top of page

The EU AI Act: where to start.

  • Aug 5
  • 2 min read



The EU AI Act has changed in the last few months. As of now, its timelines are (officially speaking) different from what most summaries online still say — so it's a good moment to set out what the Act actually is, and who it applies to.


What is the EU Act?

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive law regulating artificial intelligence. It's been in force since August 2024 and is rolling out in stages through 2027.


There are four broad tiers of AI systems:

1. Prohibited — a set of uses banned outright, such as social scoring and certain forms of biometric surveillance. Already enforceable.

2. High-risk — AI used in areas like hiring, credit scoring, education, medical devices and critical infrastructure. This is where the heaviest requirements sit.

3. Limited-risk — mainly transparency, such as telling people when they're dealing with AI or looking at AI-generated content.

4. Minimal-risk — most everyday AI, largely untouched.


Who does it apply to?

Like GDPR, the Act reaches beyond the EU's borders. What decides scope isn't where your organisation is based, but where your AI is placed on the market or where its outputs are used. A UK organisation is generally covered if it puts an AI system or general-purpose AI model onto the EU market, or if the output of its AI is used by people in the EU.

It also runs across the whole chain, not just the companies building AI. Providers who develop it, deployers who use it in a professional setting, importers and distributors all carry obligations. A team using an AI tool in its daily work can be as much in scope as one training a model.


Penalties reach €35 million, or 7% of worldwide annual turnover.


What changed recently: the heaviest high-risk obligations, originally due in August 2026, have now been formally moved to December 2027. That gives some organisations breathing room. 


But the transparency rules still take effect this August, so parts of the Act are live regardless of the postponed deadlines.

For most organisations the hard part will be working out where they actually sit. Are they provider or deployer, high-risk or not? That's what we're building Veritas_Fox to do. 


Comments


bottom of page