The EU AI Act, translated for the people building the product
Most business AI features land in the lighter tiers of the EU AI Act, but that is a conclusion you should reach deliberately and record, rather than assume.
By Quality AboveAll · · 9 min read
- Obligations scale with risk tier, and most internal productivity features sit in the minimal or limited tier.
- Transparency obligations, telling people they are interacting with AI, apply widely and are easy to satisfy if designed in.
- High-risk classification, which covers areas like employment and credit, brings substantial documentation and oversight duties.
The tiering, briefly
The AI Act categorises systems by risk. A small set of practices is prohibited outright. A defined list of high-risk uses carries heavy obligations. A limited-risk tier attracts transparency duties, and everything else sits in minimal risk with essentially no specific obligations.
The practical first task is classification: work out honestly which tier each AI feature falls into and write down the reasoning. That document is what you produce when someone asks, and producing it takes an afternoon while reconstructing it later takes weeks.
Where typical features land
Internal productivity tools, drafting assistants, summarisation, search and most customer support applications generally fall into minimal or limited risk. The main duty is transparency, and it is easily met by telling users they are interacting with an AI system.
The categories that change the picture are things like recruitment and employee evaluation, credit assessment, education access decisions, and certain critical infrastructure and biometric uses. If your feature influences one of those decisions, the classification question deserves proper legal input rather than an engineering judgement.
The question is not whether you use AI. It is whether your AI affects a decision about a person that the law has decided matters.
What high-risk actually requires
Risk management across the lifecycle, data governance covering the training and input data, technical documentation, logging, human oversight, and accuracy and robustness commitments, plus a conformity process before going to market.
That is a substantial programme, not a checklist item. If a feature is heading into that territory, the sensible sequence is to confirm classification early and budget the compliance work as part of the project rather than discovering it at launch.
General-purpose model obligations
Obligations also attach to providers of general-purpose models, covering documentation and transparency about training data among other things. Most product teams are deployers rather than providers, which is a lighter position.
That distinction is worth confirming for your specific arrangement, particularly if you fine-tune models or distribute them. Your provider's documentation is also something you may need to rely on, so knowing what they publish is part of vendor assessment, as in the vendor checklist.
What to do now regardless of tier
Keep an inventory of AI features with their purpose, data, model and classification reasoning. Implement transparency in the interface. Keep humans in the loop where decisions affect people. Log enough to explain a specific output after the fact.
None of that is wasted even if your features stay in minimal risk, because it is the same documentation that makes an AI feature defensible in a customer security review or an internal audit. The mechanics are in AI model governance, and this is general information rather than legal advice, so take proper counsel on classification questions.
Frequently asked questions
Does the AI Act apply to companies outside the EU?
It can apply based on where the system's output is used, so serving EU users can bring you into scope regardless of where you are established. Confirm your position with counsel.
Is a customer support chatbot high risk?
Generally not. It typically attracts transparency obligations rather than high-risk duties, though the specific use and what decisions it influences determine the answer.
What should we prepare first?
An inventory of AI features with documented classification reasoning, plus transparency in the interface. Both are useful immediately and required later if scope changes.
Unsure where your AI features sit under the AI Act? A free 30-minute consultation covers the technical documentation and controls side, alongside your legal advice.