The EU AI Act is the world’s first comprehensive AI law: it regulates artificial intelligence with a risk-based approach — prohibited practices, high-risk systems with strict duties, transparency requirements for certain applications and dedicated rules for general-purpose AI models (GPAI).
Not only AI manufacturers are affected: companies deploying AI systems carry duties as operators too — from transparency towards users to human oversight for high-risk applications. The duties phase in since 2025.
The risk classes at a glance
Prohibited are practices such as social scoring or manipulative systems with substantial harm potential. High-risk are AI systems in sensitive fields — such as recruitment, credit scoring, critical infrastructure, law enforcement: for them, requirements apply to risk management, data quality, documentation, human oversight, robustness and cybersecurity.
Limited risk triggers transparency duties — users must learn they are interacting with AI, and AI-generated content must be labelled. For GPAI models, dedicated provider duties apply, tightened for models with systemic risk. Minimal-risk applications remain free.
What companies should do now
- Build an AI inventory: which systems are in use — including in purchased software?
- Assign risk classes and clarify operator duties per system.
- Ensure AI literacy: the AI Act requires trained staff handling AI.
- Rein in shadow AI: ungoverned AI use undermines any compliance.