Beginner

What the EU AI Act Is

The EU AI Act is the first law anywhere to regulate artificial intelligence across every industry at once. Before you can comply with it, you need two answers: does it apply to you, and in what role? This lesson settles both.

✍️ AI School Editorial Team · Lilly Tech Systems 📅 Published Jun 13, 2026 · Reviewed Jun 13, 2026

A First-of-Its-Kind Law

The EU AI Act - formally Regulation (EU) 2024/1689 - entered into force on 1 August 2024. It is the world’s first horizontal AI law: rather than regulating AI sector by sector (health AI here, financial AI there), it sets one risk-based framework that applies to all artificial intelligence placed on the EU market or used within the EU, regardless of industry.

Because it is a Regulation and not a Directive, it applies directly in all 27 member states without each country needing to pass its own implementing law. That gives it a single, uniform text across Europe - and, as we will see, a long reach beyond it.

📚
Why this matters even if you are not in Europe: The Act is widely expected to set the global baseline for AI regulation, the way the GDPR did for privacy. Many companies will build to the EU standard everywhere simply because maintaining two product versions is more expensive than meeting the stricter bar once.

What Counts as an "AI System"

The Act defines an AI system broadly, following the OECD definition: a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs - such as predictions, content, recommendations, or decisions - that can influence physical or virtual environments. The key word is infers: systems that learn patterns or reason over inputs are in scope, while purely deterministic, hand-coded software generally is not.

This definition is intentionally wide. A fraud-detection model, a recommendation engine, a generative chatbot, a computer-vision quality inspector, and a résumé-screening tool are all AI systems under the Act. A spreadsheet formula or a basic rules engine generally is not. When the line is genuinely unclear, the safer assumption is that you are in scope.

Who the Act Applies To

The Act does not regulate "AI companies" as a category. It regulates roles. The same organisation can hold more than one role for different systems, and your obligations flow almost entirely from which role you occupy:

RoleWho you areRough obligation weight
ProviderYou develop an AI system (or have it developed) and place it on the market or put it into service under your own name or trademark.Heaviest - most obligations sit here
DeployerYou use an AI system under your own authority in a professional context (the Act’s word for what most people call the "user").Lighter, but real - especially for high-risk systems
ImporterYou place on the EU market an AI system that carries the name of a provider established outside the EU.Verification and record-keeping duties
DistributorYou make an AI system available on the market without being the provider or importer.Check that compliance markings are present

A crucial trap: if you take a high-risk system and put your own name on it, substantially modify it, or change its intended purpose, you can become the provider and inherit the provider’s obligations - even if you only meant to be a deployer. We return to this in Lesson 4.

Start every analysis with the role question. "Are we the provider or the deployer of this system?" is the single most useful question in the whole Act. Answer it per system, not per company - you may be a provider of your own model and a deployer of someone else’s.

Why It Reaches Outside the EU

Like the GDPR, the AI Act has extraterritorial effect. It applies to:

  • Providers who place AI systems on the EU market or put them into service in the EU - wherever the provider is established;
  • Deployers located in the EU; and
  • Providers and deployers located outside the EU where the output produced by the system is used in the EU.

That last clause is the one that catches companies by surprise. A US startup with no European office, serving European users from American servers, can be fully in scope because the output of its AI lands with people in the EU. Geography of incorporation does not shield you; geography of use is what matters.

What the Act Does Not Cover

The Act carves out several areas. AI systems developed and used exclusively for military, defence, or national-security purposes are excluded. So is AI used purely for scientific research and development, and free and open-source AI components - until they are placed on the market or put into service as part of a high-risk or otherwise regulated system. Personal, non-professional use by individuals is also out of scope. These carve-outs are narrower than they first appear, so do not lean on them without checking the conditions.

The Shape of What Is Coming

The rest of this course follows the structure of the Act itself:

  1. The risk tiers (Lesson 2) - the four-level framework that determines how heavily any given system is regulated.
  2. Prohibited practices (Lesson 3) - the uses banned outright.
  3. High-risk systems (Lesson 4) - the largest body of obligations.
  4. General-purpose AI (Lesson 5) - the separate regime for foundation models.
  5. Transparency duties (Lesson 6) - the lighter rules for chatbots, deepfakes, and the like.
  6. Compliance in practice and the playbook (Lessons 7-8) - timelines, documentation, and what to do now.
📚
Prerequisites: None - this course assumes no legal background. If you want the broader governance context (NIST AI RMF, ISO 42001) alongside the law, pair it with AI Governance. If you build AI products, AI Bias & Fairness covers the data-governance practices the Act’s high-risk rules require.

Ready to Go Deeper?

Live instructor-led courses from our partners. Affiliate disclosure.