A Watershed Moment for AI Governance

The European Union has passed the AI Safety Regulation, the most comprehensive piece of AI legislation in history. The regulation creates a risk-based framework that categorizes AI systems into four tiers — unacceptable risk, high risk, limited risk, and minimal risk — with corresponding obligations for developers and deployers.

What's Covered

High-risk AI systems — those used in critical infrastructure, education, employment, law enforcement, and healthcare — must comply with strict requirements: human oversight, transparency, accuracy, robustness, and cybersecurity. General-purpose AI models like GPT-5 must provide detailed technical documentation and comply with copyright transparency requirements.

Timeline and Penalties

The regulation will be implemented in phases: prohibited practices provisions within 6 months, general-purpose AI rules within 12 months, and full compliance for high-risk systems within 24 months. Penalties range up to 7% of global annual turnover or €35 million, whichever is higher.

What Developers Must Do Now

Companies deploying AI in the EU should immediately begin: (1) classifying all AI systems by risk tier; (2) implementing transparency documentation; (3) establishing human oversight protocols; (4) conducting fundamental rights impact assessments for high-risk systems.