How does the Act sort AI systems into tiers?
Four bands. Unacceptable practices are banned outright: manipulative systems, social scoring, and live biometric tracking in public spaces outside narrow law-enforcement exceptions. High risk covers uses that can redirect someone’s life, such as CV screening or credit scoring, carrying duties around documentation, data quality, human oversight, and incident reporting. Limited risk triggers transparency duties: people must know they talk to a machine, and synthetic media must be labelled. Everything else is minimal risk and largely unregulated. The tier follows what a system is used for, never the technology inside it.
Are you a provider or a deployer, and why does it matter?
A provider builds or sells the system; a deployer runs one inside its own operations, and the obligations differ between the two roles. A bank using a CV screening tool is a deployer: it must operate the tool as instructed, keep a competent person overseeing outcomes through human in the loop arrangements, keeping affected workers informed. The vendor carries the heavier engineering duties. Most companies sit in both seats, so serious AI governance starts by listing every system and naming its role, with AI readiness scoring showing where each workflow stands. Penalties scale with worldwide turnover, so misreading a high risk use case is costly.