If you live in the European Union and use AI-powered products or services for personal or business matters, the EU AI Act is likely to affect you in some way.

You may already have seen one of its effects: labels or disclosures indicating that an image, video, audio clip, or other content was generated or manipulated using AI on platforms like Instagram or TikTok(ventana nueva). These became applicable in August 2026 as part of the EU AI Act’s transparency rules, and they are part of a much broader law that is being introduced in stages.

The EU AI Act also bans certain uses of AI, places strict requirements on systems considered high-risk, and sets rules for companies developing, providing, or using AI, with different provisions taking effect at different times.

So what exactly is the EU AI Act, which AI systems does it cover, and what does it mean for you or your business? Here’s what you need to know.

What is the EU AI Act?

The EU AI Act is the European Union’s law for regulating artificial intelligence. Formally known as Regulation (EU) 2024/1689, its goal is to make AI safer, more transparent, trustworthy, and human-centric while protecting fundamental rights and allowing innovation and adoption of AI in the EU.

In simple terms, you can think of the EU AI Act as the GDPR for AI, although it regulates different things: GDPR primarily governs how personal data is collected and processed, while the EU AI Act governs how AI systems are developed, provided, deployed, and used, particularly when they could affect people’s rights, safety, or important life decisions.

How AI risk is treated under the EU Artificial Intelligence Act

Instead of regulating all AI in the same way, the EU AI Act takes a risk-based approach, which can be classified in four levels:

  • Unacceptable (banned)
  • High-risk
  • Limited (transparency) risk
  • Low or no risk

The first eight bans came into force in February 2025, while the last one takes effect in December 2026.

Generally, the greater the potential harm an AI system can cause, the stricter the rules. The law does not formally define four “risk levels,” but its rules are often grouped into four broad categories to make them easier to understand.

The real-world examples below are not cases brought under the EU AI Act. Instead, they illustrate the kinds of harms or uses the AI law is designed to prevent, restrict, or regulate in the EU.

Unacceptable-risk AI

Certain AI uses are considered inherently unacceptable rather than something that can be managed through risk mitigation, documentation, or oversight. Here’s what’s banned:

Manipulation and deception

AI that manipulates or deceives people into making harmful decisions they otherwise would not make.

A Belgian man died by suicide in 2023(ventana nueva) after an AI chatbot encouraged him and mirrored his feelings for weeks.

Exploiting vulnerable people

AI that takes advantage of people because of their age, disability, or social or economic situation.

The chatbot platform Character.AI and Google agreed in January 2026 to settle lawsuits(ventana nueva) over harm caused to teens, including one lawsuit from a mother whose teenage son died by suicide after developing a deep emotional attachment to a chatbot that encouraged him to “come home” to it.

Social scoring

AI that ranks people based on their behavior or personal traits and uses those scores to treat them unfairly.

China’s social credit system has been used to bar low-scored citizens for things like buying plane or train tickets. In 2021, China signed a non-binding UN pledge(ventana nueva) to end social scoring, but it has only kept expanding the system since then, and it’s unclear how much of it still runs on AI.

Predictive policing

AI that predicts whether someone will commit a crime based only on profiling or personality traits. Other AI uses in law enforcement, like evaluating evidence or assessing risk based on verifiable facts, are high-risk but not banned.

In December 2025, Dutch police discontinued CAS, an algorithm used since 2017 to predict where crime was likely to happen, after an audit found reinforced bias caused by historical over-policing of certain neighborhoods.

Facial recognition databases

AI that indiscriminately scrapes images from the internet or CCTV footage to build facial recognition databases.

The US company Clearview AI scraped billions of online photos (including many of EU citizens) for law enforcement and government agencies and has been fined tens of millions of euros by EU regulators(ventana nueva).

Emotion recognition

AI that tries to infer how employees or students feel in workplaces or schools, except for genuine medical or safety reasons. Emotion recognition outside those two settings falls under the high-risk rules instead of being banned.

In 2018, a middle school in Hangzhou, China installed classroom cameras(ventana nueva) that scanned students’ faces to measure how attentive and focused they were, which sparked a national debate on child surveillance. That program was reportedly paused after the backlash, but similar monitoring soon spread to other schools.

By 2022, some had moved on to brain-wave headbands, with surveillance extending into remote learning and summer homework tracking(ventana nueva).

Sensitive biometric profiling

AI that uses biometric data to infer traits such as race, political views, union membership, religion, sex life, or sexual orientation. Biometric categorization for other purposes is high-risk, not banned.

In 2025, the World Uyghur Congress sued(ventana nueva) Hikvision, Huawei, and Dahua in France, alleging facial recognition technology helped identify and persecute Uyghurs.

Live facial recognition by police

Real-time facial recognition used by law enforcement in public spaces, except in a small number of tightly controlled cases, such as finding missing or abducted people, preventing an imminent threat, or locating suspects in serious crimes. Facial recognition that isn’t real-time, isn’t in a public space, or isn’t used by law enforcement is high-risk instead of banned.

In 2025, Hungary banned LGBTQ Pride events and passed a law allowing police to use live facial recognition to identify attendees. Civil liberties groups challenged the law(ventana nueva), arguing it directly violates Article 5 of the EU AI Act. In April 2026, the EU’s top court ruled Hungary had violated LGBTQ people’s fundamental rights; charges against Pride organizers were dropped, and a change of government that same month revoked the ban.

Sexual abuse and non-consensual intimate content

AI systems that generate child sexual abuse material (CSAM), or which generate or manipulate sexually explicit or intimate depictions of real, identifiable people without their consent.

Grok, the AI chatbot built into X, had a “spicy mode” that generated sexualized deepfakes of real people, including children, producing over 4.4 million images in just over 9 days. In January 2026, US state attorneys general demanded that xAI eliminate the feature, and multiple lawsuits followed(ventana nueva).

High-risk AI

High-risk AI systems are allowed on the EU market as long as the provider meets a demanding set of obligations. An AI system is considered high-risk in one of two ways:

  1. It is a product or the safety component of a product already covered by EU product-safety law and subject to a third-party conformity assessment, such as medical devices, machinery, lifts, or toys. These systems are classified as high-risk under Article 6(1) and Annex I, and become subject to the high-risk obligations starting in August 2028.
  2. It falls into one of the specific use-case categories listed in Article 6(2) and Annex III. The obligations for this group begin in December 2027 and include the following:

Biometrics

This includes remote biometric identification that isn’t real-time, isn’t in a publicly accessible space, or isn’t used by law enforcement, biometric categorization for purposes other than inferring the sensitive traits banned above, and emotion recognition outside the workplace or education context (this excludes basic biometric verification, like unlocking your phone with your face).

A high school in Sweden trialed facial recognition to track student attendance in 2019. Sweden’s data protection authority fined the school(ventana nueva), ruling that students couldn’t validly consent given their dependence on the school.

Critical infrastructure

AI managing digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity is considered high-risk.

In August 2024, Prague deployed an AI traffic control system(ventana nueva) that adjusts traffic light timing in real time based on current conditions and prioritizes public transport and emergency vehicles. It’s one of the first large-scale deployments of this kind in Europe.

Education and vocational training

AI deciding who gets into a school or training program, grading, evaluating the right level of education for someone, or monitoring students during exams is considered high-risk.

England’s exam regulator used an algorithm to assign 2020 grades after the COVID pandemic canceled exams, downgrading many students(ventana nueva) and disadvantaging those at historically lower-performing schools. This triggered protests and a government reversal.

Employment and worker management

This concerns AI used to screen or evaluate job candidates, or that affects promotions, task assignment, or performance monitoring on the job.

An Italian court ruled Deliveroo’s rider-ranking algorithm(ventana nueva) discriminatory(ventana nueva), as it penalized food delivery workers for low availability without identifying legitimate reasons, such as illness or strikes. Deliveroo was ordered to pay damages.

Essential services

AI that decides eligibility for public benefits or healthcare, assesses creditworthiness, prices life or health insurance, or triages emergency calls is considered high-risk.

Netherlands tax authorities used an algorithmic fraud-risk system that wrongly flagged around 26,000 parents(ventana nueva), disproportionately targeting people with dual nationality, for repayment of benefits. The scandal brought down the Dutch cabinet in January 2021.

Law enforcement

AI assessing a victim’s or offender’s risk, evaluating the reliability of evidence, or profiling people during criminal investigations is considered high-risk.

England and Wales use OASys to score reoffending risk for over 7 million people(ventana nueva), feeding into bail, sentencing, and parole decisions. Official evaluations found it’s less accurate for Black, Asian, and mixed-ethnicity individuals than for white offenders, and prisoners have limited ability to challenge inaccurate data used for their scores. A replacement system (ARNS) is being developed, with a national rollout targeted for 2026.

Migration, asylum, and border control

This concerns AI assessing security or migration risk, examining asylum applications, or identifying people at the border.

The UK Home Office refused a Moroccan woman and her child’s asylum claim(ventana nueva) citing a safety document that turned out not to exist. On appeal, a senior court judge suggested the refusal letter showed signs of AI hallucination, calling it “analogous to relying on bogus evidence.”

Justice and democratic processes

AI assisting judges in interpreting facts or law, or systems that could influence election outcomes or how people vote is concerned high-risk.

Perhaps the most well-known example — Cambridge Analytica harvested data from up to 87 million Facebook users without consent to build psychographic profiles for targeted political ads(ventana nueva), notably for the 2016 Trump campaign and Brexit referendum.

Requirements for high-risk AI systems

Under the EU AI Act, high-risk AI systems must meet strict requirements before they can be placed on the market or put into use. These include:

Risk management: Providers must identify, assess, and reduce potential risks throughout the system’s lifecycle.

Data quality: Training, validation, and testing data must be appropriate and managed to reduce errors and discriminatory outcomes.

Logging and traceability: Systems must keep records of their activity so their operation and results can be traced.

Technical documentation: Providers must document how the system works, what it is designed to do, and how it complies with the AI Act.

Information for deployers: People and organizations using the system must receive clear instructions about its capabilities, limitations, and proper use.

Human oversight: Systems must be designed so qualified people can understand, monitor, and intervene in their operation when necessary.

Accuracy, robustness, and cybersecurity: Systems must meet appropriate standards for accuracy, reliability, resilience, and protection against security threats.

However, article 6(3) provides for certain derogations for AI systems listed in Annex III. They should not be considered high-risk if they do not “pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making.” Article 6(3) includes more details on how to define whether an AI system falls into this derogation.

Transparency-risk (limited-risk) AI

For transparency risk, Article 50 focuses on AI that can make it difficult for people to distinguish between AI-generated or human-created content. The concern is mainly deception, impersonation, misinformation, manipulation, and consumer fraud. These systems are generally allowed, but providers and deployers must make the use of AI sufficiently transparent. Article 50’s transparency obligations took effect in August 2026.

There are four main situations covered by the AI transparency rules:

AI interactions

When an AI system directly interacts with a person, the provider must make it clear that they are interacting with AI rather than a human. This could apply to interactive systems that include conversational AI or customer-service agents.

An AI disclaimer must be provided from the beginning of the first interaction and in an accessible, clear, and distinguishable way. AI running only in the background or communicating machine-to-machine isn’t covered by this particular requirement.

Standard AI-generated content

Providers of AI systems that generate or manipulate text, images, audio, or video must make the output technically identifiable as AI-generated or manipulated, for example through machine-readable metadata.

This does not necessarily mean adding a visible label for the person viewing the content. Simple editing tools that do not substantially alter the input data or its meaning are exempt.

Deepfakes and certain public-interest content

If an organization creates or manipulates deepfake images, audio, or video, a machine-readable marker alone isn’t enough. They must clearly disclose it to the public in an easily perceivable manner, such as through a visible label or an audible note.

The same standard applies to AI-generated or manipulated text published to inform the public on matters of public interest, unless a human has meaningfully reviewed it and taken editorial responsibility for it.

Emotion recognition and biometric categorization

People must be informed when AI is being used to detect their emotions or categorize them using biometric data; this applies whether or not the system is also classified as high-risk.

Low- or no-risk AI

Most AI systems fall into this category and are not subject to additional mandatory requirements under the AI Act. Examples include spam filters and AI used in video games. Providers can still voluntarily follow best practices and codes of conduct.

What are GPAI models and what obligations do they have?

GPAI (general-purpose AI) models are AI models designed to handle many different tasks rather than one specific and narrow purpose. Examples of GPAI models include the large language models (LLMs) that power ChatGPT, Gemini, Claude, and Meta AI. They can generate or analyze content and can be integrated into other AI systems and applications.

GPAI models are subject to their own requirements under the AI Act. Providers must maintain technical documentation, give downstream developers information about the model’s capabilities and limitations, comply with EU copyright rules, and publish a public summary describing the data types (such as text, images, audio, or video) and sources (for example, public datasets, private datasets, scraped websites, user data, or synthetic data) used to train the model.

GPAI models that pose systemic risk — powerful or widely used enough that problems with it could cause large-scale harm across the EU — face additional requirements, including model evaluations and adversarial testing, ongoing risk management, incident reporting, and stronger cybersecurity protections.

Does the EU AI Act prohibit AI systems from using people’s data for AI training?

No. The EU AI Act does not ban the use of people’s data for AI training. It does require high-risk systems to use good-quality data and general-purpose AI providers to be transparent about what they trained on, but whether personal data can legally be used to train AI is primarily governed by the GDPR. Companies must have a valid legal basis for processing personal data and respect applicable data protection rights and safeguards.

Does the EU AI Act protect intellectual property?

Yes, but only in a limited and indirect way. The EU AI Act does not create new intellectual property rights or replace existing copyright law. However, it requires GPAI providers to comply with EU copyright rules, respect rights holders’ opt-outs for text and data mining, and publish a summary of the content used to train their models.

EU AI Act implementation timeline

Here are important dates you need to know:

1 August 2024: The EU AI Act went into effect.

2 February 2025: The Act’s general provisions and definitions began to apply, along with the first eight bans on prohibited AI practices. Requirements for providers and deployers to support AI literacy among staff also began to apply.

2 August 2025: Rules for GPAI models came into effect, along with provisions covering AI governance and penalties.

27 July 2026: The AI Omnibus went into effect. Formally known as Regulation (EU) 2026/1744, the AI Omnibus is a 2026 amendment to the EU AI Act designed to simplify its implementation, reduce compliance burdens, and give companies and regulators more time to prepare, while keeping the Act’s core safety and fundamental-rights protections.

2 August 2026: Most of the remaining AI Act became applicable, including the transparency rules requiring disclosure or technical marking for certain AI systems and AI-generated content.

2 December 2026: The ninth prohibition covering AI-generated CSAM and non-consensual sexually explicit or intimate depictions takes effect. Providers of AI systems placed on the market before 2 August 2026 that generate synthetic text, images, audio, or video must also comply with the Act’s machine-readable marking requirements by this date.

2 August 2027: EU Member States must have at least one national AI regulatory sandbox available by this date for companies to develop and test AI systems under regulatory supervision.

2 December 2027: High-risk AI rules begin to apply to systems used in sensitive areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice.

2 August 2028: High-risk requirements begin to apply to AI systems that are part of, or safety components of, regulated products covered by EU product legislation, such as certain machinery, medical devices, toys, and lifts.

How to prepare your business for EU AI Act compliance

For businesses, the biggest practical change is that compliance starts with figuring out what role the company plays and what kind of AI it uses. A company that simply uses an AI writing assistant will have far fewer obligations than one that develops a hiring algorithm, sells an AI-powered medical device, or provides a GPAI model. The Act can also apply to companies outside the EU if they place AI systems or GPAI models on the EU market or if the output of their AI system is used in the EU.

To prepare for and maintain compliance with the EU AI Act, your business should:

Know what AI you use: Keep track of AI systems used across your teams (including third-party tools), and understand what they are being used for. This can include AI used in HR, customer service, marketing, security, analytics, and other business processes.

Determine your role: Establish whether your business is a provider that develops or sells an AI system, a deployer that uses one, or an importer or distributor. Different obligations apply to each role.

Classify AI by risk: Check whether any AI use is prohibited, high-risk, subject to transparency requirements, or minimal risk. If you’re using AI to screen job applicants, for example, rules are considerably stricter than for AI spam filters.

Stop prohibited AI uses: Audit your AI tools and workflows for any banned practices and disable or replace systems that cross the line. Focus especially on AI used to monitor employees, profile people, analyze biometric data, manipulate behavior, or make sensitive assessments about individuals.

Train employees who use AI: Providers and deployers must take measures to support AI literacy among employees and others who operate AI systems on their behalf. Training should reflect how AI is actually being used and the risks involved.

Meet AI transparency requirements: You may need to tell people when they are interacting with AI, label certain AI-generated or manipulated content, or inform people when permitted emotion recognition or biometric categorization systems are being used.

Apply stricter controls to high-risk AI: Providers must manage risks, use appropriate data, keep documentation and logs, ensure human oversight, and meet accuracy, security, and reliability requirements. They may also need to complete conformity assessments and register the system. Businesses using high-risk AI must follow the provider’s instructions, monitor how it performs, and keep the required records.

Check GPAI obligations: If you provide GPAI models, you have separate requirements covering technical documentation, information for downstream developers, copyright compliance, and summaries of training content. Models that pose systemic risk face additional safety and cybersecurity requirements.

Review AI suppliers: If you use third-party AI, check the systems provided by vendors, how they are classified, what documentation is available, and who is responsible for complying with each part of the EU AI Act. Modifying or rebranding certain AI systems can also transfer provider responsibilities onto your business.

Keep AI governance up to date: AI systems, their uses, and the law can change. Businesses should document how AI is used, monitor systems for new risks or incidents, and reassess compliance when an AI system is substantially changed or repurposed.

Compliance with the AI Act does not replace other legal obligations. Businesses using personal data, copyrighted material, or AI in regulated sectors may also need to comply with laws such as the GDPR, EU copyright rules, consumer protection law, and sector-specific regulations.

Build a privacy-first approach to AI

The EU AI Act takes a risk-based approach to AI, and you do not necessarily have to use AI yourself to be affected by it. If you live in the EU, AI may influence the content you see, the services you interact with, or decisions made about you, such as whether you can buy certain things. Familiarizing yourself with the Act can therefore help you understand when AI must be disclosed, what protections apply, and when you may be able to question or challenge how an AI system is being used.

For businesses, the obligations depend on the role the organization plays, how its AI systems are used, and the level of risk involved.

For people who do choose to use AI, Lumo offers a privacy-first, European AI alternative. Our AI assistant never logs your chats or trains on your data. Your data is protected with zero-access encryption so that only you can read it. Not even Proton can see your data.

The same protections extend to Lumo for Business, our AI assistant for teams, which lets organizations provide employees with an approved AI tool while helping keep confidential company, customer, and other sensitive data private. Using Lumo does not by itself make a business compliant with the EU AI Act, but it can support a more privacy-conscious approach to adopting and governing AI across an organization.

If you’re new to AI or want to understand the technology behind these rules, check out our guide to AI for a deep dive on AI privacy, surveillance, security risks, and an overview of the often deceptive practices of some of the most popular AI providers.