The European Union's Artificial Intelligence Act became binding law on 1 August 2024, marking the first comprehensive legal framework anywhere in the world governing how artificial intelligence systems are built, sold, and used. The regulation was first proposed by the European Commission in April 2021 and finalised by the Parliament and Council in December 2023. Its entry into force starts a phased countdown for companies across every sector, from healthcare software to recruitment platforms and consumer-facing chatbots, to bring their systems into line.
A Risk-Based Structure, Not a Blanket Ban
Rather than treating all AI the same way, the Act sorts systems into four tiers according to the harm they could cause. Minimal-risk tools, such as spam filters or AI-driven video games, carry no legal obligations, though providers can adopt voluntary codes of conduct. Systems posing a specific transparency risk, like chatbots or tools generating synthetic media, must disclose that a user is dealing with a machine, and AI-generated content must be labelled. High-risk applications, including medical diagnostic software and AI used in hiring decisions, face the heaviest obligations: rigorous data-quality standards, documented risk mitigation, human oversight, and clear disclosure to those affected. At the top sits a short list of practices the EU considers incompatible with fundamental rights, such as government or corporate social-scoring systems, which are banned outright.
Why Brussels Chose This Approach
The logic behind the tiered model is pragmatic: regulate proportionally to risk rather than imposing uniform red tape on every algorithm. The Commission argues this reduces administrative and financial burden on lower-risk innovators while concentrating scrutiny where the stakes for citizens are highest. The EU frames the Act as part of a broader ambition to lead globally on "trustworthy AI," betting that a credible rulebook grounded in fundamental rights can coexist with a competitive AI industry. If that bet pays off, the Commission envisions gains across public services, transport, energy, and healthcare, alongside productivity improvements for manufacturers and businesses that adopt compliant systems.
What Comes Next for General-Purpose AI
Large general-purpose AI models, the kind underpinning many chatbots and generative tools, are subject to their own emerging rulebook. The Commission has opened a consultation on a Code of Practice for GPAI providers, covering transparency obligations, copyright compliance, and risk management. Model developers with EU operations, along with businesses, rights holders, civil society groups, and academic experts, have been invited to submit input that will shape the Commission's draft Code. The relevant GPAI provisions apply twelve months after entry into force, and the Commission expects to finalise the Code of Practice by April 2025. Feedback gathered through the consultation will also guide the newly established AI Office, which is tasked with supervising and enforcing the Act's rules on general-purpose models going forward.
Implications for Businesses and Consumers
For companies operating in or selling into the EU, the practical challenge is classification: knowing which tier a given AI system falls into determines the scope of compliance work required. Getting that assessment wrong carries legal exposure once enforcement ramps up. Consumers, meanwhile, gain clearer rights to know when they are interacting with automated systems and greater assurance that high-stakes applications, in medicine, employment, and public administration, meet baseline standards for accuracy, oversight, and fairness. The coming months, particularly the finalisation of the GPAI Code of Practice, will show how much detail regulators are prepared to demand from an industry that has, until now, largely set its own rules.