Article content
In briefShow moreShow lessThe Council gave final approval to the AI Act on 21 May 2024.
- The Council gave final approval to the AI Act on 21 May 2024.
- Approval completed the EU legislative process but did not start every duty.
- Final EU adoption did not make the regulation applicable in Norway. EEA incorporation and Norwegian legislation remained outstanding.
What happened
The Council gave final approval to the AI Act on 21 May 2024. Its risk-based model combined prohibitions, requirements for high-risk systems, lighter transparency duties and dedicated rules for general-purpose models.
Approval completed the EU legislative process but did not start every duty. Signature, publication, entry into force and the phased application dates still had to be distinguished.
Legal status in Norway
Final EU adoption did not make the regulation applicable in Norway. EEA incorporation and Norwegian legislation remained outstanding.
What the sources clarify
The Council decision also described the enforcement architecture. The AI Office received a central role for general-purpose AI models, while an AI Board of member-state representatives would support consistent application. Certain public-sector deployers of high-risk systems would need a fundamental-rights impact assessment and registration in an EU database. Procurement teams therefore had to know whether the organisation was a deployer, importer or had modified a system so substantially that its role changed. Role and intended purpose determine which documents, controls and reporting capabilities must be obtained before deployment.
This makes the supplier's label less decisive than the organisation's actual use. A customer that changes purpose, adds its own data or embeds the system in a decision process may acquire duties the original contract did not anticipate. Approval should therefore record role, permitted use, accountable owner and the changes that trigger renewed legal and technical assessment.
Practical implications
Management should specify who approves role changes and which supplier evidence is mandatory before launch. Where documentation, logging or an incident channel is absent, the decision should be to restrict or postpone use. Role mapping then becomes an effective control rather than merely a field in the system inventory.
Sources
Council of the European Union: “AI Act: Council gives final green light,” 21 May 2024.
European Parliament: “European Parliament legislative resolution on the Artificial Intelligence Act,” 13 March 2024.
For discussion
Where is the largest gap between documented control and actual practice?







