Back to Guides
Guide16 September 2026

What is the EU AI Act and why should developers care?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. What is the EU AI Act?
  2. Who does the EU AI Act apply to?
  3. How does the EU AI Act classify AI risk?
  4. What practices are prohibited outright?
  5. What obligations do high - risk AI systems face?
  6. What transparency duties apply to limited - risk AI?
  7. What are the obligations for general - purpose AI models?
  8. When does the EU AI Act become enforceable?
  9. How is the EU AI Act enforced and what are the penalties?
  10. How does the EU AI Act interact with other EU laws?
  11. What does this mean for developers and businesses?
  12. Key takeaways

What is the EU AI Act?

The EU AI Act is a Regulation (EU 2024/1689) that directly applies in all EU Member States without needing national transposition. It establishes a uniform, risk - based legal framework for the development, placement on the market, and use of AI systems.

Who does the EU AI Act apply to?

The Act covers providers placing AI systems or general - purpose AI (GPAI) models on the EU market, deployers located in the EU, and any non - EU provider or deployer whose AI output is used in the EU. It also applies to importers, distributors, product manufacturers, authorised representatives, and other "affected persons". Purely personal non - professional use, military or national - security applications, pure scientific - research activities, and open - source AI that is not high - risk are excluded.

How does the EU AI Act classify AI risk?

The regulation uses a five - tier classification:

  1. Unacceptable risk - outright prohibited (e.g., real - time remote biometric identification in public spaces, social - scoring).
  2. High - risk - subject to strict obligations such as risk - management, data - governance, technical documentation, human - in - the - loop oversight, conformity assessment, and post - market monitoring.
  3. Limited risk - limited transparency duties, for example informing users they are interacting with AI.
  4. Minimal risk - no specific obligations.
  5. General - purpose AI models - a separate regime with transparency, documentation and, for "systemic - risk" models, additional evaluation and mitigation duties.

What practices are prohibited outright?

The Act bans several high - impact practices, including:

What obligations do high - risk AI systems face?

High - risk systems must comply with a set of detailed requirements:

What transparency duties apply to limited - risk AI?

Under Article 50, providers of limited - risk AI must:

What are the obligations for general - purpose AI models?

For GPAI models the Act requires:

When does the EU AI Act become enforceable?

Key dates:

How is the EU AI Act enforced and what are the penalties?

National competent authorities, the EU AI Office and an AI Board coordinate supervision. Fines can reach up to 6 % of global annual turnover or €30 million, whichever is higher; SMEs face proportionally lower caps.

How does the EU AI Act interact with other EU laws?

The Act aligns with the New Legislative Framework (Reg. EC No 765/2008, Decision No 768/2008, Reg. EU 2019/1020) and does not prejudice existing regulations such as GDPR, product - safety, consumer - protection, employment or environmental law.

What does this mean for developers and businesses?

Key takeaways

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary