







AI is now part of everyday life, from the recommendations you see in AI overviews to systems that detect fraud. As its use grows, so do concerns around transparency, fairness and how user data is handled.
The European Union (EU) has already introduced laws like the General Data Protection Regulation (GDPR) and the ePrivacy Directive to protect personal data. But AI introduces new privacy challenges and ethical questions, especially when systems start making or influencing decisions.
To address this, the EU introduced the EU AI Act, a regulation that ensures businesses use AI safely and responsibly.
In this post, we will see how it works and what it means for how businesses and how they use web analytics.
The EU AI Act is the EU’s first comprehensive law for artificial intelligence and shares guidelines on how to develop and use AI systems. It was proposed by the European Commission in 2021. The EU adopted the AI Act in 2024, with obligations applying in phases.
The Act defines an AI system broadly as a machine-based system that can infer, from inputs, how to generate outputs such as predictions, content, recommendations or decisions that may influence physical or virtual environments. It classifies AI systems into various risk categories and applies requirements accordingly, which we cover in the next sections.
The Act uses a risk-based approach to help create regulatory guidelines. AI systems are grouped based on how much risk they pose.
The Act groups AI into four main categories. These labels aren’t just technical names: they decide how much control, transparency and oversight the AI system must have. The framework applies mainly to AI systems. General-purpose AI models are treated separately under the Act.
Unacceptable-risk is considered dangerous, so the law bans it. These are uses that can violate privacy or create unfair control over individuals. In practice, businesses should avoid building or using these systems.
Examples:
This category matters because it draws a clear red line. If an AI is used here, the question is not how to make it compliant, it is whether it should be used at all.
The EU AI Act allows high-risk AI, but it must follow some rules in cases where it can affect people’s lives. That is why the EU expects extra care and documentation.
Examples:
What happens after a system is classified as high risk? The business must treat it with much more care and:
Limited risk, also called transparency risk, is not usually considered dangerous, but users need to know that they are interacting with AI. This is why the main concern here is transparency and the systems must not mislead them.
Examples:
These transparency obligations are due to apply from 2 August 2026.
Minimal-risk AI has very little impact on people’s rights or safety. Examples include spam filters or simple AI tools that do not affect important decisions.
These tools can generally be used freely, with no special AI Act obligations. In other words, the law expects very little here because the risk to people is low.
First, a business has to figure out what AI tools it uses or builds, whether they count as an AI system, how they are used, and what role the business plays, such as provider or deployer. Then it checks which risk category the system falls into, because that category determines the next steps.
If the system is high risk, the business must prepare for the extra obligations that apply before and after launch, although the relevant rules are being phased in over time. If the system is high risk, the business must prepare for the extra obligations that apply before and after launch, although the relevant rules are being phased in over time. Current Commission guidance refers to application from 2 December 2027 for certain high-risk areas and from 2 August 2028 for systems integrated into regulated products. Organisations should verify the latest implementation timeline before relying on these dates.
General-purpose AI, or GPAI, is AI that can do many different tasks like answer questions, summarise documents or help generate images. It’s flexible, so it could be for high-risk or low-risk both.
That is why the EU AI Act treats GPAI separately instead of putting it into the normal risk categories. These rules are about clarity, safety and accountability. They also make it easier to build on AI in a responsible way.
The Act asks GPAI providers to be transparent and responsible. They must draw up technical documentation and provide relevant information to downstream providers so those providers can understand the model’s capabilities and limitations and meet their own AI Act obligations.
In addition, providers must establish a policy to respect EU copyright rules. They also need to publish a detailed summary of what content they use to train the model. In simple terms, the provider has to explain what the model is, how it was built, and what kind of data helped shape it.
Some GPAI models are released under a free and open licence. This means the model’s parameters, weights, architecture and usage terms are publicly available, so people can access, use, modify and share it more freely.
Free and open-licence GPAI models benefit from lighter obligations where the model doesn’t present systemic risk. In general, the open-source exemption reduces documentation and downstream-information duties, but copyright-policy and training-content-summary obligations may still apply. Stricter obligations apply where a model presents systemic risk.
The AI Act isn’t only about restrictions. It also gives companies a way to test AI safely, especially when the rules are new and they need clearer guidance. So the Act does two things simultaneously: control AI risk and still encourage new ideas.
AI regulatory sandboxes are controlled testing spaces for AI systems before they are launched. They help companies develop, train, test and validate AI systems and give businesses legal guidance while helping them understand what compliance can look like in practice. They are especially useful for SMEs and startups since they may not have large compliance teams or much legal support. These can also let regulators and companies learn from each other, which can help create better rules.
Each EU Member State must set up at least one sandbox, and some can do it together. National authorities guide, supervise and help identify risks and compliance issues.
Companies can use sandbox documentation to help show compliance with the AI Act. Participation in a sandbox doesn’t remove legal responsibility, but where companies follow the approved sandbox plan and guidance in good faith, this may reduce the risk of administrative fines for issues covered by the sandbox process.
In some public-interest projects, personal data may be used inside a sandbox, but only if it is necessary, kept secure, not shared outside and deleted after use.
Web analytics may seem unrelated to the EU AI Act. After all, many analytics tools simply measure website traffic and user engagement.
But modern analytics platforms go beyond just counting visits and page views. Some use AI to:
Not every analytics platform, dashboard or reporting function will qualify as an AI system under the AI Act. The assessment depends on the specific feature, its intended purpose, the outputs it generates, and whether the organisation is acting as a provider, deployer, importer, distributor or another regulated role.
Under the Act, providers of AI systems need to assess whether their products follow the regulation’s framework. The obligations depend on the type of technology, how it is used and the level of risk it carries.
Choosing an analytics platform is not just a technology decision. Organisations should understand how the tool works as well as what data it depends on and what responsibilities may arise from its use. For businesses evaluating analytics tools, they need to ask questions like:
As a result, many organisations are exploring privacy-focused platforms such as Matomo. We’ll look at Matomo and its approach to analytics in the next section.
Many organisations, due to regulatory demands, now want in-depth website insights without collecting excessive data.
This is where Matomo comes in. It’s a privacy-first platform and with it you can:
In analytics, it’s important to know how the software accesses data and how it is being used. With Matomo, organisations get to retain control over their analytics data. They can decide where it is stored, who can use it and how long it should remain available.
Many organisations that have strict compliance requirements, like healthcare, can’t store data outside their systems. Matomo offers a self-hosted option that lets businesses keep analytics data within their own infrastructure.
Due to privacy expectations, organisations need to now rethink their approach to cookies. Matomo supports cookieless tracking options. These help teams measure website performance while reducing dependence on cookie-based tracking methods.
What matters in privacy is really small operational decisions. For example, organisations can anonymise visitor data by masking parts of IP addresses and set retention periods that automatically remove information when it is no longer needed. These controls make it easier to align analytics practices with broader privacy goals.
Privacy-focused analytics doesn’t mean that you need to sacrifice visibility into data. Organisations still need to understand traffic sources, user journeys, conversions and content performance. Matomo can provide these types of insights while giving businesses more control over how data is collected and managed.
The EU AI Act encourages organisations to take a closer look at how they use AI and the responsibilities that come with it.
This means considering the technologies used every day, including web analytics platforms that influence how data is collected, analysed and applied across the customer journey.
This is one reason why many organisations are searching for solutions that offer both transparency and control. Platforms such as Matomo help businesses gain valuable insights into website performance while giving them greater control over analytics data and, especially with self-hosted deployments, reducing reliance on third-party data processing.
Today, Matomo powers more than 1 million websites worldwide.
Get started with Matomo by downloading the free on-premise version or trying Matomo Cloud with a 21-day free trial, no credit card required.
The EU AI Act does not cover every AI use. It exempts AI used only for military, defence or national security purposes, and it also leaves out research, testing and development that happen before an AI system is put on the market or into service.
The EU AI Act includes significant financial penalties. For many organisations, the relevant cap is the higher of the fixed amount or turnover percentage, while for SMEs the AI Act applies the lower of the two thresholds.
Most of its requirements will start applying from 2 August 2026, which will give organisations time to understand the rules and prepare accordingly.
However, some provisions arrive sooner. Rules banning AI systems that present an unacceptable level of risk began applying six months after the Act entered into force. Requirements for general-purpose AI models, such as large language models, follow after 12 months.
The European Commission has also launched an AI Pact which is a voluntary initiative to encourage companies to start adopting key principles before it becomes formal.
The Commission is also working on practical guidance and codes of practice to help businesses interpret and apply the new rules.
Three bodies support the implementation of the AI Act.
Yes. While the AI Act primarily focuses on safety and fundamental rights, it also recognises the environmental impact of AI systems.
Large AI models can require significant computing power and energy. To improve transparency, providers of certain GPAI models must disclose information about their energy consumption. For the most powerful models, energy efficiency may also form part of the risk assessment process.
The European Commission is also working with standards bodies to develop guidance on measuring and improving the resource efficiency of AI systems, including energy use throughout their lifecycle.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。