You built a chatbot. It writes emails, summarizes reports, maybe even generates code. You think you're safe because it's just text, right? Wrong. If your users are in Europe, the EU AI Act is already knocking on your door. And it doesn't care that your model is "just" a language model. It cares about what that model does to people.
The EU AI Act isn't some distant future law. It entered into force in August 2024, and key parts are already live. For generative AI providers, this means specific rules kicked in as of August 2025. If you're shipping AI products to the EU market, you need to know where you stand. This guide breaks down exactly how the Act classifies generative AI, what obligations you face, and what happens if you ignore it.
The Four-Tier Risk Framework: Where Does GenAI Fit?
The EU AI Act uses a risk-based approach. It doesn't ban all AI or regulate everything equally. Instead, it sorts AI systems into four categories based on how much harm they could cause. Think of it like food safety labels: some things are toxic (banned), some need strict handling (high-risk), some just need clear labeling (limited-risk), and others are basically fine (minimal-risk).
| Risk Tier | Description | Examples | Status |
|---|---|---|---|
| Unacceptable Risk | Banned outright due to fundamental rights violations. | Social scoring by governments; real-time remote biometric ID in public spaces (with exceptions). | Banned since Feb 2025 |
| High Risk | Strict compliance required before market entry. | CV screening tools; credit scoring; medical device AI. | Phased implementation through 2027-2028 |
| Limited Risk | Transparency obligations only. | Chatbots, Generative AI models, deepfakes. | GPAI rules active since Aug 2025; transparency rules Aug 2026 |
| Minimal Risk | No specific obligations. | Spam filters; video game AI. | Voluntary codes of conduct encouraged |
Most generative AI falls into the Limited Risk category. But here's the twist: if your generative model is used in a high-risk context-say, an LLM helps diagnose patients-the application might be high-risk even if the underlying model is general-purpose. The Act distinguishes between the model and the system. A foundation model like GPT-4 is a General-Purpose AI (GPAI). An app using GPT-4 to screen job candidates is a high-risk system.
General-Purpose AI (GPAI): The New Regulatory Category
The EU didn't have a box for large language models when it started drafting the law. So it created one. General-Purpose AI (GPAI) is a type of AI model trained on broad data that can be adapted to perform a wide variety of tasks. Think of it as a Swiss Army knife versus a scalpel. A scalpel (task-specific AI) has one job. A Swiss Army knife (GPAI) can do many jobs, so regulators treat it differently.
As of August 2, 2025, GPAI providers must comply with specific obligations. These aren't optional. They apply to anyone placing a GPAI model on the EU market, regardless of where the company is headquartered. If you serve European customers, you're in scope.
- Technical Documentation: You must maintain a "black-box" dossier showing how the model was built, tested, and validated. Regulators can ask for this.
- Copyright Compliance: You need policies ensuring training data respects EU copyright laws. This includes licenses, opt-outs, or attribution mechanisms.
- Public Summary: You must publish a concise summary of the copyrighted material used for training, using templates provided by the Commission.
- Model Card: Provide downstream users with a clear description of the model’s capabilities and limitations.
Why does this matter? Because previously, training data was proprietary. Companies kept it secret. Now, transparency is mandatory. You don't have to reveal every single image or text snippet, but you must disclose enough for regulators to assess copyright risks.
High-Impact Models: When Size Matters
Not all GPAI models are equal. The Act flags high-impact GPAI models-those trained on more than 10^25 FLOPs (floating-point operations) or deemed strategically important. These models face stricter scrutiny.
If your model qualifies as high-impact, you must:
- Conduct thorough model evaluations, including adversarial testing.
- Assess and mitigate systemic risks (e.g., bias, security vulnerabilities).
- Report serious incidents to the European Commission promptly.
- Ensure adequate cybersecurity protections.
This tier targets giants like OpenAI, Anthropic, and Google. But if you fine-tune a smaller model and deploy it widely, you might still fall under standard GPAI rules. The distinction hinges on compute power and potential impact, not just brand name.
Transparency Rules: Labeling Your AI Content
Here’s where it gets practical for product teams. Starting August 2026, Article 50 of the AI Act kicks in fully. This section mandates transparency for limited-risk systems, which includes most generative AI applications.
What does this mean for your UI?
- Disclose AI Interaction: Users must know they’re talking to an AI. If you have a chatbot, say so. Don’t hide behind a human-like avatar without disclosure.
- Label Generated Content: Text, audio, images, or videos generated by AI must be identifiable. For deepfakes, this is non-negotiable. For text published to inform the public, you need visible labeling.
- Machine-Readable Markers: Ideally, use technical standards (like C2PA) to embed provenance metadata. This helps platforms detect and label AI content automatically.
Imagine a news site using AI to summarize articles. Under the new rules, readers should see a clear indicator that the summary was machine-generated. No more ambiguity. This protects against misinformation and builds trust.
Penalties: The Cost of Non-Compliance
Don't underestimate the fines. The EU AI Act carries teeth. Penalties for GPAI providers became enforceable on August 2, 2026.
| Violation Type | Maximum Fine | Percentage of Global Turnover |
|---|---|---|
| Prohibited Practices | €35 million | 7% |
| Other Violations (including GPAI obligations) | €15 million | 3% |
For a startup, €15 million might seem abstract. But for established tech companies, 3% of global turnover is massive. Compare this to GDPR fines, which capped at 4%. The AI Act is stricter. And remember, these fines apply per violation, not per company. Multiple breaches can stack up quickly.
Practical Steps for Generative AI Providers
So, what do you actually need to do? Here’s a checklist for compliance:
- Audit Your Training Data: Can you prove you had the right to use copyrighted materials? Do you have license agreements? Did you respect robots.txt or other opt-out signals?
- Create Model Cards: Document your model’s intended use, limitations, and evaluation results. Make this accessible to enterprise clients.
- Implement Transparency Features: Add UI elements that disclose AI generation. Use watermarks or metadata for media outputs.
- Monitor for High-Risk Uses: Track how your API is being used. If a customer uses your LLM for hiring decisions, they bear the high-risk burden-but you should support their compliance efforts.
- Engage with Sandboxes: By August 2026, each EU member state must offer an AI regulatory sandbox. Use these to test new features with regulator guidance before full rollout.
One common pitfall: assuming your US-based team is exempt. You’re not. If you sell to the EU, you’re subject to extraterritorial reach. Another mistake: ignoring downstream users. Even if you provide an API, your documentation must help integrators understand their own obligations.
Related Concepts and Future Outlook
The EU AI Act doesn't exist in a vacuum. It intersects with existing frameworks like GDPR, which governs personal data processing. If your generative AI processes user inputs containing PII, you need both AI Act compliance and GDPR adherence.
Also watch for the Digital Omnibus proposal. Introduced in late 2025, it aims to simplify certain timelines and reduce bureaucratic friction. While not yet law, it signals the EU’s willingness to adjust rules if they stifle innovation too much.
Finally, consider the global ripple effect. Countries like Canada, Brazil, and South Korea are drafting similar laws. Building for EU compliance now often prepares you for future regulations elsewhere. The EU sets the bar; others follow.
Does the EU AI Act apply to my US-based startup?
Yes, if you place your AI system on the EU market or its output is used within the EU. The Act has extraterritorial reach, meaning location of headquarters doesn't exempt you from compliance obligations for European users.
Are all chatbots considered high-risk?
No. Most chatbots fall under Limited Risk, requiring only transparency disclosures. However, if a chatbot is used in a high-risk context, such as providing legal advice or medical triage, the application itself may be classified as high-risk, triggering stricter obligations.
What is a General-Purpose AI (GPAI) model?
A GPAI model is a foundational AI system trained on vast amounts of data that can be adapted to perform a wide range of tasks, such as text generation, coding, or translation. Unlike task-specific AI, GPAI models serve as building blocks for numerous downstream applications.
When do transparency rules for AI-generated content start?
The full transparency requirements under Article 50, which mandate labeling AI-generated content and disclosing AI interactions, become applicable in August 2026. However, GPAI providers already have documentation and copyright obligations as of August 2025.
How does the EU AI Act affect copyright for training data?
Providers of GPAI models must implement policies to ensure compliance with EU copyright laws. This includes publishing a public summary of copyrighted training materials and respecting opt-out mechanisms, shifting the burden of proof toward developers regarding data sourcing.