Skip to content
Compliance

EU AI Act

Updated Aug 20261 min read
Definition

The EU AI Act is the European Union's comprehensive regulation on artificial intelligence, published in the Official Journal in July 2024. It classifies AI systems by risk tier (unacceptable, high, limited, minimal) and imposes graduated compliance obligations on providers and deployers, phased in by obligation type through 2028.

Why It Matters

The EU AI Act operates on product safety logic, not data protection logic. Where GDPR governs how data is handled, the AI Act governs whether an AI system can be placed on the EU market at all. If a high-risk system cannot demonstrate conformity by the applicable deadline, it faces a hard market-access barrier.

Enforcement unfolds in phases. Prohibited-practice bans took effect in February 2025 and general-purpose AI obligations in August 2025. Transparency obligations under Article 50, which require AI systems that interact with people to disclose their nature, apply from August 2026, which is also when high-risk obligations apply under the Act as enacted. Those high-risk deadlines are being deferred: the Digital Omnibus on AI moves stand-alone systems under Annex III to December 2027 and systems embedded in regulated products under Annex I to August 2028. Check whether the Omnibus has been published in the Official Journal before relying on either date, because the deferral binds only on publication.

For organizations deploying AI agents in EU markets, the Act creates direct obligations around risk assessment, human oversight and audit trails. Agent governance systems that log every action and enforce policy at runtime provide the operational infrastructure these obligations require.