The EU AI Act (the Act) comprehensively regulates the development and deployment of AI along the AI value chain. The Act forms part of a wider landscape of EU technology and data regulation — including the GDPR, Revised Product Liability Directive, Digital Services Act, Data Act — which presents both significant opportunities and complex compliance challenges.
The scope of the Act is broad and extends beyond the borders of the EU. The Act applies to companies providing or using AI in the EU, regardless of where the company is established. The Act establishes a risk-based framework of requirements for AI systems, including a ban on certain AI practices considered the most harmful to individuals, extensive requirements for AI systems categorised as high-risk, and transparency obligations for providers and deployers of certain AI systems that generate or modify media content. A specific regime applies to general purpose AI (GPAI) models, with additional obligations imposed on providers of GPAI models with systemic risk. Whilst the Act sets out a complex and detailed regime, there are core requirements including robust protection of individual rights, actively managed risk assessments, effective transparency, and adaptable governance.
The Act becomes applicable in a phased implementation, including transition periods for GPAI models and high-risk AI in regulated products. The AI Act Omnibus extends compliance deadlines for high-risk AI systems and introduces new rules on AI-generated intimate content.
This report leverages Latham’s experience advising on the AI ecosystem to help companies navigate different aspects of the Act, equipping them with key takeaways and practical steps to stay ahead of an ever-evolving AI regulatory landscape.
Read the report.
