EU AI Act, plain-English definition from TheAICommand
← Glossary
Definition

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's horizontal law on artificial intelligence. It sorts AI systems by risk, bans a set of practices outright, and imposes obligations on high-risk uses. It reaches providers and deployers outside the Union where the output of the system is used in the Union.

Quick answer

The EU AI Act is Regulation (EU) 2024/1689, the European Union's horizontal law on artificial intelligence. It sorts AI systems by risk, banning some practices outright and imposing obligations on high-risk uses. It binds providers and deployers outside the Union where the system's output is used in the Union.

What is the EU AI Act and what does it regulate?

The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, laying down harmonised rules on artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It is the first horizontal statute of its kind, meaning it regulates AI as a technology across sectors rather than through sector-specific rules.

Article 3 defines an AI system as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. The same article separates the two roles that carry most of the obligations. A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority, other than in a personal non-professional activity.

The regulation then sorts systems by risk. A small set of practices is prohibited outright under Article 5, including certain manipulative techniques, social scoring, untargeted scraping of facial images to build databases, emotion recognition in workplaces and education, and some biometric categorisation. A larger set is classified as high risk under Article 6, covering areas such as biometric identification, critical infrastructure, education and employment decisions. Article 50 imposes transparency duties, such as telling people they are interacting with an AI system. Chapter V covers general-purpose AI models, with additional duties for those presenting systemic risk. Everything else attracts no specific obligations.

Article 99 sets the penalties. Breaching the Article 5 prohibitions can attract administrative fines up to 35 million euro or 7 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. Non-compliance with most other obligations reaches 15 million euro or 3 per cent, and supplying incorrect, incomplete or misleading information reaches 7.5 million euro or 1 per cent.

Who does the EU AI Act apply to?

Article 2 sets a scope that is explicitly extraterritorial, and this is the provision Australian organisations most often overlook.

The regulation applies to providers placing AI systems on the market or putting them into service in the Union, or placing general-purpose AI models on the Union market, irrespective of whether those providers are established in the Union or in a third country. It applies to deployers established or located in the Union. Critically, it also applies to providers and deployers established or located in a third country where the output produced by the AI system is used in the Union.

It further covers importers and distributors, product manufacturers placing an AI system on the market together with their product under their own name or trademark, authorised representatives of non-EU providers, and affected persons located in the Union.

An Australian organisation therefore cannot rely on its place of establishment. The questions that decide scope are whether it puts an AI system or general-purpose model on the Union market, and whether the output of a system it provides or deploys is used in the Union. Multinational employers, insurers and service providers with European customers, staff or subsidiaries are the typical exposure.

The timetable has changed. Prohibitions and the AI literacy duty applied from 2 February 2025, and general-purpose AI model obligations, governance arrangements, notified bodies and penalties applied from 2 August 2025. Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, then amended the original regulation and deferred the high-risk obligations: standalone Annex III systems move to 2 December 2027, and AI embedded in regulated products under Annex I moves to 2 August 2028. Anyone working from a compliance plan built on the original 2 August 2026 high-risk date is working from a superseded timetable.

Where does the EU AI Act fit for Australian practitioners?

Australia has no equivalent statute. Obligations here come from the Privacy Act 1988, work health and safety law, anti-discrimination law, prudential standards such as APRA CPS 230, and sector regulation. The EU AI Act does not change any of that.

It matters for three practical reasons. First, direct application through Article 2 for organisations whose AI output reaches the Union. Second, procurement: the vendors selling AI into Australian enterprises are largely the same vendors preparing for the EU regime, so their documentation, conformity work and technical files are being built to that template. Australian buyers can ask for that material and use it, whether or not they are in scope themselves.

Third, and most usefully, the Act supplies vocabulary that Australian governance documents currently lack. The provider and deployer split maps cleanly onto the build-versus-buy question that dominates most AI registers. The risk tiers give a defensible basis for deciding how much control a use case warrants. Australian organisations adopting that structure should be clear internally that they are borrowing a taxonomy, not acquiring a legal obligation, so that the register does not drift into implying compliance duties that do not apply.

What should practitioners do about the EU AI Act?

Answer the scope question in writing before anything else. For each AI system, record whether it is placed on the Union market and whether its output is used in the Union, and identify whether the organisation is acting as provider or deployer for that system. Those two answers determine everything that follows, and the deployer obligations are considerably lighter than the provider obligations.

Where the organisation is in scope, classify against the risk tiers and work to the amended dates rather than the original ones. Where it is not in scope, the sensible position is to use the Act as a design reference and say so explicitly in the register.

Either way, put the question to vendors. Ask which role the vendor takes for the system being sold, whether it treats the system as high risk, and what documentation it will provide. That is a reasonable procurement question in 2026 regardless of the buyer's own jurisdiction, and the answer is a useful signal about the maturity of the supplier. Related material sits under the AI governance hub, the vendor risk hub and across the GRC section.

Bottom line

The EU AI Act is not an Australian obligation, but it is not safely ignorable either. Article 2 catches providers and deployers outside the Union whenever the output of their AI system is used in the Union, so establishment in Australia decides nothing on its own. The timetable has also moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, pushed high-risk obligations out to 2 December 2027 and 2 August 2028, so any plan still built on 2 August 2026 is out of date. For organisations genuinely outside scope, the Act remains the clearest available vocabulary for AI governance, provided the register says so plainly.

TheAICommand. Intelligence, At Your Command.*

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Does the EU AI Act apply to Australian organisations?
It can. Article 2 extends the regulation to providers and deployers established in a third country where the output produced by the AI system is used in the Union, and to anyone placing an AI system on the Union market. Australian establishment alone does not put an organisation outside it.
When do the EU AI Act's high-risk rules apply?
Later than originally legislated. Regulation (EU) 2026/1744, the Digital Omnibus on AI adopted on 8 July 2026, moved the high-risk obligations for standalone Annex III systems to 2 December 2027 and for AI embedded in regulated products under Annex I to 2 August 2028.
What are the penalties under the EU AI Act?
Article 99 sets three tiers. Breaching the Article 5 prohibitions can draw fines up to 35 million euro or 7 per cent of total worldwide annual turnover, whichever is higher. Most other breaches reach 15 million euro or 3 per cent, and supplying misleading information 7.5 million euro or 1 per cent.
What does the EU AI Act count as an AI system?
Article 3 defines it as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments.
Which EU AI Act rules already apply?
The prohibitions on unacceptable-risk practices and the AI literacy duty applied from 2 February 2025. Obligations for general-purpose AI models, governance arrangements, notified bodies and penalties applied from 2 August 2025. The regulation itself entered into force on 1 August 2024.

Primary sources

← Back to the glossary

General information and education only. Not legal, compliance, financial, or professional advice. Always confirm obligations against the primary source and current regulator guidance.