The EU AI Act: A Risk-Based Overview

Last updated: 20 August 2026

The European Union’s Artificial Intelligence Act is a law regulating artificial intelligence. It takes a risk-based approach: the obligations that apply to an AI system depend on the level of risk it is considered to pose. It entered into force in 2024 and applies in phases.

The four risk levels

How it applies

The Act applies in stages. Following its entry into force in 2024, the prohibitions on unacceptable-risk practices took effect first, with the obligations for high-risk systems being brought into force over the following period. Businesses outside the EU may be affected where their AI systems are placed on the EU market or used within the EU.

The regulation of AI is still developing, both in the EU and elsewhere. Organisations that build or deploy AI can prepare by identifying which risk category their systems are likely to fall into and monitoring how the rules take effect.