Essentials

What you need to know about the EU AI Act 

The EU AI Act sets out rules for the safe and trustworthy use of artificial intelligence in Europe. Here is what the Act forbids, includes and doesn't include.

About the EU AI Act

The AI Act is a new set of rules for using artificial intelligence in the EU. It is designed to protect people’s safety and fundamental rights. The law categorizes AI systems by the level of risk they pose. High-risk AI systems must follow strict rules and be very transparent. Limited-risk AI systems have fewer rules to follow. Companies need to show that their AI systems are safe and ethical. 

Those who break the rules can face large fines.



08/2025 

Governance rules and obligations for general-purpose AI (GPAI) providers must be in place
.

08/2026

High risk AI systems must be compliant with their obligations
.

08/2027

Full compliance required for high-risk AI systems integrated into regulated products (e.g., medical devices or vehicles).

 

EU AI Act explained

Scope (and exceptions) of the AI Act

From 2 February 2025, the use of AI systems that are classified as being “unacceptable risks” (e.g., social assessment systems or emotion recognition in the workplace) will be prohibited. Non-compliance can lead to fines of up to 7% of annual turnover and significant reputational damage.

If your AI system is developed exclusivley for

  1. Military
  2. National defense
  3. Scientific research

then the regulation of the EU AI Act does not apply to your AI system.

Find more info here.

Prohibited practices

These practices are prohibited  under the EU AI Act because they are considered unacceptable for society and fundamental rights.

Biometric categorization

Prohibits AI systems from categorizing people based on biometric data to derive sensitive attributes such as political views or sexual orientation.

Unauthorized facial recognition databases

Prohibits the use of AI systems to create or extend facial recognition databases through the untargeted collection of facial images from the internet or CCTV footage.

Emotion recognition in sensitive areas

Prohibits the use of AI systems to recognize emotions in the workplace and in educational institutions, except for medical or security purposes.

Social scoring

Prohibits AI systems from evaluating or ranking individuals based on their social behavior or personality traits that result in adverse or unjustified treatment.

Manipulative or subliminal AI

Prohibits AI systems that use subliminal or deliberately manipulative techniques to influence behavior and significantly impair decision making.

Exploitation of vulnerabilities

Prohibits AI systems that exploit vulnerabilities based on age, disability or socioeconomic conditions to influence behavior and cause significant harm.

Real-time biometric identification

Prohibits the use of AI systems for real-time biometric identification in publicly accessible spaces by law enforcement agencies, except under specific and narrowly defined conditions.

Predictive criminal profiling

Prohibits AI systems from predicting criminal behavior based solely on profiling or personality traits without human assessment.

Obligation cards

The obligation cards give you a checklist of requirements for AI systems under the EU AI Act. Based on your answers in the evaluation, you will see which cards apply to your use case. If you want to explore specific cards directly, use the list below.

 

Obligation cardEnglishGerman
No risk – self commitmentLinkLink
System providerLinkLink
DeployerLinkLink
DistributorLinkLink
ImporterLinkLink
Authorized representativeLinkLink
Product manufacturerLinkLink
Exception regulationsLinkLink
Transparency obligationsLinkLink