EU AI Act
The world's first comprehensive AI statute, with risk tiers, heavy obligations on high-risk systems and reach that extends well beyond Europe. EU AI Act framework content is available in Aicura on the Enterprise tier.
What it is
The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, is the world's first comprehensive AI statute. It entered into force on 1 August 2024 and applies in stages, with prohibitions on unacceptable-risk practices from February 2025, obligations on general-purpose AI models from August 2025 and the main body of high-risk obligations from August 2026, plus longer transitions for high-risk AI embedded in already-regulated products. Penalties scale to the highest tiers of any technology regulation, reaching up to 35 million euros or 7 percent of global turnover for prohibited practices.
The risk tiers
- Prohibited practices. A short list of uses the EU has banned outright, including social scoring by public authorities and certain manipulative or exploitative systems.
- High-risk systems. The Act's centre of gravity. AI in areas such as employment, credit, essential services, education and law enforcement carries obligations across the lifecycle, covering risk management, data governance, technical documentation, record-keeping and logging, transparency to deployers, human oversight, accuracy, robustness and cybersecurity, plus conformity assessment before market and post-market monitoring after.
- Limited-risk transparency. Systems such as chatbots and synthetic content generators must disclose their nature to the people interacting with them.
- General-purpose AI models. A separate regime for foundation models, with documentation and transparency duties, and additional obligations for models designated as carrying systemic risk.
Article 73 adds a reporting spine, under which providers of high-risk systems report serious incidents to market surveillance authorities, on deadlines that start when the incident is known.
Why an Australian organisation might care
The Act's territorial reach extends to providers placing systems on the EU market wherever they are established, and in defined circumstances to providers and deployers outside the EU where the system's output is used in the EU. An Australian organisation with European customers, European users of its AI-enabled product or a European group entity can be in scope without a European office. Beyond direct application, the Act is functioning as the reference point international customers and partners reach for in due diligence, so its vocabulary arrives in questionnaires even where the law itself does not apply.
Common misreadings
"We're an Australian company, so the EU AI Act doesn't apply to us." Check before you rely on that. The Act reaches providers placing AI systems on the EU market and, in defined circumstances, providers and deployers outside the EU where the system's output is used in the EU. Australian organisations with European customers, users or group entities can be in scope without ever incorporating in Europe.
"It's a law about banning AI." The prohibitions are the narrowest tier. Most of the Act's weight sits on high-risk systems, which remain lawful but carry obligations covering risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment. It is a governance statute far more than a ban.
"Compliance is a project we can run once before the deadline." The obligations are continuous. Risk management runs across the lifecycle, logs accumulate, post-market monitoring watches deployed systems and Article 73 puts clocks on serious incident reporting. A one-off compliance project produces a binder that stops being true the week after it closes.
How Aicura supports work against it
EU AI Act framework content is available in Aicura on the Enterprise tier. The framework operates the way every Aicura framework does, as loaded content applied through the product, so risk and impact assessments draw on it, governance policy reviews use it as a source and the multi-framework view shows it alongside the Australian frameworks the same systems answer to. The incident lifecycle includes an EU AI Act Article 73 serious incident reporting pathway on Enterprise, alongside the GDPR Article 33 personal data breach pathway, and the record of the work lands in the Evidence Vault as evidence you don't have to trust us for.
A note on this page
This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source, and for a statute of this size, whether and how it applies to your organisation is squarely a question for your advisors.
For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.