No history yet

Introduction to the EU AI Act

The EU's Rulebook for AI

The European Union has created the world's first comprehensive law for artificial intelligence, known as the EU AI Act. The goal is to ensure that AI systems used in the EU are safe, transparent, and respect fundamental human rights. At the same time, the Act aims to support innovation and make Europe a leader in trustworthy AI.

Lesson image

The law doesn't just apply to companies based in the EU. It affects any organization that develops, deploys, or uses AI systems within the European Union, regardless of where they are located. This means a company in the United States or Japan must follow these rules if its AI services are available to people in EU countries.

The Act starts by defining what an 'AI system' is. Instead of listing specific technologies like machine learning, it uses a broad, future-proof definition.

AI System

noun

A machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

This wide definition ensures the law can adapt as technology evolves, covering systems we can't even imagine yet.

A Risk-Based Approach

Not all AI systems are treated equally under the Act. The core of the legislation is a risk-based approach, which means the level of regulation an AI system faces depends on the potential harm it could cause to society.

One of the most critical aspects of the AI Act is its risk-based classification system.

This method sorts AI systems into four distinct categories of risk. The higher the risk, the stricter the rules.

Let's look at what each of these tiers means.

The Four Tiers of Risk

Unacceptable Risk: This category includes AI systems considered a clear threat to the safety and rights of people. These systems are banned entirely in the EU.

Examples include:

  • Government-run social scoring systems that rank citizens.
  • AI that uses manipulative techniques to cause harm.
  • Real-time biometric identification in public spaces by law enforcement (with very narrow exceptions).

High Risk: These are AI systems that could have a significant negative impact on people's safety or fundamental rights. They aren't banned, but they must follow strict rules before and after they're put on the market.

This category covers AI used in critical areas like:

  • Medical devices
  • Recruitment and employee management
  • Credit scoring
  • Law enforcement and the justice system

For high-risk systems, the Act requires things like risk management, high-quality data sets, human oversight, and robust security.

Limited Risk: This tier covers AI systems that pose a lower risk but still require transparency. The main rule here is that users must be aware they are interacting with an AI system.

This includes chatbots, deepfakes, and AI-generated content. For example, if you're talking to a customer service chatbot, it must identify itself as an AI. Any audio, image, or video content generated or manipulated by AI (a deepfake) must be clearly labeled as such.

Minimal or No Risk: This is the largest category, covering the vast majority of AI systems in use today. These are applications like spam filters, AI-powered video games, or inventory management systems.

The AI Act places no new legal obligations on these systems. Companies are encouraged to voluntarily adopt codes of conduct for these applications, but it's not a requirement.

I'm about to give you a quiz to see what you've learned. Ready to test your knowledge?

Quiz Questions 1/5

What is the core regulatory strategy of the EU AI Act?

Quiz Questions 2/5

Who is required to comply with the EU AI Act?

By sorting AI into these risk categories, the EU AI Act aims to build public trust and manage potential harms without stifling the development of low-risk technologies.