Skip to main content

AI GOVERNANCE

What Is EU AI Act?

DEFINITION

The EU AI Act is the European Union's comprehensive, risk-based regulation of artificial intelligence. It bans certain AI practices, imposes strict obligations on high-risk systems, and sets transparency and general-purpose AI model requirements. It applies extraterritorially, so companies outside the EU that place AI systems on the EU market or whose AI outputs are used in the EU are in scope.

The EU AI Act is the European Union's risk-based regulation of artificial intelligence, in force since August 2024 with obligations phasing in over several years. It prohibits certain practices outright, imposes conformity assessment, documentation, and human oversight obligations on high-risk systems, sets transparency duties for AI that interacts with people or generates synthetic content, and regulates general-purpose AI models.

Its reach is extraterritorial. Providers and deployers outside the EU are covered when they place AI systems on the EU market or when the output of their systems is used in the EU, which puts many U.S. mid-market SaaS, financial services, and industrial companies in scope whether or not they have European offices.

The timeline shifted in 2026. Transparency obligations under Article 50 and enforcement of general-purpose AI model requirements applied on August 2, 2026, while the July 2026 Digital Omnibus deferred the high-risk system deadlines to December 2027 and August 2028. The deferral is breathing room, not a reprieve: classifying AI systems, assembling technical documentation, and standing up oversight processes takes most organizations well over a year. An AI governance assessment is the standard first step to determine what falls in scope.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →