Pyramide mit den vier Risikostufen des AI Act: unten minimales Risiko (Spamfilter), darüber begrenztes Risiko mit Transparenzpflicht (Chatbots), darüber Hochrisiko mit Auflagen (Bewerberauswahl, Kreditvergabe), an der Spitze verbotene Praktiken (Social Scoring, Emotionserkennung am Arbeitsplatz).

AI Act

The AI Act is the European Union's law for artificial intelligence. It sorts applications according to their risk and specifies which are prohibited and which remain permitted only under strict requirements.

The AI Act is a law of the European Union. It regulates how computer programs may be used that learn patterns from data themselves and use them to generate decisions or texts. Such programs are called artificial intelligence. The law bans some uses entirely and permits others only under strict requirements. What matters here is not the technology itself, but the harm its use can cause. The EU adopted the AI Act in 2024; the rules take effect in stages through 2027.

The world’s first comprehensive AI law

Before the AI Act, there was no law in Europe written specifically for AI. Anyone who sold a system for selecting job applicants did not have to explain to anyone how it arrived at its judgments. That is exactly what is changing. The AI Act is the first comprehensive regulation of its kind worldwide.

This has consequences far beyond Europe. The EU single market is too large to ignore. So many companies adapt their products to the European requirements worldwide right away, instead of maintaining two versions. Experts call this effect the Brussels effect. It has already worked once before, with the General Data Protection Regulation, the EU law protecting personal data.

Nevertheless, the law remains controversial. Critics from industry warn that the burden of documentation and testing hits small companies particularly hard. Consumer advocates, on the other hand, consider some exemptions too broadly drawn, for instance regarding use by police and authorities. How strictly the law ultimately takes effect will be decided in the practice of the supervisory authorities.

Four risk levels as an organizing principle

The AI Act sorts applications into four levels. At the top level are prohibited practices. These include evaluating people according to their general social behavior, often called social scoring. Systems designed to recognize the emotions of employees in the workplace are also banned.

The second level is called high risk. This concerns uses that help decide on people’s lives: screening job applications, assessing loans, grading exams, supporting medical diagnoses. This is not banned, but it is bound by obligations. The provider must document the training data, check for sources of error, provide for human oversight, and register the system.

The third level covers applications with limited risk. Here, above all, a transparency obligation applies: users must be able to recognize that they are talking to a machine or seeing an artificially generated image. Everything else falls into the fourth level and remains practically unregulated, such as a spam filter or a music recommendation. In addition, there are separate rules for very general-purpose models like those behind chatbots. Their providers must, among other things, disclose what content was used for training.

From the application process to the watermark

In everyday life, the AI Act mostly appears unobtrusively. When a chatbot on a company website states right at the start that it is an AI assistant, this obligation is behind it. Labels under AI-generated images and videos also stem from it. Such markers within content are called watermarks.

Other aspects appear in business news. These concern deadlines, fines of up to seven percent of global annual revenue, and the question of whether Europe is holding itself back with this law. Major providers from the US have repeatedly announced delays in rolling out new features in the EU. For publicly traded technology companies, the AI Act is thus a real cost factor.

A common misconception: the AI Act does not ban technologies, but purposes of use. Facial recognition is not blanket illegal. But its use for mass surveillance in public spaces is, with narrow exceptions for serious crimes. Anyone wanting to judge whether an application is permitted must therefore always ask what it is being used for.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.