Back to Frameworks
Emerging

EU AI Act

The EU AI Act is the first comprehensive, horizontal regulation of artificial intelligence, entering into force in 2024 with obligations phased in over the following years.

It classifies AI systems into risk tiers — unacceptable risk (banned outright), high-risk (subject to strict obligations like conformity assessments and human oversight), limited risk (transparency obligations, e.g. disclosing AI-generated content), and minimal risk (largely unregulated). Obligations fall on both providers who build AI systems and deployers who use them, with penalties that can reach into the tens of millions of euros or a percentage of global turnover for the most serious violations.

See how LumiGRC handles EU AI Act

Get a Demo
4

AI risk tiers

0%
Typical certification profile
Audit Rigor50%
Time to Certify50%
Surveillance Burden61%
Issued & Enforced By

European Commission

Regulation (EU) 2024/1689

Key Points

  • Four risk tiers: unacceptable, high, limited, minimal
  • High-risk systems require conformity assessment and human oversight
  • Obligations apply to both AI providers and deployers
  • Penalties scale up to a percentage of global turnover