Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- What is the EU AI Act?
- Who does the EU AI Act apply to?
- How does the EU AI Act classify AI risk?
- What practices are prohibited outright?
- What obligations do high - risk AI systems face?
- What transparency duties apply to limited - risk AI?
- What are the obligations for general - purpose AI models?
- When does the EU AI Act become enforceable?
- How is the EU AI Act enforced and what are the penalties?
- How does the EU AI Act interact with other EU laws?
- What does this mean for developers and businesses?
- Key takeaways
What is the EU AI Act?
The EU AI Act is a Regulation (EU 2024/1689) that directly applies in all EU Member States without needing national transposition. It establishes a uniform, risk - based legal framework for the development, placement on the market, and use of AI systems.
Who does the EU AI Act apply to?
The Act covers providers placing AI systems or general - purpose AI (GPAI) models on the EU market, deployers located in the EU, and any non - EU provider or deployer whose AI output is used in the EU. It also applies to importers, distributors, product manufacturers, authorised representatives, and other "affected persons". Purely personal non - professional use, military or national - security applications, pure scientific - research activities, and open - source AI that is not high - risk are excluded.
How does the EU AI Act classify AI risk?
The regulation uses a five - tier classification:
- Unacceptable risk - outright prohibited (e.g., real - time remote biometric identification in public spaces, social - scoring).
- High - risk - subject to strict obligations such as risk - management, data - governance, technical documentation, human - in - the - loop oversight, conformity assessment, and post - market monitoring.
- Limited risk - limited transparency duties, for example informing users they are interacting with AI.
- Minimal risk - no specific obligations.
- General - purpose AI models - a separate regime with transparency, documentation and, for "systemic - risk" models, additional evaluation and mitigation duties.
What practices are prohibited outright?
The Act bans several high - impact practices, including:
- Real - time remote biometric identification in public spaces (unless a narrow law - enforcement exception applies).
- Government - run social - scoring systems.
- Subliminal manipulation that exploits vulnerabilities.
- AI that manipulates human behaviour causing physical or psychological harm.
What obligations do high - risk AI systems face?
High - risk systems must comply with a set of detailed requirements:
- Risk - management system (Article 9) - continuous identification, assessment and mitigation of risks.
- Data - governance and quality (Article 10) - ensure training, validation and test data are relevant, accurate and free from bias.
- Technical documentation & conformity assessment (Articles 11 - 13) - maintain comprehensive documentation and undergo a conformity assessment before market placement.
- Human - in - the - loop oversight (Article 14) - provide mechanisms for human monitoring and intervention.
- Post - market monitoring & incident reporting (Articles 15 - 16) - monitor AI performance after deployment and report serious incidents to authorities.
What transparency duties apply to limited - risk AI?
Under Article 50, providers of limited - risk AI must:
- Inform users when they are interacting with an AI system (e.g., chat - bots).
- Label synthetic media (deep - fakes, AI - generated images).
- Disclose the use of biometric categorisation or emotion - recognition functionalities.
What are the obligations for general - purpose AI models?
For GPAI models the Act requires:
- Detailed technical documentation covering model architecture, training data, computational resources and energy use.
- Information for downstream developers, including acceptable - use policies and licensing terms.
- For models deemed "systemic - risk", additional adversarial testing, risk - mitigation documentation and a higher level of evaluation.
When does the EU AI Act become enforceable?
Key dates:
- Regulation entered into force 1 August 2024.
- Prohibited practices and AI - literacy rules apply 2 February 2025.
- General - purpose AI obligations apply 2 August 2025.
- Most provisions become fully applicable 2 August 2026.
- High - risk classification deadline December 2027 and full high - risk obligations August 2028.
How is the EU AI Act enforced and what are the penalties?
National competent authorities, the EU AI Office and an AI Board coordinate supervision. Fines can reach up to 6 % of global annual turnover or €30 million, whichever is higher; SMEs face proportionally lower caps.
How does the EU AI Act interact with other EU laws?
The Act aligns with the New Legislative Framework (Reg. EC No 765/2008, Decision No 768/2008, Reg. EU 2019/1020) and does not prejudice existing regulations such as GDPR, product - safety, consumer - protection, employment or environmental law.
What does this mean for developers and businesses?
- Assess risk early - Determine whether your AI system falls into the unacceptable, high, limited, or minimal risk category.
- Document everything - Prepare risk - management files, data - governance records and technical documentation well before market launch.
- Implement transparency - Add clear notices for users when they interact with AI, especially for chat - bots or synthetic media.
- Plan for post - market monitoring - Set up processes to track performance, log incidents and report to authorities.
- Watch the timeline - Align product roadmaps with the staggered enforcement dates to avoid non - compliance penalties.
Key takeaways
- The EU AI Act is a Regulation that directly applies across the EU.
- It uses a risk - based classification, prohibiting the most dangerous AI uses.
- High - risk AI faces strict obligations covering risk management, data quality, documentation, human oversight and post - market monitoring.
- Limited - risk AI must provide user transparency.
- General - purpose AI models have a separate transparency and evaluation regime.
- Enforcement can levy fines up to 6 % of global turnover or €30 million.
- Compliance deadlines stretch from 2025 to 2028, so start preparing now.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.