AI & Technology Law · European Union
The EU AI Act in Plain Language: Risk Categories and What They Mean
A plain-language walkthrough of the EU AI Act's risk-based framework, who it applies to, and the rough compliance timeline businesses deploying AI should be aware of.
The EU AI Act is the first comprehensive law regulating artificial intelligence by a major regulator, and it’s built around a core idea: obligations scale with risk, rather than applying the same rules to every AI system.
Who it applies to
Like the GDPR, the AI Act has extraterritorial reach. It covers providers and deployers of AI systems placed on the EU market or whose output is used within the EU — meaning a company outside Europe can fall within scope if its AI product is used by people or businesses in the EU.
The four risk tiers
- Unacceptable risk — banned outright. This includes things like social scoring by governments, certain forms of biometric categorization, and manipulative AI that exploits vulnerabilities to cause harm.
- High risk — heavily regulated, not banned. Systems used in areas like hiring, credit scoring, law enforcement, education, and critical infrastructure fall here. These require risk management systems, human oversight, detailed documentation, and conformity assessments before deployment.
- Limited risk — transparency obligations. Chatbots, deepfakes, and AI-generated content generally fall here: the main requirement is disclosure — telling users they’re interacting with AI or that content was AI-generated.
- Minimal risk — largely unregulated. Things like spam filters or AI-enabled video game features face no specific obligations under the Act.
General-purpose AI models get their own rules
Foundation models and general-purpose AI systems (the kind powering many chatbots and assistants) are subject to a separate set of obligations, including technical documentation and, for the most capable models, additional risk assessment and incident reporting requirements.
Rough timeline
The Act entered into force in August 2024, but its obligations phase in over several years rather than all at once: bans on unacceptable-risk practices applied first, followed by rules for general-purpose AI models, with the bulk of high-risk system obligations phasing in over roughly two to three years from entry into force. Businesses building or deploying AI in the EU should check the current phase-in status, since the schedule has specific milestones rather than one single deadline.
What this means for a typical business
Most companies using AI tools (rather than building foundation models themselves) will care most about two things: whether any AI feature they deploy falls into the “high-risk” category, and whether they’re meeting the transparency requirements for anything user-facing, like chatbots or AI-generated content. Providers of the underlying models carry the bulk of the heavier compliance burden.
This article summarizes a fast-evolving area of law; specific compliance obligations should be confirmed against the current regulatory guidance and, where relevant, discussed with legal counsel.
- AI regulation
- EU AI Act
- technology law
- compliance
This article is provided for general informational purposes only and does not constitute legal advice. Read our full disclaimer.