The EU AI Act, explained for teams building with AI

The EU AI Act is the first comprehensive law on artificial intelligence. It sorts AI systems by risk and phases in obligations from 2025 to 2028. Here is what applies, and when.

Assess EU AI Act free

12 questions · about 8 min · no signup

Type
EU regulation
Reference
Regulation (EU) 2024/1689
In force since
1 August 2024
Maximum fine
€35M or 7% of turnover

This guide is growing. A fuller EU AI Act guide, with requirement-by-requirement detail and worked examples, is being written. Last updated 1st October 2026.

On this page
01

What is the EU AI Act?

The AI Act sets harmonised rules for AI systems placed on the market or used in the EU. Like GDPR, it reaches companies outside the EU when their AI systems, or the output of those systems, are used in the EU.

It separates roles. Providers develop an AI system, or have one developed, and place it on the market under their name. Deployers use an AI system in a professional setting. Most obligations sit with providers, but deployers have duties too.

02

The four risk levels

Risk level

Unacceptable

Examples

Social scoring, manipulative AI, emotion recognition at work or school

What it means

Banned since 2 February 2025

Risk level

High

Examples

AI in hiring, credit scoring, education and essential services, and safety parts of regulated products

What it means

Strict requirements before and after the system reaches the market

Risk level

Limited (transparency)

Examples

Chatbots, deepfakes, AI-generated content

What it means

People must be told they are dealing with AI, or that content is AI-generated

Risk level

Minimal

Examples

Spam filters, AI in video games

What it means

No new obligations

General-purpose AI models, such as the large language models behind many chatbots, have a separate set of rules for the companies that provide them.

03

When each part applies

Date

2 February 2025

What applies

Banned practices and AI literacy

Reference

Art. 5, Art. 4

Date

2 August 2025

What applies

General-purpose AI models, governance and penalties

Reference

Art. 53 to 55, Art. 99

Date

2 August 2026

What applies

Transparency obligations

Reference

Art. 50

Date

2 December 2027

What applies

High-risk systems listed in Annex III

Reference

Annex III

Date

2 August 2028

What applies

High-risk AI in regulated products

Reference

Annex I

The high-risk dates were moved back by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026. It is a delay, not a cancellation. AI systems already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking to the content they generate.

04

What high-risk AI systems must do

  • A risk management system across the whole life cycle (Article 9).
  • Data governance: training data that is relevant, representative and examined for bias (Article 10).
  • Technical documentation (Article 11) and automatic logging (Article 12).
  • Transparency and instructions for use for deployers (Article 13).
  • Human oversight that lets people understand, intervene in and override the system (Article 14).
  • Accuracy, robustness and cybersecurity (Article 15).
  • A quality management system (Article 17), a conformity assessment and registration before the system reaches the market.

Deployers of high-risk systems must use them according to their instructions, assign human oversight, monitor them and keep their logs. Some deployers must also carry out a fundamental rights impact assessment (Article 27).

05

EU AI Act fines

Breach

Banned AI practices

Maximum fine

€35M or 7% of worldwide annual turnover

Reference

Art. 99(3)

Breach

Most other obligations, including high-risk and transparency rules

Maximum fine

€15M or 3%

Reference

Art. 99(4)

Breach

Incorrect or misleading information to authorities

Maximum fine

€7.5M or 1%

Reference

Art. 99(5)

The higher of the two amounts applies, except for SMEs and startups, where the lower one does.

06

Where teams usually fall short

  • No inventory of the AI systems in use and their risk level.
  • Chatbots and AI features that do not tell users they are AI.
  • No human oversight designed in for AI that makes or supports decisions about people.
  • Training data with undocumented sources or no bias checks.
  • No technical documentation or logging for systems that may be high-risk.
07

What the free assessment covers

The free SwaSec EU AI Act assessment asks 12 questions across 5 domains and takes about 8 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.

  • AI System Classification (Art. 5-6). Risk classification of AI systems and prohibited AI practices.
  • High-Risk AI Requirements (Art. 8-15). Mandatory requirements for high-risk AI systems covering risk management, data governance, documentation, transparency, human oversight, and robustness.
  • Transparency for All AI (Art. 50). Transparency obligations applying to all AI systems, including chatbots and AI-generated content.
  • General-Purpose AI Models (Art. 51-56). Obligations for providers and deployers of general-purpose AI models including foundation models and LLMs.
  • Governance and Compliance (Art. 16-27). Quality management systems, provider obligations, and deployer obligations for high-risk AI systems.

Start the EU AI Act assessment. It is a self-assessment, not an audit or a certification.

08

How EU AI Act overlaps with other frameworks

EU AI Act shares 4 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.

  • Risk Assessment, shared with ISO 27001, ISO 42001, SOC 2 and GDPR. Asked separately, because each framework wants something different.
  • Data Governance, shared with ISO 42001 and GDPR. Asked separately, because each framework wants something different.
  • Human Oversight of AI, shared with ISO 42001. Asked once.
  • Transparency, shared with GDPR. Asked separately, because each framework wants something different.
09

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes, when their AI systems are placed on the market in the EU or their output is used in the EU, wherever the company is based.

Was the EU AI Act delayed?

Only the high-risk rules. The Digital Omnibus moved them to 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products. The bans, AI literacy, general-purpose AI rules and transparency obligations already apply.

Is my chatbot high-risk?

Usually not. Most chatbots are limited risk: you must tell people they are talking to an AI. A chatbot becomes high-risk when it is used for a high-risk purpose, such as screening job candidates.

What is the difference between a provider and a deployer?

A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system in a professional setting. A company can be both.

What does the free SwaSec EU AI Act assessment cover?

12 questions across 5 domains, taking about 8 minutes, with no signup. It gives you a score for EU AI Act, the gaps it found, and the clause, control or article each gap relates to.

10

Sources

This guide is general information, not legal advice. Last updated 1st October 2026.

The other frameworks