The European Union's AI Act, after political agreement in December 2023 and formal adoption earlier in 2024, entered into force on August 1, 2024, becoming the world's first comprehensive, horizontally applicable law regulating artificial intelligence systems by risk level rather than by sector or use case alone. The law sorts AI applications into four tiers — unacceptable risk (banned outright), high risk, limited risk, and minimal risk — with obligations scaling sharply as risk classification rises.

The mechanism worth tracking is the ban list and the general-purpose AI provisions layered on top of the risk tiers: the Act outlaws social scoring by governments, most forms of real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), and emotion-recognition systems in workplaces and schools, while imposing extra transparency and risk-assessment obligations on 'general-purpose AI models with systemic risk,' defined using a compute threshold of roughly 10^25 floating-point operations used in training — a technical line that, as of the law's passage, only the very largest frontier models from OpenAI, Google, and a handful of others crossed.

High-risk systems, covering areas like hiring, credit scoring, law enforcement, and critical infrastructure, face mandatory conformity assessments, human oversight requirements, and detailed technical documentation obligations phased in through 2026 and 2027 rather than all at once, giving companies a multi-year runway to build compliance infrastructure rather than facing a single hard deadline.

Global AI vendors, weighing the cost of building separate compliant and noncompliant versions of their products against simply meeting the EU's bar everywhere, largely chose the latter — a dynamic regulatory scholars call the 'Brussels Effect,' previously seen with GDPR's global influence on privacy law. Smaller AI startups without compliance departments the size of a Microsoft or Google's, however, cited disproportionate cost burdens, and some U.S.-based AI companies including certain Meta AI products delayed European launches specifically over Act-related uncertainty.

Coverage at passage focused heavily on the novelty of 'the first AI law' and on speculative fears about stifled innovation. It underweighted the specific enforcement architecture: fines reaching up to 7 percent of global annual turnover for the most serious violations — a higher ceiling than GDPR's 4 percent — and a network of national supervisory authorities plus a new EU AI Office coordinating enforcement, whose actual capacity and rigor would only become visible once enforcement actions began years into implementation.

Industry groups, including some representing European startups, warned during negotiations that compliance costs would disproportionately burden smaller companies relative to well-resourced American incumbents, prompting last-minute carve-outs and lighter-touch obligations for limited-risk applications, a compromise that satisfied neither the strictest safety advocates nor industry lobbyists pushing for a narrower law.

By 2025 and into 2026, the law's phased provisions began taking practical effect: the ban on prohibited practices applied first, in February 2025, while obligations for general-purpose AI model providers followed in August 2025, and high-risk system requirements continue phasing in on a multi-year schedule. Other jurisdictions, including Brazil, South Korea, and several U.S. states, referenced the EU's risk-tiered structure directly when drafting their own AI legislation, even where they diverged on specific thresholds.

The EU AI Act's risk-tiered approach — prohibited practices, high-risk obligations, transparency for general-purpose models — set the first comprehensive horizontal AI statute among major markets. Compliance timelines forced product and documentation redesigns well before fines land.

U.S. executive orders and voluntary commitments offered a contrasting soft-law path; China advanced its own algorithmic rules. Brussels again attempted the Brussels Effect: regulate the market, export the standard. Whether innovation flight or global baseline wins remains the live experiment.

Compliance consultancies bloomed in Brussels and Dublin. Foundation-model providers negotiate how ‘systemic risk’ duties apply across borders. The Act’s success metric is whether rules shape design early — or merely generate paperwork after deployment.

High-risk classifiers will keep lawyers busy arguing edge cases — hiring tools, biometric systems, critical infrastructure. The Act’s bite depends on enforcement culture as much as on recital language.

The Act's lasting inheritance is definitional: 'high-risk AI system,' 'general-purpose AI model,' and 'systemic risk' compute thresholds, terms that did not exist in binding law before 2024, now function as the reference vocabulary international regulators reach for by default, making the EU's specific risk-classification choices — not any single country's preferred approach — the starting template for AI governance conversations worldwide.

Century Signals note: EU AI Act official text; Commission guidance; contemporaneous Brussels and industry compliance reporting. Editorial judgment about what still structures the present — not a comprehensive history.