Proceed to contents

What is the AI ​​Act?

24.01.2025

The EU AI Act (Artificial Intelligence Act) is the world's first legal framework for artificial intelligence. It addresses AI-related risks to ensure safe, reliable, and transparent AI usage while respecting fundamental rights and values in Europe. The AI Act will be rolled out between August 2024 and August 2027.

Why an EU AI Act?

AI opens up many possibilities but also raises risks and uncertainties. Some key concerns include:

  • Who is responsible for mistakes made by an AI system?
  • If AI can write in the style of McEwan or Atwood, what does that mean for copyright?
  • Historical data often (usually) contains biases: without intervention, AI systems simply adopt past prejudices.

With the AI Act, Europe aims to prevent these issues while encouraging innovation. The law was approved on August 1, 2024, and will be gradually implemented over the next two years.

Eigenschappen

  • De EU AI Act is een set regels die bepaalt hoe bedrijven en mensen in Europa AI mogen gebruiken. Als eerste volledige wettenpakket, wordt verwacht dat deze act de norm zal worden voor AI-regels wereldwijd, zoals dat ook met de GDPR-regelgeving is gebeurd.
  • De AI Act is van toepassing op alle producten met AI die in de markt geplaatst worden, met twee uitzonderingen: niet-professionele doeleinden en wetenschappelijk onderzoek & ontwikkeling.
  • Deze nieuwe wet werkt naast bestaande wetgeving (bv. GDPR) en vervangt of wijzigt geen andere bestaande regelgeving.
  • Elke partij betrokken bij een AI-product heeft andere verplichtingen, die telkens bepaald worden aan de hand van het risico.
  • Overtredingen van de regels van de AI Act zullen bestraft worden.

Key features

The EU AI Act is a set of rules defining how companies and individuals in Europe may use AI. As the first comprehensive legal framework for AI, it is expected to set the global standard, similar to how GDPR shaped data privacy regulations worldwide.

The AI Act applies to all AI-powered products on the market, with two exceptions: non-professional (personal) use and scientific research & development

This new law works alongside existing legislation (e.g., GDPR) and does not replace or modify any other existing regulation.

Additionally, different AI stakeholders (developers, deployers, users) have different obligations, depending on the risk level of the AI system.

Violating the AI Act will lead to penalties.

1. Unacceptable Risk = Completely Banned

AI applications that violate fundamental rights are entirely prohibited. Examples include:

  • manipulation of human behavior
  • government-led human scoring: rewarding or punishing citizens based on behavior
  • predicting criminal behavior based on AI profiling (by law enforcement services)

Rule: completely prohibited 🚫

2. High risk = strict regulations

Some AI applications are useful but pose significant risks to human rights. Some examples:

  • AI selects whether a person qualifies for education, a job, a loan, a subsidy...
  • AI-controlled critical infrastructure (e.g., trains, electricity grids, internet...)
  • AI use in police investigations, immigration, asylum, and border control

Rule: systems must undergo strict testing and monitoring for reliability, transparency and fairness. Human oversight must always be present (art. 14) while the human overseer is sufficiently AI literate (art. 4) to evaluate the results. This person must have the means to overrule the system's decision at all times. The system's interface optimally explains each step of the procedure. De system is trained and tested with high quality, representative and complete datasets (art. 10)⚠️

3. Limited risk = transparency required

AI applications with limited risk to human rights operate transparently without significant potential for discrimination, privacy violations, or harmful societal impact.

  • accessibility tools (screen readers, translators for hearing impaired...)
  • AI-powered traffic & navigation tools
  • translators & AI tutors for languages, computer code...

Rule: companies must disclose their use of AI (e.g., informing users when they are interacting with an AI chatbot). 🟡

4. Minimal risk = no additional rules

Lots of AI systems carry hardly any risk to human rights:

  • spam filters
  • AI-generated video game stories
  • AI systems sorting produce

Rule: no additional AI-specific regulations, but the existing laws (e.g., GDPR, copyright) still apply ✅

The AI Act intends to increase trust and respect for fundamental rights, values, and safety.
Isabela Maria Rosal, KU Leuven CiTiP

Some relevant articles & regulations

Obligation of "AI literacy"

AI literacy is essential for anyone to work critically and effectively with AI systems.

That’s why the first provision of the EU AI Act introduces a mandatory AI literacy requirement: Article 4 of the EU AI Act requires AI providers and deployers to ensure that their staff and stakeholders have a sufficient level of AI literacy. This means that these organisations carry the responsibility to ensure that the professionals who work with AI systems have sufficient knowledge and skills to fulfill their role.

Human Oversight (EU AI Act Art. 14)

For high-risk AI systems affecting human rights, Article 14 on human oversight comes into play. This article ensures that AI systems do not operate autonomously without human intervention. To effectively oversee an AI system, a human supervisor must have sufficient knowledge and insight to:

  • understand how the system works
  • monitor the outputs of the system
  • correct the system if it generates unintended or harmful results

Context matters: The level of AI literacy required depends on how reliable the system is and how significant its decisions are. The more critical the decision, the deeper the human understanding needed.

Additionally, developers of high-risk AI systems must provide transparent and explainable interfaces so users can understand how the system operates.

Data & Data Governance

Article 10 of the AI Act addresses the data used to train, validate and test AI systems.

For high-risk systems, the AI Act sets strict requirements regarding:

  • proper data management, covering both data collection and processing, as well as potential biases and missing data

  • the datasets used must be relevant, representative, as error-free and as complete as possible

  • the context in which the AI system will ultimately be used must always be taken into account

GDPR

The AI Act is "new regulation that applies alongside and does not modify existing laws such as the General Data Protection Regulation" (GDPR), says Isabela Maria Rosal from KU Leuven CiTiP: just because something is allowed under the AI Act doesn’t mean it complies with GDPR - and vice versa. However, the frameworks are aligned: individuals must be informed of how their data is processed via AI (Article 13(2)(f) GDPR).

This includes:

  • which data is collected,
  • the purposes of data collection,
  • how algorithms will generate new data,
  • how algorithms make decisions, and their impact on people and society,
  • the broader societal implications of AI processes.

Learn more?

The impact of the EU AI Act in 6 steps

downloadable flowchart - Kenniscentrum Data & Maatschappij

Navigating the EU AI Act

study day - Bruges - PUC KU Leuven Continue, KU Leuven CiTiP, Knowledge Centre Data & Society, VAIA

AI Literacy

webinar - EU AI Office

AI literacy (EU AI Act Article 4)

AI literacy helps people assess whether using AI is a good or bad idea and how to apply it correctly. As of 2 February 2025, every organisation in the EU should take measures to support the development of sufficient AI literacy among their employees, end-users, and anyone else affected by their use of AI systems.

How to increase AI Literacy in your company? Answer: training programmes and a learning culture

From February 2025, AI literacy is mandatory under the European AI Act. How do you deal with this in your company? Nadja Desmet of Someflex provides some tips on how to have a good training programme and a suitable learning culture.

What is human-centered AI?

No one likes systems that are rigid and force you to work in just one way. When such systems make counterintuitive decisions, people naturally avoid them – because they simply don’t trust them. So, how can an AI system be truly helpful? David Geerts lists the three conditions for placing humans at the heart of any AI system: human control, transparency, and trust.

Isabelle Borremans

Isabelle is not an AI expert, but she has been communicating about AI (and AI training) for VAIA for four years. So, she knows exactly how to communicate effectively about AI training. Feel free to contact her with any questions on how to promote your AI course. She’ll gladly challenge you with questions like:

  • Who is your target audience? Can you be more specific?
  • What networks reach that audience?
  • Where does your audience prefer to take courses?
  • What AI skills does your audience need?
  • Does your training match their needs?

Besides communication, Isabelle also works on VAIA’s strategy: Who is our audience? How can we reach them? How can we spark their interest in AI?

David Frost Cruz

David is passionate about education, technology, and AI. He works on creating tools that help improve how people learn and teach.

He has experience in:

  1. Managing e-learning projects and online courses in AI.
  2. Application of Machine Learning, Learning Analytics, and Statistical Analysis.
  3. Psychological Research and counselling in higher education.

David enjoys helping others understand and use digital tools (including AI) in Education. David is always open to conversations about e-learning initiatives, AI education programs, and talks on AI in education.

E: davidfrostcruz@gmail.com

Isabela Maria Rosal

Isabela is a legal researcher at the Centre for IT & IP Law – CiTiP – imec - KU Leuven, where she works on data governance projects, currently with focus on ENACT and CEDAR. In parallel, she is working on her PhD over the intersection between open data initiatives and the right to data protection, aiming to understand how the interconnection of these systems can guarantee the right to memory. She obtained a Master’s degree in Economic and Regulatory Law from the University of Brasília (UnB, Brazil) in 2022, presenting a thesis on “The processing of personal data for marketing purposes”, which was published as a book by Ed. Fórum. She also holds a LL.B degree in Law from UnB (2019), having written her thesis on “The definition of the legitimate interest according to the GDPR and the Brazilian Data Protection Law (LGPD)”. As a recipient of the SANTANDER grant, she studied at the University of Granada (Spain) in 2016-2017.

Prior to joining CiTiP, Isabela worked as a lawyer and consultant at a prestigious Brazilian law firm and as a project manager at the CEDIS-IDP (2020-2022), where she contributed to projects such as “Effective LGPD” and “LGPD in the Courts”. She has also worked as head of Data Governance and Digital Economy” at LAPIN and as an assistant in the Brazilian Administrative Council of Economic Defense (CADE).

Isabela is interested in the following research topics:

  • Ethical and legal impacts of new technologies
  • Data Protection
  • Regulation of new technologies
  • Cybersecurity
  • Data governance
  • Government access to personal data
  • Impact Assessments

Share on social media

Legal Technology and Responsible AI

24 August 2026

Summerschool - Antwerp - ACRAI

HPC Café

6 August 2026

Seminarie - Online, Karlsruhe - KIT, HammerHAI, Training geselecteerd in de Belgische AI Factory Antenna (AIFA)

SAIAR Summer Studio: From latent to physical space

24 August 2026

Zomerschool - Kortrijk - Howest Hogeschool, SAIARlab