2026-08-26 · 4 min read

The EU AI Act: risk tiers, who it applies to, and how to prepare

How do the risk tiers work?

The Act sorts AI uses into four tiers, each with its own regime — from a complete ban down to nothing. Classification follows the system's intended purpose and context, not the underlying technology.

Risk tierExamplesWhat is required
Unacceptable riskSocial scoring by authorities, harmful manipulationProhibited outright
High riskAI in hiring, credit scoring, critical infrastructure, healthcareRisk management, data quality, documentation, human oversight, conformity assessment
Limited risk (transparency)Chatbots, AI-generated contentDisclosure duties — users must know they face AI or generated content
Minimal riskSpam filters, AI in gamesNo dedicated obligations

Who does the AI Act apply to — including outside the EU?

The Act binds providers who develop AI systems and deployers who use them — including those established outside the EU, when the system is placed on the EU market or its output is used in the EU. It is the same extraterritorial pattern the world learned from GDPR.

  • A non-EU vendor selling an AI product to EU customers — a provider in scope, with obligations set by the product's risk tier.
  • A company using AI in operations that touch the EU — potentially a deployer with usage duties.
  • A company with no EU nexus — outside formal scope, but the Act is likely to shape global standards, as GDPR did.

How does the AI Act interact with GDPR?

They are complementary, not alternatives. The AI Act regulates the system — safety, transparency, oversight — while GDPR keeps governing any personal data flowing through it. Feeding personal data into an AI system engages both regimes at once, which is why data minimization is the one move that helps everywhere.

What should most organizations actually do?

Unless you build high-risk systems, preparation is reasonable AI governance rather than a compliance megaproject — the same foundation as any safe AI adoption effort. Five steps cover the essentials:

  1. Map your AI uses — every tool and system in the organization, including those employees adopted on their own.
  2. Classify by risk — does anything touch the sensitive domains (hiring, credit, health)? That is where the obligations concentrate.
  3. Meet transparency duties — label AI-generated content and tell users when they are talking to a bot.
  4. Minimize personal dataanonymizing documents before they go into AI tools cuts exposure under GDPR and the AI Act's data-quality expectations in one move.
  5. Anchor a policy — an AI-use procedure, owners and training; teams certified to ISO 27001 can attach this to the existing ISMS, as covered in our guide to ISO 27001 and AI usage.

Frequently asked questions

Does the EU AI Act apply to companies outside Europe?

It can. Providers and deployers outside the EU are in scope when their system is offered on the EU market or its output is used in the EU. A vendor selling an AI product to European customers is almost certainly covered.

When does the AI Act take effect?

It was adopted in 2024 and applies in phases — the outright prohibitions first, with the heavier high-risk obligations following on a staggered timeline.

What counts as a high-risk AI system?

Systems in domains the Act designates as sensitive — for example hiring and employment, credit scoring, critical infrastructure, education and healthcare. These carry risk management, documentation, human oversight and conformity-assessment duties.

We only use ChatGPT internally — does the Act affect us?

Internal use of a general-purpose tool is usually minimal risk under the Act. The real exposure is privacy law: personal data you feed in remains governed by GDPR and local law — which is why minimization and anonymization matter in every scenario.

Does the AI Act replace GDPR?

No. The AI Act regulates AI systems themselves; GDPR continues to apply in parallel to any processing of personal data. Organizations in scope of both must comply with both.