In a landmark decision in June 2023, the European Parliament voted on the European Commission's proposal for the EU Artificial Intelligence Act, marking a significant advancement in the regulation of artificial intelligence within the EU.
This groundbreaking step is part of broader European efforts to protect personal data, akin to the General Data Protection Regulation (GDPR). According to the European Commission's AI Office, more than 6,000 AI systems were identified across EU member states during its 2024 mapping exercise, illustrating the sheer scale of the regulatory task ahead. While recognizing the numerous advantages AI offers in daily life, EU representatives underscored the necessity of implementing binding regulations to address potential risks.
As the final version of the EU AI Act was being negotiated, it became essential to explore AI regulations both within the EU and globally. This exploration involved understanding the adoption process of the EU AI Act, its scope, and the requirements it imposes on AI system providers and users. By examining AI governance alongside the EU's commitment to data protection, we can better appreciate the complex regulatory framework aimed at balancing AI innovation with the protection of individual rights.
These risks include concerns related to privacy and security, lack of transparency in AI systems, and issues of bias and discrimination. The EU Charter of Fundamental Rights provides the constitutional foundation for addressing these challenges through dedicated legislation.
Global Perspectives on AI Regulation
TL;DRBy late 2023, AI regulation was gaining momentum worldwide. The United States issued its first Executive Order on AI safety, China and the UK were developing their own frameworks, and international bodies including the OECD and UNESCO had published non-binding AI governance recommendations. The Bletchley Declaration on AI Safety, signed by global leaders in November 2023, signalled a coordinated international commitment to managing AI risks.
Globally, there is increasing recognition of the need for AI regulation. Until recently, the United States had no mandatory AI regulations, relying only on the American National Institute of Standards and Technology's (NIST) AI Risk Management Framework as a voluntary guide for responsible AI development. On October 30, 2023, the U.S. President issued an Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence, requiring AI developers to report their safety results and critical information to the government. Meanwhile, China's Cyberspace Administration was considering proposals for AI regulation, and the UK was developing a framework designed to encourage innovation while addressing AI-related issues.
The pace of international coordination was accelerating. Internationally, the Organisation for Economic Co-operation and Development (OECD) introduced a non-binding Recommendation on AI in 2019, and UNESCO adopted Recommendations on the Ethics of AI in 2021. The Council of Europe was working on an international convention to regulate artificial intelligence.
On November 1, 2023, global leaders convened in the UK to address the urgent issue of AI safety. They signed the Bletchley Declaration on AI Safety, which highlights the "urgent need to understand and collectively manage potential risks through a new joint global effort." Follow-up meetings were scheduled in South Korea and France to continue this collaborative effort.
Scope of the EU AI Act
TL;DRThe EU AI Act was the culmination of years of non-binding frameworks, white papers, and ethics guidelines that European policymakers recognized were insufficient for the pace of AI advancement. The Act implements a risk-based classification system, categorizing AI systems by their potential societal harm and applying proportionate regulatory requirements. It also sought to legally define AI systems despite the absence of a universally accepted scientific definition at the time of drafting.
In recent years, setting rules for artificial intelligence was a major focus for European Union representatives. While earlier documents such as the White Paper on Artificial Intelligence, Ethics Guidelines for Trustworthy AI, and Policy and Investment Recommendations were non-binding, policymakers recognized the need for enforceable regulations due to the rapid advancement of AI technology.
The European Commission proposed the EU AI Act to establish conditions for AI systems within the EU market, prevent market fragmentation, and encourage the development of AI while safeguarding citizens' rights.
The EU AI Act sought to implement risk-based conditions for AI systems. This approach involves categorizing AI systems based on the level of risk they pose to society. AI systems deemed high-risk face stricter regulations and controls, potentially leading to their prohibition, whereas lower-risk systems are subject to more relaxed transparency requirements.
Additionally, the Act aimed to legally define AI systems, despite the lack of a universally accepted definition in the scientific community at the time of its drafting. That ambiguity made the legislative task considerably harder.
Who Will Be Affected by the EU AI Act?
TL;DRThe EU AI Act applies primarily to AI system providers and users within the EU, but its reach extends to third-country providers whose systems produce outputs used within EU borders. Exemptions exist for military applications, third-country public authorities, international organizations, and AI systems used under law enforcement cooperation agreements. The extraterritorial scope mirrors the approach taken by the GDPR.
The regulations primarily target AI system providers within the EU and extend to those from third countries that either introduce AI systems to the EU market or use them within EU borders.
To prevent evasion, the regulations also cover AI system providers and users from third countries if their systems' outputs are used within the EU. However, the regulation does not apply to AI systems designed solely for military purposes, those used by public authorities in third countries, or international organizations. Exemptions also include AI systems used by authorities under international agreements related to law enforcement and judicial cooperation.
Risk Assessment in Focus
TL;DRThe AI Act employs a risk-based approach that calibrates regulatory obligations to the level of harm each AI system can cause. Systems are classified into four tiers: unacceptable risk (banned outright), high risk (subject to conformity assessments and registration), limited risk (transparency obligations), and low or minimal risk (no mandatory obligations). The classification determines which compliance requirements apply.
The AI Act employs a risk-based approach, tailoring legal measures to the level of risk associated with different AI systems.
To implement this strategy, the Act classifies AI systems into various categories based on their risk profiles. These categories help determine the appropriate regulatory requirements for each type of AI system.
Risk Level and Measures
- Unacceptable risk: Prohibited AI practices
- High Risk: Regulated high-risk AI system
- Limited risk: Transparency obligations
- Low risk: No obligations
1. Unacceptable Risk
AI systems classified as presenting an unacceptable risk, meaning they pose a clear and significant threat to individuals' rights and safety, are banned from the EU market.
This category includes:
- AI systems that use harmful manipulative techniques, such as subliminal messaging
- AI systems targeting particularly vulnerable groups (for example, individuals with physical or mental disabilities)
- AI systems employed by public authorities, or on their behalf, for social scoring purposes
- Real-time remote biometric identification systems in publicly accessible areas for law enforcement, with exceptions for limited cases such as post-incident identification for serious crimes, contingent upon court approval
2. High Risk
Examples include AI systems used in products regulated under EU safety legislation and eight specific areas including biometric identification, critical infrastructure, education, employment, law enforcement, and more.
High-risk AI systems are subject to the following requirements:
- Mandatory registration in an EU database for providers subject to EU rules, or self-assessment of compliance for providers not governed by EU rules
- Compliance with regulations on cybersecurity, data protection, and risk management
- Non-EU providers must designate an authorized representative within the EU to confirm compliance with the AI Act
3. Limited Risk
AI systems with limited risk must adhere to basic transparency standards to allow users to make informed decisions. Users must be notified when interacting with AI, including systems that generate or modify content such as deepfakes.
4. Low or Minimal Risk
No additional legal obligations, but voluntary codes of conduct are encouraged.
EU AI Act Under Fire from France, Germany, and Italy
TL;DRFrance, Germany, and Italy opposed strict regulation of foundation models, arguing that binding rules on general-purpose AI could hinder European competitiveness against American and Chinese rivals. They proposed self-regulation through voluntary codes of conduct instead. Critics warned that self-regulation of powerful AI systems could produce unenforceable rules, and the disagreement created a significant deadlock in negotiations.
These countries argue that stringent regulations on foundation models could hinder Europe's progress in AI technology. They propose self-regulation through company commitments and codes of conduct.
Critics warn that self-regulation through codes of conduct could result in unenforceable rules for powerful and potentially dangerous AI systems, raising concerns about the effectiveness of such an approach. The stark differences in views created a deadlock, threatening the overall negotiation process for the Artificial Intelligence Act.
AI Governance, Enforcement, and Sanctions
TL;DRThe Act requires each Member State to appoint competent authorities and a national supervisory authority to monitor compliance. The European Artificial Intelligence Board coordinates enforcement at EU level. Administrative fines under the final adopted Act can reach up to 35 million EUR or 7% of global annual turnover for the most serious violations, revised upward from the draft figures that were under negotiation at the time of writing.
The draft proposes:
- Member States must appoint competent authorities, including a national supervisory authority, to enforce the regulations
- The European Artificial Intelligence Board is established at the EU level
- National market surveillance authorities monitor compliance with obligations for high-risk AI systems, with access to confidential information, and can enforce corrective measures, including prohibition, restriction, withdrawal, or recall of AI systems, for non-compliance. Member States may intervene in cases of persistent issues
- Administrative fines under the final EU AI Act can reach up to 35 million EUR or 7% of total worldwide annual turnover for the most serious violations, with lower tiers of 15 million EUR or 3% for other breaches, an increase from the draft figures under negotiation at the time of writing
Despite existing disagreements, enacting binding AI legislation remains crucial to protect citizens' fundamental rights while fostering technological advancement within the EU and beyond.
Further Reading on Whisperly

Reviewed by: Tamara Zavisic, AI Governance Specialist