Prohibited AI. High-risk systems. Transparency requirements. General-purpose AI. For months, we have been hearing more and more terminology surrounding the European AI Act.
But what does it actually mean?
Here is a closer look at the European Union’s comprehensive legal framework for artificial intelligence — without getting lost in legal jargon.

Updated: August 30, 2026 · This article is intended for general information purposes only and does not constitute legal advice.

Artificial intelligence is developing at a pace that can be difficult to keep up with — even for people who work with technology every day.
Today, we talk about chatbots.
Tomorrow, AI agents.
And the day after that, systems capable of carrying out increasingly complex tasks autonomously.
At the same time, AI is entering companies, schools, public authorities, healthcare, HR departments and countless products.

Eventually, one question becomes unavoidable:

  • Do we actually need rules for all of this?

The European Union has given a fairly clear answer:

  • Yes.

With Regulation (EU) 2024/1689 — better known as the AI Act — the EU created a comprehensive legal framework specifically for artificial intelligence.
The regulation entered into force on August 1, 2024. But its provisions did not all become applicable at once. Instead, they have been introduced progressively. EUR-Lex

And this is where one of the most common misunderstandings begins.

When we say:

  • “The AI Act applies.”

That does not mean:

  • Every provision applies to every AI system from one particular date.

It is more complicated than that.

WHAT HAPPENED?

August 2, 2026 marked another major step in the implementation of the European AI Act. From that date, the European Commission’s AI Office, together with national authorities, began enforcing further provisions of the Act. New transparency requirements for certain AI systems also started to apply. Digitale Strategie Europas

But the road to this point began much earlier.
The AI Act entered into force on August 1, 2024.
On February 2, 2025, the first provisions became applicable, including rules on certain prohibited AI practices and AI literacy.
On August 2, 2025, governance rules and obligations for providers of general-purpose AI models — GPAI — followed.
Since August 2, 2026, another major part of the framework applies.
Other provisions will follow later. Under the current implementation timeline, for example, certain high-risk AI rules have later application dates. Digitale Strategie Europas

The AI Act is therefore less like one big regulatory starting gun and more like a multi-year implementation roadmap.

WHY DOES THE AI ACT EXIST IN THE FIRST PLACE?

To understand that, we first need to ask another question:

  • What is so different about AI that we need specific rules for it?

After all, laws existed before the AI Act.
Data protection law did not suddenly disappear.
Consumer protection already existed.
Product safety law existed too.
And other existing legislation continues to apply.
The basic argument behind the AI Act is that existing rules alone may not address all of the specific challenges created by AI systems.
AI systems can analyze patterns across enormous amounts of data.
They can prepare or influence decisions.
Their outputs may be difficult for users to understand.
And when something goes wrong, the consequences can sometimes affect large numbers of people.

That does not automatically mean:

  • AI is dangerous.

It means:

  • The risk depends on what the AI is being used for.

And that is one of the central ideas behind the AI Act.

NOT ALL AI POSES THE SAME RISK

One of the most important principles of the AI Act is surprisingly easy to understand:

  • The greater the potential risk of an AI application, the stricter the requirements may become.

The European approach is therefore risk-based.
The framework distinguishes between prohibited or unacceptable-risk practices, high-risk applications, AI systems subject to specific transparency obligations, and applications presenting minimal or no risk. Digitale Strategie Europas

And this distinction matters.
A spam filter is not the same as an AI system helping determine whether someone receives access to an essential service.
An AI opponent in a video game is not the same as software evaluating job applicants.
And generating an image for fun is not the same as producing a highly realistic deepfake of a real person.
The AI Act therefore does not simply treat every use of artificial intelligence in the same way.
Let’s look at the different areas more closely.

1. UNACCEPTABLE RISK: WHAT THE EU DOES NOT WANT TO ACCEPT

There are certain AI practices where the European Union essentially says:

  • This risk is not something we simply want to regulate. Certain practices are prohibited.

The prohibited practices include, under defined conditions, certain harmful manipulative or deceptive techniques, certain forms of social scoring, certain biometric categorisation practices and certain uses of real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrowly defined exceptions. Digitale Strategie Europas

Precision matters here.

The AI Act does not simply say:

  • “Facial recognition is completely banned in Europe.”

It regulates specific practices and specific contexts.
That is an important distinction.
And it is why simplified headlines about legislation should be treated with caution.
“EU bans AI” sounds dramatic.
But it does not accurately describe what the AI Act actually does.

2. HIGH-RISK AI: ALLOWED — BUT SUBJECT TO STRICT REQUIREMENTS

The next category is particularly interesting.

  • High-risk AI.

Here, the EU does not generally say:

  • This technology may not be used.

Instead, the approach is:

When AI is used in particularly sensitive areas and the legal criteria for classification as high-risk are met, additional requirements apply. This can include certain applications in areas such as biometrics, critical infrastructure, education, employment, migration, asylum and access to essential private and public services. Certain AI systems embedded in regulated products can also fall within the high-risk framework. Digitale Strategie Europas

One example is something we already encountered in the first article:

  • Recruitment.

If AI is used to analyze job applications, filter candidates or evaluate people in certain employment-related contexts, it can fall under the high-risk rules.

Why?

Because an error here may have far more serious consequences than a bad recommendation from a streaming service. The AI Act therefore establishes requirements for high-risk systems covering areas such as risk management, data and data governance, technical documentation, record-keeping, human oversight, accuracy, robustness and cybersecurity. But timing matters here.

Under the current implementation timeline, rules for systems used in certain high-risk areas listed in Annex III are scheduled to apply from December 2, 2027.

For certain high-risk AI systems embedded in regulated products, the relevant date is August 2, 2028. Digitale Strategie Europas

This is a good example of why saying:

  • “The entire AI Act has applied since August 2026.”

would be too simplistic.

3. TRANSPARENCY: WHEN WE SHOULD KNOW AI IS INVOLVED

This is where many people may begin to notice the AI Act in everyday life.
Article 50 transparency obligations started to apply on August 2, 2026. Digitale Strategie Europas

The basic idea is simple:

  • In certain situations, people should be able to recognize that they are dealing with AI or with AI-generated or manipulated content.

Certain interactive AI systems, for example, must inform people that they are interacting with an AI system rather than a human, unless this is already obvious.
There are also transparency requirements for certain artificially generated or manipulated content.
Deepfakes must be disclosed under the conditions set out in the Act.
And providers of certain generative AI systems must ensure that synthetic content is marked in a machine-readable format so that it can be detected as artificially generated or manipulated. Digitale Strategie Europas

Why does that matter?

Because AI can now generate images, voices and videos that may be extremely difficult for us to distinguish from authentic material. Technology is not the only thing changing.

Our information environment is changing too.

4. MINIMAL OR NO RISK: YES, THAT EXISTS TOO

This part often gets lost in public debate.
When people hear that the EU is “regulating AI,” it can sound as though anyone using an algorithm will suddenly need to fill out mountains of paperwork.
That is not the basic structure of the AI Act.
Many everyday AI applications fall into the minimal or no-risk category.
The Commission gives examples such as AI-enabled video games and spam filters.
For these systems, the AI Act does not introduce additional mandatory requirements simply because they use AI.
That distinction is crucial to understanding the framework.

The AI Act is not:

  • “AI is dangerous, so let’s regulate everything.”

It is closer to:

  • “Let’s look at the risk created by a particular application and respond accordingly.”

AND WHAT ABOUT CHATGPT & CO.?

Now things become slightly more complicated.

Modern AI models do not always fit neatly into the idea of:

  • One system. One task. One risk.

Large general-purpose AI models — GPAI models — can be used for very different purposes.

They can generate text.
Write code.
Summarize information.
Analyze images.
Or become the foundation for many other AI applications.
That is why the AI Act contains specific rules for providers of these models.
GPAI providers face obligations relating, among other things, to transparency and documentation and to compliance with EU copyright law.
For the most capable GPAI models presenting systemic risks, additional obligations apply, including requirements relating to risk assessment and mitigation, model evaluation, cybersecurity and the reporting of serious incidents. Digitale Strategie Europas

And this reveals something interesting about the AI Act.
It does not only look at the final AI product.
In some cases, it reaches further into the AI value chain.
Because one general-purpose model may later become part of hundreds or thousands of other applications.

SHOULD EVERY COMPANY NOW FEAR MILLION-EURO FINES?

No.
But companies should not simply ignore the AI Act either.

One of the first questions is not:

  • “How large could the fine be?”

It is:

  • “What role do we actually have?”

Does the company develop an AI system itself?
Does it provide one under its own name?
Does it simply use a third-party system?
Is the technology even an AI system within the meaning of the Regulation?
What does the system actually do?
And in what context is it being used?
Only then can you start determining which provisions may be relevant.

This is why the AI Act cannot be reduced to a simple checklist saying:

  • Company uses AI → complete these ten tasks.

The role of the organization and the specific use case matter.

WHAT DOES AI LITERACY HAVE TO DO WITH ALL OF THIS?

There is one provision of the AI Act that I find particularly interesting because it shows that regulation is not only about technology.

Article 4: AI literacy.

These rules have applied since February 2, 2025. Digitale Strategie Europas

Providers and deployers of AI systems are required to take measures, to their best extent, to ensure a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf.

That does not simply mean:

  • Everyone must now take an AI course.

The idea is more fundamental.
If people work with AI, they should have an appropriate understanding of what they are actually using.
What can the system do?
Where are its limitations?
What risks exist?
In what context is it being used?
And this is where regulation and education meet.
Responsible use of AI does not emerge from legislation alone.

It requires people who understand what they are doing.

DOES THE AI ACT SLOW DOWN INNOVATION?

And now we reach one of the biggest debates surrounding European AI policy.
One side sees the AI Act as an important framework for protection.
AI can affect fundamental rights, safety and wider societal processes. From this perspective, clear rules are necessary before harmful practices become normalised.
The other side warns about bureaucracy.
Complex requirements can be expensive, particularly for smaller companies and start-ups.
A global technology corporation may have entire legal and compliance departments.
A small European AI company may not.
This debate is far from over.

The fact that the EU has itself adjusted and simplified parts of the implementation framework illustrates something important:

  • Regulation is not static.

The challenge is therefore perhaps not simply:

  • Regulation or innovation?

A more useful question might be:

  • How can we create rules that protect people without unnecessarily preventing useful innovation?

Europe will have to keep answering that question as the technology develops.

WHAT DOES THE AI ACT MEAN FOR US?

For most people, the AI Act does not mean spending their evenings reading hundreds of pages of EU legislation.
But its effects will increasingly become visible.
We may more often be informed when we are interacting with AI.
We will encounter labels and technical markings for certain AI-generated or manipulated content.
Companies will have to think more carefully about which AI systems they use and what responsibilities come with them.
Developers and providers will have to deal with new requirements.
Authorities will enforce those rules.
Courts will interpret them.
And in some areas, rules will probably have to be adjusted because technology develops faster than lawmakers could anticipate.
That is not unusual.

Laws are not endpoints.

They are an attempt by society to create rules for a reality that continues to change.

THE AI ACT IS NOT A “LAW BOOK FOR EVERYTHING AI”

Perhaps this is the most important takeaway.
The AI Act does not answer every legal question involving artificial intelligence.
Data protection law still exists.
Copyright still exists.
Product liability still exists.
Employment law still exists.
Consumer protection still exists.

The AI Act sits alongside an already existing legal system.

So in the future, it will rarely be enough to respond to every legal question about artificial intelligence with:

  • “It must be in the AI Act.”

Sometimes the answer will be there.
Sometimes it will be found in the GDPR.
Sometimes in copyright law.
Sometimes in employment law.
And sometimes several areas of law will apply at the same time.
That is exactly what makes AI and law so interesting — and so challenging.

SO, WHERE DOES THAT LEAVE US?

The AI Act is no longer something waiting somewhere in the distant future.
It is European law whose provisions have progressively become applicable — and will continue to do so.
Some rules already apply.
Others will follow later.
Certain practices are prohibited.
Other AI systems are subject to specific requirements.
And many everyday AI applications remain in a low-risk category.

So neither panic nor the simplistic statement

  • “Brussels is regulating every AI system now.”

helps us understand what is actually happening.

What helps is understanding what is being regulated — and why.

Only then can we have a meaningful discussion about whether particular rules work, where they may go too far, and where something may still be missing. And that is why it is worth looking beyond the headline.

Not so someone else can tell us what to think. But so we have enough information to form our own view.

This article is intended for general information and educational purposes only. It does not constitute legal advice. The applicable legal provisions and circumstances of each individual case remain decisive.

Leave A Comment

Are you human? Please solve:Captcha