International Edition
Latest News
Technology

Y Combinator Comments: Insight into Startup Ecosystem

The State of AI Governance: Understanding the EU AI Act Implementation The European Union’s Artificial Intelligence Act, the world’s first comprehensive horizontal legal framework for AI, officially entered into force on August 1, 2024. According to the [European…

Y Combinator Comments: Insight into Startup Ecosystem

The State of AI Governance: Understanding the EU AI Act Implementation

The European Union’s Artificial Intelligence Act, the world’s first comprehensive horizontal legal framework for AI, officially entered into force on August 1, 2024. According to the [European Commission](https://digital-strategy.ec.europa.eu/en/policies/ai-act), the regulation establishes a tiered risk-based approach to AI development and deployment, mandating strict compliance for high-risk systems while placing light-touch obligations on lower-risk applications.

Risk Categorization and Regulatory Requirements

The EU AI Act classifies AI systems into four distinct categories based on the potential harm they pose to fundamental rights and safety. This framework dictates the legal obligations for developers and deployers:

* Unacceptable Risk: AI systems deemed to pose a clear threat to fundamental rights—such as social scoring systems or real-time biometric identification in public spaces by law enforcement—are strictly prohibited, with limited, narrow exceptions for specific criminal investigations.
* High-Risk: This category includes AI used in critical infrastructure, education, employment, and essential private and public services. According to the [European Parliament](https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence), these systems must undergo mandatory conformity assessments, maintain high-quality data governance, and ensure human oversight before reaching the market.
* Limited Risk: Systems such as chatbots or AI-generated content tools face transparency obligations. Users must be clearly informed they are interacting with an AI, allowing them to make informed decisions.
* Minimal Risk: The vast majority of AI systems, including spam filters or AI-enabled video games, fall into this category and remain largely unregulated, allowing for free use without additional legal requirements.

Compliance Timelines and Enforcement

Y Combinator's Michael Siebel on Startup Success: The Real Challenges and Insights

While the regulation is now in force, the application of its rules is staggered to allow organizations time to adapt. As noted by the [European Union Agency for Cybersecurity (ENISA)](https://www.enisa.europa.eu/topics/cybersecurity-policy/ai-act), the prohibitions on unacceptable-risk AI systems apply six months after the entry into force date.

Rules for General Purpose AI (GPAI) models—the foundational technology behind systems like large language models—will apply 12 months after the regulation’s start. Most other provisions, including the governance structure and the full suite of requirements for high-risk systems, will become enforceable 24 months after the effective date. The European AI Office, established within the Commission, serves as the central enforcement body, coordinating with national authorities to ensure consistent application across all EU member states.

Global Implications for AI Development

The EU AI Act functions as a “Brussels Effect” instrument, likely influencing global standards in a manner similar to the General Data Protection Regulation (GDPR). Because the act applies to any AI provider placing systems on the EU market, regardless of where the company is headquartered, international firms must adjust their development pipelines to meet these specifications.

Critics and industry proponents have offered varying perspectives on the impact of these regulations. Some industry groups have expressed concerns regarding potential stifling of innovation, while civil society organizations, such as [European Digital Rights (EDRi)](https://edri.org/our-work/ai-act-a-first-step-towards-regulating-ai/), have highlighted the need for rigorous enforcement to prevent the misuse of biometric surveillance and automated decision-making.

Key Takeaways

* Scope: The law applies to any AI system used or placed on the EU market, regardless of the developer’s location.
* Prohibitions: Social scoring and certain forms of predictive policing are banned.
* Transparency: Deepfakes and AI-generated content must be clearly labeled to prevent misinformation.
* Governance: The European AI Office will oversee systemic risk, particularly regarding powerful foundational models.

As the regulation moves into its implementation phase, the focus shifts from legislative debate to technical standard-setting. The European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC) are currently working to define the harmonized standards that will provide the technical roadmap for companies to prove their compliance with the law’s safety and transparency requirements.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”