The EU AI Act – What Is It?
The EU AI Act establishes a harmonized legal framework for the use of artificial
intelligence within the European Union. Its objective is to promote innovation in the
field of AI while limiting risks to people's health, safety, and fundamental
rights.
A key element of the AI Act is its risk-based regulatory approach. Depending on the level
of risk posed by an AI system, different requirements apply. In addition, the regulation
introduces transparency obligations for certain AI applications. For example, users
should be able to recognize when they are interacting directly with an AI system or when
content has been created or modified using AI. The aim is to strengthen trust in AI
systems and encourage their responsible use.
The AI Act entered into force on August 1, 2024. Its provisions are becoming applicable
in stages: the first rules, including prohibitions on certain AI practices, have applied
since February 2025. A large part of the remaining provisions, including the
transparency obligations, have applied since August 2, 2026. Requirements for certain
high-risk AI systems will follow later: for high-risk use cases listed in Annex III from
December 2, 2027, and for high-risk AI in certain regulated products from August 2,
2028.
The regulation applies, among others, to providers of AI systems, deployers who use AI in
a professional context, as well as importers, distributors, and manufacturers of
products containing AI components that are placed on the EU market.
The Risk-Based Regulatory Model
The EU AI Act follows a risk-based approach. The greater the risk an AI system poses to
individuals and society, the stricter the requirements for its development and use. In
simplified terms, the regulation can be divided into four risk categories:
Unacceptable Risk
Certain AI applications that pose an unacceptable risk are generally prohibited. These
include, for example, certain forms of social scoring, so-called predictive policing
(such as assessing the risk of a criminal offense solely on the basis of profiling or
personal characteristics), and certain forms of emotion recognition in workplaces or
educational institutions.
High Risk
High-risk AI systems are subject to extensive requirements, including risk management,
documentation, and human oversight. These include certain AI systems used in critical
infrastructure, education, recruitment and human resources management, as well as law
enforcement. The decisive factor is not only the technology used but, above all, the
specific intended purpose of the system.
Limited Risk
Certain AI systems and AI-generated content are subject to transparency obligations.
These include AI systems that interact directly with people, such as chatbots, as well
as deepfakes and certain AI-generated text concerning matters of public interest.
Minimal Risk
For AI applications that pose minimal or no risk, the AI Act generally does not impose
any additional risk-specific requirements. These include, for example, spam filters or
many everyday assistance functions, provided they are not used for a particularly
regulated purpose.
What Does This Mean for Software Projects?
For software teams, the key question is how AI is used within a specific project. For
example, does it make a difference whether GitHub Copilot merely assists with writing
code or whether an AI assistant communicates directly with the users of an application?
The answer is yes, because the applicable requirements depend on how AI is used.
AI in the Development Process
Organizations using generative AI during the development process, for example for
designs, source code, draft texts, or illustrations, are not required to label those
results solely because AI was used.
However, specific disclosure obligations apply to certain types of content. The European
Commission provides voluntary
labeling icons for this purpose. These include, in particular:
- Deepfakes: AI-generated or manipulated image, audio, or
video content that depicts existing persons, objects, places, entities, or events in
a way that could falsely appear authentic or truthful.
-
AI-generated or manipulated texts on matters of public interest: If
such texts are published for the purpose of informing the public, it must generally
be disclosed that they have been artificially generated or modified. Such disclosure
is not required if the content has undergone substantive human review or editorial
oversight and a natural or legal person assumes editorial responsibility for its
publication.
| Example |
Disclosure Required to Users? |
Reason |
| Source code for a website generated with
the help of an AI tool
|
No
|
Source code does not need to be labeled as AI-generated.
|
| An AI-generated illustration used as the
header image of a website
|
Generally no
|
A standard AI-generated illustration does not have to be labeled for users
solely because it was created using AI.
|
| AI-generated product copy on a company
website
|
Generally no
|
The specific disclosure obligation for AI-generated text applies only to
publications about matters of public interest.
|
| A fully AI-generated news article
published automatically without human editorial review
|
Yes, if it concerns a matter of public interest
|
AI-generated text published to inform the public about matters of public
interest is generally subject to a disclosure obligation.
|
| An authentic photograph of a hotel room
from which objects have been removed using AI, making the room appear different
from the original photograph
|
Yes
|
An existing authentic photograph has been substantively altered using AI. If the
modification causes the actual condition of the room to be misrepresented while
appearing authentic, the image falls under the AI Act's deepfake provisions.
|
| A video of the actual owners of a
restaurant in which their voices have been synthetically replicated using AI
|
Yes
|
The video contains AI-generated voices of real people and may therefore falsely
appear to be an authentic recording. The AI label is accompanied by a brief
notice such as "Voices generated using AI."
|
Table 1: Examples of labeling requirements for AI-generated content
AI as a Feature of Your Own Application
If AI becomes an integral part of an application, the first step is to determine the role
a company assumes under the AI Act in that specific scenario. The regulation
distinguishes, among others, between providers and deployers and assigns different
transparency obligations to each. For typical software projects, the following
requirements may be relevant:
- Direct interaction with AI: Providers of AI systems that
interact directly with people must generally design those systems so that users are
informed, at the beginning of their first interaction, that they are communicating
with an AI system. No additional information is required if this is already obvious
to the user. This may be relevant, for example, for chatbots or AI assistants.
- Generated content: Providers of AI systems that generate
or manipulate synthetic text, images, audio, or video content must, where
technically feasible, ensure that the outputs are marked in a machine-readable
format and are technically identifiable as artificially generated or modified.
Conclusion
The EU AI Act does not mean that every use of ChatGPT, Claude, or other AI tools
automatically triggers new labeling obligations. What matters is the specific purpose
for which the AI is used and the role that a company assumes within the AI system.