What is the EU AI Act?

A plain-English overview of the EU's regulation for artificial intelligence — what it covers, how it classifies risk, and what that means for you.

Why it exists

The EU AI Act is the first comprehensive law regulating artificial intelligence across the European Union. Rather than treating all AI the same, it takes a risk-based approach: the more an AI system could affect people's safety, rights, or livelihoods, the more obligations apply to whoever builds or deploys it.

The risk tiers

  • Unacceptable risk — a small set of practices banned outright (e.g. certain manipulative or social-scoring systems).
  • High-risk — systems used in areas like employment, education, credit, law enforcement, or safety-critical products. Subject to the heaviest obligations: risk management, data governance, technical documentation, human oversight, accuracy/robustness/cybersecurity, and conformity assessment.
  • Limited-risk — systems with specific transparency duties, such as disclosing that a user is interacting with AI or that content is AI-generated.
  • Minimal-risk — everything else. No mandatory obligations under the Act, though voluntary codes of conduct exist.
  • General-purpose AI (GPAI) — models with their own documentation and transparency obligations, layered on top of the tiers above when a GPAI model is used inside a downstream system.

Who it applies to

The Act applies to both providers (who build or place an AI system on the market) and deployers (who use one in the course of their own activities), including organizations outside the EU if their system's output is used within the EU. Your obligations depend on which role you have and which tier your system falls into.

Where to start

The fastest way to find your obligations is to classify your specific AI system — the tiers above are only a starting point, and the details that decide your tier (sector, who's affected, your role, how much human oversight is involved) are specific to each system.

Classify an AI system — free