Back to Guides
Guide16 September 2026

What You Need to Know About the EU AI Act 2024

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. When does the EU AI Act actually start?
  3. What risk categories does the EU AI Act define?
  4. Which AI systems fall into the high - risk category?
  5. What concrete obligations do high - risk providers face?
  6. Are there any exemptions from the EU AI Act?
  7. How are violations punished?
  8. Who enforces the EU AI Act?
  9. What is the implementation timeline?
  10. How does the EU AI Act affect companies outside the EU?
  11. What steps should developers take right now?
  12. Where can I find more detailed guidance?

Key takeaways

When does the EU AI Act actually start?

The regulation entered into force on 1 August 2024, which means it is legally binding from that date. Enforcement begins with the first phase on 2 Feb 2025, covering general provisions and prohibited practices.

What risk categories does the EU AI Act define?

The Act uses a four - tier risk model:

  1. Unacceptable risk - outright ban (e.g., real - time remote biometric identification in public spaces, social - scoring, subliminal manipulation, political deep - fakes).
  2. High risk - mandatory obligations such as risk management, data - governance, transparency, human - oversight and conformity assessment.
  3. Limited risk - only transparency duties, like informing users they are interacting with AI.
  4. Minimal risk - no specific EU obligations.

Which AI systems fall into the high - risk category?

High - risk AI includes systems that are safety components of regulated products (medical devices, transport) and those used in critical sectors such as employment, education, law - enforcement, migration, credit scoring and essential public services.

What concrete obligations do high - risk providers face?

Are there any exemptions from the EU AI Act?

Yes. The Act does not apply to AI used solely for military or national - security purposes, pure scientific research and development (unless later used for civilian purposes), or personal non - professional use.

How are violations punished?

Fines are tiered:

Who enforces the EU AI Act?

The European Commission hosts the AI Office for central oversight and guideline issuance. Each Member State designates a national competent authority to supervise the market, conduct surveillance and levy penalties.

What is the implementation timeline?

PhaseDateScope
Phase 12 Feb 2025General provisions and prohibited practices
Phase 22 Aug 2025Full high - risk obligations (conformity assessment, monitoring, etc.)
Phase 32 Aug 2026Complete set of obligations for providers, users and the AI Office

How does the EU AI Act affect companies outside the EU?

If an AI system is placed on the EU market, put into service, or its output is used within the Union, the regulation applies regardless of where the system is developed. Non - EU providers must therefore assess their products for compliance before offering them to EU customers.

What steps should developers take right now?

  1. Inventory AI systems - list every AI component, its purpose and the sector it serves.
  2. Classify risk - map each system to the four risk tiers.
  3. Gap analysis - for high - risk systems, compare current practices against the required obligations (documentation, testing, human - in - the - loop).
  4. Plan for conformity assessment - engage a notified body early if self - assessment is not permitted.
  5. Implement transparency notices - add user - facing disclosures for limited - risk AI.
  6. Set up post - market monitoring - define incident reporting processes and retain logs for ten years.
  7. Monitor national authority guidance - each Member State may publish additional requirements.

Where can I find more detailed guidance?

The official regulation text is available at the EU’s EUR - LEX portal. For practical checklists and sector - specific advice, see the EU AI Act website and relevant national competent authority publications.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary