Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the EU AI Act and why does it matter?
- Who does the regulation cover?
- How does the risk - based classification work?
- Which AI practices are banned outright?
- What obligations do high - risk AI providers face?
- When do the compliance deadlines apply?
- How are general - purpose AI models regulated?
- What are the enforcement mechanisms and potential penalties?
- How does the AI Act interact with existing EU legislation?
- What should companies do right now to prepare?
- Where can I find more detailed guidance?
Key takeaways
- The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 Aug 2024 and applies to providers, users and importers of AI systems targeting the EU market.
- It uses a four - tier risk classification: unacceptable, high, limited and minimal risk.
- Prohibited practices such as real - time remote biometric identification are banned outright.
- High - risk AI must undergo conformity assessment, keep technical documentation, monitor post - market performance and provide human - oversight.
- General - purpose AI models above a compute threshold face a transparency regime and must publish a model - card.
- Fines can reach €35 million or 7 % of worldwide turnover, whichever is higher.
- Main deadlines: 2 Feb 2025 for prohibited practices, 2 Aug 2025 for GPAI rules, 2 Dec 2027 for most high - risk AI, and 2 Aug 2028 for high - risk AI embedded in regulated products.
What is the EU AI Act and why does it matter?
The EU AI Act is a Europe - wide regulation that creates a uniform legal framework for developing, placing on the market and using AI systems. It matters because it applies extraterritorially, forces companies worldwide to meet EU standards if their AI impacts EU users, and introduces the first comprehensive risk - based approach to AI governance.
Who does the regulation cover?
The regulation covers any provider that places an AI system or a general - purpose AI model on the EU market, any user (deployer) of AI located in the EU or whose output is used in the EU, as well as importers, distributors, product manufacturers and authorised representatives. Natural persons using AI for purely personal non - professional activity, pure scientific research and exclusive military use are excluded.
How does the risk - based classification work?
| Risk tier | Definition | Typical obligations |
|---|---|---|
| Unacceptable | Practices that are outright prohibited (e.g., real - time remote biometric ID in public spaces) | No deployment allowed |
| High | AI that poses significant health, safety or fundamental - rights risks or is a safety component of regulated products | Conformity assessment, CE marking, technical documentation, post - market monitoring, data - governance, human - oversight |
| Limited | AI with limited impact, such as chatbots | Transparency notice to users |
| Minimal | Low impact AI | No specific EU obligations |
Which AI practices are banned outright?
Prohibited practices listed in Article 5 include real - time remote biometric identification in public spaces, biometric categorisation of individuals, government - run social - scoring and AI that manipulates human behaviour to cause physical or psychological harm. Companies must ensure these systems are not placed on the market or used in the EU.
What obligations do high - risk AI providers face?
High - risk providers must:
- Perform a conformity assessment (self - assessment or notified - body).
- Create and maintain detailed technical documentation and a register of logs.
- Implement post - market monitoring and report serious incidents to national authorities.
- Apply data - quality and governance measures, including data - set documentation and bias mitigation.
- Ensure human - oversight mechanisms are built into the system and provide clear user - facing transparency.
When do the compliance deadlines apply?
- 1 Aug 2024: Regulation entered into force.
- 2 Feb 2025: Prohibited - practice rules become applicable.
- 2 Aug 2025: General - purpose AI transparency and governance rules apply.
- 2 Dec 2027: Most standalone high - risk AI obligations must be met (after the AI Omnibus amendment).
- 2 Aug 2028: High - risk AI that is a safety component of regulated products must comply.
How are general - purpose AI models regulated?
Providers of GPAI models that exceed 10^25 FLOP must notify the European Commission, conduct systemic - risk assessments and publish a model - card with transparency information. They must also follow a “General - Purpose Code of Practice” overseen by the AI Office.
What are the enforcement mechanisms and potential penalties?
Violations of prohibited - practice rules can be fined up to €35 million or 7 % of worldwide annual turnover, whichever is higher. Other breaches (e.g., missing documentation, inadequate post - market monitoring) attract lower but still significant fines, enforced by national authorities coordinated by the European Artificial Intelligence Board.
How does the AI Act interact with existing EU legislation?
The AI Act works alongside the New Legislative Framework (Reg EC No 765/2008, Decision No 768/2008/EC, Reg EU 2019/1020) and complements sector - specific rules such as medical - device, automotive and product - safety directives. This coordination ensures that AI components embedded in regulated products are covered consistently.
What should companies do right now to prepare?
- Inventory every AI system, model or service that is offered to EU users.
- Classify each system using the four - tier risk matrix.
- For any high - risk or prohibited - risk AI, start building the required technical documentation and plan conformity - assessment pathways.
- If you develop large - scale GPAI, begin drafting a model - card and conduct a systemic - risk assessment.
- Establish a post - market monitoring process and assign a compliance lead.
- Monitor the European AI Board and AI Office for guidance updates.
Where can I find more detailed guidance?
- The official text of Regulation (EU) 2024/1689: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32024R1689
- Implementation guidance (PDF): https://futurium.ec.europa.eu/system/files/2026-07/Implementation-Guidance-EU-AI-Act_1.pdf
- AI Act service desk article 2 for scope details: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2
This article follows the latest publicly available facts as of September 2026.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.