The EU AI Act does not treat all artificial intelligence the same way. Obligations depend on the risk a system poses to people. So the first step for any company is to know which category its systems fall into.
The four levels
- Unacceptable risk: practices that are prohibited, such as harmful manipulation of behavior or social scoring of people.
- High risk: systems used in sensitive areas such as employment, education, credit or essential services. Detailed requirements apply to them.
- Limited risk: systems with transparency obligations, for example chatbots, where people must know they are talking to a machine.
- Minimal risk: most applications, for which there are no specific obligations.
What high-risk systems require
- Risk management throughout the system's life.
- Quality and governance of the data used for training.
- Technical documentation and event logging.
- Human oversight.
- Accuracy, robustness and cybersecurity.
Who it applies to
The regulation places obligations both on those who develop systems and on those who use them in their work. It also applies to companies outside the EU when their systems are offered on the EU market or their output is used there.
Where to start
Make an inventory of the AI systems you use or develop, including the off-the-shelf tools staff use every day. Classify each one by risk and focus first on those that affect decisions about people.
