惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
U
Unit 42
大猫的无限游戏
大猫的无限游戏
H
Help Net Security
G
Google Developers Blog
Recent Announcements
Recent Announcements
B
Blog RSS Feed
罗磊的独立博客
博客园 - Franky
J
Java Code Geeks
S
SegmentFault 最新的问题
D
DataBreaches.Net
C
Check Point Blog
Blog — PlanetScale
Blog — PlanetScale
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
腾讯CDC
博客园_首页
美团技术团队
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
The Cloudflare Blog
aimingoo的专栏
aimingoo的专栏

Analytics Platform – Matomo

Analytics for decision making: Is your data reliable enough to act on? - Analytics Platform - Matomo Google Analytics Limitations: What GA4 Can’t Do - Analytics Platform - Matomo Matomo launches Reseller Partner Programme - Analytics Platform - Matomo How to check website traffic: A complete guide - Analytics Platform - Matomo Bot Traffic, Ghost Spam and Fake Direct Visits: Keep Analytics Data Clean - Analytics Platform - Matomo Google Analytics Tracking Issues - Analytics Platform - Matomo What Is CNIL? A Simple Guide to France’s Data Protection Authority - Analytics Platform - Matomo 10 Ethical AI Tools for Building a Privacy-First Marketing Stack - Analytics Platform - Matomo Federated Learning: What It Is & How It Protects Privacy - Analytics Platform - Matomo Data Sovereignty vs Data Residency - Analytics Platform - Matomo AI Chatbot Traffic Guide for Web Analytics in 2026 - Analytics Platform - Matomo Social Media Analytics Tools - Analytics Platform - Matomo A Hands-On Guide to Privacy Analytics - Analytics Platform - Matomo Is there a US Data Privacy Act? The potential of data analytics in banking Faster decisions from your data: Matomo MCP is now available. From data silos to tool interoperability: where MCP fits in Google Tag Manager vs Google Analytics 4 (& other solutions) Understanding California’s data privacy laws: CCPA in 2026 Announcing our rebrand: A clearer, more intuitive Matomo CNIL compliance in Matomo is now a single click. Here’s what that changes. Matomo announces new chatbot tracking in its AI Assistants suite, offering comprehensive insights into AI traffic From humans to AI agents: understanding the new web traffic Choosing the right data privacy management software
EU AI Act: What It is and What It Means for Data and Anal...
Hannah Kaufhold · 2026-08-06 · via Analytics Platform – Matomo

AI is now part of everyday life, from the recommendations you see in AI overviews to systems that detect fraud. As its use grows, so do concerns around transparency, fairness and how user data is handled.

The European Union (EU) has already introduced laws like the General Data Protection Regulation (GDPR) and the ePrivacy Directive to protect personal data. But AI introduces new privacy challenges and ethical questions, especially when systems start making or influencing decisions.

To address this, the EU introduced the EU AI Act, a regulation that ensures businesses use AI safely and responsibly.  

In this post, we will see how it works and what it means for how businesses and how they use web analytics.

Key takeaways

  • The EU AI Act offers a risk-based framework for AI, with stricter rules for systems that pose greater risks to individuals and society.
  • Businesses should understand how AI tools use data and fit within their broader compliance responsibilities.
  • Non-compliance can result in significant financial penalties, making early preparation essential.
  • As AI features become more common in web analytics, many organisations are turning to platforms such as Matomo that prioritise privacy, transparency and responsible data practices.

What’s the EU AI Act?

The EU AI Act is the EU’s first comprehensive law for artificial intelligence and shares guidelines on how to develop and use AI systems. It was proposed by the European Commission in 2021. The EU adopted the AI Act in 2024, with obligations applying in phases.

The Act defines an AI system broadly as a machine-based system that can infer, from inputs, how to generate outputs such as predictions, content, recommendations or decisions that may influence physical or virtual environments. It classifies AI systems into various risk categories and applies requirements accordingly, which we cover in the next sections.

How the EU AI Act classifies AI: 4 risk categories

The Act uses a risk-based approach to help create regulatory guidelines. AI systems are grouped based on how much risk they pose.

The Act groups AI into four main categories. These labels aren’t just technical names: they decide how much control, transparency and oversight the AI system must have. The framework applies mainly to AI systems. General-purpose AI models are treated separately under the Act.

Unacceptable risk (banned)

Unacceptable-risk is considered dangerous, so the law bans it. These are uses that can violate privacy or create unfair control over individuals. In practice, businesses should avoid building or using these systems.

Examples:

  • Social scoring by governments or public authorities
  • AI systems that manipulate people in harmful ways
  • Certain biometric surveillance uses
  • Creating facial recognition databases by scraping images from the internet or other sources like CCTV
  • Emotion recognition in workplaces and educational institutions
  • Some forms of biometric categorisation of people

This category matters because it draws a clear red line. If an AI is used here, the question is not how to make it compliant, it is whether it should be used at all.

High risk

The EU AI Act allows high-risk AI, but it must follow some rules in cases where it can affect people’s lives. That is why the EU expects extra care and documentation.

Examples:

  • Healthcare systems that support with diagnosis and treatment decisions
  • AI used for hiring or recruitment processes like CVs or ranking candidates
  • Credit scoring systems
  • AI used in education, such as systems that influence admissions or assessments
  • AI used in critical infrastructure
  • Certain biometric identification systems
  • AI systems used for law enforcement or border control in specific cases

What happens after a system is classified as high risk? The business must treat it with much more care and:

  • Check for potential risks and design measures to reduce them
  • Use high-quality data for minimal errors and fair results  
  • Keep records of how the system functions and makes decisions
  • Provide users with enough information to use the system properly
  • Have humans intervene in critical matters so that all decisions aren’t left entirely to AI
  • Protect the system against security threats and maintain a high level of accuracy and reliability

Limited risk

Limited risk, also called transparency risk, is not usually considered dangerous, but users need to know that they are interacting with AI. This is why the main concern here is transparency and the systems must not mislead them.

Examples:

  • Chatbots that talk to customers
  • AI assistants that answer basic questions on websites
  • Tools that generate synthetic content, where users need to know it is AI-made
  • Recommendation tools that interact directly with users in a visible way
  • Virtual assistants that guide users through a process

These transparency obligations are due to apply from 2 August 2026.

Minimal risk

Minimal-risk AI has very little impact on people’s rights or safety. Examples include spam filters or simple AI tools that do not affect important decisions.

These tools can generally be used freely, with no special AI Act obligations. In other words, the law expects very little here because the risk to people is low.

What happens after classification

First, a business has to figure out what AI tools it uses or builds, whether they count as an AI system, how they are used, and what role the business plays, such as provider or deployer. Then it checks which risk category the system falls into, because that category determines the next steps.

If the system is high risk, the business must prepare for the extra obligations that apply before and after launch, although the relevant rules are being phased in over time. If the system is high risk, the business must prepare for the extra obligations that apply before and after launch, although the relevant rules are being phased in over time. Current Commission guidance refers to application from 2 December 2027 for certain high-risk areas and from 2 August 2028 for systems integrated into regulated products. Organisations should verify the latest implementation timeline before relying on these dates.

Risk classification vs. general-purpose AI

General-purpose AI, or GPAI, is AI that can do many different tasks like answer questions, summarise documents or help generate images. It’s flexible, so it could be for high-risk or low-risk both.

That is why the EU AI Act treats GPAI separately instead of putting it into the normal risk categories. These rules are about clarity, safety and accountability. They also make it easier to build on AI in a responsible way.

What all GPAI providers must do

The Act asks GPAI providers to be transparent and responsible. They must draw up technical documentation and provide relevant information to downstream providers so those providers can understand the model’s capabilities and limitations and meet their own AI Act obligations.

In addition, providers must establish a policy to respect EU copyright rules. They also need to publish a detailed summary of what content they use to train the model. In simple terms, the provider has to explain what the model is, how it was built, and what kind of data helped shape it.

Free and open licence GPAI models

Some GPAI models are released under a free and open licence. This means the model’s parameters, weights, architecture and usage terms are publicly available, so people can access, use, modify and share it more freely.

Free and open-licence GPAI models benefit from lighter obligations where the model doesn’t present systemic risk. In general, the open-source exemption reduces documentation and downstream-information duties, but copyright-policy and training-content-summary obligations may still apply. Stricter obligations apply where a model presents systemic risk.

Safe testing spaces for AI with sandboxes

The AI Act isn’t only about restrictions. It also gives companies a way to test AI safely, especially when the rules are new and they need clearer guidance. So the Act does two things simultaneously: control AI risk and still encourage new ideas.

AI regulatory sandboxes are controlled testing spaces for AI systems before they are launched. They help companies develop, train, test and validate AI systems and give businesses legal guidance while helping them understand what compliance can look like in practice. They are especially useful for SMEs and startups since they may not have large compliance teams or much legal support. These can also let regulators and companies learn from each other, which can help create better rules.

Each EU Member State must set up at least one sandbox, and some can do it together. National authorities guide, supervise and help identify risks and compliance issues.

Companies can use sandbox documentation to help show compliance with the AI Act. Participation in a sandbox doesn’t remove legal responsibility, but where companies follow the approved sandbox plan and guidance in good faith, this may reduce the risk of administrative fines for issues covered by the sandbox process.

In some public-interest projects, personal data may be used inside a sandbox, but only if it is necessary, kept secure, not shared outside and deleted after use.

How the EU AI Act affects businesses and web analytics

Web analytics may seem unrelated to the EU AI Act. After all, many analytics tools simply measure website traffic and user engagement.

But modern analytics platforms go beyond just counting visits and page views. Some use AI to:

  • Predict which users are likely to convert or leave a website
  • Identify behavioural patterns across large datasets
  • Segment audiences automatically
  • Recommend content, products or marketing actions
  • Generate reports without manual effort

Not every analytics platform, dashboard or reporting function will qualify as an AI system under the AI Act. The assessment depends on the specific feature, its intended purpose, the outputs it generates, and whether the organisation is acting as a provider, deployer, importer, distributor or another regulated role.

Under the Act, providers of AI systems need to assess whether their products follow the regulation’s framework. The obligations depend on the type of technology, how it is used and the level of risk it carries.  

Choosing an analytics platform is not just a technology decision. Organisations should understand how the tool works as well as what data it depends on and what responsibilities may arise from its use. For businesses evaluating analytics tools, they need to ask questions like:  

  • Does the platform offer AI-powered features?
  • How does the vendor describe those features?
  • Does the vendor provide information about any applicable AI Act obligations?
  • What data does the system use to generate insights?

As a result, many organisations are exploring privacy-focused platforms such as Matomo. We’ll look at Matomo and its approach to analytics in the next section.

Moving towards privacy-first analytics

Many organisations, due to regulatory demands, now want in-depth website insights without collecting excessive data.

This is where Matomo comes in. It’s a privacy-first platform and with it you can:

Keep control of your data

In analytics, it’s important to know how the software accesses data and how it is being used. With Matomo, organisations get to retain control over their analytics data. They can decide where it is stored, who can use it and how long it should remain available.

Choose where data lives

Many organisations that have strict compliance requirements, like healthcare, can’t store data outside their systems. Matomo offers a self-hosted option that lets businesses keep analytics data within their own infrastructure.

Reduce reliance on cookies

Due to privacy expectations, organisations need to now rethink their approach to cookies. Matomo supports cookieless tracking options. These help teams measure website performance while reducing dependence on cookie-based tracking methods.

Put privacy controls into practice

What matters in privacy is really small operational decisions. For example, organisations can anonymise visitor data by masking parts of IP addresses and set retention periods that automatically remove information when it is no longer needed. These controls make it easier to align analytics practices with broader privacy goals.

Still get the insights you need

Privacy-focused analytics doesn’t mean that you need to sacrifice visibility into data.  Organisations still need to understand traffic sources, user journeys, conversions and content performance. Matomo can provide these types of insights while giving businesses more control over how data is collected and managed.

Conclusion

The EU AI Act encourages organisations to take a closer look at how they use AI and the responsibilities that come with it.

This means considering the technologies used every day, including web analytics platforms that influence how data is collected, analysed and applied across the customer journey.

This is one reason why many organisations are searching for solutions that offer both transparency and control. Platforms such as Matomo help businesses gain valuable insights into website performance while giving them greater control over analytics data and, especially with self-hosted deployments, reducing reliance on third-party data processing.

Today, Matomo powers more than 1 million websites worldwide.

Get started with Matomo by downloading the free on-premise version or trying Matomo Cloud with a 21-day free trial, no credit card required.

FAQs

What exemptions are included under the EU AI Act?

​​The EU AI Act does not cover every AI use. It exempts AI used only for military, defence or national security purposes, and it also leaves out research, testing and development that happen before an AI system is put on the market or into service.

What penalties can organisations face for non-compliance?

The EU AI Act includes significant financial penalties. For many organisations, the relevant cap is the higher of the fixed amount or turnover percentage, while for SMEs the AI Act applies the lower of the two thresholds.

  • Non-compliance with the prohibition of banned AI practices can result in fines of up to €35 million or 7% of global annual turnover.
  • Failure to meet high-risk AI systems requirements, transparency obligations or other provisions of the Act can lead to fines of up to €15 million or 3% of global annual turnover.
  • Organisations that supply incorrect, incomplete or misleading information to regulators may face fines of up to €7.5 million or 1% of global annual turnover.

What is the timeline for enforcement?

​​Most of its requirements will start applying from 2 August 2026, which will give organisations time to understand the rules and prepare accordingly.

However, some provisions arrive sooner. Rules banning AI systems that present an unacceptable level of risk began applying six months after the Act entered into force. Requirements for general-purpose AI models, such as large language models, follow after 12 months.

The European Commission has also launched an AI Pact which is a voluntary initiative to encourage companies to start adopting key principles before it becomes formal.

The Commission is also working on practical guidance and codes of practice to help businesses interpret and apply the new rules.

Which authorities are responsible for oversight?

Three bodies support the implementation of the AI Act.

  • The European AI Board helps national authorities stay aligned and consistent when applying the rules.
  • Technical questions are handled by the Scientific Panel of Independent Experts. The panel advises on complex AI issues and can raise concerns if it identifies risks linked to GPAI models.
  • The Advisory Forum brings a broader perspective. It includes voices from industry, academia and civil society, helping ensure that discussions about AI are not shaped by regulators alone.

Does the EU AI Act address AI’s environmental impact?

Yes. While the AI Act primarily focuses on safety and fundamental rights, it also recognises the environmental impact of AI systems.

Large AI models can require significant computing power and energy. To improve transparency, providers of certain GPAI models must disclose information about their energy consumption. For the most powerful models, energy efficiency may also form part of the risk assessment process.

The European Commission is also working with standards bodies to develop guidance on measuring and improving the resource efficiency of AI systems, including energy use throughout their lifecycle.