TerraLex AI Guide

Description:

European Union TerraLex AI Guide Guide

Date posted:
27/10/2025
Last update:
28/10/2025

Legislation and regulations

Are there any specific laws or regulations, either issued or under discussion, that directly regulate AI?

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), hereinafter the “AI Act”, or the “Regulation”. The AI Act is directly applicable in the individual EU Member States.

The AI Act aims to foster the development and uptake of human-centric, trustworthy artificial intelligence in the EU internal market while ensuring a high level of protection for health, safety, fundamental rights, democracy, the rule of law, and the environment, and promoting innovation.

The AI Act was published in the Official Journal of the European Union on 12 July 2024, and entered into force on 1 August 2024, twenty days after its publication.

Although the AI Act will apply in full starting from 2 August 2026, the Regulation provides for a gradual entry into force with the following applicability milestones:

  • The provisions on prohibited AI practices and the general provisions of the AI Act became applicable from 2 February 2025.
  • The obligations imposed on providers of general-purpose AI models became applicable from 2 August 2025.
  • Rules on high-risk AI systems in specific sectors (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, administration of justice, and democratic processes) will apply from 2 August 2026.
  • Requirements to limited risk AI systems which interact directly with natural persons, generate or manipulate content, or use biometric categorisation and emotion recognition (unless prohibited) will apply from 2 August 2026.
  • Rules regarding classification and obligations applicable to high-risk AI systems falling under EU harmonisation legislation as products by themselves or as safety components of products will apply from 2 August 2027.

What are the key concepts, such as the definition of "AI"?

The key concepts of the AI Act include:

“AI system” means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. To explain the legal concept, the EU Commission published guidelines on the AI system definition, available here: https://ec.europa.eu/newsroom/dae/redirection/document/112455

“General-purpose AI model (GPAI model)” means an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market.

Other key concepts include:

(i) “operators” are the obligated actors charged with specific obligations under the AI Act; the individual categories of operators, such as “provider” and “deployer,” are also key concepts; (ii) “affected persons” meaning the natural persons in respect of whom AI systems or GPAI models are used and whose rights and legitimate interests are protected by and further to the AI Act; (iii) “risk” meaning a combination of the likelihood for a relevant harm to occur and the severity of that harm, where harm relates to the health, safety and/or fundamental human rights arising from the use of AI systems and GPAI models; (iv) “placing on the market” means the first making available of an AI system or a general-purpose AI model on the Union market; (v) “putting into service” means the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.

All key concepts are expressly defined in the AI Act.

What is the regulatory approach to AI?

The AI Act establishes a risk-based regulatory framework that aligns legal obligations with the level of risk an AI system or GPAI model may pose to public interests such as health, safety, and fundamental rights.

Certain AI practices, considered to involve unacceptable risk, are prohibited outright (Article 5). The European Commission has published guidelines on the scope of the prohibitions, see here.

High-risk AI systems include two categories: (i) AI systems which are intended to be used as a safety component of a product, or AI systems that in themselves are products covered by the EU product harmonisation legislation and the products in which the AI systems are embedded are required to undergo a third-party conformity assessment; and
(ii) AI systems which can endanger the health, safety or fundamental rights of natural persons with covered sectors including biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, administration of justice and democratic process.

The AI Act imposes extensive and ongoing obligations on providers, deployers, and other actors involved in the life cycle of high-risk AI systems. These systems must comply with the detailed requirements laid down in Title III, Chapter 2 (Articles 8–51), including the establishment of a risk management system, a data and data governance framework ensuring the quality and representativeness of training, validation, and testing datasets, and the preparation of technical documentation and record-keeping mechanisms. Further obligations relate to transparency and provision of information to users, human oversight, as well as ensuring accuracy, robustness, cybersecurity, and reliability. Continuous compliance is supported through a quality management system and conformity assessment procedures prior to market placement. The precise scope of these obligations varies depending on the role of the actor within the AI value chain.

AI systems presenting limited risk encompass: (i) AI systems that interact directly with natural persons (e.g., chatbots), (ii) systems that generate or manipulate image, audio, text, or video content (commonly referred to as generative AI), except where such practices are prohibited under Article 5, and (iii) systems employing biometric categorization or emotion recognition, unless otherwise prohibited by Article 5. Providers and deployers are mainly subject to transparency obligations, such as informing individuals that they are interacting with an AI system or that content has been artificially generated. A code of practice will outline a way for providers and deployers of generative AI systems to demonstrate compliance with their transparency obligations.

GPAI models may pose a systemic risk when their scale or capabilities could significantly affect multiple sectors or fundamental rights. A model is presumed to entail such a risk if it demonstrates high-impact capabilities or has been trained with computational resources exceeding 10²⁵ floating point operations (FLOPs). By a specific decision, the European Commission can also designate a GPAI model as posing systemic risk. All GPAI models, including those with systemic risk, must comply with the baseline obligations (Article 53(1)(b)–(c)), which require providers to adopt a copyright-compliance policy and to publish a sufficiently detailed summary of the content used for training the model. The limited exemption for open-source providers does not apply to GPAI models with systemic risk. Guidelines on the scope of obligations for providers of GPAI models under the AI Act has been published by the European Commission, see here. The obligations of providers of GPAI models can be complied with by adhering to the approved code of practice, see here.

AI systems and AI models that are not covered by the AI Act fall outside its scope and are not subject to its requirements.

Which actors are covered?

All organizations and professionals that are part of the value and supply chain of an AI system or use an AI system are subject to the AI Act, including those that do or participate in the design and development of such a system, to those that make the AI system available on the market for commercial and/or organizational purposes of end users. The AI Act defines all these organizations and professionals collectively as “operators”. Covered actors include:

  • “Provider” - a natural or legal person, public authority, agency or other body that develops an AI system or a GPAI model or that has an AI system or a GPAI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.
  • “Deployer” - a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.
  • “Authorised Representative” - a natural or legal person located or established in the EU who has received and accepted a written mandate from a provider of an AI system or a GPAI model to, respectively, perform and carry out on its behalf the obligations and procedures established by the AI Act.
  • “Product Manufacturer” - the manufacturer of the product, in which a high-risk AI system is embedded or incorporated, where that product is placed on the market or put into service under the manufacturer’s own name or trademark. The AI Act treats such a product manufacturer as a provider with regard to obligations and liability for the AI system.
  • “Importer” - a natural or legal person located or established in the EU that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.
  • ”Distributor” - a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the EU market.

All key actors are expressly defined in the AI Act.

What other laws or regulations affect AI?

The AI Act is a horizontal regulation that applies across all sectors, complementing other EU laws affecting AI. Its application interacts with several other EU laws and regulations that together shape the broader legal environment for artificial intelligence in the EU.

Personal data protection legislation Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) applies to the processing of personal data in the context of all activities in the AI value chain. Copyright

The EU Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market (DSM Directive )establishes EU-wide copyright exceptions for text and data mining — the process supporting for AI training — and is expressly incorporated into Article 53(1)(c) of the Artificial Intelligence AI Act, which requires AI providers to implement copyright-compliance policies respecting the rights reserved under the DSM Directive.

Access to data Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act), Regulation (EU) 2022/868 on European data governance (Data Governance Act) and Directive (EU) 2019/1024 on open data and the re-use of public sector information regulate access to data, including re-use of data held by public sector bodies.

EU Competition Law EU competition law prohibits agreements that restrict competition and the abuse of a dominant market position in markets for AI products and services. While it does not mandate technical design choices, it can influence AI system development by prohibiting features or practices that may restrict competition.

Digital Services Act (Regulation (EU) 2022/2065) (DSA) DSA complements the AI Act by regulating the use of AI-driven recommender systems and content moderation tools on online platforms and digital intermediaries, ensuring transparency, accountability, and the protection of fundamental rights in the online environment.

Digital Markets Act (Regulation EU 2022/1925) (DMA) The DMA promotes fair and contestable digital markets by imposing obligations on major online platforms (gatekeepers). While mainly competition-oriented, it also empowers the Commission to access or inspect algorithms and data (Arts. 21–23).

The Product Liability Directive (PLD) 2024/2853 The revised PLD introduces significant changes to liability rules that extend product liability to software, including AI systems, to address AI-related harms.

Territorial and Sectoral Scope

What is the territorial scope of the AI regulations?

The AI Act is directly applicable in all EU Member States. Territorially, the AI Act covers the following:

  • providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the EU, irrespective of whether those providers are established or located within the EU or in a third country;
  • deployers of AI systems that have their place of establishment or are located within the EU;
  • providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the EU;
  • importers and distributors of AI systems;
  • product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark;
  • authorised representatives of providers, which are not established in the EU; and
  • affected persons that are located in the EU.

The AI Act is also marked as EEA relevant and is under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway, see here.

What sectors are covered by the AI regulations?

The AI Act is a horizontal regulation that applies to all sectors (similar to the General Data Protection Regulation).

Competent Authorities

Which authorities are vested with the powers to supervise and enforce the implementation of the AI regulations?

The European AI Office and the national market surveillance authorities are responsible for implementing, supervising and enforcing the AI Act.

The AI Office, established within the European Commission, oversees the AI Act’s enforcement and implementation across the EU. It is also responsible for supervising the compliance of the providers of the GPAI models with the requirements of the AI Act.

At the EU level, the AI Act’s governance is supported by three advisory bodies: (i) European Artificial Intelligence Board, composed of representatives from EU Member States, (ii) Scientific Panel, composed of independent experts in the field of AI, and (iii) Advisory Forum, representing a diverse selection of stakeholders, both commercial and non-commercial.

The European Commission and the AI Office work closely with EU Member State national competent authorities. The latter supervise the implementation and application of the AI Act at national level and include the following:

  • Market surveillance authorities - competent to supervise compliance with and enforce the rules for AI systems, including prohibitions and rules for high-risk AI. In an EU Member State, specific competences in different markets may be allocated to more than one separate national authorities.
  • Notifying authorities - competent to supervise notified bodies, which are independent bodies that carry out pre-market conformity assessment of AI systems. Each EU Member State should have designated and empowered its national competent authorities by 2 August 2025.

Which other authorities may be involved with supervision of AI systems or practices?

The national market surveillance authorities shall report annually to the European Commission and relevant national competition authorities any information identified in the course of market surveillance activities that may be of potential interest for the application of Union law on competition rules.

Malfunctioning of AI systems can result in violations of fundamental rights laws, for example, those protecting privacy or the right to non-discrimination. To facilitate effective investigations of such violations by the fundamental rights protection authorities, the AI Act provides rules that ensure cooperation and information flows between all authorities.

By 2 November 2024, each EU Member State should have identified the public authorities or bodies responsible for protecting fundamental rights and made the list publicly available. Member States shall notify the list to the European Commission and the other EU Member States and shall keep it up to date.

Sanctions for Non-Compliance

What enforcement powers and sanctions are in place for non-compliance with AI regulations?

The European Commission is entrusted with the enforcement of AI Act obligations imposed on providers of the general-purpose AI models (GPAI models). Тhese enforcement powers will enter into force on 2 August 2026 (Article 113). The European Commission, acting through its AI Office, may impose on the providers of GPAI models fines of up to EUR 15 million or 3 % of their total worldwide annual turnover in the preceding financial year, whichever is higher, when it finds that the provider has infringed the relevant provisions of the Regulation, failed to provide information or access to the model, or otherwise failed to comply with a Commission request or measure.

For all AI systems and infringement of the respective operators’ obligations under the Regulation, enforcement and the imposition of penalties are the responsibility of national competent authorities or market surveillance authorities designated by the Member States (Article 99(1). The applicable fines are:

  • up to EUR 35 million or 7 % of total worldwide annual turnover, whichever is higher, for breaches of the prohibitions in Article 5 (AI systems involving an unacceptable risk);
  • up to EUR 15 million or 3 %, whichever is higher, for other infringements of the Regulation; and
  • up to EUR 7.5 million or 1 %, whichever is higher, for supplying incorrect, incomplete, or misleading information.

In the case of SMEs, including start-ups, the maximum fine is reduced to the lower threshold applicable to undertakings.

Where an AI system is based on a GPAI model, and the model and the system are developed by the same provider, the AI Office has the powers of a market surveillance authority.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.