The EU AI Act, explained
You've heard of it. Here's how to actually think about it — without the legalese. Two comparisons do most of the work: it's organised like product-safety law (by risk), and it's a close cousin of GDPR (for AI systems instead of personal data).
It's product-safety law for AI.
The Act's whole logic is risk-based. It doesn't regulate "AI" as a technology — it regulates what an AI system is used for. The same model is barely touched inside a spam filter and heavily regulated inside a hiring tool. Obligations scale with the risk of the use, not the cleverness of the tech.
If you've ever seen a CE mark on a product, you've already met this idea — the EU regulates a kettle and a surgical robot very differently, for the same reason.
Everything sorts into four levels of risk.
Most AI sits in the bottom two tiers. The Act spends almost all of its weight on the high-risk band.
…you're already halfway there.
GDPR governs what you do with personal data. The AI Act governs what you do with AI systems. A hiring tool is both — and the two laws share the same instincts.
Where they're alike
On automated decisions, GDPR's Article 22 and the AI Act's Articles 26 & 86 are two doors into the same room — human oversight plus a right to understand the decision. Regulators and courts read this broadly: even an automated score that feeds a human's final call can count.
Where they differ
Like CE-marking, but for AI.
A high-risk AI system is treated much like a regulated product. Two roles, two sets of duties:
Builds it / puts it on the market
- Run a conformity assessment
- Write the technical documentation
- Register it in the EU database
- Monitor it after launch
Uses it in their organisation
- Follow the provider's instructions
- Keep a competent human in control
- Keep logs of what it did
- Report serious incidents
Where the analogy breaks: the AI Act watches systems after launch more closely than classic product law, and it puts fundamental rights — fairness, non-discrimination — squarely in scope. Open-source is no loophole, either: self-host an open model (say, Mistral) for a high-risk use and you're still the deployer, carrying the full duties — and locality is no loophole either (see running your own AI isn't compliance). Most organisations are deployers, not providers: you're using AI someone else built — though configure, rebrand or repurpose it and the Act can flip you into its provider (see deployer or provider?). Your headline duty is already live — AI literacy for the staff who use it (Article 4), in force since February 2025 — meaning staff who can make informed choices about tools and data, not a generic awareness slide. For a worked sector example — easy wins up to high-risk hiring systems — see AI for HR & talent acquisition.
It arrives in waves — and one deadline has moved.
- 2 Feb 2025 Live now The banned practices and the AI-literacy duty (Art. 4) took effect.
- 2 Aug 2025 Live now Rules for general-purpose AI models (the large foundational models) began.
- 2 Aug 2026 Next Most of the Act applies: governance, transparency duties and the penalty regime.
- 2 Dec 2027 Adopted The heaviest high-risk obligations (Annex III stand-alone) — originally 2 August 2026, deferred to this date by the Digital Omnibus, adopted 29-06-2026.
And the penalties: they are set as a share of worldwide annual turnover — up to 7% for banned practices, 3% for high-risk failures, 1% for misleading information (GDPR reaches 4%, and the two apply in parallel rather than as alternatives). For most companies, though, the bigger cost is commercial: the deal that stalls, not the fine that lands.
From "does this apply to us?" to evidence.
Knowing the shape of the law is step one. Knowing which of your systems it catches — and what you can show for it — is the work. And the Act is only part of the picture: for the risks it doesn't reach, see the risks of AI, mapped.
Not sure which of your systems the Act catches?
Bring it along. An honest read, no pitch.
Book a discovery call →Related guides
The EU AI Act timeline
From a 2021 proposal to a law that lands in waves. The full chronology — adoption, entry into force and every date of application — what each wave switches on, who it binds, and the one high-risk deadline that has moved.
Read the guide Provider or deployerDeployer or provider?
Most companies using AI are “deployers”, with manageable duties. But configure, rebrand or repurpose that AI and the Act can treat you as its “provider” — with a manufacturer’s full obligations. The line, and how not to cross it by accident.
Read the guide