What is the EU AI Act?
The EU AI Act is the world's first comprehensive legal framework regulating artificial intelligence. It entered into force on 1 August 2024 and is being phased in through 2027. It classifies AI systems by risk and imposes obligations on providers, deployers, importers, and distributors of AI systems placed on or used in the EU market.
Does the EU AI Act apply to companies outside Europe?
Yes, under certain conditions. The Act has extraterritorial scope. It can apply when an AI system is placed on the EU market, when AI services are offered to users in the EU, or when the output of an AI system is used in the EU. Being based outside Europe does not automatically exempt a business.
Does the EU AI Act apply to Korean companies?
It may. If a Korean company uses AI in services or products offered to EU customers, or if the output of its AI system is used in an EU context, the Act can become relevant. The key factor is the connection between the AI system and the EU market - not the location of the company's headquarters.
Does the EU AI Act apply to US companies?
Yes, under the same conditions. US companies that provide AI systems or AI-powered services to EU users, or that license AI technology to EU businesses, may fall within scope as providers or importers under the Act.
Does the EU AI Act apply to SaaS businesses?
SaaS businesses that embed AI functionality in their products and offer those products to EU users may be classified as providers of AI systems under the Act. The extent of obligations depends on the risk classification of the AI involved and the specific functionality provided.
Does the EU AI Act apply to AI startups?
Yes. AI startups that develop or deploy AI systems are directly addressed by the Act. The Act includes specific provisions to reduce the administrative burden on SMEs and startups, but it does not exempt them from compliance obligations when their AI systems present significant risks or serve EU users.
Does the EU AI Act apply to clinics using AI?
Medical AI is one of the highest-risk categories under the Act. Clinics using AI for diagnosis, treatment recommendations, patient monitoring, or medical image analysis may be using high-risk AI systems and face the strictest compliance obligations, including technical documentation, human oversight requirements, and registration in the EU database.
Does the EU AI Act apply to marketing agencies using AI?
Marketing agencies using AI for content generation, personalization, or targeting directed at EU consumers should assess their obligations. AI-generated content targeting EU users typically requires transparency disclosures. Certain AI tools used in recruitment or profiling may fall into higher risk categories.
What happens if my company is not compliant?
Non-compliance can result in significant financial penalties, prohibition from placing AI systems on the EU market, and reputational damage. The EU AI Office and national competent authorities have enforcement powers. Penalties are calculated on global annual turnover, not just EU revenue.
What are the penalties for violating the EU AI Act?
Penalties range from 7.5 million EUR or 1.5 percent of global turnover for providing incorrect information, to 15 million EUR or 3 percent for high-risk AI violations, to 35 million EUR or 7 percent for using prohibited AI systems. The higher of the two figures applies in each case.
How do I know whether my business falls within the scope of the EU AI Act?
The assessment involves identifying whether you use or provide AI systems, determining the risk classification of those systems, and analyzing your connection to the EU market. A structured compliance assessment is the most reliable way to answer this question accurately. Book a free initial consultation to start the process.
When does the EU AI Act start being enforced?
The Act is being phased in: prohibited AI systems became unlawful from February 2025, general-purpose AI model obligations apply from August 2025, high-risk AI system obligations apply from August 2026, and the remaining provisions apply from August 2027. Enforcement is already underway for the earliest provisions.
What is a high-risk AI system under the EU AI Act?
High-risk AI systems are those used in critical infrastructure, education, employment and recruitment, essential private and public services, law enforcement, border management, administration of justice, and democratic processes. Medical devices and safety components in products are also classified as high-risk. These systems face the strictest compliance obligations.
What is the difference between an AI provider and an AI deployer?
A provider develops or places an AI system on the market. A deployer uses an AI system under its own responsibility in the course of business. Both have obligations under the Act, but providers carry heavier responsibilities around technical documentation, conformity assessment, and registration. Many businesses are both providers and deployers depending on the context.
Does the EU AI Act cover AI used internally within a company?
Yes, for high-risk applications. If a company uses a high-risk AI system internally - for example, for HR screening, employee monitoring, or access control - deployer obligations apply even if the AI is not sold externally. The obligations include transparency with affected individuals and human oversight requirements.
Does the EU AI Act apply to general-purpose AI models like ChatGPT or Claude?
Yes. The EU AI Act includes a dedicated chapter on general-purpose AI models (GPAI). Providers of GPAI models must meet transparency and documentation obligations. Those deemed to present systemic risk face additional requirements including adversarial testing and incident reporting.
What is an AI transparency disclosure?
A transparency disclosure informs users that they are interacting with an AI system. For chatbots, the Act requires that users are told they are speaking with AI. For AI-generated content including images and video, labeling requirements apply. Transparency disclosures must be clear, prominent, and easy to understand.
How does the EU AI Act interact with GDPR?
The EU AI Act and GDPR operate in parallel. AI systems that process personal data of EU individuals must comply with both frameworks simultaneously. GDPR governs data protection while the AI Act governs the AI system itself. High-risk AI systems that process personal data face obligations under both laws, and compliance assessments should address both.
Can I use AI-generated content commercially in the EU?
Yes, subject to disclosure and IP considerations. AI-generated content used commercially in the EU must be labeled under the Act's transparency requirements. Additionally, copyright ownership of AI-generated content is a separate but related question involving both EU copyright law and the law of the country where the content is created or published. See the
IP and Copyright section for more.
What contracts should I review for EU AI Act compliance?
Any contract involving AI technology should be reviewed. Priority contracts include AI vendor agreements, SaaS agreements with AI functionality, API terms for AI services, AI licensing agreements, procurement contracts for AI tools, data sharing agreements feeding AI systems, and any contract with an EU counterparty that involves AI in the services delivered.