Skip to content
Daily AI Intel

AI Policy, Law & Safety · AI Regulation

What Is the EU AI Act and Who Does It Apply To?

The EU AI Act is the European Union's comprehensive law governing artificial intelligence, sorting AI systems into risk tiers with different obligations; it applies not just to companies based in the EU but to any provider or deployer whose AI system's output is used within the EU market.

Legal disclaimer

This page provides general information only and is not legal advice. Laws vary by jurisdiction and change over time. Consult a licensed attorney in your jurisdiction before making decisions based on this content.

Key takeaways

  • The EU AI Act uses a risk-based framework, grouping AI systems into categories such as unacceptable risk, high risk, limited risk, and minimal risk.
  • It has extraterritorial reach, meaning companies outside the EU can still fall under its scope if their AI systems are placed on the EU market or affect people in the EU.
  • Obligations differ sharply by risk tier — a chatbot has lighter transparency duties than an AI system used in hiring, credit scoring, or law enforcement.
  • The Act designates certain uses, like real-time biometric surveillance in public spaces for law enforcement, as largely prohibited, subject to narrow exceptions.
  • Provisions are phased in over time rather than taking effect all at once, giving organizations a transition period to reach compliance.

A Risk-Based Framework for AI Across Europe

The EU AI Act is the European Union’s flagship law for regulating artificial intelligence, and its central idea is that not all AI systems deserve the same level of scrutiny. Instead of applying one uniform set of rules to every AI product, the Act sorts systems into tiers based on the potential harm they could cause — ranging from practices considered unacceptable and largely banned, through “high-risk” systems subject to strict obligations, down to limited-risk systems that mainly require transparency, and minimal-risk systems that face few or no specific new obligations.

This structure means a customer-service chatbot and an AI system used to screen job applicants are treated very differently under the law, even though both are “AI.” The chatbot might only need to disclose that users are interacting with a machine, while the hiring tool could be classified as high-risk and subject to requirements around risk management, data quality, documentation, and human oversight.

Why the Act Reaches Beyond the EU’s Borders

One of the most consequential design choices in the EU AI Act is its extraterritorial scope. The regulation is not limited to companies incorporated in EU member states. Instead, it generally applies to any provider that places an AI system on the EU market, and to any deployer whose AI system’s output is used within the EU — regardless of where the company itself is headquartered.

This mirrors the approach the EU took with the GDPR for data privacy: a US-based AI company that sells its product to European customers, or whose AI output reaches people in the EU, can find itself squarely within the law’s reach even without a physical presence in Europe. This is a major reason the Act has drawn attention from AI developers worldwide, not just European ones — companies building foundation models, generative AI tools, or embedded AI features often need to consider EU obligations as part of their global compliance planning, even if their primary market is elsewhere.

How This Plays Out for Different Kinds of AI Products

Consider the difference between a company selling AI-powered spam filters and one selling AI-based credit-scoring software to European banks. The spam filter is likely to fall into a lower-risk category, since misclassifying an email carries limited consequences and minimal obligations attach to it. The credit-scoring tool, by contrast, directly affects consumers’ access to financial services and is more likely to be treated as high-risk, triggering obligations such as maintaining technical documentation, enabling human oversight, and ensuring the system underwent adequate risk assessment before deployment.

Generative AI and general-purpose AI models are also addressed within the framework, with additional transparency expectations, such as disclosing that content was AI-generated in certain contexts. Because the Act phases in its various obligations over time rather than all at once, organizations operating in this space are generally expected to track the applicable timeline for the categories of AI systems they build or deploy.

Bottom Line

The EU AI Act creates a tiered system of obligations based on how risky an AI application is judged to be, and its reach extends to any organization — regardless of home country — whose AI systems are placed on the EU market or affect people within it. Companies building or deploying AI that touches European users should treat EU AI Act compliance as a live, evolving obligation rather than a one-time checkbox.

Go deeper

Important caveats

  • Specific compliance deadlines, exemptions, and enforcement details have continued to evolve as implementing guidance is issued, so organizations should check current official EU sources rather than relying on a fixed snapshot.
  • This is general information, not legal advice, and companies operating in or selling into the EU should consult qualified counsel for their specific situation.

Frequently asked questions

Does the EU AI Act only apply to companies headquartered in Europe?

No. The Act is designed to apply extraterritorially, similar in spirit to how the GDPR reaches beyond EU borders. A US or Asia-based company can be covered if it provides an AI system that is used or whose output is used within the EU.

What happens if a company doesn't comply with the EU AI Act?

The Act establishes a framework for penalties tied to the severity of noncompliance, with the most serious violations, such as deploying prohibited AI practices, subject to significantly larger potential fines than lower-tier violations. Exact figures and enforcement mechanisms are set out in the official regulation text.

Does the EU AI Act ban any AI uses outright?

It designates a small set of practices, such as certain forms of manipulative AI and specific real-time biometric surveillance uses, as prohibited or tightly restricted, while most AI systems fall into lower-risk categories with lighter obligations.

Sources

  1. [1]EU AI Act — Regulatory Framework — European Commission
  2. [2]EUR-Lex Official Journal of the European Union — European Union
ET

Written by Editorial Team

Last updated July 25, 2026

Get one well-sourced answer a week

No spam. Unsubscribe anytime.