Don’t do SECURITY. Do business SECURELY.

EU AI Act enters into force

The world’s first comprehensive AI law enters into force, with obligations phasing in from February 2025.

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) enters into force today.

The Act takes a risk-based approach:

  • Prohibited practices (such as social scoring and certain manipulative or biometric uses) are banned from 2 February 2025.
  • General-purpose AI models face transparency and, for systemic-risk models, additional obligations from 2 August 2025.
  • High-risk AI systems must meet requirements including risk management, data governance, human oversight, and accuracy, robustness and cybersecurity.
  • Transparency obligations apply to certain AI systems, such as chatbots and deepfakes.

The Act applies to providers and deployers placing AI on the EU market or whose outputs are used in the EU, so UK organisations can be caught. ISO/IEC 42001 and the NIST AI RMF offer a practical foundation for preparing.

Source: Regulation (EU) 2024/1689, AI Act (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights