EU AI Act Takes Effect: Companies Must Disclose AI Use and Comply with Risk-Based Framework
Key Takeaways
- ▸The AI Act is the first-ever comprehensive legal framework on AI worldwide, establishing a risk-based regulatory approach across the EU
- ▸Nine high-risk AI practices are banned outright, including harmful manipulation, untargeted biometric identification, and non-consensual intimate content generation
- ▸High-risk AI systems used in critical infrastructure, education, and employment require strict compliance, documentation, transparency, and human oversight measures
Summary
The European Union has implemented the AI Act (Regulation (EU) 2024/1689), the world's first comprehensive legal framework governing artificial intelligence. The regulation establishes a risk-based approach with four severity levels, from outright bans on nine high-risk AI practices to compliance requirements for systems classified as high-risk. Companies across the EU must now clearly disclose their use of AI and comply with specific obligations based on their AI systems' risk profiles.
The framework bans nine specific AI practices effective immediately (with eight becoming enforceable in February 2025), including harmful AI-based manipulation, untargeted biometric identification, emotion recognition in workplaces, and non-consensual intimate content generation. High-risk AI applications—such as systems used in critical infrastructure, education, and employment decisions—face strict compliance requirements including documentation, risk assessment, and human oversight. The European Commission is supporting implementation through voluntary initiatives like the AI Pact and the AI Act Service Desk to help stakeholders transition to the new regulatory landscape.
- The EU has launched support mechanisms including the voluntary AI Pact and AI Act Service Desk to facilitate industry transition and compliance


