DEFINITION
EU AI Act
The European Union's comprehensive AI regulation, which classifies AI systems by risk level and imposes conformity assessments, transparency obligations, and prohibitions on certain high-risk uses.
In depth
The EU AI Act (Regulation (EU) 2024/1689) entered into force in August 2024 and is being phased in over two years. It creates a risk-based framework for AI systems placed on the EU market or affecting EU persons: Unacceptable risk (prohibited from August 2025) — AI for social scoring by governments, real-time remote biometric identification in public spaces (with narrow exceptions), subliminal manipulation. High risk (Annex III) — AI in critical infrastructure, education, employment, essential services (credit, insurance), law enforcement, migration, and administration of justice. High-risk systems require conformity assessments, technical documentation, human oversight, logging, registration in an EU database, and post-market monitoring. Limited transparency risk — AI systems interacting with people (chatbots) must disclose they are AI; deepfakes must be labelled. Minimal risk — most current consumer AI tools. General-purpose AI (GPAI) models — large foundation models must meet transparency and copyright obligations; those with systemic risk (frontier models above 10^25 FLOPs training compute) face additional requirements. For organisations using AI tools in regulated contexts, the EU AI Act's Annex III classification is critical: using AI in employment screening, credit decisions, or healthcare triage likely puts the deployer into the high-risk category, triggering conformity assessment and human oversight requirements.
Examples
- An employer using AI to filter job applications — Annex III high-risk use case, requiring conformity assessment, bias testing, and human review mechanisms.
- A bank using an AI model to make credit-scoring decisions — high-risk, requiring explainability and the ability to contest decisions.
- A hospital using AI for diagnostic imaging triage — high-risk medical device pathway, requiring additional clinical validation.
How Locke handles eu ai act
Locke addresses the data-quality and data-minimization requirements that apply to high-risk AI systems: feeding AI decision systems with minimum-necessary, accurately labelled personal data reduces both discriminatory-proxy risk and the regulatory burden of demonstrating data governance. Local-first detection also helps organisations keep sensitive data out of foundation model training pipelines.
See the productRelated terms
- GDPR
The EU General Data Protection Regulation — the world's most comprehensive data-protection law, governing how organisations handle personal data of EU residents.
- Automated Decision-Making (ADM)
Using algorithms or AI systems to make or substantially influence decisions about individuals — regulated under GDPR Article 22, Colorado SB 24-205, and a growing number of state and sector laws.
- Data Processing Agreement (DPA)
A GDPR-mandated contract between a controller and a processor that governs how personal data is handled on the controller's behalf.