TERM · SOFTWARE & INTEGRATIONS

EU AI Act

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European law that governs how artificial intelligence may be built and used. It sorts systems by risk: a short list of banned practices, high-risk uses with strict duties, systems that owe people transparency, and everything else. It arrives in stages. For most companies the practical part is disclosure.

Example

A company puts a chatbot on its website and, separately, uses a tool that ranks incoming CVs by fit. The two land in different categories. The chatbot is a transparency case: the visitor has to understand that the other side is a machine. Sifting job applicants sits among the high-risk uses and brings a different set of duties altogether — documentation, human oversight, traceability.

For that company the conclusion is short: one needs a sentence in a visible place, the other needs a project.

Why it matters for a business

The regulation sorts uses into levels. Banned practices, among them scoring people by behaviour with consequences in an unrelated context; high-risk uses listed in the annexes, including recruitment and credit scoring; uses that owe transparency, which is where chatbots and generated content sit; and everything else, which carries no special duty.

It entered into force in August 2024 and applies in stages: the bans, and the first rules on what staff should know about the tools they use, from February 2025; rules for general-purpose models from August 2025; the transparency duties, among them marking a chatbot and machine-generated content, from 2 August 2026. An amendment adopted in July 2026 moved the high-risk dates: systems in Annex III fall due on 2 December 2027, and artificial intelligence built into products covered by Annex I on 2 August 2028. Penalties for the banned practices reach €35 million or 7% of worldwide turnover.

What to ask

  • Where is artificial intelligence already in use in the company, including inside other people’s platforms?
  • Which of those uses is only a transparency case, and which falls in the high-risk list?
  • What does the provider declare about its model, and what stays your duty?
  • Who on the team knows what the tool may and may not be used for?
  • How is machine-generated content marked?

When a feature like this goes into a system of your own, the requirements belong in the brief for the web software.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.