The EU AI Act explained
The EU AI Act is the first comprehensive AI law. It classifies AI into four risk tiers, bans the highest-risk uses, heavily regulates high-risk systems, and enforces the rules with fines up to 35M euros or 7% of global turnover, phased in from 2025 to 2027.
The four risk tiers
The Act sorts AI into unacceptable risk (banned), high risk (heavily regulated), limited risk (transparency duties), and minimal risk (largely free). Your obligations depend entirely on which tier your system falls into.
Unacceptable-risk uses, social scoring, certain biometric surveillance, manipulative systems, are banned outright, and that ban applied first, on February 2, 2025. High-risk systems, such as AI in hiring, credit, or critical infrastructure, carry the heaviest obligations: risk management, data governance, human oversight, and documentation. Limited-risk systems like chatbots owe transparency, users must know they are dealing with AI. Minimal-risk uses are largely unregulated. Classifying your system correctly is the first and most consequential compliance step.
Penalties and extraterritorial reach
Fines scale with severity, topping out at 35M euros or 7% of global turnover, and the Act reaches any provider whose AI output is used in the EU, so location outside Europe is not a shield.
The penalty tiers, 35M euros or 7% for banned uses, 15M euros or 3% for high-risk breaches, 7.5M euros or 1% for misleading information, always take the higher of the fixed sum or the turnover share for large firms. Because the Act applies wherever AI output lands in the EU, a US or UK company with European users should assume it is in scope and classify its systems accordingly.
Frequently asked questions.
Is a customer-service chatbot high-risk under the EU AI Act?
Usually no, a general chatbot is typically limited-risk, owing only transparency (telling users they are talking to AI). It becomes high-risk only if it makes or materially influences decisions in a regulated area like credit or employment.