Plain language · Educational guide
The EU AI Act, explained simply
Regulation (EU) 2024/1689 — the AI Act — is the European framework for artificial intelligence. This guide explains its core ideas in plain language for learners and classrooms. It is an educational simplification, not legal advice.
This page explains the EU AI Act (Regulation (EU) 2024/1689) in plain language for learners: its risk-based approach, prohibited practices, high-risk systems, transparency duties, general-purpose AI, human oversight and data governance. It is a simplified educational overview, not legal advice — for the binding text, see EUR-Lex. Use it alongside the serious game to make the rules concrete.
01What the AI Act is
A European regulation, directly applicable across the EU, that governs how AI systems may be developed and used. Its central intuition: the same technology can be harmless in one context and dangerous in another, so the rules follow the use, not the algorithm.
02The risk-based approach
Instead of one rule for everything, the Act sorts uses of AI into levels: a small set of practices is banned outright; a defined group of high-stakes uses carries strict obligations; some situations require transparency; most everyday uses face no specific new requirements. The full breakdown is on the risk categories page.
03Prohibited practices
Some uses are considered incompatible with fundamental rights regardless of safeguards — the classic teaching example is generalized social scoring that determines access to services in unrelated contexts. More examples and boundaries: prohibited AI practices.
These practices carry the highest penalty ceiling: see AI Act penalties.
04High-risk systems
Systems that significantly affect people's safety, opportunities or rights — in areas like education, employment, essential services or healthcare — are not banned but must earn their deployment: risk management, quality data, documentation, effective human oversight. See high-risk AI systems.
05Transparency obligations
In defined situations people must know they are dealing with AI: chatbots that could be mistaken for humans, synthetic images and deepfakes, and similar cases. Why this matters for users and citizenship: transparency obligations.
06General-purpose AI
Models built for many tasks — including the generative models behind modern chatbots — get their own chapter: obligations for their providers, plus the crucial question of what happens when such a model is used downstream in decisions that matter. See general-purpose AI.
07Human oversight
For high-stakes uses, a human must be able to genuinely understand, question and override the system. The recurring educational point: oversight that exists only on paper — a person who clicks "approve" on every output — is not oversight. The game's cases return to this distinction constantly.
08Data governance and documentation
High-risk systems must be built on relevant, representative data and be documented well enough that an authority (or a buyer) can understand what the system does and how it was validated. "The vendor's manual says it works" is exactly the kind of claim the framework refuses to accept at face value.
09The fundamental-rights frame
Behind the mechanics, the Act's yardstick is the effect of AI systems on people: dignity, non-discrimination, privacy, access to essential services, effective remedies. That is why the same scoring algorithm can be routine in one context and prohibited in another — the difference is what it does to people's rights.
10Roles, public bodies and impact assessment
Move from the general map to operational responsibility with the guides to providers and deployers, public-sector AI adoption and procurement, and the Article 27 FRIA. They answer three different questions: who holds which role, how procurement is governed, and when a fundamental-rights assessment is required.
11Read the real thing
This guide deliberately simplifies. The authoritative sources are the official text on EUR-Lex, the European Commission's AI framework pages and the European AI Office.