EU AI Act โ€” Student Guide
Regulation (EU) 2024/1689

The world's first comprehensive AI law, mapped for the classroom.

The EU AI Act doesn't regulate AI in general โ€” it regulates AI by the risk a specific use poses. The same model can be unregulated in one use and heavily regulated in another. That single idea is the whole framework.

Risk-based In force since Aug 1, 2024 Phased application through 2027
UNACCEPTABLE HIGH RISK LIMITED RISK MINIMAL / NO RISK

Fewer systems at the top, stricter rules. Most AI in use today falls in the bottom two tiers.

โš ๏ธ Timing note: as of this guide's writing (July 2026), the Act's biggest compliance milestone โ€” obligations for most high-risk systems and Article 50 transparency rules โ€” is dated August 2, 2026, just days out. The EU has also discussed simplification/delay proposals for parts of the Act (the "digital omnibus" process) that could shift specific dates. Verify current status at the official source linked in Sources before relying on any date here.
01 โ€” Foundations

Purpose & Origin

What the Act is, why the EU built it this way, and who it actually binds.

What it is

Regulation (EU) 2024/1689 โ€” the "AI Act" โ€” is the first comprehensive, horizontal legal framework for AI adopted by a major regulator. As an EU Regulation, it applies directly in all member states without needing separate national implementing legislation, unlike a Directive.

Why it was built as a risk pyramid

Rather than defining "AI" and regulating it uniformly, the Act sorts AI systems by the risk a specific use poses to health, safety, and fundamental rights. A face-recognition model used to unlock a phone and one used for mass surveillance are the same technology facing entirely different rules โ€” because the Act regulates the use, not the algorithm.

Who it binds

It has extraterritorial reach similar to GDPR: it applies to providers placing AI systems on the EU market and to providers and deployers outside the EU if the system's output is used within the EU โ€” meaning a U.S. company can fall under it without any EU office.

What's explicitly excluded

Military and defense AI, AI used solely for scientific research and development, and systems not yet placed on the market are outside scope, along with some exemptions for open-source models that don't fall into higher-risk categories.

02 โ€” Using this guide

How to Use This Guide

Built for a course session โ€” not a substitute for legal advice or a compliance program.

  1. Classify before anything else. Every question about the Act reduces to "which tier is this system in?" Get comfortable sorting examples into unacceptable / high / limited / minimal before studying the obligations attached to each.
  2. Notice the pyramid is about volume too. A handful of practices are banned outright (top). A defined but real list of high-risk use cases carries heavy obligations. Most deployed AI โ€” recommendation engines, spam filters, most generative-AI chat tools โ€” sits in the bottom two tiers.
  3. Separate "the system" from "the model." Chapter V's General-Purpose AI rules are a second, mostly separate track โ€” they attach to foundation models themselves (like an LLM), independent of what tier a specific downstream application built on that model lands in.
  4. Track the phased timeline. Almost every debate about "is this legal yet" comes down to which obligations have actually taken effect versus which are legislated for a later date.
  5. Go to EUR-Lex for anything graded. This guide paraphrases; official citations should reference the Regulation's actual article and recital numbers from the consolidated EUR-Lex text.
03 โ€” Phased application

Phased Timeline

The Act didn't take full effect on day one โ€” obligations phase in over roughly three years from entry into force.

1 AUG 2024

Entry into force

The Regulation is published and enters into force EU-wide, starting the clock on every later deadline.

2 FEB 2025

Prohibitions & AI literacy take effect

Article 5 banned practices become enforceable, along with Article 4's requirement that providers and deployers ensure staff have adequate AI literacy.

2 AUG 2025

GPAI rules, governance & penalties take effect

Chapter V obligations for general-purpose AI models apply; the AI Office and national competent authorities must be operational; the penalty regime becomes enforceable.

2 AUG 2026

Main body of the Act applies

Most high-risk AI system obligations (Annex III use cases) and Article 50 transparency obligations become enforceable โ€” the deadline this guide's status banner flags as imminent.

2 AUG 2027

Remaining high-risk obligations apply

High-risk AI systems that are safety components of products already regulated under EU product-safety law (Annex I) come fully under the Act's obligations.

Tier 1 ยท Banned

Unacceptable Risk โ€” Article 5

A short, specific list of practices considered such a clear threat to fundamental rights that they're prohibited outright โ€” no risk assessment or mitigation makes them acceptable.

  • Subliminal, manipulative, or deceptive techniques that materially distort behavior and cause harm.
  • Exploiting vulnerabilities of specific groups (age, disability, socio-economic situation) to distort their behavior in a harmful way.
  • Social scoring by public authorities based on behavior or characteristics, leading to detrimental treatment unrelated to the context in which the data was generated.
  • Individual crime-risk assessment based solely on profiling or personality traits, without objective, verifiable facts directly linked to criminal activity.
  • Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.
  • Emotion inference in the workplace and education, except for narrow medical or safety reasons.
  • Biometric categorization inferring sensitive attributes (race, political opinion, sexual orientation, religion) from biometric data.
  • Real-time remote biometric identification by law enforcement in publicly accessible spaces โ€” allowed only under narrowly defined, judicially authorized exceptions (e.g., searching for a specific victim of a serious crime).
Tier 2 ยท Heavily regulated

High-Risk AI Systems โ€” Articles 6โ€“15

Legal, but only with substantial obligations. This is where most of the Act's compliance weight sits โ€” a defined list of use cases (Annex III) plus AI used as a safety component in already-regulated products (Annex I).

Biometrics

Remote biometric identification, categorization, emotion recognition (where not outright banned).

Critical infrastructure

Safety components managing critical digital infrastructure, road traffic, water, gas, heating, electricity.

Education & training

Determining access, admission, or assessing/scoring students โ€” the category most directly relevant to your own institution.

Employment

Recruitment, screening applications, promotion/termination decisions, task allocation, performance monitoring.

Essential services

Eligibility for public benefits, creditworthiness scoring, life/health insurance pricing, emergency dispatch prioritization.

Law enforcement

Risk assessment, polygraph-style tools, evidence evaluation, crime-analytics (subject to narrower carve-outs than Art. 5).

Migration, asylum, border control

Risk and security assessments, examination of asylum/visa applications.

Justice & democratic processes

Assisting judicial research/interpretation, and AI intended to influence elections or referenda through direct interaction with voters.

  • Risk management system spanning the whole lifecycle, continually updated.
  • Data governance โ€” training, validation, and testing data must meet quality criteria and be examined for bias.
  • Technical documentation & record-keeping (automatic logging) sufficient to demonstrate compliance.
  • Transparency & instructions for use clear enough for deployers to use the system properly and interpret its output.
  • Human oversight designed in, so a natural person can effectively oversee the system's operation, including the ability to intervene or stop it.
  • Accuracy, robustness & cybersecurity appropriate to the intended purpose, throughout the system's lifecycle.

Organizations that use a high-risk system (not just build it) must use it per the provider's instructions, assign human oversight to competent people, monitor its operation, and โ€” for certain public-sector and high-impact private uses โ€” conduct a fundamental rights impact assessment before deployment.

Tier 3 ยท Disclosure required

Limited Risk โ€” Transparency Obligations (Article 50)

These systems aren't restricted in what they can do โ€” they just have to tell people what they're interacting with.

  • Chatbots & conversational AI. Users must be informed they're interacting with an AI system, unless it's obvious from context.
  • Synthetic media / deepfakes. AI-generated or manipulated image, audio, or video content resembling real people, places, or events must be labeled as artificially generated or manipulated.
  • Emotion recognition & biometric categorization systems (where not banned under Art. 5) must inform the people exposed to them.
  • AI-generated text published to inform the public on matters of public interest must be disclosed as AI-generated, with narrow exceptions (e.g., human editorial review with accountability).
Tier 4 ยท Largely unregulated

Minimal / No Risk

The tier holding most AI in everyday use โ€” spam filters, recommendation systems in non-high-risk contexts, AI-enabled video games, inventory-management tools.

No mandatory obligations under the Act. Providers are encouraged (not required) to voluntarily adopt codes of conduct reflecting the high-risk requirements, on a best-effort basis. General EU law โ€” GDPR, consumer protection, product liability โ€” still applies regardless of AI Act tier.

04 โ€” A second track

General-Purpose AI Models โ€” Chapter V

Rules that attach to foundation models themselves (like large language models), largely independent of the risk-tier pyramid above, which applies to specific AI systems and their use.

Baseline obligations โ€” all GPAI providers

Maintain technical documentation, provide information to downstream providers integrating the model, publish a policy for complying with EU copyright law, and publish a sufficiently detailed summary of the content used to train the model.

Additional obligations โ€” "systemic risk" models

Models trained with cumulative compute above a defined threshold (10^25 floating-point operations) are presumed to carry systemic risk, triggering model evaluation, adversarial testing, systemic-risk mitigation, incident tracking and reporting, and cybersecurity protections.

05 โ€” Enforcement

Governance & Penalties

Who enforces the Act, and what non-compliance actually costs.

EU AI Office

A body within the European Commission overseeing GPAI models directly and coordinating enforcement across member states.

National competent authorities

Each member state designates authorities responsible for market surveillance and enforcement within its territory for most non-GPAI matters.

ViolationMaximum penalty
Article 5 prohibited practicesUp to โ‚ฌ35M or 7% of global annual turnover, whichever is higher
Other obligations (e.g., high-risk requirements)Up to โ‚ฌ15M or 3% of global annual turnover, whichever is higher
Supplying incorrect, incomplete, or misleading information to authoritiesUp to โ‚ฌ7.5M or 1% of global annual turnover, whichever is higher
06 โ€” In the classroom

Classroom Uses

Ways instructors have used this structure with students.

Tier-sorting exercise

Give students a list of real AI products (a resume screener, a grammar checker, a facial-unlock feature, a predictive-policing tool) and have them sort each into a tier with a one-sentence justification.

"System vs. model" untangling

Have students take a single LLM-based product and separately identify what GPAI obligations apply to the underlying model versus what risk-tier obligations apply to the specific application built on it.

Deployer vs. provider debate

Assign half the class "provider" and half "deployer" for a high-risk education-sector use case, and have each side identify what it owes the other under Articles 16 and 26.

Timeline current-events check

Have students search for the current status of the August 2026 milestone and report back โ€” a live lesson in how quickly regulatory timelines can shift.

07 โ€” Go to the source

Sources & Further Reading

This guide is a teaching summary โ€” verify current dates and obligations before using in graded work.

EUR-Lex โ€” official consolidated text

The authoritative, article-numbered legal text.
eur-lex.europa.eu โ€” search "Regulation (EU) 2024/1689"

European Commission โ€” AI Act page

Official implementation timeline, guidance documents, and news on any simplification/delay proposals.
digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

EU AI Office

Guidance specific to general-purpose AI model obligations and the Code of Practice for GPAI providers.
digital-strategy.ec.europa.eu/en/policies/ai-office