The EU AI Act Takes Effect: What Enterprise Leaders Must Know Now

The Regulation That Changes Everything

On February 2, 2025, the first provisions of the European Union's Artificial Intelligence Act became enforceable, marking the beginning of a new regulatory era for AI globally. The initial enforcement phase targets AI systems classified as presenting "unacceptable risk" -- including social scoring systems, real-time biometric surveillance in public spaces with limited exceptions, and manipulative AI designed to exploit vulnerabilities.

While this first wave focuses on outright bans, the timeline ahead is what enterprise leaders need to plan for now.

Key Compliance Milestones

The EU AI Act rolls out in phases:

- February 2025: Prohibited AI practices become enforceable. Organizations must discontinue banned systems. - August 2025: Transparency requirements for general-purpose AI GPAI models take effect. Companies deploying models like GPT-4 or Claude must comply with disclosure and documentation obligations. - August 2026: Core obligations for high-risk AI systems become applicable, including requirements around data governance, risk management, human oversight, and technical documentation. - August 2027: Full enforcement of all remaining provisions, including those for AI systems embedded in regulated products.

What Counts as High-Risk

The Act classifies AI systems used in critical areas as "high-risk," requiring extensive compliance measures:

- Employment and recruitment: AI screening candidates, evaluating performance, or making termination decisions - Credit scoring and financial services: Automated lending decisions, insurance underwriting - Healthcare: AI used in clinical decision-making, diagnostic support - Law enforcement: Predictive policing, evidence analysis - Education: Automated grading, admissions decisions

For each of these categories, organizations must implement risk management systems, maintain technical documentation, ensure data quality, enable human oversight, and achieve appropriate levels of accuracy and robustness.

The Global Ripple Effect

Much like GDPR reshaped global data privacy standards, the EU AI Act is already influencing AI governance worldwide. Companies outside the EU that deploy AI systems affecting EU residents must comply. This extraterritorial reach means American, Australian, and Asian businesses serving European markets need to assess their AI portfolios immediately.

Canada's proposed Artificial Intelligence and Data Act AIDA, Japan's evolving AI governance framework, and even discussions within the US about federal AI legislation all reference the EU's risk-based approach as a benchmark.

What Enterprises Should Do Right Now

1. Audit your AI inventory. Map every AI system in use across the organization -- from chatbots to automated decision-making tools. Classify each according to the EU AI Act's risk categories.

2. Assess your supply chain. If you use third-party AI tools including embedded AI in SaaS platforms, determine whether those vendors have