As part of their AI strategy, the European Union enacted the EU AI Act to ensure AI is developed and used in a safe, reliable, and transparent way. The new regulation classifies AI systems by their risks and has significant implications for organizations that develop or use AI systems within the EU. This article briefly summarizes the EU AI Act and how you can operationalize it.
Introduced in April 2021 by the European Commission and adopted in 2024, the EU AI Act is a first-of-its-kind legal framework that tries to regulate the use of AI systems across the EU to ensure safety, reliability, and transparency. The EU wants to make sure that AI is aligned with existing laws on fundamental rights and Union values.
As different AI applications impose different risks, the EU AI Act follows a risk-based approach which leads to a horizontal regulation (i.e. applicable across sectors):
Depending on the risk classification, the AI system may be prohibited, specific requirements must be fulfilled, or users interacting with the AI must be notified about this interaction. This applies to any AI system affecting a natural person in the EU. Read more about how AI risk is classified in this article.
The EU AI Act aligns its definition of an AI system with the OECD’s definition. Now, an AI system in light of the EU AI Act is defined as a machine-based system that generates output such as predictions, content, recommendations or decisions influencing physical or virtual environments, inferring it from the input the system receives. These systems can vary in their levels of autonomy and adaptiveness.
Previously, the EU defined an AI system as software developed with machine learning or logic- and knowledge-based approaches that produce content, predictions, recommendations, decisions, or similar output with influence on the environment the AI is interacting with, including AI systems that may be part of a hardware device. This definition was heavily criticized by people in the AI ecosystem, as it could include simpler systems that are not AI systems.
The EU has published guidelines on the definition of an AI system to facilitate classifications in 2025.
The EU wants to make sure that citizens are safe from any negative consequences of AI. Thus, the EU AI Act aims to help ensure that organizations that use AI to make decisions do not discriminate against people or that these systems are not biased against certain groups based on race, gender, religion, or any other attribute.
Depending on the type and risk of an AI application, organizations using AI systems must provide an explanation for AI-based outcomes as well as the decision-making process behind these outcomes. This poses significant challenges for organizations, as the current AI development process is very scattered and lacks transparency. Solutions to unlock structured and transparent processes will be needed.
The EU AI Act gives affected individuals the right to challenge the decisions made by algorithms and have them reviewed by the responsible organizations and authorities.
The EU AI Act entered into force on 1 August 2024. Different timelines apply to different provisions. The rules on prohibited AI practices and the AI literacy requirement have applied since 2 February 2025. The obligations for providers of general-purpose AI models have applied since 2 August 2025. The regulation applies generally, including the transparency obligations, from 2 August 2026.
The high-risk requirements were postponed by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026. Chapter III now applies from 2 December 2027 to systems classified as high-risk under Annex III, and from 2 August 2028 to systems classified under Annex I – products already regulated by other laws, such as medical devices, vehicles or machinery. Two new prohibitions, on non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026.

AI systems that are classified as high-risk can still be used and developed, as long as they fulfill the proposed requirements. This includes a “conformity assessment” (or audit) to ensure that the developed AI system complies with the EU AI Act, which must be repeated when significant modifications to the system are made.
It will also be mandatory to monitor the risk and quality of the system while it is in use, which includes:
While the obligations are mainly applying to providers of such high-risk AI systems, there are also obligations for other operators in the value chain, such as deployers, importers or distributors. The compliance responsibilities could even shift completely to these other operators, depending on the use or modification.
Non-compliance with the EU AI Act can cause penalties of up to €35 million or 7% of the organization’s global annual revenue. Non-compliance with obligations, including the high-risk requirements, can cause penalties of up to €15 million or 3%. Missing to supply correct information to authorities will cause penalties of up to €7.5 million or 1% of the organization’s global annual revenue. SMEs, SMCs and start-ups have capped fines. Consult this article to learn more about the requirements to fulfill.
While the impact of the EU AI Act can be drastic and costly for some organizations (especially when providing high-risk AI), the good news is that the postponement of the high-risk requirements to 2027 through the Digital Omnibus on AI leaves time to prepare.
Nevertheless, starting your EU AI Act compliance process early in your AI system lifecycle (ideally already in use case ideation) is important and best practice among mature AI-driven organizations. And most parts of the EU AI Act are already in effect from August 2026 onwards.
As pointed out earlier, the EU’s AI strategy is to make AI trustworthy, and the key element of that is ensuring transparency and accountability through all development or procurement stages. This doesn’t only make compliance easier, but it also helps in bringing everybody involved during AI development and use on the same page.
We at trail want you to keep scaling innovative and responsible AI solutions, which is why we provide modern AI governance solutions that help you automate compliance busywork and focus on the high-impact use cases. Check out here how we can help you keep track of your AI, automate compliance and give you a head start with EU AI Act specific content.