EU AI Act Enforcement Begins — What Companies Need to Know
- The EU AI Act's high-risk system requirements are now enforceable across all EU member states
- Companies using AI in hiring, credit, education, or law enforcement face new compliance obligations
- Penalties reach up to €35 million or 7% of global annual revenue for the most serious violations
The European Union's Artificial Intelligence Act entered its full enforcement phase today, making it the world's first comprehensive AI regulatory framework with real legal teeth. While the Act was passed in 2024 and has been phased in gradually, today marks the point at which the rules governing high-risk AI systems become fully enforceable.
The law creates a tiered risk framework. Most AI applications — including general-purpose tools like ChatGPT used for productivity — face minimal requirements: basic transparency obligations and prohibitions on clearly harmful uses like social scoring. It's the "high-risk" category that carries the most significant compliance burden.
High-risk AI systems are those used in consequential domains: hiring and HR decisions, credit and insurance scoring, educational assessment, law enforcement, border control, and critical infrastructure. Companies deploying AI in these areas must now maintain technical documentation, conduct conformity assessments, implement human oversight mechanisms, and register their systems in an EU-wide database.
"This is the moment the AI Act moves from theory to practice," said EU AI Office Director Lucilla Sioli in a statement. "We expect companies to have completed their initial assessments. Our enforcement teams are operational."
What This Means For Different Stakeholders
For businesses using AI tools
If you use AI tools for hiring, performance review, or any high-stakes decision-making in the EU, you need to verify that your vendors are compliant. Request conformity documentation from your AI tool providers.
For AI tool vendors
If your product is classified as high-risk, you need CE marking, a conformity assessment, and registration. General-purpose AI models (like GPT or Claude accessed via API) face lighter requirements focused on transparency and copyright.
For individuals
You gain new rights: the right to an explanation when AI makes a significant decision about you, and the right to appeal those decisions to a human reviewer. These rights apply across all EU member states starting today.