What is the EU Artificial Intelligence Act?

The EU Artificial Intelligence Act, effective from August 1, 2024, establishes a regulatory framework governing AI development, deployment, and use within the European Union. The legislation aims to ensure AI systems are safe, transparent, traceable, non-discriminatory, and environmentally friendly. It applies to any provider or deployer of AI systems whose outputs are utilized in the EU, regardless of the provider’s location. The Act focuses on regulating specific AI applications rather than the technology itself, imposing stricter requirements on higher-risk applications.

The European Commission's AI Office, together with national authorities, began enforcing the Artificial Intelligence (AI) Act from 2 August 2026.

Compliance timeline

The EU AI Act follows a phased implementation schedule for organizations to align with the new requirements:

  • 2 February 2025: Prohibitions on AI systems posing unacceptable risks became effective.
  • 2 August 2025: Rules for general-purpose AI models and governance requirements became applicable.
  • 2 August 2026: Effective date for obligations for high-risk AI systems, including those used in credit scoring and regulatory reporting.
  • 2 August 2027: Obligations for high-risk AI systems, including those in credit scoring and regulatory reporting, must be met.

Risk-based classification framework

The framework delineates AI systems into four risk categories, each with distinct compliance obligations.

risk category

DESCRIPTION AND EXAMPLES

COMPLIANCE OBLIGATIONS

Unacceptable risk Systems threatening safety, rights, and livelihoods (e.g., social scoring or real-time biometric identification). Complete prohibition on deployment within the EU.
High risk Systems used in critical infrastructure, education, employment, law enforcement, and credit scoring. Strict obligations including risk mitigation, high-quality datasets, detailed logging, and human oversight.
Limited risk Systems with specific transparency risks, such as conversational chatbots, image generators, or deepfakes. Mandatory disclosure informing users that they are interacting with AI.
Minimal risk  Systems that pose little to no risk, such as AI-enabled video games or spam filters. No additional obligations, though voluntary codes of conduct are encouraged.

 

Implications for technology solutions and service providers

Technology providers must be aware of the following:

  • Development limitations: Software development and deployment must align with risk categories, particularly implementing conformity measures for high-risk systems.
  • Transparency obligations: Under Article 50, providers of conversational chatbots or generative tools must notify users when interacting with AI.
  • Human oversight design: Providers must design tools that allow human operators to monitor, intervene, override, or halt operations to prevent autonomous model deviation.

Considerations for financial services firms

Financial services firms must evaluate how they leverage AI models in their operations, particularly in areas such as risk management, credit assessment, and compliance reporting:

  • High-risk classification: AI used in credit scoring, risk assessment, or regulatory reporting is classified as high-risk under the regulation, necessitating compliance by August 2026.
  • Mandated human oversight: Article 14 stipulates that qualified human oversight is required for high-risk AI systems, ensuring human review of AI outcomes.
  • Full auditability: Every AI-influenced decision must be documented, traceable, and ready for audit from the outset.
  • Explainability: Clients and regulators have the right to understand AI-driven decisions, requiring clear explanations of outputs in a regulatory context.

Regnology's approach to EU AI Act compliance

Regnology proactively embeds compliance measures into its product and service delivery:

  • Human-in-charge principle: Every AI-assisted action is logged, traceable, and assessed by a qualified expert before delivery, in alignment with Article 14.
  • Built-in audit trails: Our platform automatically documents each step taken by AI, creating an immutable audit trail designed for compliance and internal reviews.
  • Domain-driven verification: Combining AI capabilities with domain expertise ensures that AI handles routine tasks while human experts oversee important judgment calls, guaranteeing regulatory submissions are validated.

 

Contact us