03.06.2025
Blog
Europe
Data & AI

What is the EU AI Act? – An overview of the European AI Act

Whether it is machine translation, chatbots in customer service or AI-powered decision support – the potential applications of artificial intelligence (AI) are wide-ranging. At the same time, this raises ethical, security-related and legal issues.

 

Stefan Reinke
Content Editor

The Artificial Intelligence Act (EU AI Act) establishes a Europe-wide legal framework for the use of AI. By categorising AI according to risk levels, it adopts a differentiated approach, enabling innovation whilst safeguarding fundamental rights. For many organisations, however, it represents a new regulatory requirement, the implementation of which should be prepared well in advance. 

Objectives of the EU AI Act 

The EU AI Act aims to promote the safe and trustworthy use of AI and classifies AI applications into different categories depending on their potential risk to people and fundamental rights. The regulatory requirements vary accordingly. 

Four risk classes for AI systems 

  1. Unacceptable risk: AI systems classified as particularly dangerous – such as social scoring by government bodies or manipulative behaviour control – are to be prohibited in principle.
  2. High risk: Applications used in areas relevant to security or fundamental rights are subject to strict requirements. These include, amongst others, AI systems in critical infrastructure, education and healthcare, in recruitment, or in tasks carried out by security authorities. For these systems, provisions include a risk assessment, technical documentation and transparency requirements.
  3. Limited risk: This category includes, for example, chatbots, which must be clearly identifiable so that users know they are interacting with a machine. Certain information requirements also apply to this category.
  4. Minimal risk: Applications posing little or no risk – such as AI-powered spam filters or AI in video games – may be used without any specific requirements.

Scope and application of the EU AI Act

The AI Act applies to all providers, operators and users of AI systems within the EU – regardless of whether they are based in the EU. The decisive factor is whether the systems are placed on the market or used within the EU. The regulation therefore also has extraterritorial effect, similar to the General Data Protection Regulation (GDPR). 

In Germany, two authorities are responsible for ensuring compliance with EU requirements: BaFin is responsible for the financial sector, whilst the Federal Network Agency oversees all other sectors. 

Implications for businesses and public bodies 

For businesses and public authorities, the EU AI Act means that AI projects will need to be more thoroughly documented and technically safeguarded in future. This applies in particular to high-risk systems and concerns, amongst other things, the development, training and operation of relevant AI solutions. 

EU AI Act comes into force in stages 

Although the EU AI Act came into force on 1 August 2024, its provisions will be phased in gradually until 2027. This phased approach is intended to enable businesses, public authorities and other stakeholders to adapt to the new requirements step by step. 

An overview of the phases 

  1. August 2024: The EU AI Act comes into force.
  2. February 2025: Bans on AI systems posing an unacceptable risk (Article 5). These include, for example, social scoring, manipulative behaviour control and certain forms of biometric surveillance.
  3. August 2025: Further provisions come into force. By this date, for example, Member States must have defined the responsibilities of their authorities and established penalties for infringements. Providers of general-purpose AI models, such as ChatGPT, must now comply with certain information requirements and security standards. Stricter requirements apply to particularly powerful models, for example with regard to cyber security, risk analyses or testing. In addition, Member States must designate the competent national authorities by this date and notify the European Commission thereof.
  4. August 2026: Two years after the Act enters into force, the remaining provisions of the AI Act will apply, with the exception of Article 6(1). This applies in particular to requirements for AI systems posing limited and low risks.
  5. August 2027: Three years after the Act enters into force, Article 6(1) will take effect; this relates to high-risk AI systems that serve as a safety-critical component of a product or are listed in Annex I to the Regulation. From this date, the AI Act will be deemed to be in full force and effect.

 For further information and the latest developments, it is advisable to check the official website on the EU AI Act regularly. 

Stefan Reinke
Content Editor

Stefan Reinke works as a content editor in the corporate communications department at Materna. His main areas of focus are energy, insurance and AI.

Related articles

Event
Data & AI
Versicherungen
Köln
05.10.2026 - 06.10.2026
AI in Insurance 2026

Generative AI has long since become a reality. Now, the focus is shifting to intelligent AI agents that support processes, prepare decisions, and unlock new efficiency potential. The 2026 AI in Insurance Conference will focus on practical…

Read more
Short News
Data & AI
28.08.2026
Corporate Twins: Why leadership needs a flight simulator

In management, wrong decisions can cause considerable damage: to staff, customers, supply chains, the company itself or the environment. However, the consequences are often not immediately apparent. They may be masked by a decline in quarterly…

Read more
Short News
Resilience
Data & AI
28.08.2026
Physical AI Cities: When cities begin to act

A look at Physical AI Cities highlights the potential inherent in an infrastructure that adapts dynamically to new situations – and why it cannot be justified without governance, resilience and democratic control.

Read more
Short News
Resilience
Data & AI
Transport und Logistik
Public Sector
Healthcare
Finanzverwaltung und Zoll
Energy & Utilities
28.08.2026
AI agents: If you automate chaos, you get chaos in real time

On the potential that Agentic AI offers for more productive organisations – and how quickly a lack of governance, unclear processes and overly broad permissions can become a risk.

Read more
Short News
Europe
Sustainability
Data & AI
28.08.2026
Green AI is not a romantic notion

Anyone wishing to operate AI in a sustainable, autonomous and responsible manner must take a holistic view of computing power, energy, governance, cybersecurity and resilience.

Read more
Blog
Data & AI
18.08.2026
From Key Figures to Decisions: The Next Stage in the Evolution of Information Sharing within Organisations

Companies today measure almost everything. Capacity utilisation, project metrics, turnover, margins and forecasts are available at any time in…

Read more
Press
Corporate
Data & AI
Public Sector
Dortmund
17.06.2026
SPARK, the AI for public authorities: Materna group helps public authorities speed up approval processes

With the launch of SPARK Workflow, public authorities now have access to a centralised AI-powered tool to process planning and approval procedures more quickly. As a member of the consortium responsible for the project, the Materna Group is…

Read more
Blog
Data & AI
10.06.2026
SmartLivingNEXT – How a data space brings together housing, care and energy

SmartLivingNEXT brings together homes, neighbourhoods and services. This benefits residents, care providers, energy suppliers and landlords.…

Read more
Blog
Data & AI
Versicherungen
16.04.2026
Maternas Fraud Shield: Secure claims reporting across all channels

Imagine this: a policyholder reports a claim quickly and easily via their trusted app. Seconds later, the claim has been recorded, the fraud check…

Read more
Blog
Data & AI
07.04.2026
97% reduction in workload: How AI is revolutionising line safety for transmission system operators

A real-world example illustrates what is possible when the underlying data is sound – and why human input remains indispensable nonetheless.

Read more