
The EU AI Act has come into law as of August 2, 2026, outlining what organisations can and can’t do when it comes to AI systems. An AI system is a machine-based system that is designed to operate with varying levels of autonomy, generating outputs such as predictions, content recommendations, or decisions that have the potential to influence physical or virtual environments.
Prohibited AI Systems
The following types of AI system are prohibited: deploying subliminal, manipulative, or deceptive techniques to distort behaviour and impair decision-making, exploiting vulnerabilities based on age, disability, or socioeconomic circumstances, and biometric categorisation systems inferring sensitive attributes.
Other prohibited systems include social scoring, assessing the risk of someone committing criminal offences solely based on profile or personality traits, compiling facial recognition databases by untargeted scraping of facial images, and inferring emotions in workplaces or educational institutions except for medical and safety reasons.
Compliance Requirements
Organisations must establish a risk management system throughout the high-risk AI system’s lifecycle, draw up technical documentation to approve compliance, and design their high-risk system for automatic record-keeping. They must also provide instructions for use for ‘downstream deployers’ and design high-risk systems to allow human oversight, while achieving robustness, accuracy, and cybersecurity.
Related: Everything you need to know about franchising
General Purpose AI models are subject to specific requirements, including creating technical documentation, compiling information and documents for downstream providers, and establishing a policy to respect the Copyright Directive. Model providers must publish a detailed summary about the content used for training these models.
Artificially generated images, audio, and text designed to look authentic must be labelled, and customers must know that they are interacting with chatbots or viewing images or text manipulated by AI.
Implementation and Enforcement
Fines of up to €15 million or 3% of the company’s global turnover will be imposed for breaches, whichever is greater.
Organisations should assess to what extent the AI rules apply to them from a governance perspective and how they should rethink their existing concepts.
Related: Final call for Tees Valley export fund
They should map the AI systems and content workflows they provide or use, build clear disclosures for deepfakes, and review processes with real accountability behind them.
The EU AI Act is part of a larger effort to regulate the use of AI and ensure that it is developed and used in a way that is transparent, accountable, and respectful of human rights. By establishing clear guidelines and requirements for the development and use of AI, the EU AI Act aims to promote trust and confidence in AI systems, and to ensure that they are used for the benefit of society as a whole.
The European AI Office will enforce the EU AI Act, monitoring compliance and investigating complaints. Organisations that fail to comply with the Act may face significant fines, and may also damage their reputation and lose the trust of their customers and stakeholders.