The EU AI Act Rollout: Risk Tiers & €35M Fines

On this page8 sections

The EU AI Act Rollout: Risk Tiers & €35M Fines

EU AI Act Rollout
Date:
August 1, 2024
Location:
European Union
Lab/Organisation:
European Union
Paper/Outcome:
Regulation (EU) 2024/1689 (phased rollout through 2026–2028)
Significance:
World’s first binding horizontal AI regulation; risk-based tiers with €35M fines
EU AI Act

The European Union’s Regulation 2024/1689 on Artificial Intelligence, the first binding horizontal AI regulation. Passed March 2024, in force August 2024, with phased application through 2026-2028. The Act uses a risk-tier framework: unacceptable risk (banned), high risk (conformity assessment), limited risk (transparency), minimal risk (no obligation).


The Long Road to Passage

The EU AI Act did not appear overnight. It was first proposed by the European Commission (the EU’s executive branch) on April 21, 2021, as part of a broader “Europe fit for the Digital Age” package. The proposal was developed against the backdrop of the GDPR — the EU’s data protection regulation, which had taken effect in 2018 and had become a global benchmark for privacy regulation. The Commission’s hope was that the AI Act would do for AI what the GDPR had done for data protection: establish a comprehensive, principled regulatory framework that would be emulated around the world.

The legislative process took nearly three years. The European Parliament adopted its negotiating position in June 2023, with MEPs Dragoș Tudorache (Romania, Renew Europe) and Brando Benifei (Italy, S&D) serving as co-rapporteurs. Trilogue negotiations — the formal process by which the Parliament, the Council, and the Commission agree on a final text — concluded with a political agreement on December 9, 2023.

The formal adoption came on March 13, 2024, when the European Parliament voted to approve the Act. The vote was 523 in favour, 46 against, and 49 abstentions — a decisive margin that reflected broad cross-party support. The Council of the European Union (representing the member states) formally approved the Act on May 21, 2024. The Act was published in the Official Journal of the European Union on July 12, 2024, and it entered into force on August 1, 2024.

The three-year legislative process was unusually long, and it was driven by the complexity of the subject. AI is a broad and rapidly evolving technology, and the Act had to cover everything from chatbots to medical diagnostic systems to autonomous weapons. The process was also driven by intense lobbying from both the AI industry — which argued that the Act was too restrictive and would stifle innovation — and from civil society organisations, which argued that the Act did not go far enough to protect fundamental rights.


The Risk-Based Framework

The core of the EU AI Act is a risk-based framework that classifies AI systems into four tiers, with different rules applying to each tier.

The first tier is unacceptable risk — the highest tier, covering eight prohibited AI practices. Article 5 of the Act lists eight prohibited practices: AI that uses subliminal manipulation, AI that exploits vulnerabilities of specific groups (such as children or people with disabilities), social scoring by public authorities, individual criminal risk prediction (predictive policing based on profiling), untargeted scraping of facial images from the internet or CCTV, emotion recognition in workplaces and educational institutions, biometric categorisation for sensitive attributes (such as race or religion), and real-time remote biometric identification in public spaces (with limited exceptions for law enforcement).

The prohibition on these practices took effect on February 2, 2025 — the first major compliance deadline under the Act. This was a significant moment: for the first time, a major jurisdiction had outright banned certain uses of AI.

The second tier is high risk — covering AI in recruitment, education, law enforcement, and other sensitive domains, with strict obligations. The Act lists, in Annex III, a number of high-risk categories, including AI used in recruitment, education, essential public services, law enforcement, migration management, and the administration of justice. High-risk AI systems must undergo conformity assessments before they can be placed on the market, they must meet requirements for data quality and governance, they must provide technical documentation, they must be designed for human oversight, and they must meet standards for accuracy, robustness, and cybersecurity.

The high-risk obligations take effect on August 2, 2026. This is the second major compliance deadline, and it is the one that will affect the largest number of companies. Many AI systems that are currently in use — in recruitment, in lending, in healthcare — will need to be assessed and potentially modified to comply with the high-risk requirements.

The third tier is limited risk — requiring transparency (chatbots must disclose they are AI; deepfakes must be labelled). The main example is AI systems that interact with humans — like chatbots — which must inform users that they are interacting with an AI. Another example is AI that generates synthetic content — like deepfakes — which must be labelled as artificially generated. The transparency obligations take effect on August 2, 2026, alongside the high-risk obligations.

The fourth tier is minimal risk — covering the majority of AI systems, with no specific obligations under the Act. The European Commission estimates that the vast majority of AI systems fall into this category. Examples include AI used in video games, spam filters, and inventory management systems. These systems can be developed and used freely, subject only to voluntary codes of conduct.


The General-Purpose AI Regime

In addition to the risk-based framework, the Act establishes a separate regime for “general-purpose AI” (GPAI) models — the large language models and other foundation models that have become central to the AI industry since the release of ChatGPT in 2022.

The GPAI regime was one of the most contentious parts of the Act, and it was added relatively late in the legislative process, in response to the rapid emergence of ChatGPT and similar systems. The regime distinguishes between GPAI models in general and GPAI models with “systemic risk.” A GPAI model is presumed to have systemic risk if it was trained using a cumulative amount of computation greater than 10^25 FLOPs (floating-point operations — the basic arithmetic measure used to quantify the scale of AI training compute). This threshold was chosen because it captures the most capable models — like GPT-4 and Gemini — while excluding smaller models.

All GPAI providers must comply with certain obligations: they must maintain technical documentation, they must provide information to downstream providers who integrate their models into products, and they must comply with EU copyright law when training their models. GPAI providers with systemic risk must comply with additional obligations: they must conduct model evaluations, they must assess and mitigate systemic risks, they must report serious incidents, and they must ensure adequate cybersecurity protection.

The GPAI rules took effect on August 2, 2025. This was the third major compliance deadline, and it was the one that most directly affected the major AI companies. To help companies comply, the European Commission published a General-Purpose AI Code of Practice on July 10, 2025. The Code of Practice is a voluntary framework that provides guidance on how to comply with the GPAI obligations. It was signed by 26 organisations, including Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Aleph Alpha, and Mistral AI.

Notably absent from the signatories were Meta and Apple. Meta publicly refused to sign, calling the rules an “over-reach.” Apple did not sign, and it had earlier withheld its Apple Intelligence feature from the EU market in June 2024, citing the regulatory environment. The absence of Meta and Apple was a sign that the GPAI regime was contested, and that not all major AI companies were willing to comply voluntarily.


The AI Office and Enforcement

The enforcement of the AI Act is a shared responsibility. Each EU member state must designate a national competent authority — a market surveillance authority — to enforce the Act within its territory. The member states had to designate these authorities by August 2, 2025.

At the EU level, the Act is enforced by the AI Office, which was established within the European Commission’s DG CONNECT (the Commission’s digital-policy department) in Brussels. The AI Office is the central coordinator for AI Act enforcement, and it has particular responsibility for GPAI models with systemic risk. The Office was first signalled in the Commission’s April 2023 AI package, formally established by Commission decision on January 24, 2024, and Lucilla Sioli — a long-serving EU official (since 1997) with a Ph.D. in economics from the University of Southampton — was appointed as its director on May 29, 2024. (The UK’s separate AI Safety Institute, often confused with the AI Office, was announced at the Bletchley Summit in November 2023 — see B40.)

The AI Office’s enforcement powers over GPAI providers began on August 2, 2025. Its enforcement powers over high-risk AI systems will begin on August 2, 2026. The AI Office can request information from providers, it can conduct evaluations of GPAI models, and it can impose sanctions for non-compliance.

The fines for non-compliance are significant. The maximum fine for violations of the prohibited practices (Article 5) is €35 million or 7% of the company’s total worldwide annual turnover, whichever is higher. The maximum fine for violations of the high-risk obligations or the GPAI obligations is €15 million or 3% of worldwide annual turnover. The maximum fine for providing incorrect, incomplete, or misleading information to authorities is €7.5 million or 1% of turnover. The 7% cap for the most serious violations deliberately exceeds the GDPR’s maximum of 4%, signalling the EU’s view that AI violations can be even more serious than data protection violations.

As of mid-2025, no formal AI Act fines had been issued. But the parallel enforcement of the Digital Markets Act (DMA) — another EU digital regulation — provided a preview of the EU’s enforcement vigour. In spring 2025, the European Commission fined Apple €500 million and Meta €200 million for DMA non-compliance. These fines were a signal that the EU was serious about enforcing its digital regulations, and they set the stage for similar enforcement under the AI Act.


The Open Source Question

One of the most contentious questions in the AI Act debate was how to treat open source AI. The open source community argued that the Act, as originally proposed, would have effectively banned open source AI by imposing the same obligations on open source developers as on commercial developers. This, they argued, would have been disastrous for innovation, for research, and for the democratic accountability of AI systems.

The final version of the Act includes a partial exemption for open source AI. Article 2(2) of the Act provides that GPAI models released under open source licenses — that allow for the modification and distribution of the model — are exempt from some of the GPAI obligations, provided that they do not have systemic risk and that the provider does not monetise the model.

The exemption is narrow. It does not extend to GPAI models with systemic risk, regardless of whether they are released as open source. And it does not extend to high-risk AI systems, which must comply with the full high-risk obligations regardless of whether they are open source.

The open source community’s response was mixed. Some argued that the exemption was a reasonable compromise that protected open source innovation while ensuring that the most powerful models were still regulated. Others argued that the exemption was too narrow, and that it would still discourage the release of open source AI models in the EU. The debate is not resolved, and the Future of Life Institute published an analysis in 2024 examining how the Act treats open source AI, which remains a key reference point for the debate.


The Geopolitical Context

The EU AI Act did not emerge in a vacuum. It was developed in a specific geopolitical context, and its rollout has been shaped by that context.

The Act was developed during a period when the United States, under the Biden administration, was also taking steps to regulate AI — through Executive Order 14110, signed on October 30, 2023, and through the work of the US AI Safety Institute. The EU and the US were, in effect, pursuing parallel but different approaches: the EU through binding legislation, the US through executive action and voluntary commitments.

This parallel approach changed significantly with the election of Donald Trump in November 2024. The Trump administration, which took office on January 20, 2025, signalled a very different approach to AI. On January 20, it rescinded Biden’s Executive Order 14110. On January 23, it signed a new Executive Order, 14179, “Removing Barriers to American Leadership in AI,” which was designed to promote AI development by reducing regulation. On February 21, 2025, the administration issued a memorandum that was widely read as targeting the EU AI Act and the DMA, suggesting that the US might take action against countries that “hindered” American AI companies. On December 11, 2025, Trump signed another Executive Order, “Ensuring a National Policy Framework for Artificial Intelligence,” which sought to preempt state laws and protect US AI innovation from foreign regulation.

The Trump administration’s hostility to the EU’s regulatory approach created a transatlantic tension. The EU was pressing ahead with the AI Act, while the US was actively opposing it. This tension was exacerbated by the decisions of several major US tech companies to delay or withhold AI features in the EU. Apple withheld Apple Intelligence from the EU market in June 2024, citing the regulatory environment (though Apple blamed the DMA, not the AI Act). Meta delayed the launch of some Llama models in the EU. Google delayed some Gemini features. These delays were, depending on your perspective, either a legitimate response to regulatory uncertainty or a form of regulatory extortion — an attempt to pressure the EU into watering down its rules.

The EU’s response to the pressure was mixed. In June 2025, Commissioner Henna Virkkunen — the new Executive Vice-President for Tech Sovereignty, Security and Democracy, who had taken over the tech portfolio from Margrethe Vestager — signalled that the AI Act’s safeguards could be “diluted” before the 2026 implementation. On November 19, 2025, the European Commission tabled the “Digital Omnibus on AI,” a package of proposed amendments that would defer or postpone certain high-risk compliance deadlines. The Digital Omnibus was presented as a targeted adjustment to address implementation challenges, but critics — including the Austrian privacy NGO noyb — warned that it could weaken the Act’s protections.

The tension between the EU’s regulatory ambition and the political and economic pressure to dilute it is one of the defining features of the AI Act’s rollout. The Act has been passed, and its basic framework is in place. But the details of how it will be implemented, and how strictly it will be enforced, are still being worked out, and they will be shaped by the ongoing political and economic context.


The Implementation Challenge

Even setting aside the political pressures, the implementation of the AI Act faces significant practical challenges.

The first challenge is the pace of AI development. The Act was designed over three years, and during that time, the AI industry changed dramatically. ChatGPT was released in November 2022, after the Act was first proposed. The GPAI regime was added late in the process, in response to the emergence of large language models. By the time the Act took effect in August 2024, the AI industry had moved on again, with reasoning models, agentic AI, and multimodal systems that the Act’s drafters had not specifically contemplated. The Act’s framework is flexible enough to cover these new developments, but the specific rules and guidance will need to be updated to keep pace.

The second challenge is the technical capacity of the regulators. The AI Office and the national competent authorities need to be able to evaluate AI systems, to understand their capabilities and risks, and to enforce the rules. National competent authorities — the member-state market-surveillance bodies — had to be designated by August 2, 2025. This requires technical expertise that is in short supply, and that is largely concentrated in the AI companies themselves. The regulators are, in effect, trying to regulate an industry that knows more about the technology than they do. This is a problem that the AI safety institutes — in the UK, the US, and elsewhere — are also facing, and it is not easily solved.

The third challenge is the global nature of the AI industry. The Act applies to AI systems that are placed on the EU market, regardless of where they are developed. But the major AI companies are based in the United States and China, and they can — and do — choose to withhold their products from the EU market rather than comply with the rules. This creates a tension between the EU’s regulatory ambition and its desire to have access to the latest AI technology. The EU does not want to be a market that is starved of AI innovation, but it also does not want to compromise on its regulatory standards.

The fourth challenge is the interaction with other regulations. The AI Act does not exist in isolation. It interacts with the GDPR (data protection), the DMA (digital markets), the DSA (digital services — the EU’s digital-services regulation), and a range of sector-specific regulations. Ensuring that these regulations work together, and that they do not impose contradictory or duplicative obligations, is a complex task. The European Commission has been working on this, but it is an ongoing process.


What the Act Means

The EU AI Act is the most ambitious attempt anywhere in the world to regulate AI. It establishes a comprehensive, principled framework that covers the full range of AI systems, from chatbots to medical diagnostic tools to autonomous weapons. It creates a risk-based system that prohibits the most dangerous uses, imposes strict obligations on high-risk systems, and requires transparency for limited-risk systems. It creates a new regime for general-purpose AI models, and it provides for significant penalties for non-compliance.

The Act’s significance extends beyond the EU. As with the GDPR, the EU is using its market power to set a global standard. Companies that want to operate in the EU market — which includes most of the world’s major tech companies — will need to comply with the Act, and the compliance costs will likely lead them to apply the same standards globally. This “Brussels effect” means that the EU AI Act will shape AI regulation not just in Europe, but around the world.

The Act is not without its critics. The AI industry argues that it is too restrictive and will stifle innovation, particularly in Europe. Civil society organisations argue that it does not go far enough to protect fundamental rights. The open source community argues that the open source exemption is too narrow. And the geopolitical context — with the US under the Trump administration actively opposing the EU’s regulatory approach — creates pressure to dilute the Act’s provisions.

But the Act is, for all its imperfections, a serious and comprehensive attempt to address the challenges posed by AI. It is the first major legal framework for AI in the world, and it will be a reference point for every other government grappling with the same challenges. Its rollout will continue through 2028, and its success or failure will be studied closely by everyone who cares about the future of AI governance.

The lesson of the EU AI Act is that regulating AI is possible, but it is hard. It requires a willingness to confront difficult trade-offs — between innovation and safety, between commercial interests and fundamental rights, between national sovereignty and global cooperation. It requires technical capacity that regulators are still building. And it requires political will that can withstand pressure from both industry and geopolitical rivals. The EU has taken the first step. Whether other governments will follow, and whether the EU’s framework will prove durable, are questions that the next several years will answer.


Further reading
  • Regulation (EU) 2024/1689 — EUR-Lex. The official text of the AI Act, published in the Official Journal of the European Union. The primary source. eur-lex.europa.eu
  • AI Act — European Commission — the Commission’s official page on the AI Act, with implementation guidance, timelines, and related documents. digital-strategy.ec.europa.eu
  • “The EU AI Act: A Practical Guide” — artificialintelligenceact.eu. A comprehensive, regularly updated guide to the Act, maintained by a community of legal experts. artificialintelligenceact.eu
  • EU AI Act Newsletter — artificialintelligenceact.substack.com. A weekly newsletter tracking the implementation of the Act. artificialintelligenceact.substack.com
  • “Digital Omnibus on AI” — European Commission, 19 November 2025. The Commission’s proposed amendments to the Act, which would defer certain high-risk compliance deadlines. ec.europa.eu
  • General-Purpose AI Code of Practice — European Commission, 10 July 2025. The voluntary compliance framework signed by 26 organisations. digital-strategy.ec.europa.eu

Series Companions

This piece is part of Minds & Machines: Beyond the Series. The companion pieces B40 — The Bletchley Declaration and What Came After (the 2023 international AI-safety summit where the AI Office was announced), B84 — The AI Election, Revisited (the election context whose Article 50(4) deepfake-labeling obligations apply from August 2026), the main-series A23 — The Governance Gap (the broader regulatory context), and B90 — White House Voluntary Commitments (the US voluntary approach the EU Act contrasts with) cover the related milestones.

Was the eu ai act inevitable — the product of forces too large to redirect — or was it a series of choices, each of which could have gone differently? The answer matters, because it determines whether the future is something that happens to us or something we make.