|
recaplica
The EU AI Act: how Europe's artificial intelligence law works | |||||||||||||||||||||||||||||||
| © 2026 Recaplica · recaplica.com — All rights reserved | |||||||||||||||||||||||||||||||
The EU AI Act: how Europe's artificial intelligence law worksWhat to print Page numbers appear when printing with default margins. SlidesChoose a cut Flash10 slidesThe essential thread, to present in classFull17 slidesEvery chapter and the deeper detailBoth come with speaker notes. In 30 seconds quick readThe AI Act is Regulation (EU) 2024/1689, the law with which the European Union governs artificial intelligence: approved by the European Parliament and the Council on 13 June 2024, it entered into force on 1 August 2024. It sorts AI systems into four risk tiers — unacceptable, high, limited, minimal — and bans the most dangerous practices, such as government social scoring. The most serious violations can cost up to 35 million euros or 7% of a company's worldwide turnover, whichever is higher. The rules phase in on a staggered schedule spread over several years, already amended once in 2026 to push back some deadlines for high-risk systems. Key Points
Key figures
Deep DiveA law meant to steer AI, not stop itThe AI Act is the name everyone uses for Regulation (EU) 2024/1689, approved by the European Parliament and the Council on 13 June 2024 and published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, but, as often happens with EU rules of this scale, it didn’t switch on all at once: the underlying logic is that risk, not the technology itself, decides how many obligations apply to an AI system. The idea is to tell apart a chatbot that suggests recipes from a system that decides who gets hired or who qualifies for a mortgage: the first carries no obligations, the second must meet safety requirements and human oversight before it can reach the market. Four risk tiersThe regulation sorts AI systems into four categories, with obligations that grow heavier as the risk to people’s safety, rights or livelihood increases.
The unacceptable-risk practices are listed one by one in Article 5: manipulative techniques that distort behavior and undermine informed choices, exploitation of vulnerabilities tied to age or disability, unauthorized biometric categorization based on sensitive traits, criminal risk assessment based solely on profiling a person, indiscriminate scraping of photos from the web or CCTV footage to build facial recognition databases, emotion inference in schools and workplaces (except for medical or safety reasons), and “real-time” biometric identification in public spaces for law enforcement purposes, narrowly limited to missing persons or serious threats. As of 2 December 2026, a ban on generating non-consensual intimate images and child sexual abuse material was added to this list. High-risk systems aren’t banned, but they are closely watched: they need a risk management system running through their whole life cycle, training data checked for quality and representativeness, technical documentation, logging capabilities, a human oversight mechanism, and a conformity marking before reaching the market. It’s the same principle that has long governed medical devices or toys: before you sell it, you prove the product is safe.
General-purpose AI (GPAI) modelsA separate part of the regulation deals with general-purpose AI models (GPAI): the large models capable of writing text, generating images or answering questions on almost any topic, the same family of systems behind generative AI. From 2 August 2025, whoever provides them must prepare technical documentation, share information with downstream providers, comply with copyright obligations and publish a sufficiently detailed summary of the content used for training. Open-source or free models are exempt from most of these duties, unless they cross a precise line: above 10^25 FLOPs of training compute, a model is classified as carrying “systemic risk”, and its providers are also asked to run adversarial testing, assess systemic risks and report serious incidents to the AI Office. Behind any of these models, generative or not, sits the same underlying method: learning from enormous amounts of data instead of following hand-written rules, as covered in the article on machine learning, often built with many-layered neural networks. The fines: up to 7% of worldwide turnoverArticle 99 sets three tiers of fines, scaled to the severity of the violation. For banned unacceptable-risk practices, fines reach 35 million euros or 7% of the company’s annual worldwide turnover, whichever is higher. For other obligations in the regulation, such as the requirements for high-risk systems, the cap drops to 15 million euros or 3% of turnover. For incomplete, incorrect or misleading information supplied to authorities, it goes up to 7.5 million euros or 1% of turnover. There’s a clause built to avoid crushing smaller businesses, though: for SMEs, including start-ups, the lower amount between percentage and fixed figure always applies, while large companies face the reverse rule and always pay the higher amount. A staggered timeline, already amended onceThe regulation doesn’t switch on all at once: Article 113 sets out a phased application, with obligations that grow tougher as each reference date passes.
The last two dates weren’t the original ones: in July 2026 the Digital Omnibus on AI arrived (Regulation (EU) 2026/1744, approved on 8 July 2026 and in force since 27 July 2026), pushing the obligations for “stand-alone” high-risk systems from 2 August 2026 to 2 December 2027, and those for high-risk systems embedded in products already covered by safety rules (such as machinery or aircraft equipment) from 2 August 2027 to 2 August 2028. The text explicitly states it isn’t introducing a new legal regime, but simplifying the implementation of the existing one and cutting administrative burden. Who oversees it, and who the obligations fall onFrom 2 August 2025, the European Commission’s AI Office oversees providers of GPAI models, with powers to request documentation, assess systems and order corrections; the power to fine GPAI providers (Article 101) only applies from 2 August 2026, alongside the regulation’s general application. An AI Board, a Scientific Panel of independent experts and a technical Advisory Forum provide guidance and advice. Day-to-day market surveillance, that is, checking that a product sold in a single member state meets the requirements, stays with national authorities. The regulation distinguishes two roles: providers, who develop or commission the development of a system to place it on the market, and deployers, meaning whoever uses it professionally (companies, public administrations, other organizations). Its scope doesn’t stop at the Union’s borders: it also applies to providers from third countries, whenever they place a high-risk system on the EU market or its output is used within the Union anyway: an extraterritorial principle that follows the same logic as other EU digital rules, and one that intersects with the broader rules governing any algorithm tasked with making decisions on sensitive data. Slide deckSlides ready to download and make your own in PowerPoint or Google Slides, with speaker notes. Pick the Flash cut or the Full one. ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Common myths
Mind mapDrag the background to move around and the nodes to reposition them; use − and + to collapse and expand branches.
Quiz: test yourselfAnswer the questions to check what you have learned: you get instant feedback and a short explanation. Grade 0/10 0/5
FlashcardsTap the card to flip it and check whether you remember the answer, then move to the next one. 1 / 8 Explain it in your own wordsThe ultimate test: if you can explain it in simple words, you've truly understood it. Write your explanation, then compare it with the Recap. Your explanation is saved only on this device.
Frequently asked questionsWhat is the EU AI Act, in short?It's Regulation (EU) 2024/1689, the law with which the European Union governs artificial intelligence according to the risk its uses carry: some practices are banned, the most sensitive systems must meet strict requirements, others only carry transparency duties, and the most harmless ones remain unrestricted. When does the AI Act apply from?Not from a single date: the bans on unacceptable-risk practices have applied since 2 February 2025, the governance and GPAI-model obligations since 2 August 2025, general application starts on 2 August 2026, while the high-risk system obligations arrive in 2027 and 2028 after being pushed back by the Digital Omnibus on AI. What can a company be fined for violating the AI Act?Administrative fines of up to 35 million euros or 7% of annual worldwide turnover for the most serious violations (banned practices), up to 15 million euros or 3% for other obligations, up to 7.5 million euros or 1% for supplying incorrect information to authorities: the higher amount always applies, except for SMEs. Does the AI Act apply to companies without a base in the EU?Yes: it applies to providers from third countries whenever they place high-risk AI systems on the European market, or whenever their system's output is used within the Union, regardless of where the company is established. Who checks that companies comply with the AI Act?The European Commission's AI Office oversees general-purpose AI models from 2 August 2025, with powers to request documentation, run assessments and order corrections; the power to fine GPAI providers (Article 101) only applies from 2 August 2026. National authorities in each member state handle market surveillance within their own territory. Every Recap goes through an independent review before publication. |















