BeCodeBeCode
Back to the glossary
Artificial intelligence

EU AI Act

The European regulation on artificial intelligence

The EU AI Act is a European Union regulation governing the development and use of artificial intelligence systems according to how risky they are. Because it is a regulation, it applies directly and identically across every member state — no national transposition is needed. Its duties reach companies that merely use AI, not only those that build it.

The risk pyramid, and who counts as what

The regulation sorts systems by risk — from prohibited practices, through high-risk systems, down to minimal-risk ones, which are the majority. How demanding the duties are follows from that classification.

The split of roles matters just as much. A provider develops a system and puts it on the market; a deployer uses it in the course of its own activity. An ordinary company subscribing to an AI tool is a deployer — and some duties land on deployers too.

What applies now and what moved

The first duty to bite was AI literacy under Article 4, which has applied since 2 February 2025. It is also the duty that touches the greatest number of companies, since it is enough that staff use AI tools at work.

Since 2 August 2026 the transparency duties in Article 50 apply — users must know they are dealing with a machine, and synthetic content including deepfakes must be labelled. The duties for stand-alone high-risk systems under Annex III, by contrast, were deferred to December 2027 by the Digital Omnibus, which a great deal of online coverage still reports on the original schedule. In practice the duty is met with training and an internal AI policy.

Want your AI Act duties covered?

See what the AI Act requires

Frequently asked questions

Does the AI Act reach a company that only uses AI?

Yes. Both providers and deployers carry duties. A company whose team uses ChatGPT, Copilot or Gemini at work is a deployer, and at minimum the duty to ensure sufficient AI literacy applies to it.

What are the fines?

The bands scale with severity. Breaching the transparency duties carries up to 7.5 million euro or 1 % of worldwide turnover; for high-risk systems the ceiling is 15 million euro or 3 %.

Do we need a certificate to comply?

Not for the AI literacy duty. The regulation prescribes neither a format nor a certificate — it asks for a sufficient level of knowledge and the ability to evidence the measures taken, which internal training, a written AI usage policy and an attendance record satisfy.

Related terms

No commitment

Tell us what you're working on.

Write a few lines about your company and what's holding you back. We'll get back within 24 hours with a concrete proposal and price.