Regulatory Landscape
The European Union has established itself as the global standard-setter for AI regulation through the AI Act, which entered into force in August 2024. This represents the world’s first comprehensive, horizontally applicable AI law, following the EU’s established pattern of leading on technology regulation as it did with GDPR for data protection.
The AI Act uses a risk-based tiered approach: unacceptable risk (banned), high risk (heavily regulated), limited risk (transparency obligations), and minimal risk (unregulated). This framework attempts to balance innovation with protection.
Key Laws
The AI Act prohibits specific AI practices deemed unacceptable: social scoring systems, real-time biometric surveillance in public spaces (with narrow exceptions), manipulation techniques exploiting vulnerabilities, and emotion recognition in workplaces and schools.
High-risk AI systems—including those used in critical infrastructure, education, employment, law enforcement, and migration—face mandatory requirements including conformity assessments, human oversight, transparency, accuracy standards, and cybersecurity requirements.
General-purpose AI models face transparency requirements, and models with “systemic risk” (trained with compute exceeding 10^25 FLOPS) must conduct adversarial testing and report serious incidents.
Enforcement
The prohibited AI practices provisions took effect in February 2025, with high-risk system requirements phasing in through 2026. The European AI Office oversees general-purpose AI compliance, while national authorities handle other enforcement. Fines range up to 35 million euros or 7% of global turnover.
Business Impact
The AI Act creates significant compliance obligations for companies serving EU markets. Impact assessments, documentation requirements, and conformity procedures add cost and time to AI deployment. However, the regulation’s extraterritorial reach means any company deploying AI systems affecting EU residents must comply, making it a de facto global standard. Many companies are adopting EU-compliant practices worldwide rather than maintaining separate regional approaches.