Glossary · simply explained

EU AI Act

The EU AI Act is the world’s first comprehensive AI law: it regulates artificial intelligence with a risk-based approach — prohibited practices, high-risk systems with strict duties, transparency requirements for certain applications and dedicated rules for general-purpose AI models (GPAI).

Not only AI manufacturers are affected: companies deploying AI systems carry duties as operators too — from transparency towards users to human oversight for high-risk applications. The duties phase in since 2025.

The risk classes at a glance

Prohibited are practices such as social scoring or manipulative systems with substantial harm potential. High-risk are AI systems in sensitive fields — such as recruitment, credit scoring, critical infrastructure, law enforcement: for them, requirements apply to risk management, data quality, documentation, human oversight, robustness and cybersecurity.

Limited risk triggers transparency duties — users must learn they are interacting with AI, and AI-generated content must be labelled. For GPAI models, dedicated provider duties apply, tightened for models with systemic risk. Minimal-risk applications remain free.

What companies should do now

  • Build an AI inventory: which systems are in use — including in purchased software?
  • Assign risk classes and clarify operator duties per system.
  • Ensure AI literacy: the AI Act requires trained staff handling AI.
  • Rein in shadow AI: ungoverned AI use undermines any compliance.

Frequently asked questions about EU AI Act

Who does the EU AI Act affect?

Providers, importers and deployers of AI systems with a connection to the EU market — regardless of company seat. Pure users carry operator duties too, such as transparency and oversight; the bulk of duties lies with providers of high-risk systems and large models.

From when do which duties apply?

Phased: the prohibitions apply since early 2025, the GPAI rules since mid-2025, the comprehensive high-risk duties follow through 2026/2027. Anyone deploying or offering AI should not postpone inventory and classification to the last stage.

What counts as high-risk AI?

Systems in the annex areas of the law — including employment and recruitment, creditworthiness, critical infrastructure, education, law enforcement and migration. The purpose of use is decisive; the same technology can be classified differently depending on deployment.

Which duties do pure AI users have?

Operator duties: use the system as intended and with human oversight, govern input data appropriately, report incidents, maintain transparency towards affected people — and deploy staff with sufficient AI literacy. For high-risk systems, documented processes come on top.

How do the AI Act and GDPR relate?

They apply in parallel: if an AI system processes personal data, all GDPR duties remain — legal basis, data subject rights, TOMs. The AI Act adds product and deployment requirements. In practice: both assessments, one shared inventory.

Wondering how this looks in your own network? Talk to KAEMI: we plan, build and manage the right solution with you.