Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the EU Artificial Intelligence Act?
- How does the AI Act classify AI risk?
- Which AI practices are prohibited?
- What must high - risk AI providers do?
- What transparency is required for limited - risk AI?
- How are powerful foundation models regulated?
- Who enforces the AI Act?
- What are the key dates for compliance?
- Are there any exemptions?
- How does the AI Act affect businesses outside the EU?
- What should you do next?
Key takeaways
- The AI Act classifies AI into four risk levels and bans unacceptable - risk practices outright.
- High - risk systems must implement a risk - management system, maintain technical documentation, undergo conformity assessment, and bear a CE mark.
- Limited - risk AI requires clear user notices about AI interaction, capabilities, and limitations.
- General - purpose foundation models face extra transparency duties and will be overseen by a new EU AI Office.
- Full compliance obligations start on 2 August 2026; earlier milestones include AI - literacy rules (Feb 2025) and model - specific rules (Aug 2025).
What is the EU Artificial Intelligence Act?
The AI Act is Regulation 2024/1689, adopted on 13 June 2024 and published in the Official Journal on 12 July 2024. It establishes a Europe - wide, risk - based regulatory regime for AI systems that applies to providers, deployers, importers, distributors, manufacturers, authorised representatives and affected persons inside the Union, regardless of where the provider is based.
How does the AI Act classify AI risk?
The Act splits AI into four categories: unacceptable - risk (banned outright), high - risk (subject to conformity - assessment, risk - management, post - market monitoring and CE marking), limited - risk (requires user transparency) and minimal - risk (no specific EU obligations). This tiered approach lets regulators focus enforcement on the most dangerous systems while keeping lighter rules for low - impact AI.
Which AI practices are prohibited?
Unacceptable - risk AI includes real - time remote biometric identification in public spaces (except narrowly defined law - enforcement exceptions), public - authority social - scoring, and manipulative techniques that exploit vulnerable groups. Providers of such systems must cease deployment immediately, as the regulation imposes no compliance pathway for these uses.
What must high - risk AI providers do?
High - risk providers must:
- Implement a risk - management system (Article 9).
- Prepare comprehensive technical documentation and undergo a conformity - assessment, either self - assessment or third - party.
- Set up post - market monitoring and incident - reporting processes.
- Affix a CE marking before placing the system on the market. These obligations ensure that high - risk AI can be audited throughout its lifecycle.
What transparency is required for limited - risk AI?
Providers of limited - risk AI must inform users that they are interacting with an AI system and disclose its capabilities, limitations and intended purpose (Articles 13 - 15). The notice must be clear, concise and presented before the user engages with the system.
How are powerful foundation models regulated?
General - purpose AI models, often called foundation models, are subject to additional duties: providers must publish technical documentation, supply information for downstream developers, and disclose training - data characteristics. Oversight will be coordinated by a new AI Office within the European Commission, which may issue delegated acts to fine - tune the rules.
Who enforces the AI Act?
Enforcement is shared between the EU AI Office, national competent authorities in each Member State, and market - surveillance authorities that conduct post - market checks. These bodies can impose administrative fines up to 30 % of a company's annual worldwide turnover or a fixed amount, whichever is higher, with proportionally lower caps for SMEs.
What are the key dates for compliance?
- 1 August 2024 - Regulation enters into force.
- Feb 2025 - AI - literacy obligations for providers and users become applicable.
- Aug 2025 - Rules for general - purpose AI models and activation of the AI Office.
- Feb 2026 - Full set of high - risk obligations (risk - management, CE marking, etc.) start.
- 2 August 2026 - Complete regime, including market - surveillance and penalties, becomes fully operational.
Are there any exemptions?
AI systems used exclusively for military, defence or national - security purposes and pure scientific research are exempt, unless they later serve civilian applications.
How does the AI Act affect businesses outside the EU?
If a non - EU provider offers AI services to EU customers or targets EU users, the Act applies to them as "providers" or "distributors" in the Union. This extraterritorial reach means foreign companies must assess their offerings against the EU risk categories and potentially implement CE marking for high - risk products.
What should you do next?
- Inventory all AI systems you develop, deploy or distribute.
- Map each system to the AI Act risk categories.
- For high - risk and general - purpose models, start building risk - management documentation and plan CE marking.
- Implement clear user notices for any limited - risk AI.
- Monitor the EU AI Office for delegated acts and guidance updates.
The information above is based on Regulation 2024/1689 and publicly available EU documentation.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.