As artificial intelligence continues to reshape industries and workplaces, understanding the evolving regulatory landscape has become essential for organisations and professionals alike. This blog post explains the EU AI Act in a clear and accessible way, helping readers understand what the legislation is, why it matters, and how it will impact the development, deployment, and use of AI. It also provides practical guidance on preparing for compliance while highlighting the importance of AI literacy, continuous learning, and skills development. 

What is the AI Act?   

The AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework governing artificial intelligence, quickly followed by South Korea’s AI Basic Act (2025), new U.S. state laws, China’s generative AI measures, and governance frameworks in Japan and India. By introducing a harmonised set of rules across the European Union, it aims to provide legal certainty and support innovation for businesses while fostering a safetransparentnon-discriminatory and trustworthy development and use of AI, in full respect of citizens’ fundamental rights. 

The Regulation has a broad reach, applying to public and private actors, from developers and businesses to public authorities, regardless of whether they are established within or outside the European Union. Its extraterritorial scope means that organisations outside the EU may also be subject to its rules when their AI systems, or the outputs they generate, are placed on or used in the EU market. 

The Act adopts a risk-based approach, classifying AI systems according to the level of risk they pose to safety and fundamental rights. This classification determines the compliance obligations that apply to organisations deploying or placing AI systems on the EU market. The four risk categories are: 

It is important to note that, in specific circumstances, a limited or minimal risk use of AI could become a high-risk use (i.e. including more or sensible data, repurposing, change of deployment context, etc.). 

To encourage compliance, the EU AI Act establishes a tiered system of fines that varies depending on the type of infringement. Penalties are calculated based on whichever amount is higher: a fixed monetary fine or a percentage of an organisation’s total worldwide annual turnover from the preceding financial year. For example: 

Implementation Timeline of the EU AI Act 

The AI Act entered into force on the 1 August 2024 and followed a phased implementation schedule, allowing organisations time to assess their AI systems, adapt internal processes, and put in place appropriate compliance measures. The first substantive obligations applied from the 2 February 2025, prohibiting AI systems that pose an unacceptable risk and requiring organisations to ensure adequate AI literacy among employees and other relevant stakeholders regarding the opportunities, risks and potential harms associated with AI. 

On 2 August 2025, the rules on GPAI models became applicable, requiring organisations to carry out appropriate due diligence on AI providers, understand the risks associated with the models they use, and assess compliance with applicable regulatory requirements.  

Transparency obligations under Article 50 will apply from 2 August 2026, while requirements for standalone high-risk AI systems will apply from 2 December 2027 and for AI embedded in regulated products from 2 August 2028.  

Preparing for Compliance with the EU AI Act   

Organisations that begin this work early will be in a stronger position to integrate compliance requirements into existing business practices rather than having to implement corrective measures under time pressure. 

Organisations should establish internal procedures to support compliance with the AI Act. As a first step, businesses should map all AI system developed or used across the organisation, as maintaining a comprehensive AI inventory is highly recommended. Once these systems have been identified, organisations should conduct an initial risk assessment to determine the level of risk associated with each AI system and identify the obligations that may apply under the AI Act. This assessment is essential for identifying prohibited AI practices, determining whether a system falls within the high-risk category, and understanding any applicable transparency requirements. 

The differences in requirements are based on organisational context (e.g., providers, deployers, importers and distributors). For high-risk AI key obligations are risk management, data governance, technical documentation, conformity/impact assessment, registration, accuracy, cybersecurity, record-keeping, human oversight, transparency and notification, incident handling and quality management. 

Provider obligations for all GPAI models include technical documentation, publishing training-data summaries (while respecting IP/copyright), ensuring transparency to downstream providers (model cards, usage conditions, limitations), appointing an EU representative if outside the EU. Providers of systemic-risk GPAI models must fulfil the above requirements, plus: conduct risk and mitigation assessments, document/report serious incidents, perform red-teaming/adversarial testing, ensure cybersecurity and physical safeguards, and disclose energy consumption. 

A cross-functional approach is essential throughout this process. Close collaboration between compliance, legal, and technical departments is necessary to properly assess risks, implement mitigation measures, identify the applicable regulatory requirements, and determine the documentation, which must be reviewed and aligned with the requirements of the AI Act. 

Finally, organisations should invest in AI literacy as a key component of their compliance strategy, ensuring that employees receive role-specific training on the technical capabilities and limitations of AI, as well as the associated ethical risks and legal requirements. 

Building AI Skills for the Future 

As AI becomes an increasingly integral part of business operations, keeping up to date with AI technologies and regulatory developments is essential. Organisations that stay up to date are better positioned to leverage the benefits of AI, adapt to legal requirements, mitigate operational and compliance risks, and ensure that AI systems are used in a responsible, ethical, and trustworthy manner. In this context, training and upskilling initiatives play a key role in building AI literacy across the organization, enabling employees to understand both the opportunities and limitations of AI and to use these technologies effectively and responsibly. 

Explore the EIT Campus and discover AI-related courses that will help you develop the knowledge and skills needed to navigate the evolving AI landscape with confidence.