EU AI Act (EU Artificial Intelligence Act)

The EU AI Act (EU Artificial Intelligence Act) is a comprehensive European Union regulation that establishes legal obligations based on the risk level of AI systems. It classifies AI into four tiers — "unacceptable risk," "high risk," "limited risk," and "minimal risk" — imposing stricter requirements as the risk level increases.
The World's First Comprehensive AI Regulation
The EU AI Act was established as the world's first comprehensive legal framework targeting AI. Just as the GDPR effectively set the international standard for data protection, the "Brussels Effect"—whereby the EU proactively shapes global standards—is anticipated to extend to the domain of AI regulation as well.
The regulation applies to businesses that provide or use AI systems within the EU. Even companies based outside the EU are subject to it if the outputs of their AI affect EU citizens. Companies in Japan or Thailand that provide services to the EU cannot treat this as someone else's concern.
The Risk Classification Framework
A four-tier risk classification forms the backbone of the regulation.
AI systems categorized as posing "unacceptable risk" are prohibited in principle. Social scoring (systems that assign scores to citizens based on their behavior) and real-time facial recognition in public spaces fall into this category.
"High-risk" AI covers systems used in areas that directly affect people's rights or safety, such as recruitment screening, credit assessment, and medical devices. Obligations include maintaining technical documentation, ensuring data governance, and establishing human oversight mechanisms.
Providers of general-purpose AI models (such as GPT and Claude) are subject to separate transparency obligations, including disclosure of an overview of training data, compliance with copyright law, and publication of technical documentation.
Relationship with Other Regulations
In the context of AI governance, the EU AI Act is not the only regulation to consider. Thailand's PDPA regulates AI input and output data from a data protection perspective, while Japan's AI Business Guidelines function as soft law, encouraging voluntary efforts by businesses.
In practice, rather than addressing each of these regulations in isolation, companies are better served by building an integrated AI governance framework and taking an approach that maps the requirements of each regulation accordingly.
Articles covering this term
- What is AI Governance? A Practical Guide from EU AI Act Compliance to Internal Policy DevelopmentLearn AI governance essentials: EU AI Act overview, risk classification, internal guidelines, and audit frameworks—key insights for practitioners navigating full-scale AI adoption.
- AI Governance for Small Teams: Scalable AI Governance for Small and Medium-Sized BusinessesLightweight AI governance frameworks & checklists for SMEs and startups to practically adopt enterprise-grade AI standards—even with limited resources.
- What Is an AI-Native Management Strategy? How to Fundamentally Redesign Your Business ModelFrom "adding AI" to "redesigning with AI." Learn AI-native management transition steps, ERP/FMS integration strategies, and real-world examples from Thai and Japanese companies.
- Claude Mythos and Project Glasswing — How Companies Should Prepare for the Era When AI Uncovers Long-Dormant BugsAnthropic's Claude Mythos Preview & Project Glasswing redefine AI-driven vulnerability discovery. From OpenBSD's 27-yr bug to FreeBSD CVE-2026-4747—5 DevSecOps actions you can take now.
Related Terms

Deepfake
Deepfake is a technology that uses deep learning to realistically manipulate and synthesize a person

Mesh VPN (Mesh VPN)
Mesh VPN is a VPN architecture in which each node communicates directly with encrypted connections w

Shadow AI
Shadow AI refers to the collective term for AI tools and services used by employees in their work wi

Zero Trust Network Access (ZTNA)
Zero Trust Network Access is a security model that continuously verifies users and devices, controll



