Glossary · A

AI Act (EU AI Act)

European Union legislation regulating AI systems by risk level — the first comprehensive, binding AI-specific law of its kind, and the reason "AI compliance" now means something distinct from general data protection compliance for any organization whose AI systems touch people in the EU.

What Is the EU AI Act?

The EU AI Act is European Union legislation that regulates AI systems based on their risk level, ranging from minimal-risk applications with few obligations to high-risk systems — such as those used in healthcare, finance, employment, or law enforcement — that face requirements around transparency, human oversight, data governance, and documented risk management. Non-compliance carries some of the steepest penalties in AI or data regulation: for the most serious violations, such as deploying prohibited AI practices, fines can reach up to €35 million or 7% of global annual turnover, whichever is higher, with lower tiers applying to other categories of violation. Any organization deploying AI systems that affect people in the EU — regardless of where the company is headquartered — generally needs to understand where its systems fall on the Act's risk spectrum.

Practical Examples of the EU AI Act

A multinational insurer using an AI system to help determine claims outcomes for EU customers is a common example of a system likely to fall into the "high-risk" category under the Act. That classification can trigger specific obligations: documented risk management for the AI system, governance controls over the data it's trained and run on, and decisions that are explainable and subject to human oversight. Before the EU AI Act, many companies treated this kind of risk management as optional best practice; under the Act, it becomes a legal requirement for systems that fall into scope, with compliance deadlines phasing in by obligation type rather than all at once.

What Happens Without It

An organization that deploys a high-risk AI system in the EU without meeting the Act's requirements is exposed to enforcement action and fines that can scale with global revenue, not just EU revenue, depending on the nature of the violation — making this a significant compliance consideration for companies operating at scale. Beyond direct penalties, non-compliance can also create reputational and contractual risk, as EU enterprise customers and partners increasingly ask vendors to demonstrate AI Act compliance as part of procurement.

Timing adds a further complication. Compliance deadlines under the Act are phased, but the underlying documentation, oversight, and data governance work needed to meet them typically takes meaningful time to put in place properly. An organization that waits until a regulator's inquiry, an enterprise customer's due-diligence questionnaire, or a public incident forces the question is no longer choosing when to address compliance — it's responding under a deadline it doesn't control, often while also managing reputational fallout.

With a Compliance Approach in Place

  • High-risk classification is a known, managed status rather than something discovered reactively
  • Audits and enterprise due-diligence requests can be answered from existing documentation
  • Governance controls that support EU AI Act compliance often overlap with protections needed for GDPR, HIPAA, and similar regulations
  • Risk and oversight obligations are addressed on the organization's own schedule rather than under external pressure

Without It

  • High-risk AI systems in production can carry undocumented compliance risk until someone specifically reviews them
  • A single regulator inquiry can surface a backlog of undocumented risk across multiple systems at once
  • Enterprise deals can stall at the compliance-review stage if AI Act readiness can't be demonstrated
  • Building governance documentation under a deadline generally costs more and takes longer than building it in from the start

How This Relates to Questa AI

Questa AI includes the EU AI Act as one of the regulatory frameworks covered under its broader AI governance and compliance approach, alongside GDPR, HIPAA, CCPA, and data protection laws in other regions. Questa's governance dashboard is designed to map applicable regulations to the region processing a given piece of data, which can help organizations see which requirements are relevant to a specific AI tool or data flow, supported by the platform's anonymization and governance controls.

Because Questa supports flexible, region-specific data residency, including self-hosted deployment options, organizations with EU-specific residency considerations can use this as part of a broader approach to data governance relevant to Act compliance. This is intended to support an organization's own compliance program rather than serve as a substitute for a legal assessment of a specific AI system's obligations under the Act.

Frequently asked questions

Yes, generally. The Act's obligations are typically triggered by whether an AI system affects people located in the EU, rather than by where the company providing or deploying it is headquartered.

Systems used in areas like healthcare, employment, credit scoring, law enforcement, and critical infrastructure commonly fall into the high-risk category, though classification depends on the specific use case rather than the industry alone.

Penalties are tiered by violation type. The most serious violations, such as deploying prohibited AI practices, can reach up to €35 million or 7% of global annual turnover, whichever is higher; other categories of violation carry lower maximum penalties.

It can contribute to it. Data governance is part of what the Act requires for high-risk systems, and anonymization is one technical control that supports that requirement, though it typically needs to be paired with other measures like documented risk management and human oversight.

No. GDPR governs personal data protection broadly, while the EU AI Act regulates AI systems based on risk category, independent of whether personal data is involved. The two can overlap significantly for AI systems that process personal data.

The Act entered into force in 2024, with obligations phasing in over time by category — bans on unacceptable-risk practices first, followed by rules for general-purpose AI models, and high-risk system obligations after that. Organizations should check which phase applies to their specific system rather than assuming a single deadline covers everything.

Prohibited systems cannot be deployed at all, regardless of safeguards. High-risk systems are permitted but only under conditions such as documented risk management, human oversight, data governance, and transparency.

The Act includes some accommodations for smaller businesses, such as simplified documentation in certain cases and access to regulatory sandboxes, but it generally does not exempt them from high-risk obligations if their system falls into a high-risk category.

A practical starting point is classification: build an inventory of AI systems in scope, determine each system's risk category, and prioritize documentation and governance work on systems that fall into the high-risk category first.

Yes, potentially. The Act's high-risk obligations concern process and governance — documentation, oversight, risk management — rather than solely whether data was exposed, so a system can fall short of compliance without any data ever having leaked.

See AI Act (EU AI Act) in practice

Questa AI anonymizes sensitive data before it reaches any AI model — across documents and live prompts, with governance and data-residency control.

Contact

Contact Us

Have questions or ready to explore how Questa AI can transform your business?