IA 360
Regulatory Framework

European Parliament passes AI Act: what changes and when

The European Parliament approved the AI Act on 13 March 2024. The useful way to read it is to separate the vote, entry into force and application, then classify each system by use, context and the organisation's role.

6 min read AI-generated Leer en español
European Parliament passes AI Act: what changes and when

On Wednesday, 13 March 2024, the European Parliament approved the European Union's Artificial Intelligence Act. The official vote was 523 in favour, 46 against and 49 abstentions. That did not switch on one universal list of obligations overnight: Parliament had completed its legislative stage, while legal-linguistic review, formal adoption by the Council and publication in the Official Journal still lay ahead.

That distinction matters more than any summary of bans. To find out what changes for a company, public authority or individual, asking whether it uses ChatGPT, a camera or a hiring algorithm is not enough. Three questions come first: what the system is used for, the context in which it makes or influences decisions, and the role each organisation occupies in the chain. A model's brand rarely settles the classification on its own.

Three clocks, not one date

European legislation has at least three clocks. The first is the legislative procedure: political agreement, the parliamentary vote and Council adoption. The second is entry into force, when the published text becomes law in force. The third is application: the date on which a particular obligation must be followed. Saying that a law has entered into force does not necessarily mean that all its duties apply today.

On 13 March 2024, only what Parliament had approved could be reported with certainty. Parliament's own notice said that legal-linguistic checks and formal Council adoption were still required. The subsequent sequence must be presented as later information: the final text became Regulation (EU) 2024/1689, was adopted on 13 June 2024, published on 12 July and entered into force on 1 August 2024.

The transferable skill is to find the provision on entry into force and application every time, then check whether an amendment followed. A press-release timeline may be accurate on publication day and become outdated. For an operational decision, the current and consolidated legal text governs, not an infographic saved two years earlier.

Risk belongs to the use, not the model name

The AI Act follows a risk-based approach, but risk is not a universal label attached to a technology. An assistant that proposes advertising copy does not occupy the same position as a system intended to rank job applicants. Even when both incorporate the same general-purpose model, their purpose, the people affected and the consequence of their outputs differ.

The Commission's AI Act guidance explains that high-risk classification depends on intended purpose, function and the specific conditions of use. There are two broad routes: systems that serve as safety components in products covered by the legislation listed in Annex I, and uses listed in Annex III, including certain applications in education, employment, essential services, law enforcement or migration.

This avoids two opposite mistakes. One is assuming that every use of AI in a hospital, school or company is automatically high-risk. The other is treating a product sold as an “assistant” as exempt because of its commercial label when it actually scores applications, recommends a sensitive decision or operates as a safety component. The right question is what the system does, for whom, with which output and consequence.

Four baskets for a first reading

As an initial map—not a substitute for legal analysis—each use can be placed in one of four baskets. The first contains prohibited practices, including certain forms of social scoring, harmful manipulation, exploitation of vulnerabilities, sensitive biometric categorisation and untargeted scraping of facial images to build recognition databases. Some exceptions and conditions are narrow, especially for police biometric identification, so a summary sentence never replaces the relevant provision.

The second basket contains high-risk systems. They are not banned, but they require controls before and during use. For providers, the Regulation sets out risk management, data governance, technical documentation, event logging, instructions, human oversight, accuracy, robustness and cybersecurity. A conformity assessment is not a permanent certificate: a substantial modification to the system or its purpose may require a new assessment.

The third basket is transparency. Certain interactive systems must tell people they are dealing with a machine, and some generated or manipulated content must be marked or disclosed. The specific duty depends on who generates or publishes the material, its type and the exceptions. Adding a generic “made with AI” label to every workflow may be inadequate in one case and unnecessary in another.

The fourth basket covers limited- or minimal-risk uses. A case that is not high-risk under this Regulation does not enter a legal vacuum. The General Data Protection Regulation, employment law, consumer protection, intellectual-property rules, product safety and contracts may still apply. “Not high-risk” is a narrow conclusion, not a general permission.

Each actor's role changes the obligation

After the use comes the role. A provider develops a system or model and places it on the market under its name; a deployer uses it under its authority; importers, distributors and product manufacturers may also be involved. The same business can be a deployer in one process and a provider in another if it meaningfully modifies or rebrands a system.

The distinction has operational consequences. A high-risk system provider must design and document conformity controls. Its deployer must follow the instructions, assign competent human oversight, monitor operation and respond to risks or incidents. Certain public-authority and public-service uses may also require a fundamental-rights impact assessment; workplace deployments carry information duties towards workers and their representatives.

General-purpose AI models add another layer. Their providers must prepare documentation and give downstream system builders relevant information, maintain a policy for complying with EU copyright law and publish a summary about training content. Models with systemic risk face additional obligations. Yet buying access to such a model does not transfer every responsibility for the final system to its maker: an organisation that uses it to assess pupils or filter applicants must examine that specific use.

The minimum inventory that makes compliance testable

Before writing a fifty-page policy, an organisation needs an inventory that answers seven questions for each system: who provides it; who decides how it is used; what its intended purpose is; what data enter; what output it produces; who may be affected; and what decision a human makes next. The model version, integrations and changes of purpose should also be recorded. Without that record there is no stable unit to classify.

Next comes the evidence file. For a sensitive use, it should gather the provider's instructions, risk assessment, data provenance and suitability, known tests and limits, logs, oversight owners, the human-review procedure, post-deployment monitoring and incident escalation. The goal is not to pile up documents, but to reconstruct why a system was authorised and how the organisation will notice that it no longer behaves as expected.

Human oversight exists only when a person can understand the output, challenge it and stop or correct the process. A nominal approval button clicked by habit is not a real safeguard. Organisations should define in advance what signals trigger review, which cases cannot be automated, how long logs are retained and who can suspend the system.

What changed later and how to read the timetable now

With later dates stated explicitly, the timetable became staggered. The prohibitions, definitions and AI-literacy provisions have applied since 2 February 2025; governance rules and duties for general-purpose model providers have applied since 2 August 2025. Much of the Regulation has a general application date of 2 August 2026.

The timetable changed again before that date. The Commission reported that the AI Omnibus entered into force on 27 July 2026: rules for Annex III high-risk systems move to 2 December 2027, while rules for AI embedded in Annex I products move to 2 August 2028. This update demonstrates why the third clock must be checked immediately before a decision instead of recalled from memory.

A longer deadline does not make a system harmless or suspend other legislation. Waiting until the eve of application can also be poor management if the organisation then discovers that it lacks an inventory, provider documentation or meaningful oversight. Useful preparation begins with classification and evidence; concrete measures are then scheduled against the law in force.

The AI Act is not understood by memorising a list of forbidden tools. It is understood through a method: separate the vote, entry into force and application; describe the real system; classify its purpose and context; identify every actor's role; and connect each duty to testable evidence. That method will remain useful when models, brands and—as has already happened—deadlines change.

This article was produced with artificial intelligence under human editorial oversight.

Share this article

This website uses cookies to improve the browsing experience. Cookie policy.

↑↓ navigate ↵ open esc close