STANDARDS EXPLAINED

EU AI Act explained: what it actually requires, and who it applies to

A plain-English walkthrough of what the EU AI Act requires, which systems are in scope, and the obligations that apply — so you can assess your exposure before your board asks.

iDharma · July 23, 2026 · 6 min read
EU AI Act explained: what it actually requires, and who it applies to

The EU AI Act is now in force. If your organisation deploys AI that touches EU users — whether you are headquartered in Munich or Minnesota — the Act applies to you. Here is what it actually says, stripped of the jargon that makes most guides unreadable.

What the EU AI Act is, in one paragraph

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It uses a risk-based approach: the higher the risk a system poses to people, the stricter the obligations. It covers AI providers (companies that develop or deploy AI) and operators (companies that put third-party AI to use). If an AI model makes decisions that affect people — creditworthiness, hiring, medical diagnosis, access to essential services — it is almost certainly in scope.

The four risk tiers

Unacceptable risk (banned): AI that manipulates people subconsciously, exploits vulnerable groups, or enables real-time biometric surveillance in public spaces. These uses are prohibited outright from 2 February 2025.

High risk (strict obligations): AI used in credit scoring, employment screening, healthcare triage and clinical decision support, access to essential public services, law enforcement, and education assessment. These systems must meet technical documentation, data governance, human oversight, accuracy, robustness, and transparency requirements — and must register in the EU database before deployment.

Limited risk (transparency obligations): Chatbots and other AI that interact with people must disclose that the user is talking to a machine. AI-generated content must be labelled. These rules apply regardless of sector.

Minimal risk: Spam filters, AI in video games, recommendation engines for non-critical content. No additional obligations beyond existing law.

The transparency obligations that apply to most organisations

Even if your AI is not classified as high-risk, the Act requires you to:

  • Disclose automated decision-making. People interacting with a chatbot or receiving an AI-generated output must be told so, unless it is obvious from context.
  • Maintain human oversight. High-risk systems must allow a human to understand, monitor, and override AI outputs. "The model decided" is not a compliant defence.
  • Keep records. Logs of how high-risk systems were trained, tested, and validated must be retained for at least ten years for regulatory inspection.
  • Provide an explanation on request. For AI systems making consequential individual decisions (credit, insurance, employment), affected people have a right to a meaningful explanation under Article 86 — not just a score, but the specific factors that drove the outcome.

What gets organisations fined

Our enforcement tracker surfaces two patterns that recur in every sector:

First, the explanation gap. When a model is too complex to explain in plain language, that complexity is now a regulatory liability, not just a technical property. The question regulators and courts ask is not "can your engineers explain it internally?" but "can the affected person understand why the decision went against them?" Generic denial reasons, such as "based on our model," do not satisfy this requirement.

Second, vendor AI treated as outsourced accountability. Buying an AI tool from a vendor does not transfer your regulatory obligation. If a third-party model makes decisions about your customers, you remain the accountable party. "Our vendor handles compliance" is not an accepted defence in any EU enforcement action we have reviewed.

The compliance timeline

The Act entered into force on 1 August 2024. Obligations phase in as follows:

  • February 2025: Prohibited practices take effect.
  • August 2025: GPAI (general-purpose AI) model obligations and governance provisions.
  • August 2026: High-risk system obligations (the core of the Act) take effect.

Note: a legislative proposal under the EU's Digital Omnibus package may revise certain deadlines. Verify the current enforcement timeline against the official EU AI Office publications before relying on any date in a compliance plan.

What an iDharma audit checks against this standard

An iDharma audit maps your AI deployment against the EU AI Act's high-risk obligations using the ISO/IEC 42001 AI management system standard as the structural backbone. We check: technical documentation completeness, data governance practices, human oversight mechanisms, accuracy and robustness testing, and your explanation workflow for affected individuals. The output is a gap report you can put in front of your board, your legal team, or a national market surveillance authority — with the findings traceable to the actual regulatory text, not a vendor checklist.

If you want to know where you stand before the deadline lands, request an audit or start with the free 60-second Risk Snapshot.

Wondering where your AI stands?