%3Aquality(100)&w=3840&q=75)
EU AI Act
What Is the EU AI Act?
The EU AI Act (European Union Artificial Intelligence Act) is a comprehensive regulatory framework that governs the development, placement on the market, deployment, and use of artificial intelligence systems within the EU. It applies regardless of where the provider is established, meaning organizations outside the EU may also fall within scope if their AI systems are placed on the EU market, or their outputs are used there.
The regulation introduces a risk-based governance model, meaning obligations depend on the level of risk an AI system poses to health, safety, and fundamental rights. It covers the full AI ecosystem, including providers, deployers, importers, distributors, and manufacturers integrating AI into products.
The EU AI Act also introduces rules for general-purpose AI (GPAI) models, including foundation models, with additional obligations for GPAI models designated as posing systemic risk.
Alignment with the EU Regulatory Framework
The EU AI Act works alongside other major EU digital regulations, including:
GDPR (data protection and privacy)
EU Digital Services Act (platform accountability)
EU Digital Markets Act (competition and fairness)
EU NIS2 Directive (cybersecurity resilience)
EU Data Act (data access and sharing)
Together, these regulations establish a unified digital governance framework that covers data protection, platform accountability, cybersecurity resilience, and fair competition.
Phased Implementation Timeline
The EU AI Act takes effect in phases, with different obligations activating on a defined schedule between 2024 and 2027.
Entry into force (August 2024): The regulation officially becomes law, initiating the phased implementation period.
Six months (February 2025): Prohibited AI practices apply, alongside AI literacy obligations for organizations developing or deploying AI systems.
Twelve months (August 2025): Obligations for general-purpose AI models take effect, including governance and transparency requirements.
Twenty-four months (August 2026): Most remaining provisions become applicable across regulated AI systems.
Thirty-six months (August 2027): Certain high-risk AI system requirements fully apply, completing the rollout of obligations.
Importance of the EU AI Act
Impact on Critical Sectors and Public Services
The EU AI Act is particularly important for sectors where AI directly influences safety, fundamental rights, and essential services. These sectors include healthcare, transportation, energy, financial services, public administration, and critical infrastructure.
Within these environments, the regulation strengthens accountability by requiring structured risk management, comprehensive documentation, human oversight, and ongoing monitoring. These measures help ensure AI-driven decisions remain transparent, traceable, and reliable in mission-critical environments.
Alignment with Governance and Security Practices
Organizations that already build secure-by-design principles, maintain structured documentation, and run continuous monitoring programs will recognize much of what the EU AI Act requires. The regulation is not a departure from sound governance; it formalizes it.
Where the act adds weight is in demonstrability. Regulators expect documented evidence that AI systems were designed, tested, deployed, and monitored against defined requirements, not assurances after the fact. That evidence trail strengthens legal defensibility, supports operational accountability, and reduces reputational exposure when scrutiny arrives.
Operational Clarity through Risk Classification
One of the defining features of the EU AI Act is its structured risk classification framework. AI systems are categorized as unacceptable, high, limited, or minimal risk, with obligations corresponding to each level.
This classification framework supports informed procurement, governance, development, and deployment decisions while reducing the likelihood of compliance gaps or enforcement actions.
Key Elements of the EU AI Act
Unacceptable-Risk AI Systems
The EU AI Act categorically prohibits certain AI systems. These are applications where the regulation deems fundamentally incompatible with EU fundamental rights, where no level of safeguard or oversight makes deployment acceptable.
Examples include:
Social scoring systems that result in unjustified or discriminatory treatment of individuals
Certain forms of real-time remote biometric identification in publicly accessible spaces, subject to limited narrowly defined exceptions under law enforcement conditions
AI systems that manipulate behavior in a manner that causes or is likely to cause significant harm, or exploit vulnerabilities of individuals or specific groups
Untargeted scraping of facial images from the internet or CCTV sources to build or expand facial recognition databases
High-Risk AI Systems
High-risk AI systems remain permitted but are subject to extensive regulatory requirements under the EU AI Act.
Examples include AI used in:
Critical infrastructure
Employment and workforce management
Education and student evaluation
Healthcare and medical devices
Credit assessment and access to essential services
Law enforcement
Border management
Administration of justice
These systems are subject to strict obligations, including risk management systems, data governance requirements, technical documentation, logging and record-keeping, transparency and provision of information to users, human oversight, accuracy, robustness, and cybersecurity requirements.
Limited-Risk AI Systems
Limited-risk AI systems are primarily subject to transparency obligations under the EU AI Act.
Examples include:
Chatbots interacting directly with individuals
AI systems generating or manipulating content requiring disclosure
Systems designed to simulate human interaction
Requirements include:
Informing individuals when they are interacting with AI systems
Disclosing AI-generated or manipulated content where required
Ensuring outputs are clearly identifiable as AI-generated where applicable
Minimal or No-Risk AI Systems
Minimal or no-risk AI systems are not subject to mandatory obligations under the EU AI Act.
These systems are considered to present minimal or no risk to health, safety, or fundamental rights and therefore fall outside the act’s specific compliance requirements.
Examples include:
Spam filters and email sorting tools
AI-enabled video games and entertainment features
Basic inventory or logistics optimization tools
Simple recommendation or personalization systems
While not regulated under the EU AI Act, organizations may still apply voluntary governance measures, including transparency practices, internal testing, and cybersecurity controls. Depending on the context of use, other regulatory frameworks such as the GDPR may still apply.
EU AI Act Use Cases
Implementing EU AI Act Compliance
EU AI Act compliance starts with knowing what you have. Organizations begin by building a full inventory of AI systems across the business: internally developed solutions, embedded AI capabilities, and third-party tools. Each system is then classified by intended purpose, user impact, and regulatory risk category. That classification determines which obligations apply and where remediation work is needed first.
Accountability across the AI lifecycle requires more than a legal review. Legal, cybersecurity, engineering, privacy, procurement, and executive leadership each carry defined responsibilities under the regulation. Cross-functional governance structures make accountability explicit and traceable, rather than assumed.
Many organizations align governance activities with established standards: ISO/IEC 42001 for AI management systems, ISO/IEC 27001 for information security, and ISO/IEC 23894 for AI risk management. These frameworks provide structured methods for meeting the regulation requirements and support auditability across the compliance lifecycle.
Testing, Validation, and Documentation
Testing under the EU AI Act is expected to be rigorous and repeatable. Validation activities may include performance testing, robustness assessments, fairness evaluations where appropriate, and resilience testing against adversarial attacks.
Organizations build documentation records that support conformity assessments and regulatory oversight. Typical records include technical documentation, system descriptions, model information, data governance documentation, testing evidence, and ongoing monitoring activities.
Supplier due diligence also supports compliance by improving transparency around model capabilities, limitations, and governance practices.
Procurement, Operations, and Security
Procurement represents a key governance function under the EU AI Act. Vendor evaluations commonly consider model capabilities, intended use, documentation quality, logging, explainability, auditability, and security controls.
Operational oversight includes continuous monitoring for performance drift, operational anomalies, and cybersecurity risks. Supporting controls typically include encryption, access management, secure deployment practices, incident response processes, and ongoing compliance monitoring.
AI Literacy
The EU AI Act requires organizations to take measures that promote an appropriate level of AI literacy among personnel involved in the development, deployment, or oversight of AI systems. Training should reflect operational responsibilities, governance requirements, and the level of risk associated with each AI system.
Maintaining EU AI Act Compliance
The EU AI Act should be viewed as an evolving governance framework rather than a one-time implementation exercise. Maintaining compliance requires continuous monitoring of regulatory developments, emerging standards, and guidance issued by European authorities.
Organizations that sustain compliance integrate governance, cybersecurity, procurement, documentation, and operational oversight into a continuous lifecycle rather than treating the regulation as a one-time implementation. This approach supports regulatory compliance while enabling responsible innovation, operational resilience, and trusted AI adoption across government, critical infrastructure, and other highly regulated sectors.
%3Aquality(100)&w=3840&q=75)
BlackBerry for Secure Communications
For Environments Where Failure Isn’t an Option
BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.
Explore BlackBerry Secure Communications solutionsFAQ
Frequently asked questions about EU AI Act answered
Q: What is the EU AI Act and who does it apply to?
A: The EU AI Act is the European Union's primary regulatory framework governing how AI systems are developed, placed on the market, deployed, and used. It applies to providers, deployers, importers, distributors, and manufacturers globally, covering any organization whose AI systems are placed on the EU market or whose outputs are used there.
Q: What are the four risk categories under the EU AI Act?
A: The regulation classifies AI systems into four levels: unacceptable, high, limited, and minimal risk. Unacceptable-risk systems are categorically prohibited; high-risk systems carry strict compliance obligations; limited-risk systems face transparency requirements; and minimal-risk systems have no mandatory obligations under the act, though frameworks such as the GDPR may still apply.
Q: What are the specific obligations for high-risk AI systems?
A: Organizations developing or deploying high-risk AI systems must implement risk management systems, maintain technical documentation, and keep logs that support traceability. They must also build in human oversight mechanisms and meet accuracy, robustness, and cybersecurity requirements throughout the system's operational life.
Q: When do EU AI Act obligations take full effect?
A: The regulation entered into force in August 2024 and applies in phases through August 2027. Key milestones include prohibitions on unacceptable-risk practices from February 2025, general-purpose AI obligations from August 2025, and most remaining provisions from August 2026.