EU AI Act

BusinessSafety and governancePublished By Simon Budziak

The EU AI Act is the European Union's law regulating artificial intelligence by risk tier: the riskier a use of AI, the heavier the obligations, from an outright ban on manipulative practices down to light transparency duties for chatbots and similar tools.

How does the Act sort AI systems into tiers?

Four bands. Unacceptable practices are banned outright: manipulative systems, social scoring, and live biometric tracking in public spaces outside narrow law-enforcement exceptions. High risk covers uses that can redirect someone’s life, such as CV screening or credit scoring, carrying duties around documentation, data quality, human oversight, and incident reporting. Limited risk triggers transparency duties: people must know they talk to a machine, and synthetic media must be labelled. Everything else is minimal risk and largely unregulated. The tier follows what a system is used for, never the technology inside it.

Are you a provider or a deployer, and why does it matter?

A provider builds or sells the system; a deployer runs one inside its own operations, and the obligations differ between the two roles. A bank using a CV screening tool is a deployer: it must operate the tool as instructed, keep a competent person overseeing outcomes through human in the loop arrangements, keeping affected workers informed. The vendor carries the heavier engineering duties. Most companies sit in both seats, so serious AI governance starts by listing every system and naming its role, with AI readiness scoring showing where each workflow stands. Penalties scale with worldwide turnover, so misreading a high risk use case is costly.

Frequently asked questions

Does the EU AI Act apply to companies outside Europe?

Yes, whenever the system is placed on the EU market or its output is used inside the EU. Where the company itself sits does not matter; where the effect lands does.

Is a normal customer service chatbot high risk under the Act?

No. A chatbot falls into limited risk and mainly owes transparency, telling people they are talking to a machine. High risk applies to uses affecting safety or fundamental rights, such as hiring or credit decisions.

What happens if our use of an AI system changes over time?

Obligations follow the purpose, so repurposing a system for a higher risk use restarts the assessment duties for that new tier. Recheck classification whenever a tool changes jobs.

Summarize this page with

See this working in a system we built