EU AI Act: A Practical Guide
The world's first comprehensive AI regulation — what it covers, who it affects, and what your business needs to do now.

Key Dates
- Aug 2024 — EU AI Act entered into force
- Feb 2025 — Prohibited AI provisions in effect
- Aug 2025 — GPAI model obligations apply
- Aug 2026 — High-risk AI system rules apply
- Aug 2027 — Full application complete
What is the EU AI Act?
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Enacted on 1 August 2024, it establishes rules for AI systems deployed in or affecting the European Union — and applies globally to any business serving EU customers.
Like the GDPR before it, the EU AI Act has extra-territorial reach. Singapore businesses selling AI-powered products or services to EU customers, or using AI to process information about EU residents, must understand and comply with its requirements.
The Act uses a risk-based approach — the higher the potential harm of an AI system, the stricter the requirements. At the top, certain AI applications are banned outright. At the bottom, minimal-risk AI (like spam filters) faces no specific obligations.
⚠ Important for Singapore Businesses
If your business uses AI tools that affect EU residents — even indirectly — you may have EU AI Act obligations. This includes using AI for marketing to EU customers, processing EU employee data, or providing AI-powered services to EU clients.
Penalty Scale
The Four Risk Levels
The EU AI Act classifies AI systems into four risk tiers. Your obligations depend on which tier your AI systems fall into.
Unacceptable Risk — Prohibited
AI applications that pose unacceptable risks to fundamental rights are banned outright.
- Social scoring by public authorities
- Real-time biometric surveillance in public spaces (with limited exceptions)
- Subliminal manipulation targeting vulnerabilities
- AI exploiting children or vulnerable groups
- Emotion recognition in workplaces and educational institutions
High Risk — Strict Requirements
AI systems in sensitive domains must register with EU authorities, meet rigorous technical standards, and undergo conformity assessments before deployment.
- Recruitment and employment (CV screening, performance evaluation)
- Credit scoring and insurance underwriting
- Educational access decisions
- Critical infrastructure (energy, water, transport)
- Law enforcement and judicial decision support
- Medical devices and clinical decision support
Limited Risk — Transparency Obligations
AI systems that interact with users must be transparent about their AI nature.
- Chatbots must disclose they are AI
- Deepfake images and videos must be labelled
- AI-generated content must be identified
Minimal Risk — No Specific Obligations
The vast majority of AI applications fall here and face no EU AI Act specific requirements.
- Spam filters
- AI-powered video games
- Basic recommendation systems
- Inventory management AI
General Purpose AI: What Providers Must Do
If you build or fine-tune General Purpose AI (GPAI) models — including LLMs — the EU AI Act imposes specific obligations regardless of how the model is used.
Technical Documentation
Maintain comprehensive documentation of model architecture, training processes, capabilities, limitations, and evaluation results.
Copyright Compliance
Comply with EU copyright law regarding training data. Publish a sufficiently detailed summary of training data for transparency.
Systemic Risk Assessment
GPAI models trained with >10²⁵ FLOPs are 'systemic risk' models and face additional requirements: adversarial testing, cybersecurity measures, and incident reporting.
Downstream Transparency
Provide downstream providers and users with sufficient information to use the model responsibly and comply with their own EU AI Act obligations.
EU AI Act Compliance with Avernixx
We make EU AI Act compliance practical and manageable — so you can deploy AI confidently without legal exposure.
AI System Inventory & Classification
We audit all your AI systems and classify each against the EU AI Act's risk tiers — giving you a clear picture of your compliance obligations.
Prohibited AI Check
We immediately identify any AI uses that may be prohibited under the Act and advise on remediation or cessation.
High-Risk Compliance Roadmap
For high-risk AI systems, we develop and implement the full compliance package: technical documentation, conformity assessment, registration, and monitoring.
Governance Controls Implementation
We implement the required human oversight mechanisms, data governance controls, transparency measures, and incident response procedures.
IMDA + EU AI Act Dual Alignment
We help you align with both Singapore's IMDA framework and the EU AI Act simultaneously — maximising compliance efficiency.

