Image for an article about the EU AI Act.

EU AI Act: What it is and what it means for data and analytics

Contents

Ready to use in minutes, Matomo gives you:
✔ Accurate privacy-first analytics
✔ Full data ownership
✔ GDPR compliance

AI is now part of everyday life, from the recommendations you see in AI overviews to systems that detect fraud. As its use grows, so do concerns around transparency, fairness and how user data is handled.

The European Union (EU) has already introduced laws like the General Data Protection Regulation (GDPR) and the ePrivacy Directive to protect personal data. But AI introduces new privacy challenges and ethical questions, especially when systems start making or influencing decisions.

To address this, the EU introduced the EU AI Act, a regulation that ensures businesses use AI safely and responsibly.  

In this post, we will see how it works and what it means for how businesses and how they use web analytics.

Key takeaways

  • The EU AI Act offers a risk-based framework for AI, with stricter rules for systems that pose greater risks to individuals and society.
  • Businesses should understand how AI tools use data and fit within their broader compliance responsibilities.
  • Non-compliance can result in significant financial penalties, making early preparation essential.
  • As AI features become more common in web analytics, many organisations are turning to platforms such as Matomo that prioritise privacy, transparency and responsible data practices.

What’s the EU AI Act?

The EU AI Act is the EU’s first comprehensive law for artificial intelligence and shares guidelines on how to develop and use AI systems. It was proposed by the European Commission in 2021. The EU adopted the AI Act in 2024, with obligations applying in phases.

The Act defines an AI system broadly as a machine-based system that can infer, from inputs, how to generate outputs such as predictions, content, recommendations or decisions that may influence physical or virtual environments. It classifies AI systems into various risk categories and applies requirements accordingly, which we cover in the next sections.

How the EU AI Act classifies AI: 4 risk categories

The Act uses a risk-based approach to help create regulatory guidelines. AI systems are grouped based on how much risk they pose.

The Act groups AI into four main categories. These labels aren’t just technical names: they decide how much control, transparency and oversight the AI system must have. The framework applies mainly to AI systems. General-purpose AI models are treated separately under the Act.

Unacceptable risk (banned)

Unacceptable-risk is considered dangerous, so the law bans it. These are uses that can violate privacy or create unfair control over individuals. In practice, businesses should avoid building or using these systems.

Examples:

  • Social scoring by governments or public authorities
  • AI systems that manipulate people in harmful ways
  • Certain biometric surveillance uses
  • Creating facial recognition databases by scraping images from the internet or other sources like CCTV
  • Emotion recognition in workplaces and educational institutions
  • Some forms of biometric categorisation of people

This category matters because it draws a clear red line. If an AI is used here, the question is not how to make it compliant, it is whether it should be used at all.

High risk

The EU AI Act allows high-risk AI, but it must follow some rules in cases where it can affect people’s lives. That is why the EU expects extra care and documentation.

Examples:

  • Healthcare systems that support with diagnosis and treatment decisions
  • AI used for hiring or recruitment processes like CVs or ranking candidates
  • Credit scoring systems
  • AI used in education, such as systems that influence admissions or assessments
  • AI used in critical infrastructure
  • Certain biometric identification systems
  • AI systems used for law enforcement or border control in specific cases

What happens after a system is classified as high risk? The business must treat it with much more care and:

  • Check for potential risks and design measures to reduce them
  • Use high-quality data for minimal errors and fair results  
  • Keep records of how the system functions and makes decisions
  • Provide users with enough information to use the system properly
  • Have humans intervene in critical matters so that all decisions aren’t left entirely to AI
  • Protect the system against security threats and maintain a high level of accuracy and reliability

Limited risk

Limited risk, also called transparency risk, is not usually considered dangerous, but users need to know that they are interacting with AI. This is why the main concern here is transparency and the systems must not mislead them.

Examples:

  • Chatbots that talk to customers
  • AI assistants that answer basic questions on websites
  • Tools that generate synthetic content, where users need to know it is AI-made
  • Recommendation tools that interact directly with users in a visible way
  • Virtual assistants that guide users through a process

These transparency obligations are due to apply from 2 August 2026.

Minimal risk

Minimal-risk AI has very little impact on people’s rights or safety. Examples include spam filters or simple AI tools that do not affect important decisions.

These tools can generally be used freely, with no special AI Act obligations. In other words, the law expects very little here because the risk to people is low.

What happens after classification

First, a business has to figure out what AI tools it uses or builds, whether they count as an AI system, how they are used, and what role the business plays, such as provider or deployer. Then it checks which risk category the system falls into, because that category determines the next steps.

If the system is high risk, the business must prepare for the extra obligations that apply before and after launch, although the relevant rules are being phased in over time. If the system is high risk, the business must prepare for the extra obligations that apply before and after launch, although the relevant rules are being phased in over time. Current Commission guidance refers to application from 2 December 2027 for certain high-risk areas and from 2 August 2028 for systems integrated into regulated products. Organisations should verify the latest implementation timeline before relying on these dates.

Risk classification vs. general-purpose AI

General-purpose AI, or GPAI, is AI that can do many different tasks like answer questions, summarise documents or help generate images. It’s flexible, so it could be for high-risk or low-risk both.

That is why the EU AI Act treats GPAI separately instead of putting it into the normal risk categories. These rules are about clarity, safety and accountability. They also make it easier to build on AI in a responsible way.

What all GPAI providers must do

The Act asks GPAI providers to be transparent and responsible. They must draw up technical documentation and provide relevant information to downstream providers so those providers can understand the model’s capabilities and limitations and meet their own AI Act obligations.

In addition, providers must establish a policy to respect EU copyright rules. They also need to publish a detailed summary of what content they use to train the model. In simple terms, the provider has to explain what the model is, how it was built, and what kind of data helped shape it.

Free and open licence GPAI models

Some GPAI models are released under a free and open licence. This means the model’s parameters, weights, architecture and usage terms are publicly available, so people can access, use, modify and share it more freely.

Free and open-licence GPAI models benefit from lighter obligations where the model doesn’t present systemic risk. In general, the open-source exemption reduces documentation and downstream-information duties, but copyright-policy and training-content-summary obligations may still apply. Stricter obligations apply where a model presents systemic risk.

Safe testing spaces for AI with sandboxes

The AI Act isn’t only about restrictions. It also gives companies a way to test AI safely, especially when the rules are new and they need clearer guidance. So the Act does two things simultaneously: control AI risk and still encourage new ideas.

AI regulatory sandboxes are controlled testing spaces for AI systems before they are launched. They help companies develop, train, test and validate AI systems and give businesses legal guidance while helping them understand what compliance can look like in practice. They are especially useful for SMEs and startups since they may not have large compliance teams or much legal support. These can also let regulators and companies learn from each other, which can help create better rules.

Each EU Member State must set up at least one sandbox, and some can do it together. National authorities guide, supervise and help identify risks and compliance issues.

Companies can use sandbox documentation to help show compliance with the AI Act. Participation in a sandbox doesn’t remove legal responsibility, but where companies follow the approved sandbox plan and guidance in good faith, this may reduce the risk of administrative fines for issues covered by the sandbox process.

In some public-interest projects, personal data may be used inside a sandbox, but only if it is necessary, kept secure, not shared outside and deleted after use.

How the EU AI Act affects businesses and web analytics

Web analytics may seem unrelated to the EU AI Act. After all, many analytics tools simply measure website traffic and user engagement.

But modern analytics platforms go beyond just counting visits and page views. Some use AI to:

  • Predict which users are likely to convert or leave a website
  • Identify behavioural patterns across large datasets
  • Segment audiences automatically
  • Recommend content, products or marketing actions
  • Generate reports without manual effort

Not every analytics platform, dashboard or reporting function will qualify as an AI system under the AI Act. The assessment depends on the specific feature, its intended purpose, the outputs it generates, and whether the organisation is acting as a provider, deployer, importer, distributor or another regulated role.

Under the Act, providers of AI systems need to assess whether their products follow the regulation’s framework. The obligations depend on the type of technology, how it is used and the level of risk it carries.  

Choosing an analytics platform is not just a technology decision. Organisations should understand how the tool works as well as what data it depends on and what responsibilities may arise from its use. For businesses evaluating analytics tools, they need to ask questions like:  

  • Does the platform offer AI-powered features?
  • How does the vendor describe those features?
  • Does the vendor provide information about any applicable AI Act obligations?
  • What data does the system use to generate insights?

As a result, many organisations are exploring privacy-focused platforms such as Matomo. We’ll look at Matomo and its approach to analytics in the next section.

Moving towards privacy-first analytics

Many organisations, due to regulatory demands, now want in-depth website insights without collecting excessive data.

This is where Matomo comes in. It’s a privacy-first platform and with it you can:

Keep control of your data

In analytics, it’s important to know how the software accesses data and how it is being used. With Matomo, organisations get to retain control over their analytics data. They can decide where it is stored, who can use it and how long it should remain available.

Choose where data lives

Many organisations that have strict compliance requirements, like healthcare, can’t store data outside their systems. Matomo offers a self-hosted option that lets businesses keep analytics data within their own infrastructure.

Reduce reliance on cookies

Due to privacy expectations, organisations need to now rethink their approach to cookies. Matomo supports cookieless tracking options. These help teams measure website performance while reducing dependence on cookie-based tracking methods.

Put privacy controls into practice

What matters in privacy is really small operational decisions. For example, organisations can anonymise visitor data by masking parts of IP addresses and set retention periods that automatically remove information when it is no longer needed. These controls make it easier to align analytics practices with broader privacy goals.

Still get the insights you need

Privacy-focused analytics doesn’t mean that you need to sacrifice visibility into data.  Organisations still need to understand traffic sources, user journeys, conversions and content performance. Matomo can provide these types of insights while giving businesses more control over how data is collected and managed.

Conclusion

The EU AI Act encourages organisations to take a closer look at how they use AI and the responsibilities that come with it.

This means considering the technologies used every day, including web analytics platforms that influence how data is collected, analysed and applied across the customer journey.

This is one reason why many organisations are searching for solutions that offer both transparency and control. Platforms such as Matomo help businesses gain valuable insights into website performance while giving them greater control over analytics data and, especially with self-hosted deployments, reducing reliance on third-party data processing.

Today, Matomo powers more than 1 million websites worldwide.

Get started with Matomo by downloading the free on-premise version or trying Matomo Cloud with a 21-day free trial, no credit card required.

FAQs

What exemptions are included under the EU AI Act?

​​The EU AI Act does not cover every AI use. It exempts AI used only for military, defence or national security purposes, and it also leaves out research, testing and development that happen before an AI system is put on the market or into service.

What penalties can organisations face for non-compliance?

The EU AI Act includes significant financial penalties. For many organisations, the relevant cap is the higher of the fixed amount or turnover percentage, while for SMEs the AI Act applies the lower of the two thresholds.

  • Non-compliance with the prohibition of banned AI practices can result in fines of up to €35 million or 7% of global annual turnover.
  • Failure to meet high-risk AI systems requirements, transparency obligations or other provisions of the Act can lead to fines of up to €15 million or 3% of global annual turnover.
  • Organisations that supply incorrect, incomplete or misleading information to regulators may face fines of up to €7.5 million or 1% of global annual turnover.

What is the timeline for enforcement?

​​Most of its requirements will start applying from 2 August 2026, which will give organisations time to understand the rules and prepare accordingly.

However, some provisions arrive sooner. Rules banning AI systems that present an unacceptable level of risk began applying six months after the Act entered into force. Requirements for general-purpose AI models, such as large language models, follow after 12 months.

The European Commission has also launched an AI Pact which is a voluntary initiative to encourage companies to start adopting key principles before it becomes formal.

The Commission is also working on practical guidance and codes of practice to help businesses interpret and apply the new rules.

Which authorities are responsible for oversight?

Three bodies support the implementation of the AI Act.

  • The European AI Board helps national authorities stay aligned and consistent when applying the rules.
  • Technical questions are handled by the Scientific Panel of Independent Experts. The panel advises on complex AI issues and can raise concerns if it identifies risks linked to GPAI models.
  • The Advisory Forum brings a broader perspective. It includes voices from industry, academia and civil society, helping ensure that discussions about AI are not shaped by regulators alone.

Does the EU AI Act address AI’s environmental impact?

Yes. While the AI Act primarily focuses on safety and fundamental rights, it also recognises the environmental impact of AI systems.

Large AI models can require significant computing power and energy. To improve transparency, providers of certain GPAI models must disclose information about their energy consumption. For the most powerful models, energy efficiency may also form part of the risk assessment process.

The European Commission is also working with standards bodies to develop guidance on measuring and improving the resource efficiency of AI systems, including energy use throughout their lifecycle.

Démarrez avec Matomo

En choisissant Matomo, l’alternative éthique pour l’analyse web, vous ne faîtes aucun compromis concernant la confidentialité et la sécurité de vos données privées.

Enjoyed this post?
Join the 160,000+ subscribers who receive the Matomo Newsletter straight to their inbox every month

https://matomo.org/newsletter (last update: 2026/07/22)

Ce champ n’est utilisé qu’à des fins de validation et devrait rester inchangé.

Certifié ISO 27001:2022

Vos données analytics sont protégées par des standards de sécurité reconnus à l’international. La certification ISO 27001 garantit que nous appliquons les plus hauts standards de gestion de la sécurité de l’information.

Sites web en ligne à travers le monde
0 K
de sites web ont utilisé Matomo
0 M
de satisfaction client
0 %

Gardez le contrôle de vos données. Respectez la vie privée de vos utilisateurs. Accédez à des analyses plus performantes.

Les organisations devraient pouvoir comprendre leurs performances numériques tout en conservant la pleine propriété et le contrôle de leurs données.

Aucune carte bancaire requise.