AI Ethics & Compliance

The AI Act: the regulatory framework

How the European Union structured the world’s first comprehensive law on artificial intelligence.

The EU AI Act sorts artificial intelligence by the risk it poses rather than by the technology involved. The higher the risk to people’s safety or rights, the stricter the obligations that follow.

The risk tiers

A small number of practices are prohibited outright. High-risk uses, such as AI in recruitment or in access to essential services, carry substantial duties around risk management, documentation and human oversight. Most everyday tools sit in a lighter category with transparency duties attached.

A phased timeline

The Act entered into force in August 2024 and applies in stages. Prohibited practices and the AI literacy duty came first, in February 2025. Obligations for general-purpose AI models followed in August 2025, and the bulk of the framework applies from August 2026.

Why classification comes first

Nothing else can be planned until an organisation knows which category its tools fall into. That assessment determines the documentation, oversight and reporting that follow, which is why it belongs early in any compliance effort.

Official source · European Commission Read the Commission’s regulatory framework overview →

Train your teams on this

Our AI Ethics & Compliance courses cover the EU AI Act role by role, for everyone who touches AI.

See the courses →
All resources