The EU AI Act sets out rules for the safe and trustworthy use of artificial intelligence in Europe. Here is what the Act forbids, includes and doesn't include.
About the EU AI Act
The AI Act is a new set of rules for using artificial intelligence in the EU. It is designed to protect people’s safety and fundamental rights. The law categorizes AI systems by the level of risk they pose. High-risk AI systems must follow strict rules and be very transparent. Limited-risk AI systems have fewer rules to follow. Companies need to show that their AI systems are safe and ethical.
Those who break the rules can face large fines.
08/2025
Governance rules and obligations for general-purpose AI (GPAI) providers must be in place
.
08/2026
High risk AI systems must be compliant with their obligations
.
08/2027
Full compliance required for high-risk AI systems integrated into regulated products (e.g., medical devices or vehicles).
EU AI Act explained
Scope (and exceptions) of the AI Act
From 2 February 2025, the use of AI systems that are classified as being “unacceptable risks” (e.g., social assessment systems or emotion recognition in the workplace) will be prohibited. Non-compliance can lead to fines of up to 7% of annual turnover and significant reputational damage.
If your AI system is developed exclusivley for
- Military
- National defense
- Scientific research
then the regulation of the EU AI Act does not apply to your AI system.
Find more info here.
Prohibited practices
These practices are prohibited under the EU AI Act because they are considered unacceptable for society and fundamental rights.
Biometric categorization
Prohibits AI systems from categorizing people based on biometric data to derive sensitive attributes such as political views or sexual orientation.
Unauthorized facial recognition databases
Prohibits the use of AI systems to create or extend facial recognition databases through the untargeted collection of facial images from the internet or CCTV footage.
Emotion recognition in sensitive areas
Prohibits the use of AI systems to recognize emotions in the workplace and in educational institutions, except for medical or security purposes.
Social scoring
Prohibits AI systems from evaluating or ranking individuals based on their social behavior or personality traits that result in adverse or unjustified treatment.
Manipulative or subliminal AI
Prohibits AI systems that use subliminal or deliberately manipulative techniques to influence behavior and significantly impair decision making.
Exploitation of vulnerabilities
Prohibits AI systems that exploit vulnerabilities based on age, disability or socioeconomic conditions to influence behavior and cause significant harm.
Real-time biometric identification
Prohibits the use of AI systems for real-time biometric identification in publicly accessible spaces by law enforcement agencies, except under specific and narrowly defined conditions.
Predictive criminal profiling
Prohibits AI systems from predicting criminal behavior based solely on profiling or personality traits without human assessment.
Obligation cards
The obligation cards give you a checklist of requirements for AI systems under the EU AI Act. Based on your answers in the evaluation, you will see which cards apply to your use case. If you want to explore specific cards directly, use the list below.