EU AI Act — Briefing
The EU Artificial Intelligence Act (EU AI Act) is a horizontal EU regulation that sets harmonized, risk-based rules for the development…
EU AI Act — Briefing
The EU Artificial Intelligence Act (EU AI Act) is a horizontal EU regulation that sets harmonized, risk-based rules for the development, placing on the market, and use of AI systems to promote trustworthy, human‑centric AI while protecting health, safety, fundamental rights, and the internal market.[1][2]
Definition
The EU AI Act classifies AI systems into four risk tiers — unacceptable, high, limited, and minimal — and attaches obligations proportionate to the level of risk. Its core objectives are to prohibit certain harmful AI practices, impose strict requirements on high‑risk AI, mandate transparency for certain limited‑risk uses, and support innovation through a common EU‑wide framework that prevents fragmented national rules.[3][4][2][1]
Scope
The Act applies to all key actors in the AI value chain: providers (developers placing AI on the EU market under their name), deployers (users), importers, and distributors of AI systems and general‑purpose AI models. Its territorial scope is extraterritorial: it covers entities established in the EU and organizations outside the EU that place AI systems on the EU market, put them into service in the EU, or whose AI outputs are used in the EU, regardless of where they are based. Impacted sectors include, among others, critical infrastructure, education, employment, essential private and public services, law enforcement, migration and border control, and systems assisting legal interpretation.[5][6][3][1]
Risk tiers
· Unacceptable risk: AI practices that are considered incompatible with EU values are banned, such as social scoring by public authorities, manipulative or exploitative AI that significantly distorts behavior, and certain types of real‑time remote biometric identification in public spaces (subject to narrow exceptions).[4][3]
· High risk: AI systems that pose significant risks to health, safety, or fundamental rights — e.g., AI used in managing critical infrastructure, education and exams, recruitment and worker management, credit scoring and access to essential services, law‑enforcement risk assessments, migration and border control, and tools assisting judicial decisions — are allowed but subject to stringent requirements. These include risk management, high‑quality data, technical documentation, logging, transparency to users, human oversight, robustness, and cybersecurity, plus conformity assessments and CE marking before market placement.[7][3][1]
· Limited risk: Systems with limited risk are mainly subject to transparency obligations so that users know they are interacting with AI; typical examples are chatbots and AI systems that generate or manipulate content such as deepfakes, which must be clearly disclosed as AI‑generated.[8][4]
· Minimal risk: Most AI systems, such as spam filters, simple recommendation engines, or many productivity tools, fall under minimal risk and are largely unregulated by the Act, though providers are encouraged to follow voluntary codes of conduct and best‑practice standards.[8][4]
Key dates
The Act uses a phased timeline; the central date for high‑risk systems is 2 August 2026, by which providers of high‑risk AI must have completed conformity assessments, finalized technical documentation, affixed the CE marking, and registered systems in the EU database to meet the core Articles 8–15 requirements. Additional timelines extend obligations to certain product categories and large‑scale IT systems through 2027 and 2030, but 2 August 2026 is the primary compliance deadline for newly placed high‑risk systems.[9][10][7]
Fines
The EU AI Act introduces a tiered administrative fine regime, calibrated to global annual turnover.[10][7]
· For violations of prohibited AI practices (e.g., using banned unacceptable‑risk systems), fines can reach up to 35 million EUR or 7% of the offender’s total worldwide annual turnover, whichever is higher.[7][10]
· For non‑compliance with obligations governing high‑risk systems, transparency, documentation, or human oversight, maximum fines are set at slightly lower but still substantial levels (commonly cited as up to 15–35 million EUR or 3–7% of worldwide turnover, depending on the specific breach).[10][7]
· For supplying incorrect, incomplete, or misleading information to competent authorities, the Act foresees lower‑tier penalties, typically up to around 7.5 million EUR or 1–2% of worldwide turnover, providing a proportionate response to less severe infringements.[10]
References:
-
https://www.legalnodes.com/article/eu-ai-act-2026-updates-compliance-requirements-and-business-risks
-
https://about.citiprogram.org/blog/an-overview-of-the-eu-ai-act-what-you-need-to-know/
-
https://www.modelop.com/ai-governance/ai-regulations-standards/eu-ai-act
-
https://www.spektr.com/blog/eu-ai-act-timeline-enforcement-fines-and-how-to-prepare
-
https://www.dnv.com/cyber/insights/articles/introduction-to-the-eus-ai-act-what-you-should-know/
메타데이터
- post_id
- 52a6d0d22d8b
- slug
- eu-ai-act-briefing-52a6d0d22d8b
- url
- https://medium.com/@geomichl/eu-ai-act-briefing-52a6d0d22d8b
- canonical_url
- https://medium.com/@geomichl/eu-ai-act-briefing-52a6d0d22d8b
- author_url
- https://medium.com/@geomichl
- status
- ok
- fetched_at
- 2026-07-13 06:23:13