EU Artificial Intelligence Act (AI Act)
Regulation (EU) 2024/1689, the European Union's risk-based legal framework for artificial intelligence, which bans certain AI practices, sets requirements for high-risk AI systems and imposes duties on providers of general-purpose AI models.
The AI Act sorts AI systems by risk. Practices posing unacceptable risk, such as social scoring and certain manipulative or exploitative techniques, are prohibited. High-risk systems, including AI used as a safety component of products covered by EU product legislation such as machinery, and AI used in listed areas such as employment, critical infrastructure and access to essential services, must meet requirements for risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity. Some systems, such as chatbots, carry transparency obligations.
The Act entered into force on 1 August 2024 and applies in stages, beginning with the prohibitions and AI literacy provisions in February 2025 and obligations for general-purpose AI models from August 2025. It applies to providers placing AI systems on the EU market, wherever they are established, and to deployers using them in the EU. For manufacturers, AI that acts as a safety component of machinery or other regulated products may fall within the high-risk rules.
Most high-risk requirements apply later, and the European Commission has proposed adjustments to parts of the timeline, so the current official text and guidance should always be checked. Harmonised standards being developed by CEN and CENELEC are intended to give a presumption of conformity. Fines for prohibited practices can reach 35 million euros or 7 per cent of worldwide annual turnover. Interpretation of scope and obligations requires qualified legal advice.
Key points
- Regulation (EU) 2024/1689, in force since 1 August 2024.
- Risk-based: prohibited practices, high-risk systems and transparency duties.
- High-risk systems need risk management, human oversight and cybersecurity.
- Applies to non-EU providers placing AI systems on the EU market.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.