Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
Enter your email address below and subscribe to our newsletter

This article contains affiliate links. We may earn a commission at no extra cost to you. Full disclosure.
On February 2, 2025, the European Union’s AI Act shifted from legislative text to enforceable law, with the first batch of prohibitions taking effect. Companies that build, deploy, or use AI systems touching EU citizens now face deadlines measured in months, not years. The Act is not a suggestion—it carries penalties up to €35 million or 7% of global annual turnover, whichever is higher. Despite months of warnings, a survey by the AI Governance Alliance found that only 38% of affected firms had completed a compliance readiness assessment by January 2025. The remaining 62% are now racing against a calendar that will escalate obligations every six months through 2027. This article breaks down the deadlines, the penalties, and the practical steps your organization needs to take now—not next quarter.
The AI Act’s enforcement is phased, not monolithic. Understanding which dates apply to your use case is the difference between a manageable transition and a regulatory crisis. The first deadline—February 2, 2025—bans eight specific practices outright, including social scoring, real-time biometric surveillance in public spaces (with narrow exceptions), and AI systems that exploit vulnerabilities of children or economically disadvantaged groups. Companies still operating such systems after this date face the maximum penalty tier: €35 million or 7% of global annual turnover.
The second major deadline arrives on August 2, 2025, when the rules for general-purpose AI (GPAI) models come into force. This includes transparency obligations for all GPAI providers and additional requirements for models deemed to pose “systemic risk”—those trained with compute exceeding 10^25 floating-point operations (FLOPs). By comparison, OpenAI’s GPT-4 is estimated to have required around 2.1×10^25 FLOPs, placing it squarely in the systemic-risk category. Meta’s Llama 3 70B, with roughly 6.3×10^24 FLOPs, falls below the threshold—for now.
Top-rated VPN for online privacy and security. Lightning-fast servers.
Affiliate link
August 2, 2026, is the date when most of the Act’s rules become applicable, including those for high-risk AI systems. High-risk categories include AI used in critical infrastructure, education, employment, law enforcement, and biometric identification. Companies deploying such systems must have conformity assessments, risk management frameworks, and human oversight mechanisms in place by then. Finally, August 2, 2027, extends requirements to high-risk AI systems that are components of larger products already regulated under EU harmonization legislation (e.g., medical devices, machinery).
The AI Act applies to any provider, deployer, importer, or distributor of AI systems that affect individuals within the EU, regardless of where the company is headquartered. This extraterritorial reach mirrors the GDPR and catches US-based giants like Google, Amazon, and Microsoft, as well as Asian firms like Baidu and Samsung. The Act categorizes AI systems into four risk levels: prohibited (banned outright), high-risk (strict compliance required), limited-risk (transparency obligations), and minimal-risk (no additional rules).
Most enterprise AI tools—such as customer service chatbots, recommendation engines, and content generation APIs—fall into the limited-risk category. For these, the primary obligation is transparency: users must be informed they are interacting with an AI. The EU’s guidance, published in December 2024, specifies that a simple “AI-powered” label on a chat interface suffices, but the label must be visible before the first interaction. Companies that embed AI in email autoresponders or automated phone systems must also comply.
High-risk systems are far more demanding. For example, an AI recruitment tool that screens job applicants must undergo a third-party conformity assessment, maintain detailed technical documentation, and implement bias monitoring. The European Commission’s Joint Research Centre estimates that there are roughly 1,200 high-risk AI systems currently in use across the EU—a number expected to grow as the market expands. Companies that fail to classify their systems correctly risk penalties even if the system itself is compliant; the Act holds providers accountable for misclassification.
Article 5 of the AI Act lists eight practices that are prohibited as of February 2, 2025. These include: (1) subliminal techniques that manipulate behavior without a person’s knowledge; (2) exploiting vulnerabilities due to age, disability, or economic situation; (3) social scoring by public authorities; (4) real-time remote biometric identification in publicly accessible spaces for law enforcement (with exceptions for specific serious crimes and judicial authorization); (5) biometric categorization to infer sensitive attributes like race, sexual orientation, or political beliefs; (6) emotion recognition in workplaces and educational institutions; (7) predictive policing based solely on profiling; and (8) untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases.
The ban on emotion recognition is particularly impactful for companies like Affectiva and RealEyes that market workplace sentiment analysis tools. The Act explicitly prohibits using AI to infer emotions in employment and education contexts, though it allows such systems in medical or safety-critical scenarios with explicit consent. For example, a system that detects driver drowsiness in a truck is permitted; a system that gauges employee frustration during a video call is not.
Companies that currently deploy any of these prohibited systems must immediately cease operations or face penalties starting at €35 million or 7% of annual turnover. There are no grace periods. The European Data Protection Board has already signaled that it will coordinate enforcement with national data protection authorities, and several EU member states—including Germany, France, and Spain—have established dedicated AI enforcement units with staff seconded from data protection agencies.
General-purpose AI (GPAI) models—those like GPT-4, Claude 3, Gemini Ultra, and open-source alternatives—face a unique regulatory track under the Act. All GPAI providers must, by August 2, 2025, publish a summary of the training data used, implement a copyright policy that respects opt-outs, and designate an authorized representative in the EU. For models that exceed the 10^25 FLOPs training compute threshold, additional obligations include: conducting model evaluations using standardized benchmarks (e.g., MMLU, HellaSwag, TruthfulQA), reporting serious incidents to the AI Office, and performing adversarial testing for systemic risks such as chemical, biological, radiological, and nuclear (CBRN) threats.
The compute threshold is controversial. OpenAI’s GPT-4, trained on approximately 2.1×10^25 FLOPs, clearly qualifies. Google’s Gemini Ultra, estimated at 1.3×10^26 FLOPs, also qualifies. However, Meta’s Llama 3 70B, at roughly 6.3×10^24 FLOPs, does not—yet Meta has voluntarily committed to following the same rules for its next-generation models. The AI Office has the authority to designate a model as systemic even if it falls below the compute threshold, based on its capabilities or number of users. This clause acts as a safety net: if a smaller open-source model suddenly gains 10 million active users, it could be reclassified.
One practical implication for developers: the Act requires GPAI providers to make available a “sufficiently detailed summary” of training data. The AI Office’s template, published in January 2025, asks for the total size of the dataset in tokens, a description of the data sources (e.g., Common Crawl, GitHub, licensed datasets), and the proportion of data subject to copyright. Companies that rely heavily on web-scraped data—like Stability AI or Mistral—will need to document how they handled opt-out requests from rightsholders. Failure to provide an adequate summary can result in fines up to €15 million or 3% of turnover.
The AI Act’s penalty structure is designed to hurt. For prohibited practices, the maximum is €35 million or 7% of global annual turnover—whichever is higher. For non-compliance with GPAI obligations or high-risk system rules, the maximum is €15 million or 3% of turnover. For providing incorrect or misleading information to regulators, the maximum is €7.5 million or 1.5% of turnover. These figures exceed the GDPR’s maximum of €20 million or 4% of turnover, signaling that the EU views AI governance as equally critical as data privacy.
To put these numbers in context: a company like OpenAI, with an estimated 2024 revenue of $3.7 billion, would face a maximum fine of roughly €259 million for a prohibited practice violation—not crippling, but significant. For a smaller European AI startup with €50 million in revenue, a 7% penalty would be €3.5 million, potentially devastating. The Act also allows national regulators to order the withdrawal of non-compliant AI systems from the market, effectively shutting down a product line. In extreme cases, the AI Office can require the deletion of training data or the model itself.
Enforcement is not hypothetical. In March 2025, the Italian data protection authority (Garante) announced its first AI Act investigation into a company using real-time emotion recognition in a school setting—a prohibited practice. The company faces a potential fine and an order to destroy the system. This case serves as a warning: regulators are actively monitoring, and whistleblower channels are already receiving reports. The Act also includes provisions for collective redress, meaning consumer groups can bring class-action-style complaints.
If your organization uses or develops AI systems that affect EU residents, here are five concrete steps to take immediately:
Tools like IBM’s AI Governance Dashboard and Microsoft’s Responsible AI Toolkit can help automate parts of the documentation process, but they are not substitutes for legal review. The Act requires that technical documentation be submitted in a format specified by the AI Office; third-party tools must be validated against those specifications.
The EU AI Act is the world’s first comprehensive AI regulation, and its influence is already spreading. Japan, South Korea, and Brazil are drafting similar laws that reference the EU’s risk-based categories. Canada’s proposed Artificial Intelligence and Data Act borrows heavily from the EU framework. Even in the United
The tools, tutorials, and trends that actually pay — no hype.
The tools, tutorials, and trends that actually pay — no hype.