Back to Guides
Guide16 September 2026

What You Need to Know About the EU Artificial Intelligence Act (Regulation 2024/1689)

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the EU Artificial Intelligence Act?
  3. How does the AI Act classify AI risk?
  4. Which AI practices are prohibited?
  5. What must high - risk AI providers do?
  6. What transparency is required for limited - risk AI?
  7. How are powerful foundation models regulated?
  8. Who enforces the AI Act?
  9. What are the key dates for compliance?
  10. Are there any exemptions?
  11. How does the AI Act affect businesses outside the EU?
  12. What should you do next?

Key takeaways

What is the EU Artificial Intelligence Act?

The AI Act is Regulation 2024/1689, adopted on 13 June 2024 and published in the Official Journal on 12 July 2024. It establishes a Europe - wide, risk - based regulatory regime for AI systems that applies to providers, deployers, importers, distributors, manufacturers, authorised representatives and affected persons inside the Union, regardless of where the provider is based.

How does the AI Act classify AI risk?

The Act splits AI into four categories: unacceptable - risk (banned outright), high - risk (subject to conformity - assessment, risk - management, post - market monitoring and CE marking), limited - risk (requires user transparency) and minimal - risk (no specific EU obligations). This tiered approach lets regulators focus enforcement on the most dangerous systems while keeping lighter rules for low - impact AI.

Which AI practices are prohibited?

Unacceptable - risk AI includes real - time remote biometric identification in public spaces (except narrowly defined law - enforcement exceptions), public - authority social - scoring, and manipulative techniques that exploit vulnerable groups. Providers of such systems must cease deployment immediately, as the regulation imposes no compliance pathway for these uses.

What must high - risk AI providers do?

High - risk providers must:

What transparency is required for limited - risk AI?

Providers of limited - risk AI must inform users that they are interacting with an AI system and disclose its capabilities, limitations and intended purpose (Articles 13 - 15). The notice must be clear, concise and presented before the user engages with the system.

How are powerful foundation models regulated?

General - purpose AI models, often called foundation models, are subject to additional duties: providers must publish technical documentation, supply information for downstream developers, and disclose training - data characteristics. Oversight will be coordinated by a new AI Office within the European Commission, which may issue delegated acts to fine - tune the rules.

Who enforces the AI Act?

Enforcement is shared between the EU AI Office, national competent authorities in each Member State, and market - surveillance authorities that conduct post - market checks. These bodies can impose administrative fines up to 30 % of a company's annual worldwide turnover or a fixed amount, whichever is higher, with proportionally lower caps for SMEs.

What are the key dates for compliance?

Are there any exemptions?

AI systems used exclusively for military, defence or national - security purposes and pure scientific research are exempt, unless they later serve civilian applications.

How does the AI Act affect businesses outside the EU?

If a non - EU provider offers AI services to EU customers or targets EU users, the Act applies to them as "providers" or "distributors" in the Union. This extraterritorial reach means foreign companies must assess their offerings against the EU risk categories and potentially implement CE marking for high - risk products.

What should you do next?

  1. Inventory all AI systems you develop, deploy or distribute.
  2. Map each system to the AI Act risk categories.
  3. For high - risk and general - purpose models, start building risk - management documentation and plan CE marking.
  4. Implement clear user notices for any limited - risk AI.
  5. Monitor the EU AI Office for delegated acts and guidance updates.

The information above is based on Regulation 2024/1689 and publicly available EU documentation.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary