10.3 The EU AI Act and Global Legal Requirements

Key Takeaways

  • The European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world's first comprehensive, legally binding, extraterritorial AI regulation, establishing a risk-tiered compliance architecture.
  • Article 5 strictly prohibits Unacceptable Risk AI systems, including cognitive behavioral manipulation, social scoring, biometric categorization of sensitive attributes, emotion recognition in workplaces/schools, and untargeted scraping of facial images.
  • High-Risk AI systems (Article 6 & Annex III) are permitted subject to rigorous mandatory requirements: continuous risk management, representative data governance, automated logging, technical documentation, human oversight (HITL/HOTL), Fundamental Rights Impact Assessments (FRIA), and CE marking.
  • A GPAI model is presumed to have high-impact capabilities when cumulative training compute exceeds 10^25 FLOPs, subject to Article 51 designation and rebuttal rules; systemic-risk providers have additional evaluation, adversarial testing, risk, incident, and cybersecurity duties.
  • Enforcement carries severe financial penalties: up to 35 million EUR or 7% of worldwide annual turnover for prohibited practices, up to 15 million EUR or 3% for high-risk non-compliance, and up to 7.5 million EUR or 1.5% for supplying misleading information.
Last updated: September 2026

10.3 The EU AI Act and Global Legal Requirements

While frameworks like the NIST AI RMF and standards like ISO/IEC 42001 provide organizational and voluntary blueprints for trustworthy artificial intelligence, the global legal landscape has shifted decisively toward mandatory, enforceable statutory regulation. At the vanguard of this regulatory transformation is the European Union's Artificial Intelligence Act (Regulation (EU) 2024/1689).

Entering into force in August 2024, the Act applies in phases. Prohibitions began applying in February 2025, GPAI rules in August 2025, most provisions from August 2, 2026, and specified product-related high-risk rules later. Its territorial scope follows Article 2 and can cover providers or deployers outside the EU, including when output produced by the system is used in the Union.


The Four-Tier Risk Classification Architecture

The EU AI Act rejects a blunt, one-size-fits-all regulatory mandate in favor of a proportionate, risk-based classification architecture. An AI system's legal obligations are determined entirely by the severity and probability of the harm it can inflict on fundamental human rights, public safety, and health.

+---------------------------------------------------------------------------------------------------+
|                                 EU AI ACT RISK-TIER TAXONOMY                                      |
+----------------------------------+----------------------------------+-----------------------------+
|            RISK TIER             |          LEGAL STATUS            |       CORE EXAMPLES         |
+----------------------------------+----------------------------------+-----------------------------+
| 1. UNACCEPTABLE RISK             | STRICTLY PROHIBITED              | • Social scoring            |
|    (Article 5)                   | Ban enforced within 6 months of  | • Behavioral manipulation   |
|                                  | entry into force                 | • Untargeted facial scraping|
+----------------------------------+----------------------------------+-----------------------------+
| 2. HIGH RISK                     | PERMITTED UNDER STRICT           | • CV/resume screening       |
|    (Articles 6-15, Annex III)    | MANDATORY CONFORMITY             | • Critical infrastructure   |
|                                  | Full CE marking, FRIA, logging   | • Credit scoring & loans    |
+----------------------------------+----------------------------------+-----------------------------+
| 3. SPECIFIC TRANSPARENCY         | PERMITTED WITH DISCLOSURE        | • Consumer chatbots (AI)    |
|    (Article 50)                  | Must inform users of AI nature   | • Deepfakes & synthetic text|
|                                  | and machine-readable watermark   | • Emotion detection systems |
+----------------------------------+----------------------------------+-----------------------------+
| 4. MINIMAL / ZERO RISK           | PERMITTED WITHOUT RESTRICTION    | • AI spam filters           |
|    (Unregulated baseline)        | Free deployment; voluntary codes | • Video game AI             |
|                                  | of conduct encouraged            | • Inventory management      |
+----------------------------------+----------------------------------+-----------------------------+

1. Unacceptable Risk: Prohibited AI Practices (Article 5)

AI practices categorized as Unacceptable Risk are recognized as direct threats to democratic values, human dignity, and fundamental rights. Under Article 5, these practices are banned outright across the European Union:

  • Subliminal & Deceptive Manipulation: AI systems deploying subliminal techniques beyond human consciousness, or purposefully manipulative and deceptive tactics that significantly impair an individual's ability to make an informed decision, causing physical or psychological harm.
  • Exploitation of Vulnerabilities: Systems that exploit vulnerabilities associated with specific demographics—including age, physical or mental disability, or socio-economic distress—to distort behavior and cause significant harm.
  • Social Scoring: AI systems deployed by public authorities or private entities that evaluate or classify individuals based on their social behavior, personality characteristics, or socio-economic profile, leading to unjustified detrimental treatment in unrelated social contexts.
  • Individual Predictive Policing: Systems evaluating individual risk profiles to assess or predict the likelihood of a natural person committing a criminal offense based solely on profiling or personality traits (excluding predictive systems supporting human-validated factual evidence).
  • Untargeted Facial Image Scraping: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or closed-circuit television (CCTV) footage.
  • Biometric Categorization of Sensitive Attributes: Categorizing individuals using biometric data to deduce or infer protected characteristics: race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation (excluding lawful law enforcement labeling of verified criminal biometric samples).
  • Emotion Recognition in Workplace & Education: AI systems inferring emotional states of workers in workplace environments or students in educational institutions (except where strictly deployed for verified medical or safety reasons, such as driver fatigue detection).
  • Real-Time Remote Biometric Identification (RBI) in Public: Using real-time RBI (e.g., live facial recognition) in publicly accessible spaces by law enforcement is strictly prohibited, subject to extremely narrow, prior judicially authorized exceptions: targeted searches for specific kidnapping or human trafficking victims, preventing an imminent terror attack, or tracking suspects of enumerated serious crimes.

2. High-Risk AI Systems (Articles 6–15 & Annex III)

High-risk systems are fully lawful to develop and commercialize, but they are subjected to extensive, legally binding conformity assessment requirements before entering the EU market. High-risk systems fall into two categories:

  1. Category A (Product Safety Components): AI systems acting as safety components of products already governed by EU harmonization legislation (e.g., medical devices, civil aviation, industrial machinery, elevators, toys).
  2. Category B (Standalone Annex III Systems): AI systems deployed in high-consequence operational domains explicitly enumerated in Annex III:
    • Biometrics: Remote biometric identification, biometric categorization, and emotion recognition outside prohibited contexts.
    • Critical Infrastructure: Safety components in road traffic management, water supply, electricity grids, and digital infrastructure.
    • Education and Vocational Training: Systems determining access, admission, task allocation, or automated evaluation of students.
    • Employment & Worker Management: Systems used for recruitment, resume filtering, applicant ranking, job task allocation, performance evaluation, or employee termination decisions.
    • Essential Private & Public Services: AI systems determining eligibility for public welfare, creditworthiness scoring for loans, risk assessment for health and life insurance, and automated emergency dispatch (ambulance/fire triage).
    • Law Enforcement: Systems evaluating evidence reliability, polygraphs, and risk assessments of victims.
    • Migration, Asylum & Border Control: Automated examination of visa and asylum applications, biometric identity verification.
    • Administration of Justice & Democracy: AI used by judicial authorities to interpret facts and the law, or systems influencing voter decisions in democratic elections.

Mandatory Technical Requirements for High-Risk AI (Articles 9–15)

To achieve market clearance, providers of High-Risk AI must prove compliance with seven mandatory technical requirements:

  • Risk Management System (Article 9): A continuous, documented risk management pipeline throughout the entire lifecycle, identifying known and foreseeable risks and implementing mitigation controls.
  • Data Governance (Article 10): Training, validation, and testing datasets must adhere to strict quality benchmarks: examining data provenance, assessing data gaps, and actively detecting and mitigating discriminatory demographic biases.
  • Technical Documentation (Article 11): Up-to-date, comprehensive documentation proving conformity, prepared prior to commercial placement.
  • Automated Record-Keeping and Logging (Article 12): Mandatory, automated event logging embedded into the AI system to ensure operational traceability, post-incident forensic investigation, and drift monitoring throughout the system's operational life.
  • Transparency and Information Provision (Article 13): Providing clear, comprehensible user manuals specifying system capabilities, technical limitations, accuracy metrics, and expected operating parameters.
  • Human Oversight (Article 14): Systems must be designed with verifiable Human-in-the-Loop (HITL), Human-on-the-Loop (HOTL), or Human-in-Command (HIC) capabilities, allowing human operators to override, ignore, or completely shut down the model via emergency stop controls.
  • Accuracy, Robustness, and Cybersecurity (Article 15): The system must demonstrate resilient performance metrics and robust cybersecurity defenses specifically hardened against adversarial attacks: evasion attacks (adversarial perturbations), data poisoning, model extraction, and hardware/software faults.

Conformity Assessment, CE Marking, and FRIAs

Before placing a high-risk AI system on the market, providers must:

  1. Undergo a formal Conformity Assessment (either internal control verification or independent third-party assessment by a designated Notified Body).
  2. Affix the official CE Marking to the AI system or documentation.
  3. Register the system in the official, publicly accessible EU Database for High-Risk AI Systems.
  4. Deployers that are public bodies, or private entities operating public services (e.g., banks, hospitals), must conduct a Fundamental Rights Impact Assessment (FRIA) under Article 27 before putting the system into service.

3. Specific Transparency / Limited Risk (Article 50)

Systems in this tier pose lower societal risk but require explicit transparency disclosures to prevent deceit:

  • Direct User Interaction: Providers must ensure AI chatbots and virtual agents explicitly inform human users that they are interacting with an artificial intelligence.
  • Synthetic Media & Deepfakes: AI-generated or manipulated audio, video, image, or text content that resembles real persons or events must be clearly labeled and disclosed in a machine-readable format (e.g., cryptographic metadata watermarking under C2PA standards).
  • Emotion Recognition & Biometric Categorization: Systems operating outside prohibited zones must explicitly notify individuals that they are being exposed to biometric analysis.

4. Minimal or Zero Risk

The vast majority of AI systems in production today—including spam filtering algorithms, AI-driven video game non-player characters (NPCs), industrial predictive maintenance, and inventory optimization—fall into Minimal Risk. These systems are unregulated by the Act and may be freely deployed without statutory burdens, though providers are encouraged to adhere to voluntary codes of conduct.


General Purpose AI (GPAI) Models and Systemic Risk

Recognizing that foundation models and generative LLMs (e.g., GPT-4, Claude, Gemini, Llama) can be adapted to thousands of downstream tasks, the EU AI Act establishes a dedicated regulatory framework for General Purpose AI (GPAI) models under Articles 51 through 55.

                                   [ GENERAL PURPOSE AI (GPAI) MODELS ]
                                                     |
         +-------------------------------------------+-------------------------------------------+
         |                                                                                       |
         v                                                                                       v
[ Standard GPAI Models ]                                                [ GPAI Models with Systemic Risk ]
• Technical documentation for downstream providers                      • Criteria: Cumulative training compute > 10^25 FLOPs
• Compliance with EU Copyright Directive                                  (or European Commission designation)
• Published summary of training content                                 • Mandatory adversarial red-teaming
• Information for EU AI Office                                          • Comprehensive model evaluations
                                                                        • Track & report serious cybersecurity incidents
                                                                        • Documented state-of-the-art cybersecurity

GPAI Classification and the $10^{25}$ FLOPs Threshold

The Act categorizes foundation models into two tiers based on computational capacity and systemic threat profile:

  1. Standard GPAI Models: All foundation models placed on the EU market must maintain technical documentation for downstream deployers, implement policies respecting the EU Directive on Copyright, and publish a detailed summary of the datasets used for training.
  2. GPAI Models with Systemic Risk (Article 51): Foundation models possess systemic risk if they have high-impact capabilities exceeding state-of-the-art baselines. The primary objective quantitative threshold is established at:

Cumulative Compute Used for Training>1025 Floating Point Operations (FLOPs)\text{Cumulative Compute Used for Training} > 10^{25} \text{ Floating Point Operations (FLOPs)}

The greater-than-$10^{25}$ compute threshold creates a rebuttable presumption of high-impact capabilities, not automatic classification in every case; the Commission can also designate a model under Article 51. Providers of GPAI models with systemic risk have additional Article 55 obligations:

  • Adversarial Red-Teaming: Mandatory model evaluations and continuous adversarial probing to identify systemic vulnerabilities, CBRN proliferation risks, and weaponization pathways.
  • Incident Reporting: Monitoring, documenting, and reporting relevant serious incidents under the Act's criteria and timelines to the EU AI Office.
  • Cybersecurity Architecture: Implementing state-of-the-art cybersecurity protections across the model weights, compute clusters, and storage infrastructure.
  • Energy Efficiency: Documenting and reporting the model's estimated energy consumption and carbon footprint.

Governance, Enforcement, and Financial Penalties

Enforcement of the EU AI Act is governed at the Union level by the EU AI Office (established within the European Commission) and the European Artificial Intelligence Board (EAIB), working in conjunction with national Market Surveillance Authorities in each EU Member State.

To ensure stringent compliance, the EU AI Act establishes three tiers of astronomical administrative fines under Article 99:

Violation CategoryStatutory Maximum Financial Penalty (Whichever is Higher)
Violations of Prohibited AI Practices (Article 5)Up to €35,000,000 OR 7% of worldwide annual turnover for the preceding financial year.
Non-Compliance with High-Risk Obligations (Articles 9–15)Up to €15,000,000 OR 3% of worldwide annual turnover for the preceding financial year.
Supplying Incorrect, Incomplete, or Misleading InformationUp to €7,500,000 OR 1.5% of worldwide annual turnover for the preceding financial year.

[!IMPORTANT] SME and Startup Safeguards: For small and medium-sized enterprises (SMEs) and startups, the administrative fines are capped at the lower of the two figures, ensuring that regulatory enforcement does not automatically cause corporate bankruptcy for emerging innovators.


Worked Scenario: Assessing Compliance for an AI Hiring Platform

A Silicon Valley SaaS vendor develops an automated AI video interviewing platform that evaluates applicant facial micro-expressions and vocal intonations to generate an employability ranking for global enterprises, including European multinationals.

  1. Extraterritorial Jurisdiction: Although the SaaS provider has no physical offices in Europe, because European job applicants are evaluated and EU-based enterprise customers utilize the outputs, the EU AI Act applies directly.
  2. Risk Classification:
    • Emotion Recognition in the Workplace (Article 5): The platform's module that infers applicant emotional states (e.g., stress, honesty) from micro-expressions constitutes an Unacceptable Risk Prohibited Practice under Article 5. Deploying this module in the EU carries a statutory fine of up to €35 million or 7% of worldwide turnover.
    • Employment & Recruitment Ranking (Annex III): The core resume screening and candidate ranking engine is classified as High-Risk under Annex III, Category 4.
  3. Remediation Strategy:
    • The provider immediately strips the biometric emotion recognition module from European deployments.
    • For the High-Risk ranking engine, the provider executes demographic bias audits (Article 10), implements Human-in-the-Loop override gates for HR recruiters (Article 14), embeds immutable audit logging (Article 12), compiles comprehensive technical documentation (Article 11), executes an internal Conformity Assessment, affixes the CE marking, and registers the platform in the EU AI Database.

CompTIA SecAI+ Exam Traps and Pitfalls

[!WARNING] Exam Trap 1: High-Risk Does Not Mean Prohibited Exam questions often test whether high-risk systems are banned under EU law. They are not banned; they are permitted, provided they satisfy all mandatory conformity requirements (Articles 9–15), pass conformity assessments, carry CE marking, and maintain human oversight. Only Article 5 Unacceptable Risk systems are prohibited.

[!CAUTION] Exam Trap 2: Extraterritorial Jurisdiction Applies Regardless of Corporate Headquarters Do not select answer choices claiming that US, UK, or Asian firms are exempt from the EU AI Act because they are located outside the European Union. Apply the specific Article 2 tests instead: for example, covered actors outside the Union may be in scope when output produced by the AI system is used in the Union. Headquarters alone does not decide scope.

[!NOTE] Exam Trap 3: The GPAI Systemic Risk Compute Threshold Metric Be prepared to identify the exact quantitative metric for General Purpose AI systemic risk: cumulative compute exceeding $10^{25}$ total FLOPs. Distractors will attempt to confuse candidates with parameter counts (e.g., "models with over 100 billion parameters") or context window sizes (e.g., "models exceeding 1 million tokens"). Compute in FLOPs is the statutory threshold.

Loading diagram...
EU AI Act Risk Classification and Compliance Decision Tree
Test Your Knowledge

A US-based enterprise develops an automated natural language processing model that parses incoming job applicant resumes, ranks candidates based on predicted job performance, and automatically dispatches rejection notices. The enterprise licenses this tool to multinational corporations operating across Germany, France, and Spain. Under the European Union Artificial Intelligence Act, how is this AI system classified, and what legal obligations apply?

A
B
C
D
Test Your Knowledge

A GPAI provider reports cumulative training compute of 3.2 x 10^25 FLOPs. Under the EU AI Act, what is the best description, subject to the Article 51 designation and rebuttal process?

A
B
C
D
Test Your Knowledge

A commercial retail corporation deploys an AI computer vision system in its flagship European department stores that uses closed-circuit television cameras to deduce the political affiliations and sexual orientation of shoppers from their gait and facial expressions, using the data to display targeted digital marketing. Under Article 99 of the EU AI Act, what is the maximum administrative penalty for deploying this prohibited AI practice?

A
B
C
D