AI Act
The AI Act is a European Union law that regulates artificial intelligence based on the level of risk an AI system may pose. It is generally described as the first comprehensive legal framework for AI adopted by a major regulator, and it aims to address the potential harms of AI while supporting Europe's role in the field. It applies within the EU context and should be read alongside, rather than as a substitute for, data protection law such as the GDPR.
The AI Act is an EU regulation establishing a common regulatory framework for artificial intelligence, adopted in 2024, that assigns obligations according to a risk-based approach (including categories such as prohibited practices and higher-risk uses). It is a distinct instrument from the GDPR and does not replace data protection requirements; where an AI system processes personal data, GDPR obligations continue to apply in parallel and must be assessed separately. Practitioners should verify specific article numbers, risk classifications, obligations, and applicability or transition dates against the current official text of the Regulation, as detailed provisions and implementing guidance continue to evolve and are not fully established by the evidence available here.
Why it matters
The AI Act is generally described as the first comprehensive legal framework for artificial intelligence adopted by a major regulator, which makes it a reference point for organisations developing or deploying AI systems that touch the EU market. It regulates AI according to the level of risk a system may pose, meaning that the obligations attaching to a given use case depend on how that use is classified. For privacy and compliance professionals, this signals a shift toward AI-specific regulatory expectations that sit alongside existing data protection duties rather than displacing them.
A central point for practitioners is that the AI Act is a distinct instrument from the GDPR. Where an AI system processes personal data, GDPR obligations continue to apply in parallel and must be assessed on their own terms; compliance with one framework does not establish compliance with the other. Treating the AI Act as a replacement for data protection analysis, or vice versa, risks leaving material obligations unaddressed. Organisations should map where the two frameworks overlap and where each imposes separate requirements.
Because detailed provisions, risk classifications, and applicability or transition timelines continue to evolve and are supported by implementing guidance that is not fully settled, the practical impact of the AI Act should be treated as developing rather than fixed. Readers should verify specific obligations and dates against the current official text of the Regulation before relying on them in a compliance program.
Who it's relevant to
Inside AI Act
Common questions
Answers to the questions practitioners most commonly ask about AI Act.