AI for business · Regulation

EU Artificial Intelligence Act

The world’s first comprehensive AI law. It sorts AI systems by risk: some practices are banned, high-risk systems must meet strict requirements, some systems must be transparent, and most everyday uses have no new duties.

Applies in phasesEUAI rulesRegulation (EU) 2024/1689

What it means for AI

Applies to anyone who develops AI (provider), uses AI in their business (deployer), imports or distributes it in the EU — also to companies outside the EU if the output is used in the EU. Private, non-professional use is excluded.

What you must do

  • All companies using AI: take measures to build the AI literacy of staff who use it (Art. 4).
  • Never use prohibited practices (Art. 5) — e.g. emotion recognition of employees, social scoring, manipulation.
  • Chatbots and voice assistants: tell people they are talking to AI; label deepfakes; disclose AI texts on public-interest matters (Art. 50, from 2 Aug 2026).
  • High-risk uses (hiring, credit, education, critical infrastructure …): human oversight, logs, informing affected people and workers, risk assessment — from 2 Dec 2027.
  • Providers of high-risk AI: risk management, data quality, technical documentation, conformity assessment, CE marking, registration in the EU database.
  • Providers of general-purpose AI models: technical documentation, copyright policy, summary of training data (since 2 Aug 2025).

Examples

An accounting firm uses ChatGPT for e-mails

Minimal risk. The firm needs AI literacy measures (a short training and internal rules) — and GDPR still applies to client data typed into the tool.

An online shop adds a chatbot

Transparency: the bot must say it is AI at the first contact (e.g. “I am a virtual assistant”). No other AI Act duty.

HR software ranks job applicants

High risk (Annex III). The employer as deployer must ensure human oversight, keep logs, inform candidates and the works council — from 2 Dec 2027.

A camera system “reads” employees’ mood

Prohibited since 2 Feb 2025 (emotion recognition at work), except for medical or safety reasons.

Key dates

  1. The AI Act enters into force.

  2. Prohibited practices and the AI literacy obligation apply.

  3. Rules for general-purpose AI models, governance and penalties apply.

  4. Transparency duties (Art. 50) apply; the Commission can enforce the rules for general-purpose AI models.

  5. New bans (non-consensual intimate images, child sexual abuse material) apply; end of the grace period for machine-readable marking of AI content (Art. 50(2)) for systems already on the market.

  6. General-purpose AI models placed on the market before 2 Aug 2025 must comply; national regulatory sandboxes must be operational.

  7. Obligations for stand-alone high-risk AI (Annex III: employment, credit, education, essential services …).

  8. Obligations for high-risk AI inside regulated products (Annex I: medical devices, toys, lifts …).

  9. High-risk AI systems used by public authorities that were on the market before the rules applied must comply.

Who supervises

In Slovenia: AKOS (single point of contact), Information Commissioner, Bank of Slovenia, Insurance Supervision Agency and Market Inspectorate (ZIUDHPUI). General-purpose AI models: the European AI Office.

Fines

Up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for most other breaches; up to €7.5 million or 1% for incorrect information — whichever is higher; for SMEs and small mid-caps whichever is lower.

← All regulations

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.