AI governance & ethics

EU AI Act summary: risk tiers, obligations and timeline

A UK software team building a hiring tool gets an email from a customer's legal department in Germany asking whether the product falls under the EU AI Act. Nobody in the room has a confident answer. The tool screens CVs, which sounds high-risk, but it is also just a feature bolted onto a bigger platform, which sounds like someone else's problem. Working it out means knowing which risk tier the system sits in, who counts as a provider or deployer, and what each role actually has to do.

The EU AI Act is the European Union's law governing how artificial intelligence is built and used, in force since August 2024. It sorts AI systems into risk tiers, from practices that are banned outright to tools with almost no rules, and sets duties for providers and deployers, including organisations outside the EU whose systems reach EU users.

What the EU AI Act actually covers

The EU AI Act is the European Union's flagship regulation for artificial intelligence, adopted in 2024 and treated by other jurisdictions as a reference point for their own rules. It does not single out one industry or one type of model. Instead it applies horizontally, across sectors, and sets rules based on what a system does and how much harm it could cause if it goes wrong, rather than on what it is called or who built it.

The core idea is proportionality. A spam filter and a system that decides who gets a mortgage are both artificial intelligence loosely speaking, but they carry very different levels of risk, so the Act does not treat them the same way. It sorts systems into tiers, from practices judged incompatible with EU fundamental rights, through high-risk systems needing substantial compliance work, down to tools with light transparency duties or none at all.

The Act sits alongside existing EU law rather than replacing it. GDPR still applies in full to any AI system processing personal data, and sector rules covering things like medical devices or vehicles continue to apply on top. Meeting one set of rules does not automatically satisfy the other.

Who counts as a provider or deployer

Two roles do most of the work in the Act's text. A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own authority, typically a business buying and running someone else's tool rather than building it. An organisation can be both at once, for instance if it builds a tool in-house and also runs it operationally.

Scope is not limited to companies based inside the EU. If a provider outside the EU places a system on the EU market, or its output is used within the EU, the Act can apply regardless of where the company is headquartered, much as GDPR reaches organisations processing EU residents' data from anywhere. A UK consultancy building a tool that a client rolls out to EU customers needs to think about this even without an EU office.

Importers and distributors carry lighter obligations, mainly checking that a system already has the right documentation before it moves further down the supply chain. Most of the substantive work sits with providers, and a meaningful share sits with deployers, particularly once a system is classified as high-risk.

Unacceptable risk: the practices banned outright

At the top of the structure sit practices the Act treats as too damaging to fundamental rights to allow at all, regardless of safeguards. These include social scoring of individuals by public authorities, AI that manipulates people through subliminal or deceptive techniques in ways likely to cause harm, and systems that exploit the vulnerabilities of children or people with disabilities.

Also prohibited are certain uses of biometric data: untargeted scraping of facial images from the internet or CCTV to build recognition databases, and, with narrow exceptions, real-time remote biometric identification in public spaces for law enforcement. Emotion recognition in workplaces and schools is banned outside limited safety or medical uses, and predictive policing based solely on profiling a person, rather than on objective facts, is out of bounds too.

There is no compliance route for this tier. A system in this category cannot be placed on the market or put into service in the EU at all, which makes it the one place in the Act where the question is not how to comply but whether the product should exist in its current form.

High-risk systems and what they demand

High-risk covers AI used where a wrong decision has serious consequences for someone's rights, safety or access to services: recruitment and HR decisions, creditworthiness and insurance pricing, biometric identification, critical infrastructure, education access, essential public and private services, law enforcement, migration control, and the administration of justice.

Providers of high-risk systems carry the heaviest workload: risk management across the system's life, controls over training data quality, technical documentation, automatic logging of behaviour, clear information for deployers, human oversight built into the design, testing for accuracy and robustness, a formal conformity assessment before market entry, and registration in an EU database.

Deployers of high-risk systems are not passive here either. They must use the system as instructed, monitor it in operation, keep records, and in some cases assess its impact on people's fundamental rights before switching it on. Buying a compliant tool from a vendor does not remove a deployer's own obligations around how it is used.

Limited-risk systems: transparency rather than approval

Below high-risk sits a tier built around honesty rather than heavy process. Systems that interact directly with people, or generate content people might mistake for something a human made, carry disclosure duties. A chatbot has to make clear it is an AI system unless that is already obvious, and deepfake images, audio or video need to be labelled as artificially generated or manipulated.

The same logic covers emotion recognition and biometric categorisation systems used outside the banned use cases: people need to be told they are interacting with, or being assessed by, such a system. None of this requires a conformity assessment or registration, just enough disclosure that people can make an informed choice about what they are seeing or talking to.

Minimal-risk AI and the separate rules for general-purpose models

Most AI in everyday use, recommendation engines, spam filters, inventory forecasting and similar tools, sits in the minimal-risk tier and carries no mandatory obligations under the Act. The EU encourages voluntary codes of conduct here, but nothing is enforceable in the way the higher tiers are.

General-purpose AI models, the large models underpinning many chatbots and copilots, sit in a separate regime running alongside the risk tiers rather than inside them. All providers face baseline transparency duties: technical documentation, a summary of training content, and policies to respect copyright law. Models judged to carry systemic risk, based on the compute used to train them, face extra obligations around evaluating that risk, reporting serious incidents, and meeting a higher cybersecurity bar.

How the rules are phasing in

The Act entered into force on 1 August 2024, but very little applied immediately. It carries a staggered timeline so organisations have time to work out where they sit and build the right processes, rather than facing every obligation on the same day.

Banned practices took effect first, from February 2025, six months after entry into force. Obligations for general-purpose AI model providers followed in August 2025. The bulk of the high-risk requirements become applicable from August 2026, two years after entry into force, giving providers and deployers the longest run-up for the heaviest tier.

A narrower set of high-risk obligations, covering AI embedded in products already regulated under existing EU safety law such as machinery, toys and medical devices, extends to August 2027. Most organisations should be classifying their systems now, even where the specific deadline that applies to them is still some way off.

Getting ready without slowing down what you are building

Organisations that handle this well start with an honest inventory: which AI systems does the business build, buy, or simply use inside a bigger product, and which tier does each one sit in. Skipping this step is the most common mistake, particularly among teams who assume that using a vendor's AI feature rather than building a model in-house takes them out of scope. It usually does not, since deployer obligations still apply.

A lot of what the high-risk tier demands, data quality controls, documentation, logging, traceability, is a data problem wearing an AI label, and it is far more manageable for organisations that already have a governed, compliant data foundation than for teams patching evidence together after a regulator or customer asks for it.

None of this is legal advice. This article is a practical summary of a complex regulation, and the detail that matters for a specific system, contract or sector depends on facts a summary cannot capture. Organisations working out where they sit under the Act should get advice from a qualified lawyer alongside doing the technical and data work described here.

Frequently asked questions

What is the EU AI Act?

The EU AI Act is the European Union's regulation governing the development and use of artificial intelligence systems. It groups AI into risk tiers, bans a small number of practices outright, and places the heaviest compliance duties on high-risk systems used in areas like recruitment, credit and law enforcement. It has applied in phases since August 2024.

Who does the EU AI Act apply to?

It applies to providers, the organisations that build or place AI systems on the market, and deployers, the organisations that use them. This includes organisations based outside the EU if their AI system is placed on the EU market or its output is used within the EU, similar to how GDPR reaches beyond EU borders.

What are the EU AI Act's risk categories?

There are four tiers: unacceptable-risk practices that are banned outright, high-risk systems that require formal risk management, documentation and conformity assessment, limited-risk systems that mainly need to disclose that people are dealing with AI, and minimal-risk systems that carry no mandatory obligations.

When do the EU AI Act's obligations take effect?

The Act entered into force in August 2024. Banned practices became prohibited from February 2025, obligations for general-purpose AI model providers followed in August 2025, most high-risk system requirements apply from August 2026, and a narrower set tied to already-regulated products extends to August 2027.

What happens if an organisation does not comply with the EU AI Act?

The Act sets fines on a sliding scale tied to global annual turnover, with the highest tier for using banned practices reported at up to 7% of worldwide turnover or a fixed multi-million euro sum, whichever is higher. Lower tiers apply to other breaches, such as failing to meet high-risk obligations.

Want a straight view of where AI can help your business first? Talk to us and start with a clear picture instead of a vendor demo.

Start at your core.

Tell us where your data is today and what you want AI to do. We will come back with a straight answer on what your foundation needs and where the quickest real win is.

Talk to us