EU AI Act: A Practical Guide

The world's first comprehensive AI regulation — what it covers, who it affects, and what your business needs to do now.

EU AI Act — Regulation meets Innovation

Key Dates

  • Aug 2024 — EU AI Act entered into force
  • Feb 2025 — Prohibited AI provisions in effect
  • Aug 2025 — GPAI model obligations apply
  • Aug 2026 — High-risk AI system rules apply
  • Aug 2027 — Full application complete

What is the EU AI Act?

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Enacted on 1 August 2024, it establishes rules for AI systems deployed in or affecting the European Union — and applies globally to any business serving EU customers.

Like the GDPR before it, the EU AI Act has extra-territorial reach. Singapore businesses selling AI-powered products or services to EU customers, or using AI to process information about EU residents, must understand and comply with its requirements.

The Act uses a risk-based approach — the higher the potential harm of an AI system, the stricter the requirements. At the top, certain AI applications are banned outright. At the bottom, minimal-risk AI (like spam filters) faces no specific obligations.

⚠ Important for Singapore Businesses

If your business uses AI tools that affect EU residents — even indirectly — you may have EU AI Act obligations. This includes using AI for marketing to EU customers, processing EU employee data, or providing AI-powered services to EU clients.

Penalty Scale

Prohibited AI
€35M or 7% global turnover
High-Risk violations
€15M or 3% global turnover
Incorrect information
€7.5M or 1.5% global turnover

The Four Risk Levels

The EU AI Act classifies AI systems into four risk tiers. Your obligations depend on which tier your AI systems fall into.

Unacceptable Risk — Prohibited

AI applications that pose unacceptable risks to fundamental rights are banned outright.

  • Social scoring by public authorities
  • Real-time biometric surveillance in public spaces (with limited exceptions)
  • Subliminal manipulation targeting vulnerabilities
  • AI exploiting children or vulnerable groups
  • Emotion recognition in workplaces and educational institutions

High Risk — Strict Requirements

AI systems in sensitive domains must register with EU authorities, meet rigorous technical standards, and undergo conformity assessments before deployment.

  • Recruitment and employment (CV screening, performance evaluation)
  • Credit scoring and insurance underwriting
  • Educational access decisions
  • Critical infrastructure (energy, water, transport)
  • Law enforcement and judicial decision support
  • Medical devices and clinical decision support

Limited Risk — Transparency Obligations

AI systems that interact with users must be transparent about their AI nature.

  • Chatbots must disclose they are AI
  • Deepfake images and videos must be labelled
  • AI-generated content must be identified

Minimal Risk — No Specific Obligations

The vast majority of AI applications fall here and face no EU AI Act specific requirements.

  • Spam filters
  • AI-powered video games
  • Basic recommendation systems
  • Inventory management AI

General Purpose AI: What Providers Must Do

If you build or fine-tune General Purpose AI (GPAI) models — including LLMs — the EU AI Act imposes specific obligations regardless of how the model is used.

1

Technical Documentation

Maintain comprehensive documentation of model architecture, training processes, capabilities, limitations, and evaluation results.

2

Copyright Compliance

Comply with EU copyright law regarding training data. Publish a sufficiently detailed summary of training data for transparency.

3

Systemic Risk Assessment

GPAI models trained with >10²⁵ FLOPs are 'systemic risk' models and face additional requirements: adversarial testing, cybersecurity measures, and incident reporting.

4

Downstream Transparency

Provide downstream providers and users with sufficient information to use the model responsibly and comply with their own EU AI Act obligations.

Does Your AI Stack Need EU AI Act Review?

Avernixx helps Singapore businesses assess their EU AI Act exposure, classify their AI systems, and implement the required governance controls.

Book Free Consultation

EU AI Act Compliance with Avernixx

We make EU AI Act compliance practical and manageable — so you can deploy AI confidently without legal exposure.

🔍

AI System Inventory & Classification

We audit all your AI systems and classify each against the EU AI Act's risk tiers — giving you a clear picture of your compliance obligations.

Prohibited AI Check

We immediately identify any AI uses that may be prohibited under the Act and advise on remediation or cessation.

📋

High-Risk Compliance Roadmap

For high-risk AI systems, we develop and implement the full compliance package: technical documentation, conformity assessment, registration, and monitoring.

🛡

Governance Controls Implementation

We implement the required human oversight mechanisms, data governance controls, transparency measures, and incident response procedures.

🌏

IMDA + EU AI Act Dual Alignment

We help you align with both Singapore's IMDA framework and the EU AI Act simultaneously — maximising compliance efficiency.

Frequently Asked Questions

The EU AI Act entered into force on 1 August 2024. It applies in stages: prohibitions on unacceptable risk AI took effect in February 2025, obligations for General Purpose AI (GPAI) models apply from August 2025, and high-risk AI system requirements apply from August 2026. Full application across all provisions completes in August 2027.
Yes. Like the GDPR, the EU AI Act has extra-territorial reach. If you deploy AI systems that affect EU residents — even from Singapore — you may be subject to the Act's requirements. Any business selling AI-powered products or services to EU customers should assess their obligations.
Penalties are substantial. Prohibited AI applications: up to €35 million or 7% of global annual turnover. High-risk AI system violations: up to €15 million or 3% of global turnover. Incorrect information to regulators: up to €7.5 million or 1.5% of global turnover. SMEs and startups have proportionate limits.
High-risk AI systems are those used in safety-critical or fundamental-rights-sensitive contexts. This includes: AI in recruitment and employment decisions, credit scoring and financial services, educational access decisions, law enforcement, critical infrastructure, medical devices, and border management. High-risk AI systems must register with EU authorities and meet strict requirements.
General Purpose AI (GPAI) models — including large language models (LLMs) — have specific obligations under the Act. Providers of GPAI models must maintain technical documentation, comply with copyright law, and publish training data summaries. GPAI models with 'systemic risk' (trained with over 10^25 FLOPs) face additional requirements including adversarial testing and incident reporting.
Avernixx provides AI governance and compliance services for Singapore businesses with EU exposure. We conduct AI system risk classification, identify compliance gaps, implement required technical and procedural controls, and prepare the documentation needed under the Act. We can also help you align simultaneously with the IMDA framework and other international standards.

Ready to explore how AI fits your business?

In a free 30-minute consultation, you'll get 3 priority AI use cases, clarity on where to start, and a practical next step.

Book Free Consultation