Understanding the EU AI Act’s Impact on Legacy Systems

Does the EU AI Act Apply to “Old” AI Systems?

As the discussion around artificial intelligence (AI) regulation intensifies, a pressing question emerges: What happens to AI systems that were built and deployed before the EU AI Act enters into force? The short answer is that the Act is generally not retroactive, but important exceptions and transitional obligations exist.

The Non-Retroactivity Principle

The AI Act is not retroactive, meaning that:

  • AI systems placed on the market or put into service before 2 August 2025 are largely exempt from the Act’s new obligations.
  • However, this exemption does not apply to certain prohibited AI practices under Article 5 of the Act.

Key Prohibited Practices Affecting All AI Systems

Regardless of when the AI system was deployed, the following uses are banned and must be phased out:

  • Social scoring by governments
  • Real-time biometric identification in public spaces (with limited exceptions)
  • Exploitative manipulation of vulnerable groups
  • Dark pattern AI designed to materially distort user behavior

Any legacy AI falling under these categories must be immediately remediated or discontinued.

Important Transition Dates & Compliance Triggers

When Do Legacy AI Systems Have to Comply?

1. Substantial Modification

If an AI system placed on the market before 2 August 2025 is substantially modified after 2 August 2026, it is treated as a new system and must comply fully with the AI Act.

  • Substantial modification refers to significant changes to design, functionality, or intended purpose (see Article 3(23), Recital 177).
  • The party performing the modification could be considered a quasi-provider and thus take on legal obligations.

2. Special Rules for General-Purpose AI Models (GPAI)

For foundation models like GPT, LLaMA, and similar systems:

  • Models already on the market before 2 August 2025 must comply with certain transparency, risk management, and copyright obligations starting 2 August 2027.
  • This transition period allows for auditing, policy updates, and implementation of safeguards against systemic risks.

3. Public Sector High-Risk AI Systems

Public authorities using high-risk AI systems deployed before 2 August 2025 have until 2 August 2030 to ensure full compliance.

  • The AI Act acknowledges the complexity and budget cycles of public administrations.
  • Providers and deployers in this space must retrofit, replace, or decommission older AI to meet requirements by this deadline.

4. Special Consideration: Large-Scale European Information Systems

Legacy AI systems used in critical EU public infrastructures (under Annex X, e.g., Schengen Information System, Eurodac):

  • Exempt only temporarily if deployed before 2 August 2027.
  • Any substantial modification triggers compliance immediately.
  • New deployments after this date must comply fully from the outset.

Summary: AI Act Applicability to Legacy AI

While the AI Act generally exempts legacy AI systems from most new obligations, non-compliance, especially related to prohibited practices or high-risk AI, can lead to substantial fines under Article 99. These penalties can reach up to €35 million or 7% of global annual turnover.

Importantly, the AI Act is not intended to hinder technological progress. Instead, it reflects the EU’s commitment to strike a balance between innovation and the protection of fundamental rights and critical infrastructure.

Effective AI Governance

Effective AI governance begins with proactive readiness. Organizations should first identify their most opaque or high-impact AI systems, those where risks and uncertainties converge, and prioritize these. From there, building a structured, risk-based AI management approach becomes not just a regulatory necessity but a strategic advantage.

More Insights

The Perils of ‘Good Enough’ AI in Compliance

In today's fast-paced world, the allure of 'good enough' AI in compliance can lead to significant legal risks when speed compromises accuracy. Leaders must ensure that AI tools provide explainable...

European Commission Unveils AI Code of Practice for General-Purpose Models

On July 10, 2025, the European Commission published the final version of the General-Purpose AI Code of Practice, which aims to provide a framework for compliance with certain provisions of the EU AI...

EU Introduces New Code to Streamline AI Compliance

The European Union has introduced a voluntary code of practice to assist companies in complying with the upcoming AI Act, which will regulate AI usage across its member states. This code addresses...

Reforming AI Procurement for Government Accountability

This article discusses the importance of procurement processes in the adoption of AI technologies by local governments, highlighting how loopholes can lead to a lack of oversight. It emphasizes the...

Pillar Security Launches Comprehensive AI Security Framework

Pillar Security has developed an AI security framework called the Secure AI Lifecycle Framework (SAIL), aimed at enhancing the industry's approach to AI security through strategy and governance. The...

Tokio Marine Unveils Comprehensive AI Governance Framework

Tokio Marine Holdings has established a formal AI governance framework to guide its global operations in developing and using artificial intelligence. The policy emphasizes transparency, human...

Shadow AI: The Urgent Need for Governance Solutions

Generative AI (GenAI) is rapidly becoming integral to business operations, often without proper oversight or approval, leading to what is termed as Shadow AI. Companies must establish clear governance...

Fragmented Futures: The Battle for AI Regulation

The article discusses the complexities of regulating artificial intelligence (AI) as various countries adopt different approaches to governance, resulting in a fragmented landscape. It explores how...

Fragmented Futures: The Battle for AI Regulation

The article discusses the complexities of regulating artificial intelligence (AI) as various countries adopt different approaches to governance, resulting in a fragmented landscape. It explores how...