What it means
The AI Act regulates by risk tier rather than by technology. A narrow set of uses is prohibited outright — including social scoring and certain biometric categorization. A larger high-risk tier, covering employment, education, credit, essential services and critical infrastructure, carries substantial obligations: risk management, data governance, technical documentation, logging, human oversight and conformity assessment. Limited-risk uses carry transparency duties, such as disclosing that a user is interacting with an AI. Most applications fall outside these tiers entirely.
General-purpose model providers have their own obligations, scaled up for models above a compute threshold deemed to carry systemic risk.
The implementation timeline has been amended since the original text, and the deadlines for high-risk obligations moved. Do not cite a schedule from memory or from older coverage — check the current consolidated text, since this is exactly the kind of date that gets restated confidently long after it changed.
Why it matters
Extraterritorial scope means it binds non-EU companies whose systems are used in the EU, so it functions as a global compliance floor much as GDPR did. Penalties are turnover-based and substantial. Most importantly, the obligations attach to the *use case*, not the technology — the same model is unregulated in one product and high-risk in another.
In practice
Classify by use case first; most deployments are not high-risk and the distinction is where compliance effort should be spent. If you are high-risk, documentation and meaningful human oversight are the load-bearing requirements. Verify current dates against the official text.