If you've been keeping tabs on the AI regulatory landscape, you've heard about the EU AI Act. It's been described as everything from a landmark achievement in tech governance to a bureaucratic nightmare for businesses. The truth, as usual, is somewhere in the middle, but one thing is certain: if your business builds, uses, or integrates AI in any way, this regulation deserves your attention right now.
Here's what you actually need to know.
What is the EU AI Act?
The EU AI Act is a comprehensive legal framework governing the development, deployment, and use of artificial intelligence. It applies not just to EU-based companies, but to any business anywhere in the world that offers AI-powered products or services to users in the EU. Yes, that means US companies too.
The regulation takes a risk-based approach, meaning the more potentially harmful your AI system is, the stricter the rules. Think of it like a four-tier ladder: unacceptable risk at the top (banned outright), followed by high-risk, limited risk, and minimal risk (the catch-all) at the bottom. Each tier is broken out in detail below.
What's Already In Effect?
Here's where things stand right now:
As of February 2025, prohibited AI practices must have ceased, and AI literacy obligations began for all providers and deployers. By August 2025, governance provisions and obligations for general-purpose AI ("GPAI") models came into effect. (Providers of GPAI models already on the market before August 2025 have until August 2, 2027, to achieve full compliance.)
Certain applications have been expressly prohibited since February 2025, including biometric categorization based on sensitive characteristics. These prohibitions apply comprehensively to both to the development and to the mere use of such systems. In plain terms: any business using AI for social scoring, manipulative behavioral targeting, or real-time biometric identification without strict justification, is already in violation territory.
The next major deadline is August 2, 2026, when the remainder of the EU AI Act kicks in for most operators, and high-risk AI systems must be fully compliant. Conformity assessments should be completed, technical documentation finalized, CE marking affixed, and EU database registration for high-risk systems completed. High-risk AI systems (explained further below) include hiring algorithms, credit scoring tools, medical diagnostics, law enforcement tools, educational assessment systems, and biometric systems. If your product or platform touches any of these areas, the August 2026 deadline is not optional. AI Act violations may be punished with significant penalties, including fines of up to €35 million or 7% of global annual turnover.
What Does This Mean for Your Business?
The EU AI Act's reach is broader than most businesses expect. The answer to "does this apply to me?" starts with two questions: does your business fall within the scope of the Act, and what is your role in the AI ecosystem?
Does Your Business Fall Within Scope?
The Act applies to your business if you are:
- Building or selling AI systems in the EU market, regardless of where your company is headquartered
- Using AI systems operationally (in a professional capacity) within the EU
- Based outside the EU but producing AI outputs that are used by people in the EU
- Importing, distributing, or reselling AI systems within the EU market
- Manufacturing products with AI built in and selling them under your own brand in the EU
- It also applies to authorized representatives of developers (where the representative is located in the EU) and affected persons within the EU
The Act does not apply to:
- AI used exclusively for military, defense, or national security purposes
- AI built solely for scientific research (though real-world testing is not exempt)
- Pre-market research and development (but this exemption ends the moment testing moves into the real world)
- Individuals using AI for purely personal, non-professional purposes
- Free and open-source AI unless it is high-risk or falls under the prohibited practices or transparency provisions
What Is Your Role in the AI Ecosystem?
Your obligations under the Act depend heavily on where you sit in the AI supply chain.
If you're building AI, you carry the heaviest compliance burden, which can include required technical documentation, instructions for use, copyright compliance, and published summaries of training data. The most powerful GPAI models (those trained using more than 10²⁵ floating point operations) are classified as presenting systemic risk and face additional obligations, including model evaluations, adversarial testing, incident reporting, and cybersecurity protection requirements.
If you're integrating AI into your products or platforms professionally, you need to understand what risk tier your system falls within and whether the integration could make your company responsible as a developer. If the resulting system qualifies as high-risk, certain compliance obligations attach to the product itself, not just the underlying model. Significantly modifying an existing AI system can also elevate a business from user to provider under the Act, triggering compliance requirements.
If you're using AI operationally in a professional capacity, you're not off the hook either. Businesses using high-risk AI systems are expected to keep records, maintain human oversight, and ensure the system isn't being used in ways that exceed its intended purpose or compliance boundaries. At a minimum, that means knowing what AI systems your organization uses, how they're classified, and whether your current documentation and data practices hold up to scrutiny.
In addition, importers and distributors carry a responsibility for ensuring the systems they bring to market comply with the EU AI Act before making them available. If a system isn't compliant, they are expected to flag it, withhold it, or pull it from the market.
Breaking Down the Risk Tiers
Your company's obligations under the law depend entirely on which bucket your system falls into, so getting this classification right is one of the most important things you can do right now.
Tier 1: Unacceptable Risk - Banned Outright
These are AI applications the EU has decided pose too great a threat to safety, rights, and democracy to exist at all. They've been prohibited since February 2025, and include things like:
- AI systems that manipulate people through subliminal techniques (for example, analyzing user behavior and history in order to steer users toward certain purchases or decisions)
- AI that exploits vulnerabilities of specific groups due to age, disability or specific social or economic situation
- Social scoring systems (based on social behavior or known, inferred or predicted personal or personality characteristics) used by governments or private companies
- Predictive policing tools that profile individuals based on personal characteristics
- Facial recognition databases built by mass-scraping faces from the internet or CCTV footage
- Emotion detection AI used in workplaces or schools, except for medical or safety purposes
- Biometric categorization systems that infer race, political opinions, religion, union membership, or sexual orientation
- Real-time biometric identification in public spaces for law enforcement, except in cases involving missing persons or trafficking victims, imminent threats to life or terrorist attacks, or criminal investigations involving offenses carrying a minimum four-year sentence
Tier 2: High Risk - Heavy Obligations
This is where most businesses need to pay close attention. High-risk AI systems aren't banned, but they come with significant compliance obligations.
The EU defines high-risk systems across two categories: AI embedded in regulated products (medical devices, machinery, vehicles) and standalone AI applications listed in Annex III of the Act.
Annex III is the list you need to know. It covers eight specific domains where AI is considered high-risk:
- Biometric identification and categorization: systems that identify or categorize people based on biometric data
- Critical infrastructure: AI managing roads, water, energy, or digital infrastructure
- Education and vocational training: systems that determine access to educational institutions or evaluate students
- Employment and workforce management: hiring tools, performance monitoring, task allocation, and promotion or termination decisions
- Access to essential services: AI used in credit scoring, insurance risk assessment, or determining eligibility for public benefits
- Law enforcement: tools used to assess the risk of criminal activity, evaluate evidence, or conduct investigations
- Migration, asylum, and border control: systems used to assess immigration applications or risks
- Administration of justice and democratic processes: AI assisting courts or influencing elections
There are limited exceptions if:
- the AI system performs a narrow procedural task;
- improves the result of a previously completed human activity;
- detects decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or
- performs a preparatory task to an assessment relevant for the purpose of the use cases listed in Annex III.
That said, an AI system listed under Annex III is always considered high-risk if it profiles individuals (i.e. automated processing of personal data to assess various aspects of a person's life, such as work performance, economic situation, health, preferences, interests, reliability, behavior, location or movement).
Providers with AI systems that fall under Annex III categories who believe their system is not high-risk must document such an assessment before placing the system on the market or putting it into service.
Tier 3: Limited Risk - Transparency Obligations
These systems aren't considered dangerous but still require honesty with users. This category includes AI systems that interact directly with people, such as chatbots, as well as systems that generate or manipulate image, audio, text, or video content, including deepfakes.
The main rule here is disclosure. If someone is interacting with an AI chatbot, viewing AI-generated content, or being subject to emotion recognition, they need to know it. Deepfakes and synthetic media must be clearly labeled as AI-generated. For most consumer-facing AI applications, this is the tier that applies, and while the obligations are lighter, they're still real.
Tier 4: Minimal Risk - Largely Unregulated
Minimal risk is essentially a catch-all category defined by exclusion rather than by a defined provision in the EU AI Act. The term "minimal or no risk" is commonly used to describe AI systems that fall outside the specific obligations of the Act. In other words, if your system isn't prohibited, high-risk, or subject to Article 50 transparency obligations, it falls here by default. This includes the majority of AI applications on the EU single market, such as spam filters, recommendation engines, basic automation tools, and AI in video games. There are no mandatory requirements for this tier, though the EU encourages voluntary codes of conduct.
The Bottom Line on Risk Classification
Risk classification isn't always obvious, and getting it wrong has real consequences. A hiring tool might seem like minimal risk until you realize it falls squarely in Annex III. An AI-powered customer service platform might look like a chatbot until it's making decisions that affect access to financial services. As the August 2026 deadline approaches, risk classification is a business-critical decision.
High-Risk System Compliance
High-risk AI systems must meet specific standards in Section 2 of the EU AI Act across risk management, data governance, transparency, human oversight, and cybersecurity. Providers must also have a quality management system in place, keep specific documentation and logs of risk events, complete conformity assessments, register with the EU, obtain and affix CE marking, and keep monitoring their systems long after launch in accordance with Section 3.
By August 2026, high-risk AI providers must:
- Establish a risk management system throughout the high risk AI system's lifecycle;
- Conduct data governance, ensuring that training, validation and testing datasets are relevant, sufficiently representative and, to the best extent possible, free of errors and complete according to the intended purpose;
- Draw up technical documentation to demonstrate compliance and provide authorities with the information to assess that compliance;
- Design their high risk AI system for record-keeping to enable it to automatically record events relevant for identifying national level risks and substantial modifications throughout the system's lifecycle;
- Provide instructions for use to downstream deployers to enable the latter's compliance;
- Design their high risk AI system to allow deployers to implement human oversight;
- Design their high risk AI system to achieve appropriate levels of accuracy, robustness, and cybersecurity;
- Establish a quality management system to ensure compliance.
The Good News
Businesses that get ahead of compliance now aren't just avoiding fines - they're building the kind of credibility with customers, partners, and investors that is hard to earn in a crowded market. The window to get this right is now.
Readers with questions or corrections, please contact info@abusselaw.com.
