The EU AI Act: What Does It Mean for Your Organization?
The European AI regulation - better known as the EU AI Act - has been in force since August 2024. It is the world’s first comprehensive law regulating artificial intelligence. For organizations that use AI, this means they must be able to demonstrate compliance with requirements related to transparency, risk management, and human oversight.
A risk-based approach
At the core of the AI Act is a classification into four risk categories. The higher the risk, the stricter the requirements. Systems with an unacceptable risk - such as social scoring - are simply prohibited. For high-risk applications, extensive obligations apply regarding documentation, data quality, and logging.
Which deadlines are coming up?
Implementation is phased. The bans on unacceptable AI are already in effect. As of August 2025, the rules for General Purpose AI (such as ChatGPT integrations) will apply, and by August 2026 all high-risk systems must be fully compliant.
Start today with a baseline assessment
The most important first step is gaining insight: which AI systems does your organization actually use, and which risk category do they fall into? With a structured AI inventory, you’ll know exactly where you stand - and what still needs to be done. Don’t wait until the deadline is near.