vigil.hr
Home
vigil.hrThe EU AI Act, in plain EnglishRegulation (EU) 2024/1689
Generated Jul 31, 2026

01 What it is

The first comprehensive binding AI law. A risk-based regulation that sorts AI by its impact on people, then sets matching duties. It governs builders (providers) and users (deployers). Employers using AI in the workplace are deployers, and buying a system does not move the duties off you.

In force since 1 August 2024. Directly applicable across the EU and EEA, with no need for national law to repeat it.

02 Who it applies to

It follows the people the AI impacts, not just your headquarters. If your company is based in the EU or EEA, you are in scope. If you sit outside the EU but the AI output affects people in the EU or EEA, you are in scope for those people.

The right question is not where is my company? but are any of the people this AI impacts in the EU or EEA?

03 The four risk tiers

Most workplace AI is high-risk.

Prohibited

Banned outright. Includes emotion recognition in the workplace, social scoring, and certain manipulative or exploitative uses. Live since 2 February 2025.

High-risk

Annex III(4): recruitment and selection, promotion and termination, task allocation, performance monitoring. Allowed with strict deployer duties.

Limited risk

Chatbots, AI-generated content, deepfakes. Transparency duties apply: people must be told they are interacting with AI.

Minimal risk

Spam filters, basic productivity tools. No specific duties under the Act.

Material-influence ruleIf AI ranks, scores, filters, or recommends people, it is in scope even if a human signs off. A rubber-stamp is not a defence.

04 Deployer duties

What the employer has to do.

ArticleDutyWhat it means
Art 4AI literacyStaff who use or are affected by AI need a baseline of training. Live now.
Art 26Human oversightA qualified person must be able to understand, monitor, and override the system.
Art 26Instructions for useFollow the provider's instructions. Use the system only as intended.
Art 26Input-data qualityMake sure the data you feed in is relevant and representative.
Art 26Monitoring and incidentsWatch performance, report serious incidents, keep logs for at least six months.
Art 26Inform workersTell workers and their representatives before a high-risk system is used on them.
Art 86Right to explanationPeople affected by a high-risk AI decision can ask for a meaningful explanation.
Art 27Fundamental rights assessmentMainly for public bodies, but worth knowing.

05 Timeline

Live, coming and contested.

1 Aug 2024
In force
Regulation (EU) 2024/1689 enters into force across the EU and EEA.
2 Feb 2025
Live
Prohibited uses banned, including emotion recognition in the workplace. AI-literacy duty (Art 4) live.
2 Aug 2025
Live
Governance and general-purpose AI rules, mainly for model builders.
2 Aug 2026
Contested
High-risk employment duties originally due. Contested, may move to about 2 Dec 2027 under the provisional Digital Omnibus reform. Until that is published, the original date stands.
2 Aug 2028
Future
Embedded high-risk AI (systems built into regulated products) comes into scope.

06 Penalties

The biggest fines of any AI law to date.

Live
$40M / 7%
of global turnover for prohibited uses. Already in force.
Contested
$17 Mn / 3%
for breaches of high-risk duties, once those duties take effect.
Live
$8.6M / 1%
for supplying incorrect or misleading information to a regulator.

Figures shown in USD, converted from euros at current rates. The Act sets penalties in euros. Lower thresholds apply for SMEs.

07 Other laws to watch

We assess the EU AI Act only. Local employment, privacy and AI laws may also affect your AI use, depending on your jurisdiction.

This tool gives general information, not legal or compliance advice. Refer terms and conditions.

See where your HR AI use sits.

Ten minutes. A quick readiness check to address potential risks