
Trade Me Houses for Sale: Fees, Tips & Comparison
The EU AI Act is already reshaping how providers must build, test, and deploy systems for European users. High-risk obligations begin binding most systems in August 2026, but prohibited practices are already enforceable as of February 2025.
Quick snapshot
- The AI Act classifies systems into unacceptable, high, limited, and minimal risk tiers (EU AI Act Explorer).
- High-risk systems must pass a conformity assessment and maintain human oversight (European Parliament).
- Unacceptable risk (e.g., social scoring, real-time biometric surveillance in public) is outright banned (European Commission).
- Prohibitions on unacceptable risk took effect February 2025 (AI Act Timeline).
- High-risk rules for most systems are enforceable from August 2026 (White & Case AI Tracker).
- Full compliance, including for high-risk AI systems embedded in regulated products, by August 2027 (Official Journal of the EU).
- U.S. state laws (e.g., Colorado AI Act) and emerging frameworks in Japan, Canada, and Brazil mirror EU risk-tiering (OECD AI Policy Observatory).
- China’s 2023 generative AI regulation diverges sharply on content control but aligns on transparency (CSET Georgetown).
- Compliance with the EU Act is a de facto global standard for any non-EU firm serving EU users (Bloomberg).
- AI Office within the European Commission oversees general-purpose AI (European Commission AI Office).
- National market surveillance authorities handle local enforcement and fines (EPRS).
- Fines can reach up to 7% of global annual turnover or €35 million, whichever is higher (Council of the EU).
The core structure: risk-based tiers
The AI Act doesn’t apply a single rule to all systems. It uses a four-tier pyramid: unacceptable risk (banned), high risk (regulated), limited risk (transparency obligations), and minimal risk (no obligations). The burden is intentionally graduated. Systems classified as “unacceptable risk” — including social scoring by governments, real-time remote biometric identification in public spaces for law enforcement, and manipulative AI that exploits vulnerabilities — are simply prohibited from the February 2025 compliance date. There is no grace period for these systems.
“High risk” is where the heavy operational lift sits. This includes AI used in critical infrastructure, education, employment, law enforcement, migration, and access to essential services like credit and insurance. High-risk providers must implement a risk management system, ensure data governance and transparency, enable human oversight, and achieve accuracy and cybersecurity standards. Crucially, these systems require a conformity assessment — often self-declaration unless the system is a biometric or safety component of a regulated product, in which case a notified body must review it. A dedicated “high-risk” list is maintained by the European Commission and will be updated as applications evolve.
The lower-risk tiers impose lighter but real duties. Limited-risk systems (like chatbots or deepfake generators) must comply with transparency obligations: users must know they are interacting with an AI. This includes labeling deepfakes and disclosing that generated content is AI-produced. Minimal-risk systems, such as AI-powered video games or spam filters, face no mandatory requirements under the Act, though providers may voluntarily adopt codes of conduct. The message is clear: the higher the risk to fundamental rights or safety, the higher the compliance cost.
Timeline in motion
The phased implementation means some obligations are already law. The February 2025 deadline for unacceptable-risk prohibitions is already in force. By August 2026, high-risk rules for most AI systems become enforceable, including obligations for providers and deployers to maintain human oversight and transparency.
For high-risk systems that fall within the scope of existing product safety legislation — such as medical devices, aviation, and machinery — an additional year is granted, pushing full compliance to August 2027. General-purpose AI models, including foundation models like GPT-4 and Llama, face a separate regime: providers must be transparent about training data (including a summary of copyrighted content used) and meet cybersecurity standards, with additional obligations for “systemic risk” models (measured by cumulative compute exceeding 10^25 FLOPs).
The clock is tight. Any provider still relying on early 2024’s grace periods should note that the regulatory machinery is already staffed: the EU AI Office is actively engaging with industry, and national authorities are appointing market surveillance bodies. The gap between rule and enforcement is closing.
The EU AI Act officially entered into force August 1, 2024, and the February 2, 2025 deadline for prohibited practices has passed. The next major deadline — August 2, 2026 — triggers high-risk rules for most non-embedded systems. Fines scale with global turnover up to 7%, not just EU revenue. The “Brussels effect” is visible: South Korea, Japan, and Brazil are actively modeling risk-tier legislation on the EU structure, according to the OECD AI Policy Observatory.
Global alignment and divergence
The AI Act’s reach extends far beyond the EU’s borders through the “Brussels effect.” Any company that develops or deploys AI for use within the EU — regardless of where the company is headquartered — must comply. This has already reshaped how global firms approach AI governance. The U.S. National Institute of Standards and Technology (NIST) AI Risk Management Framework has been mapped by some firms to the EU’s high-risk requirements, even though it remains voluntary at the federal level.
State-level activity in the U.S. adds a complicating layer. Colorado’s AI Act (SB 24-205), effective 2026, uses a similar risk-tier approach and requires impact assessments for high-risk systems, creating a patchwork of compliance obligations for firms operating across multiple states. Unlike the EU’s single regulatory authority, U.S. firms face fragmentation across state lines. Meanwhile, China’s 2023 AI regulation focuses heavily on content control, data sovereignty, and alignment with socialist core values, diverging sharply on the ground of free expression but converging on transparency and model registration. Japan has taken a soft-law approach, pushing guidelines rather than binding regulation, while Canada’s proposed AIDA (Artificial Intelligence and Data Act) closely follows the EU’s risk-tier model.
The net effect: the EU Act functions as the most comprehensive binding framework globally, and non-EU nations are using it as a reference point. This creates both an opportunity and a risk for multinational providers: aligning with the EU’s standard can streamline compliance in other jurisdictions, but it may also require over-compliance in regions with lighter legal frameworks, increasing operational cost for no local benefit.
Enforcement and the stakes
The enforcement structure is a dual-key system. The European Commission’s AI Office handles general-purpose AI and cross-border cases, while national authorities (like Ireland’s DPC or Germany’s BfDI) handle local surveillance. This mirrors the GDPR’s structure but with a key difference: the AI Office has direct enforcement power over foundation models, not just oversight. Fines of up to 7% of global annual turnover or €35 million — whichever is higher — apply to violations of prohibited practices. Non-compliance with high-risk obligations draws up to 3% or €15 million, while incorrect information to regulators attracts 1.5% or €7.5 million.
The comparison with GDPR fines is instructive. GDPR’s maximum is 4% of global turnover, and the average GDPR fine, though growing, remains in the low millions. AI Act fines are structurally higher — up to 7% — and the expectation is that the first high-profile enforcement will be a deterrent case. The European Consumer Organization (BEUC) has already signaled it will file complaints on unfair AI practices, suggesting enforcement will not rely solely on regulator surveillance but will also be driven by civil society and competitor complaints.
Individual rights are also embedded in the Act. Anyone affected by a high-risk AI system has the right to an explanation of the decision, the right to complain to a national authority, and the right to seek judicial redress. This opens the door to litigation beyond regulatory fines, including class actions from consumer groups.
The definition of “substantial modification” — a change to a high-risk system that triggers a new conformity assessment — remains vague. Guidance from the European Commission’s AI Office is expected but not yet published. Providers face a practical risk: if they continuously update a system via machine learning, each update could technically be a “substantial modification,” requiring a new assessment. The line between routine improvement and substantial change is the single biggest operational ambiguity in the Act. Additionally, the interplay between the AI Act and the GDPR on data processing for AI training — particularly the legal basis for using personal data — remains contested among EU data protection authorities.
What comes next
The AI Act is not a static document. The European Commission is already tasked with producing delegated acts that will refine technical specifications, update the high-risk list, and define the scope of general-purpose AI obligations. Codes of practice for general-purpose AI — including transparency and copyright compliance — are due to be finalized by mid-2025. The first practical stress test will be how the AI Office handles foundation model enforcement, particularly for non-EU developers like OpenAI and Google.
Providers should expect the period between August 2026 and August 2027 to be a litigation-heavy phase as the boundaries of high-risk classification are tested. The real-world political economy of AI regulation will also matter: a future European Commission could tighten or loosen obligations depending on market competitiveness concerns, though the current structure is designed to be difficult to reverse.
The biggest uncertainty is enforcement intensity. The GDPR created a cottage industry of data protection advisors and litigation, but its enforcement has been uneven across member states. The AI Act learns from that experience by centralizing power in the AI Office and standardizing conformity assessments. Whether that actually produces uniform enforcement or creates a new two-tier compliance market — fast-track for funded firms, slow-lane for everyone else — remains to be seen.