own general application date.
- Stand-alone high-risk systems under Annex III: 2 August 2026 → 2 December 2027
- High-risk systems embedded in regulated products under Annex I: 2 August 2027 → 2 August 2028
- New Article 5 prohibitions: AI-generated non-consensual intimate imagery and child sexual abuse material, with a transition to 2 December 2026
- Deadline for member states to stand up AI regulatory sandboxes: 2 August 2026 → 2 August 2027
The GPAI regime (Articles 51–56) and the 10²⁵ FLOP threshold were left alone. But "the world's first comprehensive AI regulation" had its central high-risk chapter pushed back once before it ever took effect.
The Brussels Effect
The Act has de facto reach beyond the EU. American companies selling AI systems into the European market must comply; in practice, building one global product to the EU standard is cheaper than maintaining two variants.
This is the latest case of the "Brussels effect"—European regulation becoming the de facto global standard for firms based in countries without equivalent law—first widely observed under the GDPR (in force 2016, applicable from 25 May 2018).
National AI policies in the United States, Japan, the United Kingdom, and elsewhere have used the AI Act as a reference, explicit or otherwise. The pull is not uniform, though. Washington rescinded its own executive order in January 2025 and has since pressed the opposite case; Brussels itself, under industry and diplomatic pressure, spent 2026 simplifying and deferring. The plenary vote of 13 March 2024 still stands as the day the first comprehensive standard for AI regulation left Brussels—but the standard has been negotiable since.
Questions this page answers
- When does the EU AI Act actually apply?
- It entered into force on 1 August 2024, but its obligations phase in. The Digital Omnibus of July 2026, Regulation (EU) 2026/1744, deferred the high-risk obligations to 2 December 2027 and 2 August 2028.
- What was the vote in the European Parliament?
- 523 in favour, 46 against and 49 abstentions, on 13 March 2024. The Council adopted it on 21 May, and it appeared in the Official Journal on 12 July.
Sources
Last updated: