The European Union regulates AI through a stack of overlapping laws, not a single statute. The AI Act gets the headlines, but data protection law, copyright rules, and consumer protection law all apply to AI systems simultaneously, and a company operating in Europe has to satisfy all of them at once. This is general information, not legal advice — consult qualified counsel for compliance decisions specific to your business.
What changed in 2026
- Staggered deadlines kept arriving. The AI Act rolled out in phases rather than all at once; prohibited-practice bans and literacy obligations landed first, with high-risk system requirements and broader enforcement following on a schedule set out in the regulation itself.
- The EU AI Office took a more active coordinating role, particularly for general-purpose AI models, working alongside national market surveillance authorities rather than replacing them.
- Guidance documents multiplied. The European Commission and national bodies published interpretive guidance to clarify ambiguous provisions — a sign the initial text left real gaps that industry needed resolved.
- Cross-law friction became visible. Companies increasingly reported tension between AI Act transparency obligations and GDPR data minimization principles, requiring careful legal navigation rather than a single compliance checklist.
The AI Act risk-tier structure
The AI Act sorts AI systems into risk categories, and obligations scale with the tier.
| Risk tier |
Examples |
Core obligation |
| Unacceptable |
Social scoring, certain manipulative systems |
Prohibited outright |
| High risk |
Hiring tools, credit scoring, medical devices |
Conformity assessment, documentation, human oversight |
| Limited risk |
Chatbots, some generative tools |
Transparency — disclose that users are interacting with AI |
| Minimal risk |
Spam filters, AI in video games |
No specific obligations beyond general law |
For a deeper walkthrough of this structure, see what is the EU AI Act.
How EU AI regulation interacts with other laws
The AI Act does not replace GDPR — it sits alongside it. A company deploying an AI system that processes personal data still needs a GDPR lawful basis, still needs to honor data subject rights, and still needs a data protection impact assessment where required, independent of any AI Act obligations. Copyright questions around training data and AI-generated output are handled under separate EU copyright directives, and consumer protection rules apply to AI-driven marketing and pricing the same way they apply to any other automated system. Practically, this means AI compliance in the EU is a multi-law exercise, not a single form to file.
Extraterritorial reach
The AI Act applies based on where a system is used or where its output has effect in the EU, not simply where the provider is headquartered. A US or Asian company whose AI product is used by people in the EU, or whose output affects people there, can fall within scope even without a European office. This mirrors how GDPR extended beyond EU borders and is one of the most commonly underestimated points by non-EU businesses.
What businesses should actually do
Start by classifying which of your AI systems fall into which risk tier — this determines almost everything else. High-risk systems need documentation, human oversight mechanisms, and conformity assessment before deployment. Limited-risk systems mainly need clear disclosure to users. All of it benefits from a written internal AI usage policy that assigns ownership for compliance rather than leaving it ambiguous across teams.
FAQ
Does the AI Act apply to companies outside the EU?
Yes, if their AI system is used in the EU or its output affects people there — the trigger is use and effect, not headquarters location.
What is the difference between the AI Act and GDPR for AI systems?
GDPR governs personal data processing broadly; the AI Act governs AI system risk regardless of whether personal data is involved. Many AI deployments trigger both simultaneously.
How large are AI Act penalties?
The structure uses turnover-based caps similar to GDPR, meaning fines scale with global revenue for the most serious violations. Exact figures should be verified against the current official text, since amounts can be revised.
Is a chatbot automatically high risk under the AI Act?
Not usually. Most general chatbots fall into the limited-risk transparency tier unless they are deployed in a context — like healthcare triage or hiring — that pushes them into a high-risk category.
Where to go next