Artificial Intelligence (AI) Regulation – Objectives, Scope of Application & Entry into Force
Individual Artificial Intelligence (AI) systems and AI itself, more generally, constitute a reality that can no longer be ignored; particularly by undertakings. The (global) debate remains not only extremely interesting, but also, rightly, highly intense. Legislative intervention to regulate the specific issues relating to the use of AI, although already delayed, was undoubtedly necessary. The EU legislator proceeded to establish rules governing the use of Artificial Intelligence technologies within the European Union. Regulation (EU) No. 1689/2024 – the AI Act (AI ACT) constitutes an ambitious undertaking, the effectiveness of which will, of course, be demonstrated upon its full entry into force. The present article addresses its objectives, scope of application and entry into force.
Introductory Remarks
The proposal for the creation of a Regulation governing AI-related matters within the Union was submitted by the Commission considerably earlier: in April 2021. Two years later, following significant and rapid developments in the AI sector, the European Parliament approved the European AI Regulation (AI ACT). Final approval was granted by the European Council on 21 May 2024. The Regulation was published on 12 July 2024; its provisions enter into force in stages.
Although its legislative drafting deficiencies render the AI ACT a legal instrument of particular complexity and difficulty in interpretation, its seriousness, significance and value are in no way diminished.
The Regulation is extremely extensive (180 recitals, 13 Chapters and 113 Articles) and covers, within its material scope, all sectors falling within EU law. Consequently, it does not apply to matters falling outside the competence of EU law, nor to those expressly excluded.
Objective of the Regulation
The intention of the EU legislator included, inter alia (Article 1), the protection of fundamental rights, democracy, the rule of law and environmental sustainability in the context of the use of AI. Although its central approach is entirely human-centric, the need to develop and promote AI within the Union is not overlooked. Thus, alongside the protection of fundamental rights, the Regulation also seeks to support innovation in the field of AI.
The Regulation also aims to establish uniform legal rules throughout the EU, so as to avoid divergent national legislative provisions that would not serve its aforementioned objectives.
AI Pact
In parallel with the Regulation, the AI Pact has been introduced. This constitutes a preparatory instrument designed to assist with implementation and compliance with the Regulation. Its purpose will be fulfilled until the Regulation enters into full force.
The AI Pact is based on two pillars: (a) the collection and exchange of information (regarding practices already used by the parties prior to the Regulation’s entry into force, organisation of informational seminars, etc.) and (b) the facilitation and communication of corporate commitments (publication of company practices regarding compliance, “commitment statements” to comply).
It is noteworthy that, although it contains commitments, participation in them is voluntary. To date, approximately two hundred (200) companies have signed such commitments. These “commitments” are not legally binding and, therefore, do not impose legal obligations on participants. Companies that so choose may adopt and sign them (i.e. voluntarily submit to them) at any time until the AI Regulation becomes fully applicable.
Importantly, however, the voluntary commitments of the AI Pact encourage participating companies to commence implementation of the Regulation prior to its entry into force.
Scope of Application
The legislator sets out all legal and natural persons to whom the Regulation applies (Article 2). In addition to personal criteria, a further criterion relating to location is established.
In particular, the Regulation applies mandatorily to:
(a) Providers placing AI systems or general-purpose AI models on the market or putting AI systems into service within the Union, irrespective of their place of establishment. This concerns making available through distribution or use in the course of commercial activity. Even where such availability occurs online or remotely, it is considered as taking place within the Union if the offer is directed to traders or end users within it (even if only in a single Member State).
It is clarified that, specifically as regards putting into service, this refers to the development of a specifically designed AI system by a Provider for use by itself (or by a third party) to meet its needs.
A particular feature of this provision is the exclusion from the scope of application of providers who, although established within the Union, do not place their AI systems on the Union market. In such cases, no obligation of compliance with the Regulation is imposed. Accordingly, provided that the systems are exclusively exported outside the Union, providers established within the Union may supply systems that are prohibited within the Union.
(b) Deployers of AI systems established or located within the Union. These are users of such systems when they use them under their responsibility. The Regulation does not apply to users where such use occurs in the context of a personal, non-professional activity.
(c) Providers and Deployers of AI systems established or located in a third country, where the output produced by the AI system is used within the Union.
(d) Importers and Distributors of AI systems. An importer is defined as a person established within the Union who places on the market AI systems bearing the name or trademark of a natural or legal person established in a third country. A distributor is defined as a natural or legal person in the supply chain, other than the provider or importer, who makes an AI system available on the Union market.
(e) Manufacturers of products placing on the market or putting into service an AI system together with their product and under their own name or trademark.
(f) Authorised Representatives of Providers not established within the Union. An authorised representative is a natural or legal person located or established within the Union who has received and accepted a written mandate from a provider of an AI system or general-purpose AI model to fulfil, on its behalf, the obligations and procedures established by the Regulation.
(g) Affected Persons located within the Union. These are data subjects located within the Union. The Regulation’s application to them primarily concerns the right to explanation of decisions taken by AI systems (a detailed analysis of the relevant issues concerning the Regulation and the GDPR will follow in a subsequent article).
The EU legislator has expressly excluded from the scope of application the use of AI systems for military/defence purposes (Article 2 §3), for law enforcement and judicial cooperation (Article 2 §4), and for scientific research and development (Article 2 §§6 & 8).
Entry into Force & Application
The Regulation entered into force on 1 August 2024.
Its application takes place gradually (Article 113). This phased application is justified by its complexity, the significant obligations it imposes on those within its scope, and the impact of its provisions on the economy and society.
The general date of application is set for 2 August 2026.
Certain provisions, however, apply earlier than that date.
In particular, from 2 February 2025, the obligation of AI literacy (Article 4) and the prohibition on the use of AI systems presenting unacceptable risk (Article 5) already apply—analysis thereof will follow in a subsequent article.
From 2 August 2025, the rules establishing the “foundations” for the implementation of the Regulation apply. These provisions are addressed primarily to the Member States, which are required to have already established procedures and administrative structures for compliance with the Regulation (Chapter III Section 4).
Furthermore, from the same date, the provisions concerning the classification of general-purpose AI models (Chapter V), the Union governance rules (Chapter VII), the chapter concerning penalties (Chapter XII) and the rules on confidentiality (Article 78) apply.
Finally, the phased application will be completed on 2 August 2027, when the rules on the classification of high-risk AI systems used as safety components will enter into force.
As regards the remaining provisions of the Regulation, for which no separate date of application is specified, they apply from 2 August 2026.
Artificial Intelligence has, quite literally, permeated the lives of all of us; including undertakings. This reality activated, albeit with significant delay, the reflexes of the European Union. The relevant Regulation is already a reality and the obligation to comply has already commenced, at least in part. This necessitates awareness, vigilance and the initiation of compliance—particularly in the business sector. However, as the risks prove to be extremely significant, knowledge and classification thereof are essential. The latter, in particular, will be addressed in a subsequent article.
Managing Partner
Koumentakis and Associates Law Firm
Note: This article forms part of a broader series of articles by our Law Firm on the Artificial Intelligence Regulation. In this series, we seek to address the key relevant provisions and obligations under Regulation (EU) 2024/1689, always from a business perspective.