Skip to content
Back to glossary
AI

EU AI Act

The EU AI Act is Europe's AI regulation. It sorts AI systems by risk and attaches obligations to each tier, from transparency through to documented human oversight.

The EU AI Act is the European Union's AI regulation. It governs use rather than technology: a system is classified by the risk of its application, and the obligations follow from that classification. The same model can therefore be unremarkable in one use case and tightly regulated in another.

How is the AI Act structured?

Four tiers, top down.

Prohibited covers a small number of practices, such as social scoring of people by public authorities, or emotion recognition in the workplace.

High-risk is the tier that creates most of the work. It includes AI in recruitment, in creditworthiness assessment, in critical infrastructure and in parts of product safety. Obligations here are risk management, data quality, technical documentation, logging, and explicitly human oversight.

Transparency obligations apply to systems that interact with people or generate content. Anyone talking to a chatbot must be able to know it, and machine-generated content has to be marked as such.

Everything else carries no special obligations. Most mid-market applications, drafting text or internal search, fall into this category.

What does it mean in practice?

The first task is classification, not rebuilding. For each planned application, establish which tier it falls into. For the majority the answer is undramatic, and that clarity is the real gain.

The second concerns your role. Developing an AI system carries different obligations from buying and operating one. If a purchased system is substantially modified or offered under your own name, though, you can become the provider, with the stricter obligations that entails.

The third concerns evidence. Documentation and logging are required, which are precisely the things that cannot be reconstructed after the fact. They belong in AI governance from the start.

Common misreadings

The AI Act does not replace the GDPR, it sits alongside it. A system can be uncritical under the AI Act and still be sensitive in data protection terms.

And it does not ban AI in HR; it requires oversight and documentation there. Putting human-in-the-loop at the right point satisfies a substantial part of that requirement anyway.

Another common assumption is that the regulation only applies to companies building AI. Deployers have obligations of their own, including oversight and briefing the people who work with the system.

How to approach classification in practice

The obligations phase in over several years, so the current state of application should be checked before any decision. The preparatory work is independent of that and pays off either way.

It comes down to three steps. List the planned and running AI applications, each with its purpose and the groups of people affected. Assign each one a tier and write down the reasoning, because that reasoning is the evidence later. And establish the role for each: built, bought, or bought and substantially modified.

For most mid-market applications this review ends with no special obligations. The value lies in being able to demonstrate that rather than assume it. That list is also the core of AI governance.

Binding interpretation in a specific case needs legal advice. This entry places the term and does not substitute for it.