AI Policy, Law & Safety · AI Regulation
What Is the EU AI Act and Who Does It Apply To?
The EU AI Act is the European Union's comprehensive law governing artificial intelligence, sorting AI systems into risk tiers with different obligations; it applies not just to companies based in the EU but to any provider or deployer whose AI system's output is used within the EU market.
Legal disclaimer
This page provides general information only and is not legal advice. Laws vary by jurisdiction and change over time. Consult a licensed attorney in your jurisdiction before making decisions based on this content.
Key takeaways
- The EU AI Act uses a risk-based framework, grouping AI systems into categories such as unacceptable risk, high risk, limited risk, and minimal risk.
- It has extraterritorial reach, meaning companies outside the EU can still fall under its scope if their AI systems are placed on the EU market or affect people in the EU.
- Obligations differ sharply by risk tier — a chatbot has lighter transparency duties than an AI system used in hiring, credit scoring, or law enforcement.
- The Act designates certain uses, like real-time biometric surveillance in public spaces for law enforcement, as largely prohibited, subject to narrow exceptions.
- Provisions are phased in over time rather than taking effect all at once, giving organizations a transition period to reach compliance.
A Risk-Based Framework for AI Across Europe
The EU AI Act is the European Union’s flagship law for regulating artificial intelligence, and its central idea is that not all AI systems deserve the same level of scrutiny. Instead of applying one uniform set of rules to every AI product, the Act sorts systems into tiers based on the potential harm they could cause — ranging from practices considered unacceptable and largely banned, through “high-risk” systems subject to strict obligations, down to limited-risk systems that mainly require transparency, and minimal-risk systems that face few or no specific new obligations.
This structure means a customer-service chatbot and an AI system used to screen job applicants are treated very differently under the law, even though both are “AI.” The chatbot might only need to disclose that users are interacting with a machine, while the hiring tool could be classified as high-risk and subject to requirements around risk management, data quality, documentation, and human oversight.
Why the Act Reaches Beyond the EU’s Borders
One of the most consequential design choices in the EU AI Act is its extraterritorial scope. The regulation is not limited to companies incorporated in EU member states. Instead, it generally applies to any provider that places an AI system on the EU market, and to any deployer whose AI system’s output is used within the EU — regardless of where the company itself is headquartered.
This mirrors the approach the EU took with the GDPR for data privacy: a US-based AI company that sells its product to European customers, or whose AI output reaches people in the EU, can find itself squarely within the law’s reach even without a physical presence in Europe. This is a major reason the Act has drawn attention from AI developers worldwide, not just European ones — companies building foundation models, generative AI tools, or embedded AI features often need to consider EU obligations as part of their global compliance planning, even if their primary market is elsewhere.
How This Plays Out for Different Kinds of AI Products
Consider the difference between a company selling AI-powered spam filters and one selling AI-based credit-scoring software to European banks. The spam filter is likely to fall into a lower-risk category, since misclassifying an email carries limited consequences and minimal obligations attach to it. The credit-scoring tool, by contrast, directly affects consumers’ access to financial services and is more likely to be treated as high-risk, triggering obligations such as maintaining technical documentation, enabling human oversight, and ensuring the system underwent adequate risk assessment before deployment.
Generative AI and general-purpose AI models are also addressed within the framework, with additional transparency expectations, such as disclosing that content was AI-generated in certain contexts. Because the Act phases in its various obligations over time rather than all at once, organizations operating in this space are generally expected to track the applicable timeline for the categories of AI systems they build or deploy.
Bottom Line
The EU AI Act creates a tiered system of obligations based on how risky an AI application is judged to be, and its reach extends to any organization — regardless of home country — whose AI systems are placed on the EU market or affect people within it. Companies building or deploying AI that touches European users should treat EU AI Act compliance as a live, evolving obligation rather than a one-time checkbox.
Go deeper
Important caveats
- Specific compliance deadlines, exemptions, and enforcement details have continued to evolve as implementing guidance is issued, so organizations should check current official EU sources rather than relying on a fixed snapshot.
- This is general information, not legal advice, and companies operating in or selling into the EU should consult qualified counsel for their specific situation.
Frequently asked questions
Does the EU AI Act only apply to companies headquartered in Europe?
No. The Act is designed to apply extraterritorially, similar in spirit to how the GDPR reaches beyond EU borders. A US or Asia-based company can be covered if it provides an AI system that is used or whose output is used within the EU.
What happens if a company doesn't comply with the EU AI Act?
The Act establishes a framework for penalties tied to the severity of noncompliance, with the most serious violations, such as deploying prohibited AI practices, subject to significantly larger potential fines than lower-tier violations. Exact figures and enforcement mechanisms are set out in the official regulation text.
Does the EU AI Act ban any AI uses outright?
It designates a small set of practices, such as certain forms of manipulative AI and specific real-time biometric surveillance uses, as prohibited or tightly restricted, while most AI systems fall into lower-risk categories with lighter obligations.
Related questions
- What Is a 'High-Risk' AI System Under EU Regulation?
- Does the United States Have a Federal AI Law?
- What is the precautionary principle and how does it apply to ai regulation?
- How do different countries define what counts as a high risk ai system?
- What Is the NIST AI Risk Management Framework?
- What is a model card and is publishing one legally required anywhere?
Sources
- [1]EU AI Act — Regulatory Framework — European Commission
- [2]EUR-Lex Official Journal of the European Union — European Union
Written by Editorial Team
Last updated July 25, 2026
Get one well-sourced answer a week
No spam. Unsubscribe anytime.