European Union Phases In Comprehensive AI Act Regulations
The European Union is implementing a risk-based AI Act that imposes strict transparency rules and heavy fines for non-compliance across the bloc and extraterritorially.
The European Union is phasing in the Artificial Intelligence Act, a regulatory framework that governs AI development through a risk-based classification system. Starting in February 2025, the act prohibits practices deemed to carry an unacceptable risk, including social scoring and specific biometric exploitations.
High-risk systems, such as those utilized in healthcare and credit scoring, must adhere to rigorous documentation and transparency standards. The legislation maintains extraterritorial reach, requiring non-EU companies, including those based in the United Kingdom, to comply if their systems are marketed within the bloc or if their outputs are used there. Penalties for non-compliance may reach €35 million or 7% of a company's total worldwide turnover.
To simplify these and other digital regulations, the European Commission introduced the Digital Omnibus proposal in November 2025, with formal adoption expected later in 2026. In preparation, member states are updating national laws. Luxembourg has designated the Commission de Surveillance du Secteur Financier and the Commissariat aux Assurances as the supervisory authorities for AI systems related to financial services and insurance.