What is the AI Act?
The AI Act —Regulation (EU) 2024/1689— is the world's first comprehensive artificial-intelligence law. It regulates how AI systems are developed and used in the EU with a risk-based approach.
It classifies systems into four levels: prohibited, high risk, limited risk (transparency obligations) and minimal risk. The higher the risk, the more the obligations.
Who does it affect?
It's not only for those who build AI. It also —and above all— affects those who use it.
- Providers that develop or market AI systems.
- Companies using AI (deployers): most. If you use AI in hiring, customer service, scoring, etc., it applies.
- Importers and distributors of AI systems.
- Providers of general-purpose models (GPAI).
What it requires (by risk level)
- Prohibited practices: banned (e.g. manipulation, social scoring).
- High risk: risk management system, data governance, technical documentation, human oversight, logging and traceability.
- Transparency: notify when a user interacts with AI or when content is generated or manipulated (deepfakes).
- General purpose (GPAI): specific documentation and transparency obligations.
How we help you comply
- Inventory. Which AI systems you use or sell.
- Risk classification. Which level each falls into.
- Policies and governance for AI use.
- Documentation and controls required by the level.
- Training for teams using AI.
- Timeline tracking of obligations.
With Tria you don't face it alone or at the last minute. We build your AI inventory and governance and —if you already have Plan Tria— integrate it with your policies and evidence, so each phase of the timeline finds you ready.
AI Act and GDPR: how do they relate?
They complement each other. The GDPR protects the personal data that feeds and is produced by AI; the AI Act regulates the AI system itself. Many obligations (data governance, transparency, impact assessment) reinforce each other, so it's best to tackle them together.
Frequently asked questions
When does the AI Act apply?
In phases: prohibited practices and general-purpose models started in 2025; transparency obligations and most requirements in August 2026; high risk rolls out in phases through 2027.
Does it affect me if I only use AI (e.g. ChatGPT or an HR tool)?
Yes. As a deployer you have obligations, especially around transparency, training and appropriate use.
What are the fines?
The most serious (prohibited practices) reach up to €35 million or 7% of annual global turnover, whichever is higher.
Do I need to do anything if my AI is low risk?
Less, but you should keep the inventory and use policies: that's the basis for proving you have it under control.