Regulation (EU) 2024/1689

The EU AI Act: What You Need to Know

The world's first comprehensive AI regulation is here. Understand the requirements, assess your risk level, and ensure your AI systems are compliant before enforcement begins.

Key Enforcement Dates

The EU AI Act is being enforced in phases. Here are the dates that matter.

February 2, 2025

Prohibited Practices

Ban on unacceptable-risk AI systems — in force

August 2, 2026

Transparency & Enforcement

Article 50 disclosure duties apply; the AI Office and national authorities begin enforcing

December 2, 2026

New Prohibitions

Non-consensual intimate imagery and AI-generated CSAM banned

December 2, 2027

High-Risk AI

Annex III high-risk obligations, deferred from August 2026 (Annex I follows August 2, 2028)

Risk Classification System

The AI Act categorizes AI systems into four risk levels, each with different compliance requirements.

Unacceptable Risk — Banned

Social scoring, real-time biometric surveillance, manipulative AI. These are prohibited entirely.

High Risk — Strict Requirements

AI in hiring, credit scoring, healthcare, law enforcement. Requires risk management, documentation, human oversight, and conformity assessment.

Limited Risk — Transparency

Chatbots, deepfakes, emotion recognition. Must disclose that users are interacting with AI.

Minimal Risk — No Requirements

Spam filters, AI in video games, recommendation systems. Free to use with voluntary codes of conduct.

Why Compliance Matters

Penalties Up to €35M

Non-compliance can result in fines up to €35 million or 7% of global annual turnover — whichever is higher.

Competitive Advantage

Companies that demonstrate AI compliance build trust with customers, partners, and regulators — gaining market advantage.

The Clock Is Already Running

Transparency obligations are enforceable today. High-risk requirements follow on December 2, 2027 — enough time to do this properly, not enough to leave it.

How Ctrl AI Solves Compliance

Ctrl AI provides auditable AI processes where every decision is traceable, every reasoning step is expert-verified, and every output carries a trust tag.

Full Audit Trails

Every AI decision logged with complete execution traces — show auditors exactly how your AI decided.

Expert Verification

Domain experts verify reasoning units element by element. No black-box AI — every rule is reviewed.

Trust Gradient

Every output tagged as verified, expert-reviewed, synthesized, or neural — transparency built in.

Explore Ctrl AI

Latest Articles

View all
Regulation11 min read

The Digital Omnibus on AI: What Regulation (EU) 2026/1744 Changed

The first amendment to the EU AI Act deferred the high-risk regime to 2 December 2027 and 2 August 2028 — but left the 2 August 2026 general application date intact. What moved, what did not, and what your compliance programme should do about it.

Use Cases12 min read

AI Content Moderation and the EU AI Act

How the EU AI Act applies to AI-driven content moderation systems — risk classification, transparency obligations, interaction with the Digital Services Act, and the practical compliance path for platforms.

Compliance14 min read

AI-Generated Content Labelling Under the EU AI Act

Article 50 of the EU AI Act requires machine-readable marking and user-facing disclosure of AI-generated content. Practical guidance on what to label, who is responsible, and the technical implementation.

Regulation16 min read

Annex I Explained: AI in Regulated Products Under the EU AI Act

How Annex I of the EU AI Act classifies AI systems embedded in regulated products — medical devices, machinery, toys, vehicles, aviation, marine, and more. Conformity assessment, deadlines, and the MDR/IVDR interaction.

Regulation15 min read

Annex III Explained: Standalone High-Risk AI Systems Under the EU AI Act

Detailed breakdown of all eight categories of standalone high-risk AI systems in Annex III of the EU AI Act — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.

Use Cases14 min read

Biometric AI and the EU AI Act: Identification, Verification, and Categorisation

How the EU AI Act regulates biometric AI — Article 5 prohibitions on real-time remote ID and sensitive-attribute categorisation, Annex III high-risk classification, and the practical compliance path.