Europe's AI Act Takes Shape: A Comprehensive Framework for Trustworthy AI

·

The European Union has taken a significant step towards establishing a comprehensive framework for artificial intelligence (AI) with the introduction of the AI Act. This landmark legislation aims to address the risks associated with AI and position Europe as a leader in the global AI landscape.

The AI Act, Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, is the first-ever comprehensive legal framework on AI worldwide. Its primary objective is to foster trustworthy AI in Europe by setting out clear guidelines for developers and deployers of AI systems.

To achieve this goal, the AI Act introduces a risk-based approach that categorizes AI systems into four levels of risk: unacceptable, high, transparency, and minimal or no risk. This framework allows authorities to focus on the most critical areas while minimizing unnecessary regulatory burdens.

The AI Act sets out specific rules for each level of risk. For instance, unacceptable-risk AI systems are banned outright, with nine practices prohibited under the legislation. These include harmful manipulation and deception, social scoring, and untargeted scraping of internet or CCTV material to create facial recognition databases.

High-risk AI use cases pose serious risks to health, safety, or fundamental rights. Examples include AI safety components in critical infrastructure, such as transport systems, where failure could put lives at risk. Other high-risk areas include education institutions, employment management, and access to essential services like credit scoring.

The AI Act also introduces transparency obligations for providers of generative AI models. This includes ensuring that humans are informed when interacting with chatbots or other AI-generated content. Additionally, AI-generated images, audio, and text must be clearly labelled as such.

Minimal-risk AI systems, which include applications like video games and spam filters, are not subject to the same level of regulation under the AI Act. However, providers of high-risk AI systems will need to adhere to strict obligations before placing their products on the market.

These obligations include conducting thorough risk assessments, ensuring high-quality datasets, logging activity for traceability, providing detailed documentation, and implementing human oversight measures. Transparency is also crucial, with clear information provided to deployers and users about the system’s purpose and functionality.

The AI Act has a phased implementation timeline, with some provisions taking effect earlier than others. For instance, prohibited practices and AI literacy obligations entered into application on 2 February 2025, while governance rules and GPAI model obligations became applicable on 2 August 2025.

Going forward, the European Commission’s AI Office will play a key role in implementing and enforcing the AI Act. The office has already published guidelines to support compliance with transparency rules for generative AI models. Additionally, the Code of Practice on marking and labelling of AI-generated content is under preparation and expected to be published in 2026.

The AI Omnibus package, adopted in November 2025, aims to simplify the implementation of the AI Act by clarifying certain provisions and introducing new rules for high-risk AI systems. This includes a clear timeline for applying rules governing these systems, with some areas subject to stricter regulations from December 2027 onwards.

In conclusion, the AI Act represents a significant step towards establishing trust in AI across Europe. By setting out comprehensive guidelines for developers and deployers of AI systems, this legislation aims to promote innovation while safeguarding fundamental rights and public trust.