What the EU AI Act Is
The EU AI Act is the first law anywhere to regulate artificial intelligence across every industry at once. Before you can comply with it, you need two answers: does it apply to you, and in what role? This lesson settles both.
A First-of-Its-Kind Law
The EU AI Act - formally Regulation (EU) 2024/1689 - entered into force on 1 August 2024. It is the world’s first horizontal AI law: rather than regulating AI sector by sector (health AI here, financial AI there), it sets one risk-based framework that applies to all artificial intelligence placed on the EU market or used within the EU, regardless of industry.
Because it is a Regulation and not a Directive, it applies directly in all 27 member states without each country needing to pass its own implementing law. That gives it a single, uniform text across Europe - and, as we will see, a long reach beyond it.
What Counts as an "AI System"
The Act defines an AI system broadly, following the OECD definition: a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs - such as predictions, content, recommendations, or decisions - that can influence physical or virtual environments. The key word is infers: systems that learn patterns or reason over inputs are in scope, while purely deterministic, hand-coded software generally is not.
This definition is intentionally wide. A fraud-detection model, a recommendation engine, a generative chatbot, a computer-vision quality inspector, and a résumé-screening tool are all AI systems under the Act. A spreadsheet formula or a basic rules engine generally is not. When the line is genuinely unclear, the safer assumption is that you are in scope.
Who the Act Applies To
The Act does not regulate "AI companies" as a category. It regulates roles. The same organisation can hold more than one role for different systems, and your obligations flow almost entirely from which role you occupy:
| Role | Who you are | Rough obligation weight |
|---|---|---|
| Provider | You develop an AI system (or have it developed) and place it on the market or put it into service under your own name or trademark. | Heaviest - most obligations sit here |
| Deployer | You use an AI system under your own authority in a professional context (the Act’s word for what most people call the "user"). | Lighter, but real - especially for high-risk systems |
| Importer | You place on the EU market an AI system that carries the name of a provider established outside the EU. | Verification and record-keeping duties |
| Distributor | You make an AI system available on the market without being the provider or importer. | Check that compliance markings are present |
A crucial trap: if you take a high-risk system and put your own name on it, substantially modify it, or change its intended purpose, you can become the provider and inherit the provider’s obligations - even if you only meant to be a deployer. We return to this in Lesson 4.
Why It Reaches Outside the EU
Like the GDPR, the AI Act has extraterritorial effect. It applies to:
- Providers who place AI systems on the EU market or put them into service in the EU - wherever the provider is established;
- Deployers located in the EU; and
- Providers and deployers located outside the EU where the output produced by the system is used in the EU.
That last clause is the one that catches companies by surprise. A US startup with no European office, serving European users from American servers, can be fully in scope because the output of its AI lands with people in the EU. Geography of incorporation does not shield you; geography of use is what matters.
What the Act Does Not Cover
The Act carves out several areas. AI systems developed and used exclusively for military, defence, or national-security purposes are excluded. So is AI used purely for scientific research and development, and free and open-source AI components - until they are placed on the market or put into service as part of a high-risk or otherwise regulated system. Personal, non-professional use by individuals is also out of scope. These carve-outs are narrower than they first appear, so do not lean on them without checking the conditions.
The Shape of What Is Coming
The rest of this course follows the structure of the Act itself:
- The risk tiers (Lesson 2) - the four-level framework that determines how heavily any given system is regulated.
- Prohibited practices (Lesson 3) - the uses banned outright.
- High-risk systems (Lesson 4) - the largest body of obligations.
- General-purpose AI (Lesson 5) - the separate regime for foundation models.
- Transparency duties (Lesson 6) - the lighter rules for chatbots, deepfakes, and the like.
- Compliance in practice and the playbook (Lessons 7-8) - timelines, documentation, and what to do now.
Ready to Go Deeper?
Live instructor-led courses from our partners. Affiliate disclosure.
AI & ML Courses - 30% Off
Live instructor-led AI, machine learning, data science, and cloud courses for working professionals. Use code Limited30 at checkout.
EdurekaDataCamp - AI & Data Science
Hands-on Python, machine learning, and AI courses with interactive exercises and real projects.
DataCampedX - Top AI Courses
University-level AI courses from MIT, Harvard, Stanford. Earn certificates that employers recognize.
edX