How do the risk tiers work?
The Act sorts AI uses into four tiers, each with its own regime — from a complete ban down to nothing. Classification follows the system's intended purpose and context, not the underlying technology.
| Risk tier | Examples | What is required |
|---|---|---|
| Unacceptable risk | Social scoring by authorities, harmful manipulation | Prohibited outright |
| High risk | AI in hiring, credit scoring, critical infrastructure, healthcare | Risk management, data quality, documentation, human oversight, conformity assessment |
| Limited risk (transparency) | Chatbots, AI-generated content | Disclosure duties — users must know they face AI or generated content |
| Minimal risk | Spam filters, AI in games | No dedicated obligations |
Who does the AI Act apply to — including outside the EU?
The Act binds providers who develop AI systems and deployers who use them — including those established outside the EU, when the system is placed on the EU market or its output is used in the EU. It is the same extraterritorial pattern the world learned from GDPR.
- A non-EU vendor selling an AI product to EU customers — a provider in scope, with obligations set by the product's risk tier.
- A company using AI in operations that touch the EU — potentially a deployer with usage duties.
- A company with no EU nexus — outside formal scope, but the Act is likely to shape global standards, as GDPR did.
How does the AI Act interact with GDPR?
They are complementary, not alternatives. The AI Act regulates the system — safety, transparency, oversight — while GDPR keeps governing any personal data flowing through it. Feeding personal data into an AI system engages both regimes at once, which is why data minimization is the one move that helps everywhere.
What should most organizations actually do?
Unless you build high-risk systems, preparation is reasonable AI governance rather than a compliance megaproject — the same foundation as any safe AI adoption effort. Five steps cover the essentials:
- Map your AI uses — every tool and system in the organization, including those employees adopted on their own.
- Classify by risk — does anything touch the sensitive domains (hiring, credit, health)? That is where the obligations concentrate.
- Meet transparency duties — label AI-generated content and tell users when they are talking to a bot.
- Minimize personal data — anonymizing documents before they go into AI tools cuts exposure under GDPR and the AI Act's data-quality expectations in one move.
- Anchor a policy — an AI-use procedure, owners and training; teams certified to ISO 27001 can attach this to the existing ISMS, as covered in our guide to ISO 27001 and AI usage.