The AI Act — Regulation (EU) 2024/1689 — is the world's first horizontal AI law, and "does it hit my drone?" is now a standard due-diligence question from investors and enterprise customers alike. The honest answer is nuanced: for most drone builders it demands awareness and documentation rather than panic. Here's the working map. (Engineering orientation, not legal advice — get counsel for your specific product.)

The timeline you're living through

DateWhat applies
Aug 2024Act in force (nothing applies yet)
Feb 2025Prohibited practices + AI literacy obligations
Aug 2025General-purpose AI (GPAI) model obligations, governance
Aug 2026Bulk of the Act, incl. most high-risk system obligations
Aug 2027High-risk rules for AI in regulated products (the aviation-relevant tail)

The aviation carve-out, plainly

The Act treats products already governed by EU harmonised safety law in Annex I — and aviation sits in its Section B: aircraft and UAS covered by Regulation (EU) 2018/1139 and the drone product rules (2019/945). For these, the AI Act's high-risk requirements don't apply directly as a second parallel regime; instead they are to be woven into the aviation rulebook by its own processes — which is why EASA runs an AI programme (concept papers, guidance for machine-learning applications) that will carry the substance for certified aviation AI. Translation for a drone builder: your AI-enabled aircraft's compliance path still runs through EASA — the operational categories and, one level up, product certification — with AI-specific expectations arriving through that channel.

Where the Act bites drone companies directly

  • Prohibited practices (in force since Feb 2025). Untargeted facial-image scraping and, for law enforcement, real-time remote biometric identification in public spaces except narrowly authorised cases. Drone cameras are the canonical delivery vehicle for exactly these capabilities — a "find this person" feature is not a product decision, it's a legal event.
  • Annex III high-risk uses. AI for biometric identification/categorisation, as a safety component in managing critical infrastructure, in border control or law enforcement — sold as software or a payload capability, these carry the full high-risk regime: risk management, data governance, logging, human oversight, conformity assessment.
  • Standalone software and analytics. Your cloud defect-detection or mapping AI isn't aviation-certified product — it's plain AI-Act territory. Most inspection analytics land as limited/minimal risk with transparency duties, but check against Annex III case by case.
  • GPAI dependencies. If you fine-tune or embed general-purpose models, your suppliers carry GPAI obligations — and your enterprise customers will push documentation requirements (model provenance, training-data summaries) down the chain to you.

The practical compliance posture

  1. Classify every AI function you ship — one page per model: purpose, users, data, autonomy level, and where it lands in the Act's pyramid (prohibited / high / limited / minimal). Investors' lawyers ask for exactly this table.
  2. Keep flight-safety AI inside the aviation boundary. The AI-proposes-FC-disposes architecture means your horizontal-AI exposure stays on the analytics side, where obligations are lighter.
  3. Treat biometric anything as legal-first. Even "just a demo" of person identification from the air touches the prohibited-practices line.
  4. Build the evidence habit now: model versioning, training-data records, evaluation reports, human-oversight design. It's the same discipline your SORA and customers already reward — the AI Act just gives it a second reader.
  5. Track EASA's AI guidance — that's where "AI in certified aviation" becomes concrete, on aviation's timeline rather than the Act's headlines.
The strategic read

For most UAV startups the AI Act is a documentation tax, not a wall — and like EASA compliance before it, it quietly favours teams that engineer with evidence. The exception is anything biometric or law-enforcement-flavoured: there the Act has real teeth, and product strategy should know it before the pitch deck does.

Frequently asked questions

Does the EU AI Act apply to drones?

Partly. Drones certified under EU aviation product rules sit in the AI Act's Annex I Section B, where AI requirements are folded into the aviation framework rather than applying directly. But AI software sold separately, ground-based analytics, and uses like biometric identification from drone cameras fall squarely under the Act.

Is drone AI considered high-risk under the AI Act?

Not automatically. Risk depends on use: AI as a safety component of regulated products, or uses listed in Annex III (biometric identification, critical infrastructure operation, law-enforcement applications) can be high-risk. A crop-counting model is not; a person-identifying surveillance payload very much is.

Can drones do facial recognition in the EU?

Real-time remote biometric identification in publicly accessible spaces is prohibited for law enforcement except in narrow, authorised cases — and untargeted scraping of facial images is banned outright. A drone camera is exactly the kind of system these rules were written for; treat biometric features as legal-review-first territory.