Listen to this lesson
Unlock audio and more
Audio streaming, downloadable PDFs and certificates come with Plus and Pro.
What it means
The AI Act regulates by risk tier rather than by technology. A narrow set of uses is prohibited outright — including social scoring and certain biometric categorization. A larger high-risk tier, covering employment, education, credit, essential services and critical infrastructure, carries substantial obligations: risk management, data governance, technical documentation, logging, human oversight and conformity assessment. Limited-risk uses carry transparency duties, such as disclosing that a user is interacting with an AI. Most applications fall outside these tiers entirely.
General-purpose model providers have their own obligations, scaled up for models above a compute threshold deemed to carry systemic risk.
The implementation timeline has been amended since the original text, and the deadlines for high-risk obligations moved. Do not cite a schedule from memory or from older coverage — check the current consolidated text, since this is exactly the kind of date that gets restated confidently long after it changed.
Why it matters
Extraterritorial scope means it binds non-EU companies whose systems are used in the EU, so it functions as a global compliance floor much as GDPR did. Penalties are turnover-based and substantial. Most importantly, the obligations attach to the use case, not the technology — the same model is unregulated in one product and high-risk in another.
In practice
Classify by use case first; most deployments are not high-risk and the distinction is where compliance effort should be spent. If you are high-risk, documentation and meaningful human oversight are the load-bearing requirements. Verify current dates against the official text.