Understanding the EU AI Act’s Impact on Legacy Systems

Does the EU AI Act Apply to “Old” AI Systems?

As the discussion around artificial intelligence (AI) regulation intensifies, a pressing question emerges: What happens to AI systems that were built and deployed before the EU AI Act enters into force? The short answer is that the Act is generally not retroactive, but important exceptions and transitional obligations exist.

The Non-Retroactivity Principle

The AI Act is not retroactive, meaning that:

  • AI systems placed on the market or put into service before 2 August 2025 are largely exempt from the Act’s new obligations.
  • However, this exemption does not apply to certain prohibited AI practices under Article 5 of the Act.

Key Prohibited Practices Affecting All AI Systems

Regardless of when the AI system was deployed, the following uses are banned and must be phased out:

  • Social scoring by governments
  • Real-time biometric identification in public spaces (with limited exceptions)
  • Exploitative manipulation of vulnerable groups
  • Dark pattern AI designed to materially distort user behavior

Any legacy AI falling under these categories must be immediately remediated or discontinued.

Important Transition Dates & Compliance Triggers

When Do Legacy AI Systems Have to Comply?

1. Substantial Modification

If an AI system placed on the market before 2 August 2025 is substantially modified after 2 August 2026, it is treated as a new system and must comply fully with the AI Act.

  • Substantial modification refers to significant changes to design, functionality, or intended purpose (see Article 3(23), Recital 177).
  • The party performing the modification could be considered a quasi-provider and thus take on legal obligations.

2. Special Rules for General-Purpose AI Models (GPAI)

For foundation models like GPT, LLaMA, and similar systems:

  • Models already on the market before 2 August 2025 must comply with certain transparency, risk management, and copyright obligations starting 2 August 2027.
  • This transition period allows for auditing, policy updates, and implementation of safeguards against systemic risks.

3. Public Sector High-Risk AI Systems

Public authorities using high-risk AI systems deployed before 2 August 2025 have until 2 August 2030 to ensure full compliance.

  • The AI Act acknowledges the complexity and budget cycles of public administrations.
  • Providers and deployers in this space must retrofit, replace, or decommission older AI to meet requirements by this deadline.

4. Special Consideration: Large-Scale European Information Systems

Legacy AI systems used in critical EU public infrastructures (under Annex X, e.g., Schengen Information System, Eurodac):

  • Exempt only temporarily if deployed before 2 August 2027.
  • Any substantial modification triggers compliance immediately.
  • New deployments after this date must comply fully from the outset.

Summary: AI Act Applicability to Legacy AI

While the AI Act generally exempts legacy AI systems from most new obligations, non-compliance, especially related to prohibited practices or high-risk AI, can lead to substantial fines under Article 99. These penalties can reach up to €35 million or 7% of global annual turnover.

Importantly, the AI Act is not intended to hinder technological progress. Instead, it reflects the EU’s commitment to strike a balance between innovation and the protection of fundamental rights and critical infrastructure.

Effective AI Governance

Effective AI governance begins with proactive readiness. Organizations should first identify their most opaque or high-impact AI systems, those where risks and uncertainties converge, and prioritize these. From there, building a structured, risk-based AI management approach becomes not just a regulatory necessity but a strategic advantage.

More Insights

State AI Regulation: A Bipartisan Debate on Federal Preemption

The One Big Beautiful Bill Act includes a provision to prohibit state regulation of artificial intelligence (AI), which has drawn criticism from some Republicans, including Congresswoman Marjorie...

IBM Launches Groundbreaking Unified AI Security and Governance Solution

IBM has introduced a unified AI security and governance software that integrates watsonx.governance with Guardium AI Security, claiming to be the industry's first solution for managing risks...

Ethical AI: Building Responsible Governance Frameworks

As AI becomes integral to decision-making across various industries, establishing robust ethical governance frameworks is essential to address challenges such as bias and lack of transparency...

Reclaiming Africa’s AI Future: A Call for Sovereign Innovation

As Africa celebrates its month, it is crucial to emphasize that the continent's future in AI must not merely replicate global narratives but rather be rooted in its own values and contexts. Africa is...

Mastering AI and Data Sovereignty for Competitive Advantage

The global economy is undergoing a transformation driven by data and artificial intelligence, with the digital economy projected to reach $16.5 trillion by 2028. Organizations are urged to prioritize...

Pope Leo XIV: Pioneering Ethical Standards for AI Regulation

Pope Leo XIV has emerged as a key figure in global discussions on AI regulation, emphasizing the need for ethical measures to address the challenges posed by artificial intelligence. He aims to...

Empowering States to Regulate AI

The article discusses the potential negative impact of a proposed moratorium on state-level AI regulation, arguing that it could stifle innovation and endanger national security. It emphasizes that...

AI Governance Made Easy: Wild Tech’s Innovative Solution

Wild Tech has launched a new platform called Agentic Governance in a Box, designed to help organizations manage AI sprawl and improve user and data governance. This Microsoft-aligned solution aims to...

Unified AI Security: Strengthening Governance for Agentic Systems

IBM has introduced the industry's first software to unify AI security and governance for AI agents, enhancing its watsonx.governance and Guardium AI Security tools. These capabilities aim to help...