Cortexa AI Glossary · Your data, rights, and the rules
What is the EU AI Act?
From Cortexa Learn, by Cortexa Consulting. Last checked .
Europe wrote a broad law for artificial intelligence, and it reaches well past Europe.
After the cookie banners
Remember when cookie banners showed up on nearly every website? That came after Europe passed a privacy law, and companies around the world changed their sites to follow it. The European Union (EU) has now written a broad law for artificial intelligence (AI), called the AI Act. The European Commission calls it the first broad legal framework for AI anywhere in the world. And like the privacy law, it reaches companies far outside Europe.1
It regulates uses
The AI Act doesn't treat AI as one thing. It looks at what a system is used for, and how much harm that use could do. The same kind of software might sort your vacation photos or screen job applications. The law treats them differently. Its organizing idea is a ladder of risk: the greater the possible harm, the stricter the rules.1
Four rungs on the ladder
The European Commission describes four levels of risk.
- Unacceptable risk: a short list of uses that are banned outright.
- High risk: uses that can affect people's safety or rights, which face strict checks.
- Limited risk: chatbots and AI-made content, which must be open about what they are.
- Minimal risk: most everyday AI, which gets no new rules.
Most of the AI you use sits on that bottom rung. That may come as a surprise.1
What's banned
The banned list is short. It's also specific. It includes social scoring, where people are rated on their behavior in ways that can lead to unfair treatment. It covers AI that manipulates people in harmful ways or exploits their vulnerabilities. And it bans some uses of face recognition, like scraping photos from the internet to build a face database.1
High-risk uses
High-risk uses are where the law asks the most. They include AI used in hiring, in deciding who gets into a school or how students are assessed, and in credit scoring for loans. Systems like these have to manage their risks, keep records of how they run, and be built so a person can oversee them and step in when something goes wrong. When a decision can shape someone's job, schooling, or money, the law asks for more care.12
Lighter rules, and none
Further down the ladder, the rules get lighter. Chatbots have to let people know they're talking to a machine, and deepfakes and some AI-written public text have to be labeled. Topic 54, "Do I have to label AI-made content?", covers that part. For most other AI, like spam filters or the computer players in video games, the Act adds no new duties.13
Who it reaches
The law follows the people it protects. Where a company is based matters less than where its AI is used. A company based anywhere, including the United States (US), has to follow it when it offers AI systems in the EU, or when its system's output is used there. So the chatbot on a US company's website may need to meet EU rules for its European visitors.245
Reading the news about it
Expect more headlines. You'll keep seeing the AI Act in the news, often with a date attached, because its parts phase in over several years and lawmakers have been adjusting the schedule. If it touches your work, a lawyer who knows EU law is the person to ask. And when a story says the Act requires something, here's a good question to bring to it: which rung of the ladder is it talking about?
Works cited
- European Commission, "AI Act" (regulatory framework on AI) (checked )
- EU AI Act explorer (Future of Life Institute), "High-level summary of the AI Act." (checked )
- AI Act Service Desk (European Commission), "Article 50: Transparency obligations for providers and deployers of certain AI systems." (checked )
- EUR-Lex, "Proposal for a regulation amending the AI Act (digital omnibus on AI), COM(2025) 836." (checked )
- European Commission, "Transparency obligations under Article 50 of the AI Act" (FAQ) (checked )