Foundations
Understanding the EU AI Act
What the Regulation is, the risk-based approach it takes, who it applies to, and why your role in the value chain matters more than you might expect.
Updated 3 July 2026 · Reference material, not legal advice
The EU Artificial Intelligence Act — Regulation (EU) 2024/1689 — is the first comprehensive legal framework in the world dedicated to artificial intelligence. It was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024, with its provisions applying in stages over several years.
Its purpose is twofold: to support a functioning single market for AI, and to ensure that AI placed on the Union market is trustworthy — respectful of health, safety, fundamental rights, democracy and the rule of law. The Regulation is technology-neutral and risk-based: it does not regulate a technology as such, but its uses, calibrating obligations to the level of risk.
A framework built on risk
The Act sorts AI systems into four levels of risk, with a distinct regime for general-purpose AI models:
- Unacceptable risk — a short list of practices that are prohibited outright (Article 5), such as social scoring or untargeted facial-image scraping.
- High risk — systems that carry substantial obligations, either because they are safety components of regulated products (Annex I) or because they fall under one of the sensitive use cases of Annex III.
- Limited risk — systems subject to transparency obligations (Article 50), such as chatbots or systems generating synthetic content.
- Minimal risk — the large majority of systems, which carry no binding obligations.
General-purpose AI (GPAI) models — large foundation models — are governed by their own escalating regime (Articles 51–55).
Who the Act applies to
The scope (Article 2) is deliberately broad and has extraterritorial reach. It covers providers placing AI systems on the Union market regardless of where they are established; deployers located in the Union; and providers or deployers in third countries where the system’s output is used in the Union. Several areas are excluded, including systems used exclusively for military or national-security purposes, scientific research and development, and purely personal, non-professional use.
Role matters more than tier
The single most consequential question is often not “how risky is my system?” but “what is my role?”
- A provider develops an AI system (or has it developed) and places it on the market under its own name. Providers of high-risk systems carry the heavy obligations.
- A deployer uses a system under its own authority. The duties are lighter but real — using the system as instructed, ensuring human oversight, keeping logs, informing affected people.
A common trap: under Article 25, you can become a provider without intending to — by putting your name on a system, substantially modifying it, or repurposing it into a high-risk use.
What this means in practice
Knowing your risk tier is not enough to act; you also need to know which obligations apply to your role, and by when. That translation — from a dense regulation to a defensible, role-scoped list of duties with evidence to back them — is the work Euridium is built to support.
Run a guided assessment and get the obligations that apply to your role.
This guide is a plain-language summary for orientation. The authoritative text is Regulation (EU) 2024/1689 as published in the Official Journal of the European Union (12 July 2024). It does not constitute legal advice.