The EU AI Act (Regulation (EU) 2024/1689) is the world's first horizontal AI legal framework. It classifies AI systems into four risk tiers and imposes transparency, traceability and governance obligations on both providers and deployers. Phased application 2025-2027.
Legal framework and timeline
Regulation (EU) 2024/1689, the EU AI Act, entered into force on 1 August 2024. Application is staged:
- 2 February 2025: prohibitions on unacceptable practices and AI literacy duties (Art 4).
- 2 August 2025: rules for general-purpose AI (GPAI) models.
- 2 August 2026: obligations for high-risk systems (Art 6).
- 2 August 2027: full application, including embedded components.
Four risk tiers
- Unacceptable risk: prohibited (social scoring, cognitive manipulation, real-time biometric identification in public spaces, with narrow exceptions).
- High risk: hiring, credit scoring, critical infrastructure, essential public services — subject to strict documentary compliance (Annex III).
- Limited risk: chatbots, deepfakes — end-user transparency duty.
- Minimal risk: most systems — recommended best practices.
Key duties for deployers
A company that uses a third-party AI system (a deployer under Article 3) must notably:
- Article 4: ensure adequate AI literacy among staff.
- Article 26: human oversight, logging, governance of input data.
- Article 27: fundamental rights impact assessment for high-risk systems.
- Article 86: inform individuals subject to an AI-assisted decision.
- Maintain an AI Use Case Register and, where applicable, a DPIA.
Relevance for GEO/AEO tools
Auditing a brand's visibility across LLMs amounts to deploying an AI system under the regulation. As such, the professional user of an AI visibility tool is subject to Article 4 (literacy) and, where a data subject is an identifiable natural person, to Article 86 (information).
Sanctions
Fines reach EUR 35 M or 7 % of worldwide annual turnover (whichever is higher) for prohibited practices, and EUR 15 M or 3 % for other breaches.
AI Labs Audit and the EU AI Act
AI Labs Audit provides clients with a DPIA template and the traceability documentation (multi-judge AGS audit trail) needed for Articles 26 and 27. OVH France hosting and the French SAS status place the service outside the reach of the CLOUD Act — decisive for regulated sectors (banking, healthcare, defence, public sector). See also our GDPR/EU AI Act benchmark.
Every question asked to ChatGPT without your name in the answer is a competitor recommended instead of you — measured across 6,820 real AI answers.