EU AI Act
The EU AI Act is the first comprehensive statutory regulation of artificial intelligence in the European Union. It takes a risk-based approach and divides AI systems into different risk classes, from prohibited practices through to minimal risk. Depending on the classification, graded duties such as risk management, transparency and human oversight apply. The regulation concerns both providers and users of AI systems.
Also known as: EU AI Act, EU Artificial Intelligence Act, AI regulation
What is the EU AI Act?
The EU AI Act, officially the EU Artificial Intelligence Act, is the first comprehensive set of rules regulating the use of artificial intelligence uniformly within the European Union. The regulation's aim is to foster innovation and technological progress while protecting fundamental rights, safety and citizens' trust in AI applications.
Unlike sector-specific individual rules, the EU AI Act creates a horizontal legal framework applying to nearly every industry. At the centre stands a risk-based approach: not every AI application is treated the same but classified by its potential risk to people and society. The higher a system's risk, the stricter the legal requirements.
Which risk classes does the AI regulation distinguish?
The EU AI Act sorts AI systems into four risk classes. AI with unacceptable risk is prohibited. That covers practices considered particularly harmful to fundamental rights, such as certain forms of social scoring or manipulative systems that influence people's behaviour impermissibly.
The second level is high-risk AI. It is permitted but subject to strict requirements, since such systems can have considerable effects on safety or fundamental rights, for instance in recruitment, lending or critical infrastructure.
With limited risk, transparency duties apply above all. Users have to be able to tell that they are interacting with an AI or that content is AI-generated, for instance. Systems with minimal risk, which covers many everyday applications, remain largely free of extra duties.
What requirements apply to high-risk AI?
For high-risk AI the EU AI Act sets particularly extensive requirements. Providers have to establish a risk management system identifying and controlling risks across an AI system's whole life cycle. Careful data governance is meant to ensure training and input data is of high quality and bias is avoided as far as possible.
There are also obligations on technical documentation, traceability and transparency towards users. Central to this is human oversight: high-risk systems have to be designed so people understand how they work and can intervene when needed. Finally the regulation requires an appropriate level of robustness, accuracy and cybersecurity, so the systems work reliably and safely.
What obligations apply to generative AI and transparency?
For generative AI and so-called general-purpose AI models, the EU AI Act sets separate transparency duties. Providers of such models must, among other things, supply technical documentation and disclose information enabling responsible use.
Labelling AI-generated content plays an important part. Text, images, audio or video produced or altered with AI should be recognisable as such, to counter deception and disinformation. These transparency duties complement the risk-class requirements and help keep AI systems comprehensible to users.
What does the EU AI Act mean for companies?
The EU AI Act affects companies in two roles: as providers developing and placing AI systems on the market, and as deployers using AI in their own operations. Both have to check which risk class their applications fall into and which duties follow from that.
The requirements tie in closely with adjacent topics such as AI governance, data protection under the GDPR, seamless documentation and ensuring human oversight. The regulation applies step by step and in stages after coming into force, so companies should adapt their processes in good time. Breaches can bring considerable fines, which is why engaging with the rules early is advisable.
For many organisations this means inventorying existing AI applications, assigning responsibilities and building suitable governance structures, to stay compliant and capable of innovation at the same time.
Delivery with Elisabit
Elisabit helps companies use artificial intelligence in a compliant way and with fitting governance. We help you assess your AI applications against the EU AI Act, classify risk levels and derive the organisational and technical measures needed, on documentation, transparency and human oversight for instance.
As a digital agency for AI solutions and AI consulting we combine technical know-how with a clear understanding of the EU Artificial Intelligence Act’s requirements. We thus accompany you from the first assessment to building sound governance structures, so you can use AI responsibly, safely and with an eye on the future. Please note that our advice offers well-founded orientation but does not replace individual legal advice.
Frequently asked questions
What is the EU AI Act?
The EU AI Act is the first comprehensive statutory regulation of artificial intelligence in the European Union. It takes a risk-based approach and places requirements of differing strictness on AI systems depending on the risk class. The aim is to enable innovation while protecting fundamental rights and safety.
Who does the EU AI Act apply to?
The EU AI Act affects both providers developing and placing AI systems on the market and deployers using AI in their own company. Organisations in almost every industry are therefore addressed. Which duties apply in detail depends on the AI system's risk class.
What risk classes does the EU AI Act have?
The AI Act distinguishes four risk classes: unacceptable risk with prohibited practices, high-risk AI with strict requirements, limited risk with transparency duties, and minimal risk, which stays largely free of extra duties. The higher the risk, the more extensive the legal requirements.
What requirements apply to high-risk AI?
High-risk AI has to ensure risk management, careful data governance, technical documentation, transparency, human oversight, robustness and security among other things. These requirements are meant to ensure the systems work reliably and fundamental rights are preserved. Providers carry a particular responsibility here.
What obligations apply to generative AI?
Separate transparency duties apply to generative AI and general-purpose AI models. They include technical documentation and labelling AI-generated content such as text, images or video. Users should thus be able to tell when they are dealing with AI-generated content.
Related terms
A framework of policies, roles and controls for responsible and compliant AI.
Protecting AI systems and their data against risks such as prompt injection and data leaks.
Company-wide, productive use of AI with a focus on security, scalability and integration.
Guiding companies through the strategy, delivery and scaling of AI solutions.
A strategic shift towards AI-supported processes, products and ways of working across the company.
Put AI to work for your business?
We help you integrate artificial intelligence into your processes, your marketing and your website — strategically and securely.

Your contact
Stefan
I look forward to hearing about your project and finding the best solution together.