In brief
The AI Act is the European Union's regulation on artificial intelligence. It classifies AI systems by level of risk, from unacceptable risk, which is banned, down to minimal risk, and imposes obligations that rise with that level. Its reach extends beyond the European Union: an organization based here falls under it as soon as its system is used on European territory. identifiable aligns practices; legal interpretation belongs to legal counsel.
What is the EU AI Act?
Published · Last updated · Wissam Daibess
The European regulation on artificial intelligence, Regulation (EU) 2024/1689, entered into force on 1 August 2024. Its application unfolds in phases: prohibited practices first, then obligations for general-purpose AI models, then the bulk of requirements for high-risk systems.
Its reach is extraterritorial: a Quebec business whose AI system is placed on the European market, or whose outputs are used within the Union, falls within its scope. Distance is not protection.
Its logic is simple: the higher the risk of a system, the heavier the obligations. Most ordinary business uses sit in the lower levels, with reasonable transparency obligations.
Since
In force since August 2024, application rolling out in phases through 2026 and beyond.
Penalties
Up to 35 M euro or 7% of worldwide revenue for prohibited practices.
For whom
Providers and deployers of AI systems affecting the European market, wherever they are established.
What are the four EU AI Act risk levels?
| Level | Examples | Regime |
|---|---|---|
| Unacceptable | Social scoring, manipulation exploiting vulnerability | Prohibited in the Union. |
| High risk | Resume screening, credit access, medical devices | Heavy requirements: risk management, data governance, human oversight, documentation, registration. |
| Limited risk | Chatbots, generated or manipulated content | Transparency: the person must know they are interacting with AI or viewing generated content. |
| Minimal risk | Spam filters, AI in games, most internal uses | No new obligations; best practices are still recommended. |
General-purpose AI (GPAI) models have their own transparency and documentation regime. In the iDIA framework, the AI Act weighs most heavily on the Supervised, Secure, and Accountable properties.
How identifiable gets you ready
identifiable assesses your uses and policies against the AI Act: training, classification of your systems by risk level, and attestation of your trajectory.
Related reading
Quebec
Law 25
The Quebec obligations that reach your AI use.
Standard
ISO/IEC 42001
The certifiable AI management system standard.
Method
The iDIA framework
Six properties scored on evidence, weighted from the four frameworks.
Diagnostic
The AI Index
Place your posture in twelve questions, free.
Hub
AI governance in Quebec
The four frameworks, and which ones actually oblige.
Three questions that keep coming up
I do not sell in Europe. Am I safe?
For now, legally, yes. But the AI Act is becoming the de-facto global reference, just as the GDPR was before it, and your exporting clients will inherit its requirements and pass them on to you.
Is my chatbot high risk?
Rarely. A customer service assistant generally falls under limited risk: the main thing is that the person knows they are talking to an AI. High risk targets specific domains like employment, credit, or health.
What to do first, from Quebec?
Classify your systems by risk level and document your uses. That is the same inventory that Law 25 and the NIST AI RMF ask for: one piece of work, three frameworks served.
What are you going to do with your AI?
The diagnostic locates your practices against the four frameworks, including the AI Act. Twelve questions for a first map.