AI Act: What it is, how it works, and why everyone's talking about it

   

Everyone is talking about it, but bureaucratic language often makes it hard to grasp its true scope: what actually is the European Union's AI Act?

To put it simply, the AI Act is the world's first comprehensive regulation on Artificial Intelligence. Just as the EU set global privacy standards with the GDPR, it aims to do the same for AI-based systems with the AI Act, drawing a clear line between beneficial innovation and risks to citizens.

But what exactly is its purpose, and how does it impact our daily lives? Let's clear things up.

🔗 Enjoying Techelopment? Check out the website for all the details!

What is the AI Act? Key points of the regulation

To understand the AI Act, it helps to clarify the regulatory framework, its creators, and who will enforce compliance:

  • The reference regulation: The official law is Regulation (EU) 2024/1689 of the European Parliament and of the Council. It entered into force on August 1, 2024, and applies progressively across all EU Member States.
  • Who defined it: It was proposed by the European Commission and jointly discussed, amended, and approved by the European Parliament and the Council of the European Union.
  • Who is responsible for enforcement:
    • At the European level: The European AI Office, a new body established within the European Commission, tasked with supervising the most powerful AI models (those with systemic risk) and coordinating uniform application of the rules.
    • At the national level: Each Member State designates its own National Competent Authorities. In Italy, enforcement and oversight are jointly entrusted to AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency), supported by the Data Protection Authority (Garante Privacy) for fundamental rights protection.
  • Who does it apply to? (Extraterritorial effect): It doesn't only apply to companies based in Europe. If a US or Asian company develops an AI system and makes it available on the EU market, or if its outputs are used within the EU, it is still required to comply with the AI Act.
  • Progressive implementation: The AI Act did not take full effect all at once. Bans on unacceptable risks began in early 2025, rules for generative models and transparency apply from 2025–2026, while the strictest rules on high-risk systems will come into full force by 2026–2027.

What is the purpose of the AI Act?

The main goal of the European Union is not to stifle technology, but to regulate it to ensure it is safe and ethical.

In short, the AI Act serves to:

  • Protect fundamental rights: Prevent algorithms and AI from discriminating against people, violating their privacy, or manipulating their behavior.
  • Increase transparency: Ensure users always know when they are interacting with an AI or viewing AI-generated content.
  • Foster responsible innovation: Provide businesses with clear rules to build products and services, creating a market consumers can trust.

The Risk Pyramid: How does it work?

The AI Act does not apply the same level of strictness to all technologies. It uses a risk-based approach, dividing AI applications into 4 main categories:

    /\
   /  \    1. UNACCEPTABLE RISK (Banned)
  /----\
 /      \   2. HIGH RISK (Very strict rules)
/--------\
|        |  3. SPECIFIC RISK / TRANSPARENCY (Obligation to inform)
|--------|
|        |  4. MINIMAL RISK (No special restrictions)
----------

🚫 Unacceptable Risk (Banned)

Systems deemed a clear threat to people's safety or rights. These include:

  • Social scoring (Chinese-style "social credit" systems that evaluate citizens).
  • Behavioral manipulation (e.g., voice-assistant toys for children that encourage dangerous actions).
  • Real-time facial recognition in public spaces (with rare exceptions related to national security and authorized by a judge).

⚠️ High Risk (Strict regulation)

Technologies used in critical areas (e.g., healthcare, recruitment, educational exams, infrastructure management, or credit scoring).

  • The requirement: Companies developing these systems must ensure transparency, human oversight, high-quality training data, and robust cybersecurity standards.

ℹ️ Specific Risk and Transparency (Disclosure obligation)

Systems such as chatbots, deepfake tools, or image/text generators (e.g., ChatGPT, Midjourney).

  • The requirement: Users must know they are interacting with an AI. Generated content (video, audio, photos) must be clearly labeled as such (watermarking).

✅ Minimal or No Risk

The vast majority of systems currently in use (e.g., email spam filters or video game recommendations).

  • The requirement: No heavy legal obligations, only voluntary adoption of codes of conduct.

What about powerful models like GPT-4? The challenge of "Systemic Risk"

With the surge in general-purpose generative AI models (General Purpose AI or GPAI), the European Union had to introduce a special category of safeguards related to systemic risk.

📝 Types of GPAI models

Unlike "standard" GPAI models, which are only subject to certain transparency and documentation requirements, GPAI models with systemic risk must comply with additional obligations.

Systemic risk occurs when an AI model is so powerful, widespread, and pervasive that a potential malfunction, misuse, or cyberattack wouldn't just affect an individual user, but could destabilize entire sectors of society, the economy, or even the democratic and geopolitical security of multiple countries.

The AI Act defines these high-impact models (evaluated based on the total computing power used to train them) and imposes even stricter requirements on their creators:

  • Red Teaming (Attack simulations): Obligation to subject the model to continuous testing to discover vulnerabilities, critical hallucinations, or security flaws before deployment.
  • Risk assessment and mitigation: Proactively identifying whether the model could be used for large-scale cyberattacks or automated disinformation.
  • Energy consumption monitoring: Transparency regarding the environmental impact related to the computing power used.
  • Incident reporting: Obligation to immediately notify the European AI Office of any serious incident.

Why isn't systemic risk included in the risk pyramid?

Systemic risk concerns highly powerful models whose impact could extend across numerous sectors of society and the economy. For example, they could facilitate:
  • large-scale disinformation campaigns;
  • development of sophisticated malware;
  • support in designing dangerous biological or chemical agents;
  • widespread economic or social disruptions due to their broad reach.
For this reason, providers of these models must perform, among other things:
  • thorough risk evaluations;
  • safety testing (red teaming);
  • continuous monitoring;
  • reporting of serious incidents;
  • more stringent cybersecurity measures.

Why isn't it a fifth level?

Because systemic risk does not classify an AI system based on its usage, but rather qualifies the power and potential impact of a GPAI model.

In other words:
  1. The 4 risk levels apply to AI systems and depend on how they are used.
  2. Systemic risk applies to particularly advanced GPAI models and concerns their intrinsic characteristics and potential large-scale impact.
Therefore, it is accurate to say that the AI Act outlines four risk levels for AI systems, while introducing a separate set of rules for GPAI models, within which certain models may be classified as having "systemic risk". Thus, it does not represent a fifth level of the traditional classification.

What are the impacts for citizens and businesses?

  • For citizens: Reduced risk of scams, greater awareness (you will always know if an image or text was generated by an algorithm), and the assurance that fundamental rights are protected.
  • For businesses and developers: Greater responsibility. Anyone developing or integrating AI will need to carefully document their processes and comply with legal requirements, under threat of hefty financial penalties (which can reach tens of millions of euros or a percentage of global turnover).

In conclusion

The AI Act represents an ambitious endeavor for Europe: to become the global benchmark for human-centric Artificial Intelligence—that is, AI serving humanity rather than the other way around. Not a cage for innovation, but a guardrail to guide it in the right direction.



Follow me #techelopment

Official site: www.techelopment.it
facebook: Techelopment
instagram: @techelopment
X: techelopment
Bluesky: @techelopment
telegram: @techelopment_channel
whatsapp: Techelopment
youtube: @techelopment