Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

EU begins enforcing AI Act with bans on unacceptable-risk systems

First prohibitions took effect on 2 February with fines up to 35 million euros or 7% of global revenue, though full implementation stretches to 2027 and key compliance standards remain unwritten.

By , Technology Editor

Published

7 min read

The European Union began enforcing the first binding restrictions of its Artificial Intelligence Act on Sunday, 2 February, marking the moment when prohibitions on systems deemed to pose "unacceptable risk" became legally actionable. Companies that continue to deploy banned applications, among them social scoring, real-time facial recognition in public spaces, and AI that categorises people by race, sex life or sexual orientation, now face fines of up to 35 million euros or 7% of global annual turnover, whichever is higher. The regulation formally entered into force in August 2024, but the initial compliance deadline lapsed this weekend, opening the door to enforcement actions by national market-surveillance authorities.

What the law actually bans

The Act's first chapter targets a narrow but symbolically potent set of practices. Social scoring systems that evaluate citizens' behaviour across multiple domains, a concept associated with China's municipal experiments, are prohibited outright. So too are real-time remote biometric identification systems in publicly accessible spaces, with limited exceptions for law enforcement searching for specific victims or preventing imminent threats. The ban extends to AI that infers sensitive attributes such as race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation from biometric data. Also prohibited are systems that deploy subliminal, manipulative or deceptive techniques to distort behaviour in ways that cause significant harm, and AI that exploits vulnerabilities of specific groups due to age, disability or socio-economic circumstance.

These prohibitions apply to any provider or deployer whose system is used within the EU market, regardless of where the company is headquartered. A US-based firm offering a prohibited service to European users falls under the same regime as a domestic operator. The extraterritorial reach mirrors the approach taken with the General Data Protection Regulation, though the AI Act's risk-based taxonomy, unacceptable, high, limited and minimal, is without precedent in scope.

Penalties that exceed GDPR

The maximum fine of 35 million euros or 7% of worldwide annual revenue represents a step up from the GDPR's ceiling of 20 million euros or 4% of turnover. For a company the size of Meta or Alphabet, 7% of global revenue would amount to tens of billions of euros. The regulation stipulates that penalties must be "effective, proportionate and dissuasive", with the exact amount determined by the nature, gravity and duration of the infringement, the degree of responsibility, and any previous violations. National authorities will issue the fines, but the European Commission can intervene in cross-border cases through the consistency mechanism established under the Act.

The higher ceiling reflects a deliberate political calculation. When the GDPR was adopted in 2016, many observers doubted whether 4% of turnover would ever be levied; in practice, the largest penalties have remained well below the theoretical maximum. The AI Act's drafters wanted to signal that unacceptable-risk systems would not be treated as a cost of doing business. Whether national regulators have the resources and political will to pursue the largest offenders remains an open question.

Compliance depends on standards yet to be written

Tasos Stampelos, head of EU public policy and government relations at Mozilla, told a CNBC-moderated panel in November that the regulation should be understood primarily as product safety legislation. "With product safety rules, the moment you have it in place, it's not a done deal," he said. "There are a lot of things coming and following after the adoption of an act." Compliance for high-risk systems, which include AI used in recruitment, credit scoring, critical infrastructure and medical devices, will hinge on harmonised technical standards currently being developed by European standardisation bodies CEN and CENELEC under a mandate from the Commission. Those standards are not expected to be finalised before 2026 at the earliest.

In the meantime, the EU AI Office, established within the Commission in 2024, published a second draft code of practice for general-purpose AI models in December. The document introduces exemptions for providers of certain open-source models while requiring developers of "systemic" general-purpose models, those trained with more than 10^25 floating-point operations, to conduct rigorous risk assessments, report serious incidents, and ensure cybersecurity protections. The code is voluntary but carries a presumption of conformity for signatories. A final version is expected by spring 2025.

Industry split on whether rules help or hinder

The regulation has exposed a fault line in European technology circles. Prince Constantijn of the Netherlands, the country's special envoy for technology and innovation, told CNBC in June 2024 that he was "really concerned" about Europe's focus on regulating AI. "Our ambition seems to be limited to being good regulators," he said. "It's good to have guardrails. We want to bring clarity to the market, predictability and all that. But it's very hard to do that in such a fast-moving space." His intervention reflected a broader anxiety among startup founders and venture investors that compliance costs will disproportionately burden smaller European firms while US and Chinese competitors scale unfettered.

Others see a different competitive logic. Diyan Bogdanov, director of engineering intelligence and growth at Bulgarian fintech firm Payhawk, argued that the Act's requirements around bias detection, regular risk assessments and human oversight "aren't limiting innovation, they're defining what good looks like." In his view, while the United States and China compete to build the largest models, Europe is positioning itself as the jurisdiction that builds the most trustworthy ones. That proposition rests on the assumption that enterprise customers and public-sector buyers will pay a premium for certified compliance, an assumption not yet tested at scale.

The long road to full implementation

Sunday's deadline was only the first in a cascade. The prohibition on unacceptable-risk systems applies immediately. Rules for general-purpose AI models take effect in August 2025. Obligations for high-risk AI systems embedded in regulated products, medical devices, machinery, toys, follow in August 2026. The remaining high-risk categories, including standalone AI systems for recruitment, credit scoring and law enforcement, have until August 2027. Transparency requirements for limited-risk systems such as chatbots and deepfake generators also fall due in 2026. Each deadline triggers new conformity-assessment procedures, documentation obligations and post-market monitoring duties.

The staggered timeline was a compromise between the European Parliament, which pushed for faster implementation, and the Council, where member states warned that national regulators lacked the expertise and staffing to enforce the law uniformly. Germany, France and Italy all sought longer transition periods for their industrial bases. The result is a regulatory horizon stretching over three years, during which the legal framework will coexist with a rapidly evolving technology landscape. Generative AI capabilities that did not exist when the Act was negotiated in 2023 are now mainstream; by 2027, the state of the art will have moved further still.

Sources

  1. CNBC

    cnbc.com · 2025-02-03

People mentioned

  • Tasos Stampelos

    Head of EU public policy and government relations, Mozilla

  • Prince Constantijn of the Netherlands

    Special envoy for technology and innovation, Dutch Royal House

  • Diyan Bogdanov

    Director of engineering intelligence and growth, Payhawk

Organisations

European Union · European Commission · EU AI Office · Mozilla · Payhawk · OpenAI

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.