The European Union adopted the AI Act (the European regulation on artificial intelligence) in March 2024. This text, the world's first legal framework dedicated to AI, is entering into force gradually between 2025 and 2027. For French and European companies, it is no longer a distant prospect: the first concrete obligations apply as early as August 2026. Here is everything you need to know in order to plan ahead and achieve compliance.
Why Europe is regulating artificial intelligence
AI is transforming every sector: recruitment, healthcare, finance, education, justice. This rapid transformation raises fundamental questions. When an algorithm denies a bank loan, does the applicant have the right to understand why? When a facial surveillance system identifies a person in the street, what limits apply?
The AI Act answers these questions by establishing a simple principle: the more risks an AI system poses to fundamental rights, the stricter the obligations. This risk-based approach avoids stifling innovation while protecting European citizens.
The regulation applies to any organization that develops, deploys or uses an AI system on the European market, including companies established outside the EU whose systems are used in Europe.
The four risk levels of the AI Act
The regulation classifies AI systems into four categories according to their level of risk. This classification directly determines the obligations that apply to your company.
Unacceptable risk: prohibited practices
Certain uses of AI are quite simply banned in the European Union. These include social scoring (in the manner of the Chinese social credit system), subliminal manipulation of behavior, exploitation of vulnerabilities linked to age or disability, and real-time biometric surveillance in public spaces (except for strictly regulated exceptions for law enforcement).
High risk: the strictest obligations
High-risk systems are those used in sensitive areas: recruitment and human resources management, access to financial services (credit scoring), education (grading and orientation), healthcare (AI-assisted diagnosis), justice and law enforcement, management of critical infrastructure.
These systems must meet rigorous requirements:
- Conformity assessment before being placed on the market
- Risk management that is documented and updated regularly
- Training data that is high quality, representative and free of bias
- Technical documentation that is complete and transparent
- Traceability through the retention of usage logs
- Human oversight that is effective and documented
- Robustness and security that are tested and validated
Limited risk: transparency obligations
Limited-risk systems include chatbots, content-generation systems (text, image, video) and emotion-recognition systems. The main obligation is transparency: the user must know that they are interacting with an AI or that the content was generated by an AI.
In concrete terms, if you deploy a chatbot on your website, you must clearly inform your visitors that they are interacting with an automated system. AI-generated content (images, texts, videos) must be identifiable as such.
Minimal risk: no specific obligations
The majority of AI systems used on a daily basis (spam filters, content recommendations, spell checkers, productivity tools) fall under minimal risk. No specific obligation applies, apart from compliance with ordinary law (the GDPR in particular).
Application timeline: the key dates
The AI Act does not apply all at once. The timeline is gradual, to give companies time to adapt:
- February 2025: ban on unacceptable-risk practices
- August 2025: obligations for general-purpose AI (GPAI) models such as GPT, Claude or Gemini
- August 2026: obligations for high-risk systems, and the establishment of national supervisory authorities
- August 2027: full application, including for systems already on the market
The critical date for most companies is August 2026. This is the deadline at which the obligations concerning high-risk systems become effective and at which penalties begin to apply.
Want to move on to practice?
Grab our free AI templates, prompts and mini-courses. Delivered instantly by email.
Get the free resourcesThe planned penalties
The fines set out in the AI Act are significant and are modeled on the GDPR framework:
- 35 million euros or 7% of global turnover for the use of prohibited practices
- 15 million euros or 3% of global turnover for failure to comply with obligations relating to high-risk systems
- 7.5 million euros or 1.5% of global turnover for providing incorrect information to the authorities
Reduced amounts are provided for SMEs and startups. But the signal is clear: Europe takes the regulation of AI seriously.
What this means concretely for your company
The first step is to take inventory of the AI systems that you use or develop. Many companies use AI without being fully aware of it: recruitment tools with automated CV filtering, lead scoring, customer-service chatbots, marketing-content generation tools.
For each identified system, you must determine which risk category it falls into. Most AI tools used in marketing, productivity or content creation fall under minimal or limited risk, which entails few or no specific obligations beyond transparency.
On the other hand, if you use AI in decision-making processes that affect people (recruitment, credit assessment, resource allocation), you are probably subject to high-risk obligations.
The AI Act does not prohibit the use of AI. It imposes safeguards proportionate to the risks. For the vast majority of companies, achieving compliance starts first and foremost with transparency and documentation.
How to prepare right now
Here are the concrete actions to undertake in order to anticipate the entry into force of the AI Act:
- Map your AI uses: list all the tools and systems that use artificial intelligence within your organization
- Classify the risks: for each system, determine the applicable risk category according to the criteria of the regulation
- Train your teams: AI literacy is an explicit obligation of the regulation; every employee using AI must understand its capabilities and its limits
- Document your processes: begin building the technical documentation required for high-risk systems
- Appoint a lead: identify the person or team in charge of AI compliance within your organization
Training your employees is an essential lever. Article 4 of the AI Act imposes an obligation of AI literacy: the people who use AI systems must have a sufficient level of knowledge to understand how these systems work and to use them responsibly.
This is a paradigm shift: using AI in a company now requires a formal skill, on the same footing as personal-data protection. Organizations that invest today in AI training for their teams gain a head start on regulatory compliance.