The EU AI Act: the first broad rulebook for AI (2024)

The European Parliament approved the world's first comprehensive AI law, sorting systems by risk and adding transparency duties for the general-purpose models behind modern chatbots.

On March 13, 2024, the European Parliament approved the AI Act, the first broad, horizontal law aimed at artificial intelligence. After years of drafting, and a late scramble to account for the rise of general-purpose systems like the one behind ChatGPT, the EU set out to regulate not a single application but the technology across the board.

A risk-based approach

The Act’s central idea is to sort AI systems by how much risk they pose and to scale the rules accordingly:

  • Unacceptable risk. A small set of uses is banned outright, for example government social scoring and certain kinds of manipulative or indiscriminate biometric surveillance.
  • High risk. Systems used in areas like hiring, credit, medical devices, or critical infrastructure face strict duties: risk management, documentation, human oversight, and quality controls.
  • Limited risk. Tools like chatbots carry transparency duties, such as telling people they are dealing with a machine or labelling synthetic media.
  • Minimal risk. Most everyday software is left largely untouched.

Rules for general-purpose models

A late and closely watched addition targeted general-purpose AI, the large language models that can be adapted to countless tasks. Providers of these models face transparency obligations, including technical documentation and summaries of training data, with stricter requirements for the most capable systems judged to carry systemic risk.

This was the Act catching up with reality. The framework had been designed before GPT-4, and lawmakers had to add a layer for models that do not fit neatly into a single “use case.”

Why it matters

The AI Act pushes the abstract goals of AI safety and alignment toward something concrete: legally required guardrails, documentation, and oversight, phased in over the following years. Because it applies to anyone offering AI in the EU market, its reach extends well beyond Europe, much as earlier EU data rules shaped global practice.

Supporters see a template for accountable AI; critics warn about compliance costs and the risk of freezing fast-moving technology into slow-moving law. Either way, 2024 is when “how should AI be governed?” stopped being a purely academic question and became binding rules.

#regulation #guardrails