Latest developments in the European Union’s Artificial Intelligence Regulation (AI Act)
We review some of the features of the AI Act Regulation, coinciding with the activation of transparency and regulatory compliance obligations. The EU postpones the high-risk block.
The European Union’s Artificial Intelligence Regulation (AI Act) is the world’s first comprehensive AI law. Established on 1 August 2024, it is entering into force gradually.
Some prohibitions and obligations began to apply in 2025, while on 2 August 2026 new obligations linked to transparency and regulatory compliance were consolidated.
However, the postponement of the activation of the high-risk block, among other factors, confirms that it will still be a few years before the AI Act is fully operative. August 2030 is now emerging as the new date by which the remaining implementations will be completed.
With these updates and the changes to the timetable, we take a look at the main features of this Regulation.
Classification of AI systems
The regulation classifies AI systems into 4 categories, according to the risk they pose:
- Unacceptable.
- High.
- Limited.
- Minimal.
Unacceptable-risk systems (certain uses of biometric categorisation, emotion recognition in certain settings, and behavioural manipulation systems) are prohibited. In the case of real-time biometric surveillance, it may only be used by law enforcement in very specific cases and under strict safeguards.
High-risk systems, meanwhile, will need to meet strict control and safety requirements. Foundation models, such as ChatGPT, will be subject to specific transparency and copyright obligations.
Pioneering regulation
The adoption and rollout of this pioneering regulation redefines the framework for developing and using AI in Europe, while also marking a milestone in global technology governance. Among the most notable measures already in force are:
- The prohibition of certain unacceptable-risk practices.
- The establishment of specific requirements for high-risk systems and general-purpose AI models.
- The imposition of greater obligations on systems with greater potential impact on society and fundamental rights.
- The strengthening of requirements for transparency, oversight and regulatory compliance.
- The creation of dedicated oversight bodies and significant penalties for non-compliance.
Severe penalties
The AI Act introduces one of the most demanding penalty regimes in Europe, with fines ranging from €7.5M (or 1% of turnover) to €35M (or 7% of turnover) for the most serious infringements.
This scale of penalties only reinforces the importance of building regulatory compliance from the earliest stages of developing any AI system.
A compliance strategy for businesses
From now on, it will be essential for companies to have a compliance strategy in place if they want to adapt to the new regulatory requirements. In our case, we are already taking steps to comply with the Regulation, including rolling out training plans related to compliance with legal obligations, as set out in Article 4 of the AI Act.
At Herrero y Asociados (H&A), we don’t just advise you on securing the best protection for your intangible assets. We also support you in complying with the legal framework in every jurisdiction, thanks to our team of experts across multiple areas and our international network of offices.