EU AI Act for Generative AI: Risk Classes & Obligations Explained

EU AI Act for Generative AI: Risk Classes & Obligations Explained

You built a cool Generative AI tool. Maybe it writes emails, generates code, or creates images. You’re ready to sell it in Europe. Then you hit a wall called the EU AI Act. It’s not just red tape; it’s the first comprehensive law of its kind globally, and it treats your model differently than a standard app. If you ignore it, you could face fines up to €35 million. If you get it right, you gain a trust badge that competitors without it can’t claim.

The Act doesn’t ban AI. It sorts it. Think of it like airport security: some items go straight through (minimal risk), some need extra screening (high risk), and some are banned outright (unacceptable risk). Your generative AI likely falls into the middle buckets, specifically under the General-Purpose AI (GPAI) category. This article breaks down exactly where you stand, what you must do by August 2026, and how to keep your users happy while staying legal.

The Four-Tier Risk Pyramid

To understand your obligations, you need to see the big picture. The EU regulators didn’t want to crush innovation with one-size-fits-all rules. They created a pyramid based on potential harm. Here is how it works:

  • Unacceptable Risk (Banned): These are practices deemed too dangerous for human rights. Examples include social scoring by governments or real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions). These bans started applying in February 2025.
  • High Risk: AI used in critical areas like hiring, credit scoring, education, or medical devices. These systems require rigorous testing, data governance, and human oversight. Full compliance deadlines are rolling out through 2026 and 2027.
  • Limited Risk (Transparency Focus): This is where most chatbots and content generators land. The main rule? Tell users they are interacting with AI. No deception allowed.
  • Minimal Risk: Spam filters, video game AI, or inventory management tools. These have no specific regulatory obligations under the Act.

Most generative AI applications fall into the Limited Risk tier. However, the underlying models that power them-like Llama, GPT, or Claude-are treated as General-Purpose AI (GPAI) models. This distinction is crucial because the obligations attach to the model provider, not just the app developer.

Who Counts as a GPAI Provider?

If you train a large foundation model, you are a GPAI provider. If you fine-tune an existing open-source model and deploy it, you might be considered a downstream user, but if you modify it significantly, you could assume provider responsibilities. The Act defines GPAI models as adaptable building blocks that can perform a wide range of tasks. Because these models ripple across countless use cases, the regulation applies upstream. This means the company training the base model bears the heavy lifting on documentation and copyright checks.

As of August 2, 2025, governance rules for GPAI providers became applicable. If you are launching a new model now, you are already subject to these rules. The European Commission published the General-Purpose AI Code of Practice in July 2025 to help providers demonstrate compliance. Following this code is the safest path to avoiding disputes with regulators.

Core Obligations for Generative AI Providers

So, what do you actually have to do? The requirements focus on transparency, copyright, and safety. Here is the checklist for any GPAI provider operating in the EU market:

  1. Technical Documentation: You must maintain a "black-box" dossier. This isn’t public, but regulators can request it. It shows exactly how the model was built, tested, and validated. If something goes wrong, this dossier is your defense.
  2. Copyright Compliance Policy: You must prove you respect EU copyright laws. This involves having policies in place to handle text and data mining opt-outs. If a publisher says "no," your crawler should listen.
  3. Public Summary of Training Data: You must publish a concise summary of the copyrighted material used to train your model. Use the templates provided by the Commission. This prevents black-box opacity regarding where your knowledge comes from.
  4. Model Cards: Provide customers with a compact document specifying what the model does, its limitations, and intended uses. This helps downstream developers make informed decisions about deployment.
  5. Incident Reporting: For high-impact models, you must report serious incidents to the European Commission. If your model starts hallucinating facts in a way that causes significant harm, you need to flag it.

These obligations shift accountability. Previously, AI developers kept training data sources proprietary. Now, transparency is mandatory. This protects creators whose work may have been used for training without explicit permission.

Abstract geometric representation of GPAI provider compliance obligations

Transparency Rules for Users

Beyond the model provider, there are rules for the application layer. Article 50 of the AI Act mandates that users must know when they are interacting with AI. This is critical for preventing deception.

If your product is a chatbot, you must clearly label it as such. If your tool generates deepfakes (synthetic audio, video, or image content), you must disclose that the content is artificially generated. This requirement kicks in fully in August 2026. For text published to inform the public on matters of public interest, similar disclosure rules apply.

Comparison of AI Risk Categories and Key Obligations
Risk Category Examples Key Obligations Enforcement Date
Unacceptable Social scoring, manipulative techniques Prohibited entirely Feb 2025
High Risk Hiring tools, medical diagnostics Risk management, data quality, human oversight Aug 2026 - Aug 2027
Limited Risk Chatbots, image generators Transparency disclosures (Article 50) Aug 2026
GPAI Models LLMs, foundation models Copyright policy, training data summary, model cards Aug 2025 (Rules), Aug 2026 (Fines)

The Copyright Minefield

This is the trickiest part for many startups. The EU has strict copyright laws. The AI Act requires GPAI providers to implement measures to comply with these laws. In practice, this means you need a robust system to respect "robots.txt" style opt-outs from websites. If a news site blocks crawlers, you shouldn’t be using their articles for training unless you have a license.

You don’t necessarily need to pay every single creator upfront, but you must show you have a policy to respect rights. The European Parliament resolution on copyright and generative AI, adopted in March 2026, emphasizes balancing innovation with creator compensation. Expect more scrutiny here. Keeping records of your data scraping activities is non-negotiable. If a lawsuit hits, your ability to prove you respected opt-outs will determine your liability.

Stylized human and AI figures interacting with a transparency disclosure symbol

Penalties and Enforcement

Don’t let the phased rollout fool you into complacency. Penalties for non-compliance entered into force on August 2, 2025, though fines for GPAI providers specifically began on August 2, 2026. The numbers are steep:

  • Prohibited Practices: Up to €35 million or 7% of global annual turnover.
  • Other Violations: Up to €15 million or 3% of global annual turnover.

For a startup, 3% of global turnover might seem manageable until you realize it applies even if your revenue is small, because the minimum floor can still hurt. More importantly, reputational damage from being flagged as non-compliant can scare off enterprise clients who prioritize vendor risk management.

Member States are required to establish at least one AI Regulatory Sandbox by August 2, 2026. These sandboxes allow companies to test AI technologies in controlled environments with regulatory guidance. If you are unsure about your compliance status, applying to a sandbox is a smart move. It provides a safe harbor while you refine your processes.

What Should You Do Right Now?

If you are building generative AI products for the EU market, here is your action plan:

  1. Audit Your Model Source: Are you training from scratch or using an open-source model? If you use an open-source model, check if the original provider has met GPAI obligations. If you fine-tune heavily, assess if you’ve become a provider yourself.
  2. Draft Your Transparency Labels: Ensure your UI clearly states "AI Generated" or "You are chatting with a bot." Don’t hide this in the terms of service.
  3. Create Your Model Card: Write a simple document detailing capabilities, limitations, and intended use cases. Make it accessible to your API consumers.
  4. Review Your Data Pipeline: Can you trace your training data back to its source? Do you have a mechanism to exclude opted-out content? Document this process.
  5. Monitor National Guidelines: Each EU country may have slight variations in enforcement. Keep an eye on local AI offices.

The EU AI Act isn’t going away. It sets a global standard, much like GDPR did for privacy. Companies that adapt early will find it easier to expand into other jurisdictions that often mimic EU regulations. Waiting until the last minute creates unnecessary panic and potential fines.

Does the EU AI Act apply to US-based AI companies?

Yes. The Act has extraterritorial reach. If your AI system places outputs on the EU market or affects people within the EU, you are subject to the regulation, regardless of where your headquarters are located.

Are open-source models exempt from all obligations?

Not entirely. Open-source models are exempt from some technical documentation requirements, but they still must comply with copyright policies and transparency rules. Additionally, if the model poses systemic risks, full obligations apply even to open-source providers.

When do the transparency labels become mandatory?

The transparency requirements under Article 50, which mandate disclosing AI interactions and synthetic content, come into effect in August 2026. You should prepare your UI changes well before this date.

What happens if I fail to provide a training data summary?

Failure to publish a public summary of training data is a violation of GPAI obligations. This can result in administrative fines of up to €15 million or 3% of global turnover. Regulators view this as a key transparency measure for copyright protection.

Do I need to hire a lawyer to comply?

While not legally required, consulting with legal experts specializing in EU tech law is highly recommended. The definitions of "provider" and "deployer" can be complex, and misclassification can lead to significant penalties. Many firms now offer specialized AI compliance audits.

Write a comment

*

*

*