Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- When does the EU AI Act actually start?
- What risk categories does the EU AI Act define?
- Which AI systems fall into the high - risk category?
- What concrete obligations do high - risk providers face?
- Are there any exemptions from the EU AI Act?
- How are violations punished?
- Who enforces the EU AI Act?
- What is the implementation timeline?
- How does the EU AI Act affect companies outside the EU?
- What steps should developers take right now?
- Where can I find more detailed guidance?
Key takeaways
- The EU AI Act (Regulation 2024/1689) becomes legally binding on 1 August 2024.
- It classifies AI into four risk levels and bans unacceptable - risk uses.
- High - risk AI must meet conformity assessment, documentation, post - market monitoring and human - in - the - loop requirements.
- Penalties range up to €35 million or 7 % of worldwide turnover.
- Implementation phases start 2 Feb 2025 and finish 2 Aug 2026, giving firms time to comply.
When does the EU AI Act actually start?
The regulation entered into force on 1 August 2024, which means it is legally binding from that date. Enforcement begins with the first phase on 2 Feb 2025, covering general provisions and prohibited practices.
What risk categories does the EU AI Act define?
The Act uses a four - tier risk model:
- Unacceptable risk - outright ban (e.g., real - time remote biometric identification in public spaces, social - scoring, subliminal manipulation, political deep - fakes).
- High risk - mandatory obligations such as risk management, data - governance, transparency, human - oversight and conformity assessment.
- Limited risk - only transparency duties, like informing users they are interacting with AI.
- Minimal risk - no specific EU obligations.
Which AI systems fall into the high - risk category?
High - risk AI includes systems that are safety components of regulated products (medical devices, transport) and those used in critical sectors such as employment, education, law - enforcement, migration, credit scoring and essential public services.
What concrete obligations do high - risk providers face?
- Conformity assessment - either self - assessment where allowed or assessment by a notified body.
- Technical documentation - maintain detailed records for ten years.
- Post - market monitoring - plan, monitor and report serious incidents.
- Human - in - the - loop and transparency - provide clear information to users about the AI system’s capabilities and limits.
Are there any exemptions from the EU AI Act?
Yes. The Act does not apply to AI used solely for military or national - security purposes, pure scientific research and development (unless later used for civilian purposes), or personal non - professional use.
How are violations punished?
Fines are tiered:
- Up to €35 million or 7 % of worldwide annual turnover for prohibited - practice breaches or data - related violations.
- Up to €15 million or 3 % of worldwide turnover for other non - compliance such as missing documentation.
- Up to €7.5 million or 1.5 % for providing false information to authorities.
Who enforces the EU AI Act?
The European Commission hosts the AI Office for central oversight and guideline issuance. Each Member State designates a national competent authority to supervise the market, conduct surveillance and levy penalties.
What is the implementation timeline?
| Phase | Date | Scope |
|---|---|---|
| Phase 1 | 2 Feb 2025 | General provisions and prohibited practices |
| Phase 2 | 2 Aug 2025 | Full high - risk obligations (conformity assessment, monitoring, etc.) |
| Phase 3 | 2 Aug 2026 | Complete set of obligations for providers, users and the AI Office |
How does the EU AI Act affect companies outside the EU?
If an AI system is placed on the EU market, put into service, or its output is used within the Union, the regulation applies regardless of where the system is developed. Non - EU providers must therefore assess their products for compliance before offering them to EU customers.
What steps should developers take right now?
- Inventory AI systems - list every AI component, its purpose and the sector it serves.
- Classify risk - map each system to the four risk tiers.
- Gap analysis - for high - risk systems, compare current practices against the required obligations (documentation, testing, human - in - the - loop).
- Plan for conformity assessment - engage a notified body early if self - assessment is not permitted.
- Implement transparency notices - add user - facing disclosures for limited - risk AI.
- Set up post - market monitoring - define incident reporting processes and retain logs for ten years.
- Monitor national authority guidance - each Member State may publish additional requirements.
Where can I find more detailed guidance?
The official regulation text is available at the EU’s EUR - LEX portal. For practical checklists and sector - specific advice, see the EU AI Act website and relevant national competent authority publications.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.