AI Act
AI Act (EU Regulation 2024/1689)
The first comprehensive EU regulation governing the development, deployment and use of artificial intelligence — a risk-based approach with four levels.
What is the AI Act?
The AI Act (EU Regulation 2024/1689) is the world’s first comprehensive legislative framework governing the development, provision and use of artificial intelligence systems. Adopted in July 2024, it enters into force progressively during 2025–2026, becoming fully applicable from 2 August 2026.
The AI Act divides AI systems into four risk categories:
- Unacceptable risk (prohibited, effective from 2 February 2025) — e.g. social scoring, manipulative techniques, biometric identification in public spaces with limited exceptions
- High risk — AI used in HR, credit assessment, healthcare, critical infrastructure, law enforcement. Subject to strict obligations: risk analysis, data governance, logging, human oversight, technical documentation
- Limited risk — chatbots, deepfakes. Transparency obligation (informing users they are interacting with AI)
- Minimal risk — the majority of AI (e.g. spam filters, gaming AI). No additional obligations
For GPAI (General Purpose AI) models such as GPT-5 or Claude, special rules apply from 2 August 2025 — documentation, copyright compliance, and for the most powerful models, systematic risk assessments.
Fines: up to 35,000 €,000 or 7% of global turnover for prohibited practices.
When it applies
The AI Act concerns:
- AI system providers (developers)
- Deployers — companies using AI within the EU
- Importers and distributors of AI systems from third countries
See the AI page and the Security page.
Related terms
- GDPR — complementary regulation where the AI Act connects for AI systems processing personal data. See /en/glossary/gdpr.
- ISO 27001 — supports documentation of security measures. See /en/glossary/iso-27001.
- AI Agent — a specific form of AI system under the AI Act. See /en/glossary/ai-agent.
In Modulario
As a SaaS platform provider with AI capabilities, Modulario complies with the AI Act — transparently declaring when users interact with AI, maintaining documentation of AI components, and providing audit logs. Details on AI governance are available at /ai.
For customers in segments covered by the AI Act’s “high risk” category (HR, finance), Modulario provides extended documentation of the AI components used — description of training data, evaluation metrics, use limitations, and an incident reporting mechanism.
Related terms
GDPR
The EU regulation on personal data protection in force since 25 May 2018 — defines the rights of data subjects and the obligations of controllers.
ISO/IEC 27001
The international standard for an Information Security Management System (ISMS) — certification that demonstrates an organisation's maturity in IT security.
AI Agent
A software system built on an LLM that autonomously resolves tasks — planning steps, using tools and calling APIs to achieve a given goal.
RAG
A technique that extends an LLM with dynamic search across company documents — the answer is generated by combining retrieved context with a generative model.
RBAC
An authorisation model in which permissions are assigned through roles rather than to individual users — simpler management and auditability.
Implementing AI Act in your company?
Modulario covers most B2B processes modularly — deploy only what you need now and grow gradually. Book a free consultation.
Book a consultation