What Is the EU AI Act?
The EU AI Act is the world's first comprehensive AI law to regulate artificial intelligence according to its level of risk, passed by the European Union (EU) in 2024. At its core, the law takes a risk-based approach: it sorts AI systems into four tiers and imposes stricter obligations the greater the risk. It applies to any operator that places AI on the market or uses it within the EU, and even companies based outside the EU are regulated if they offer AI products or services to the EU market. As of 2026, the EU AI Act's obligations are taking effect in phases by tier, making it a pressing compliance challenge for global companies, including those in Korea.
Key Provisions of the EU AI Act
The heart of the EU AI Act is a risk-based approach that classifies AI by level of risk and regulates each tier differently. Passed in 2024, the law does not ban AI itself; instead, it imposes obligations in proportion to the risk that an AI system poses to people's safety and fundamental rights. Systems posing the greatest risk are banned outright, high-risk systems carry strict pre- and post-market obligations, and low-risk systems are subject to only minimal transparency requirements.
The law's main pillars are as follows.
- A four-tier risk classification: unacceptable, high, limited, and minimal
- Strict obligations for high-risk AI, covering risk management, data quality, documentation, and human oversight
- Transparency obligations for limited-risk AI (such as chatbots), namely informing users that they are interacting with AI
- Broad extraterritorial scope that also applies to non-EU companies placing products on the EU market
Why a "Risk-Based" Approach?
The key to understanding this law's design is that it regulates use, not technology. The same facial-recognition algorithm counts as minimal risk when it powers auto-tagging in a photo app, yet moves close to unacceptable when it drives real-time identification surveillance in public spaces. Banning a technology outright would freeze innovation and quickly leave the rules obsolete, whereas tying obligations to the risk of each use lets the technology advance while filtering out only the most harmful applications. That is precisely why the EU chose "where it is used" as its regulatory axis instead of chasing individual algorithms.
A clear intent runs through this choice. The EU is trying to standardize a "third way" that differs from America's self-regulation and China's state control: keep the market open, but treat fundamental rights as a constant of regulation. Concentrating the burden on a small set of high-risk and banned uses while leaving the vast majority of AI effectively free is also a political balancing act meant to blunt the charge that regulation crushes the whole industry. Yet "use" is a fluid criterion with shifting boundaries, so the scheme carries a built-in weakness: disputes over interpretation are all but inevitable when an actual tier is decided.
AI Risk Classification Tiers
The EU AI Act classifies AI systems into four tiers according to their level of risk. The criterion for classification is the magnitude of potential harm an AI poses to people's safety and rights, and the higher the tier, the stronger the regulation. A defining feature of this classification scheme, finalized in 2024, is that the same technology can fall into a different tier depending on where and how it is used.
| Risk Tier | Meaning | Regulatory Intensity |
|---|---|---|
| Unacceptable | Uses that seriously infringe fundamental rights | Banned in principle |
| High | AI used in critical domains such as hiring, education, and healthcare | Strict pre- and post-market obligations |
| Limited | Direct interaction with users, such as chatbots | Transparency disclosure obligations |
| Minimal | Most AI, such as spam filters and games | Few or no specific obligations |
As the table shows, the regulatory burden is concentrated at the high-risk tier and above, while the majority of AI on the market today falls under minimal risk.
How to Read the Table: Where the Burden Piles Up
The point practitioners should notice in this tier table is that regulatory intensity is not evenly distributed. Four tiers sit side by side, but the real burden concentrates in essentially one of them: high risk. Unacceptable covers a small set of uses that were never allowed in the first place and is irrelevant to most companies; minimal risk carries almost no obligations; and limited risk stops at the relatively light duty of disclosing that "this is AI." In the end, the heavy, costly obligations arise at the high-risk tier.
For companies, then, the real battleground is the boundary line of "is our AI high-risk or not?" When AI intervenes in domains that heavily shape people's lives, such as hiring, education, and healthcare, the odds of being pulled into the high-risk tier rise, and at that moment the heavy load of risk management, data governance, technical documentation, and human oversight attaches all at once. That is why the table should be read not as a simple classification chart but as a staircase where costs spike at a specific step.
What Companies Need to Prepare
The first thing companies need to do is determine which risk tier their AI falls into. As of 2026, with the EU AI Act's obligations taking effect in phases, any company with a connection to the EU market should begin with tier assessment and documentation. The recommended preparation sequence is as follows.
- Inventory your AI systems and classify the risk tier of each.
- If a system is high-risk, build out a risk-management framework, data governance, and technical documentation.
- For limited-risk AI such as chatbots, apply transparency disclosures that inform users they are interacting with AI.
- Establish human-oversight procedures and processes for responding to incidents and errors.
- Designate internal compliance owners and review cycles aligned with the enforcement timeline.
EU AI Act Enforcement Timeline
The EU AI Act does not take full effect all at once; it is enforced in phases, obligation by obligation. After the law entered into force in 2024, the rules on banned AI applied first, with the remaining provisions, such as obligations for high-risk systems, taking effect in sequence. Even as of 2026, some obligations are already in force while others are still set to take effect in later phases, so companies must individually verify the effective dates of the provisions that apply to them.
The general flow of phased enforcement is as follows.
- Immediately after entry into force: rules on the unacceptable (banned) tier apply first
- Intermediate phase: transparency and documentation obligations apply to general-purpose AI models and the like
- Later phase: strict obligations for high-risk systems come into full effect
The Trap Hidden in Phased Enforcement
The fact that the timeline is split by tier is not mere administrative convenience; it is a variable that changes how you should respond. Because banned rules switch on first and high-risk obligations arrive later, it is easy to conclude that "our obligations haven't taken effect yet, so we can prepare later." But the risk-management framework, data governance, and technical documentation required for high-risk systems are not paperwork you can produce overnight to hit an effective date. Reconstructing data lineage after the fact and embedding oversight procedures into a real organization take months to years.
So the question a company must answer is not "when does the whole law take effect?" but "exactly when does the provision that binds us switch on?" If you fail to work backward from the effective date to secure enough lead time, you can end up in a situation where the rule is still deferred yet the actual work is already behind. Phased enforcement looks like a buffer, but for companies that cannot manage each provision's deadline individually, it is closer to a trap that invites complacency.
Impact on Korean Companies
Korean companies are also subject to the EU AI Act if they offer AI products or services to the EU market. The Act applies based on whether the AI is used in the EU market, not on where the operator is located, so even a company headquartered in Korea falls under its obligations if it serves EU customers. As of 2026, Korean IT, manufacturing, and platform companies that have entered or plan to enter the EU would be wise to assess their AI's risk tier and the resulting obligations in advance.
In particular, the following impacts are expected.
- Increased burden of tier classification and technical documentation for AI products exported to the EU
- Additional compliance costs, such as certification and documentation, if a system is classified as high-risk
- Following GDPR, the spread of EU AI regulation as a global standard, which will also influence the shaping of domestic regulation
A GDPR Déjà Vu: Why This Is Not Someone Else's Problem for Korea
The reason Korean companies cannot dismiss this law as another country's regulation is that the trigger for coverage is not "where the company sits" but "whether the AI is used in the EU market." This extraterritorial structure is a replay of a scenario Korea already lived through with GDPR. Back then, many Korean firms put off preparing on the grounds that "we are not a European company," only to be forced later to overhaul their personal-data handling because they processed EU customers' data. The EU AI Act extends that same logic into the AI domain, and any company that went through GDPR already knows how the story ends.
The more consequential ripple is the backflow into domestic regulation. Just as GDPR effectively became a reference standard for amendments to Korea's data-protection law, the EU AI Act is likely to provide a blueprint for how Korea shapes its own AI rules down the road. In other words, the risk-tier assessment, documentation, and human-oversight systems a company builds now for EU compliance may not be a one-off cost for exporting to the EU, but an advance investment in capabilities that will soon be demanded domestically as well. Even companies with no plans to enter the EU stand to gain from watching this trend early.

AI & tech,
read in depth
Beyond the headlines — into the context and the structure
AGI Soon As Possible · asapai.co.kr