AI Governance Library

AI Governance around the world: Country Profile: European Union

A country profile of the European Union's approach to AI regulation and standardisation, covering the EU AI Act, the GPAI Code of Practice, the AI Pact and the European standardisation system. Published by The Alan Turing Institute.
Cover of AI Governance around the world: Country Profile: European Union

⚡ Quick Summary

Published by The Alan Turing Institute, this profile of the European Union forms part of the AI governance around the world project, which maps jurisdictions' approaches to AI regulation and standardisation through a series of country profiles built on a consistent framework and drawing exclusively on primary sources.

The profile sets out the EU's 'harder' governance approach, based on legally binding requirements designed to ensure AI is developed and used safely and responsibly. It describes the high-level aims and principles, including the three objectives of the 2018 Artificial Intelligence for Europe strategy and the ethical principles first presented by the High Level Expert Group, quotes the definition of an AI system in Art. 3(1) of the EU AI Act, and traces key policy initiatives from the 2018 strategy to the General Purpose AI Code of Practice of August 2025.

Most of the document analyses the EU AI Act: its risk-based tiers, from prohibited practices to minimal risk; obligations for general purpose AI models and for providers of models with systemic risk; its scope beyond EU borders; and the bodies responsible for implementation. It closes with the European standardisation system, the work of CEN-CENELEC/JTC 21 and international engagement.

🧩 What’s Covered

  • Executive summary: characterises the EU approach as 'harder' than most, resting on legally binding requirements, and notes that European harmonised standards will be voluntary but will grant a presumption of conformity with specific EU AI Act requirements.
  • High-level aims and principles: the three objectives of the first EU AI strategy; the ethical principles integrated into the EU AI Act (data governance and quality, traceability and technical documentation, transparency, human oversight and accuracy, robustness and security); the ten standardisation deliverables requested from CEN and CENELEC; and the five areas of intervention in the April 2025 AI Continent Action Plan.
  • Definitions of relevant technologies: the Art. 3(1) definition of an AI system, compared with the 2021 draft proposal and the OECD definition, plus the February 2025 Commission guidelines and concerns that exemptions for 'simple prediction systems' and 'systems improving mathematical optimisation' narrow its scope.
  • Key policy initiatives: a timeline from the 2018 strategy to the August 2025 GPAI Code of Practice; the wider digital regulatory ecosystem (Data Act, Data Governance Act, Digital Market Act, Digital Services Act, GDPR, Product Liability Directive); and planned measures including the Apply AI Strategy, the European Strategy for AI in Science and the Cloud and AI Development Act.
  • Horizontal initiatives: the EU AI Act's risk tiers — prohibited practices, high-risk requirements covering risk management, data management, transparency, accuracy, robustness, cybersecurity, human oversight and record-keeping, transparency obligations for certain systems and minimal-risk systems — plus GPAI obligations, systemic-risk duties (model evaluations, incident reporting, cybersecurity) and the implementing bodies, from the AI Office and AI Board to national notifying and market surveillance authorities.
  • GPAI Code of Practice and AI Pact: the Code's Transparency, Copyright and Safety and Security chapters, its multi-stakeholder drafting with over 1,000 organisations, named signatories and the positions of xAI and Meta; and the voluntary pledges of the EU AI Pact.
  • Data-related legislation and vertical initiatives: GDPR, Data Governance Act, Data Act and Open Data Directive, and the sector-specific provisions that classify certain uses as high-risk.
  • Approach to standardisation: the Commission's power to set priorities and request harmonised standards, the presumption of conformity they confer, the role of CEN, CENELEC and ETSI under Regulation (EU) No 1025/2012, the work of CEN-CENELEC/JTC 21 with more than 130 participants, and its delayed deliverables (due 31 January 2025, postponed to August 2025, now expected in summer 2026).

💡 Why it matters?

For organisations that trade into the European market or whose AI systems affect people in the EU, the profile sets out in one place the obligations that follow: the prohibited practices, the requirements attached to high-risk systems, the transparency duties and the separate regime for general purpose AI models and systemic risk. It explains how harmonised standards will operate as a compliance route through the presumption of conformity, and it identifies the bodies and instruments — AI Act Service Desk, GPAI Code of Practice, guidelines — that shape implementation. That helps compliance, legal and standards teams plan against a regime the document describes as having a very large scope.

❓ What’s Missing

The project states that it describes governance models without commenting on their efficacy, so the profile offers no assessment of whether the EU approach works, and the document itself leaves open whether the EU AI Act will be implemented as broadly as it potentially can. National implementation is treated briefly: the profile notes that Member States must designate notifying and market surveillance authorities but does not describe them. The ten standardisation deliverables are named collectively rather than itemised, and the harmonised standards remain unresolved, with publication now expected in summer 2026. Penalties, the application dates of the remaining provisions and sector-by-sector detail are not covered.

👥 Best For

Best suited to compliance and legal teams scoping what the EU AI Act and its supporting instruments require, to standards participants tracking CEN-CENELEC/JTC 21 deliverables and international alignment, and to policy analysts and researchers who need a primary-source account of EU AI governance that can be compared with the other country profiles in the series.

📄 Source Details

AI Governance around the world: Country Profile: European Union, by Arcangelo Leone de Castris, The Alan Turing Institute, August 2025. The citation printed in the document is Leone de Castris, A. (2025), The Alan Turing Institute, DOI https://doi.org/10.5281/zenodo.16779366. The profile runs to 17 pages and is in English; the acknowledgements record expert review by Matthieu Binder and Franziska Busse of Zentrum für Vertrauenswürdige KI. The text extraction covered all 17 pages, the last of which carries no substantive content.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.