Skip to main content

EU AI Act.

The EU AI Act is the world's first comprehensive AI regulation. Four risk tiers: unacceptable (banned), high (the heavy obligations and conformity assessment), limited (transparency), minimal. Applies in phases until August 2027. Pair it with ISO 42001 if you want a management-system answer rather than a checklist. The GPAI model rules sit on top.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyEU regulationsAll entries

The Cyber Academy take

The EU AI Act is the world's first comprehensive AI regulation. Four risk tiers: unacceptable (banned), high (the heavy obligations and conformity assessment), limited (transparency), minimal. Applies in phases until August 2027. Pair it with ISO 42001 if you want a management-system answer rather than a checklist. The GPAI model rules sit on top.

A risk-based law, not a technology ban

The EU AI Act regulates artificial intelligence by what a system does and who it can affect, not by the algorithm behind it. The same machine learning technique can be unregulated in one context and tightly controlled in another. That is the core idea behind the four risk tiers: unacceptable practices are prohibited outright, high-risk systems carry the heavy obligations, limited-risk systems owe transparency to the people interacting with them, and minimal-risk systems are left largely untouched. Most AI in everyday use sits in that minimal band, which is why the Act is better understood as targeted regulation of consequential uses rather than a blanket licence regime for all AI.

The Act is a regulation, so it applies directly across every member state without each country having to transpose it into national law. Its reach is also extraterritorial in spirit: providers and deployers outside the EU fall within scope when their AI system is placed on the EU market or its outputs are used in the Union. Practitioners should map their systems against the tiers early, because the classification drives everything that follows, from documentation to conformity assessment.

Where the obligations actually bite

Almost all of the operational weight lands on high-risk systems. These are typically AI used in regulated products or in sensitive domains such as critical infrastructure, employment, access to essential services, law enforcement and the administration of justice. For these, the Act expects a working set of disciplines rather than a one-off form: a risk management system maintained across the lifecycle, data governance for training and testing data, technical documentation, logging, transparency and instructions for use, human oversight that lets a person meaningfully intervene, and an appropriate level of accuracy, robustness and cybersecurity. Before a high-risk system reaches the market it must pass a conformity assessment, and providers run post-market monitoring once it is live.

GPAI, transparency and the phased timeline

On top of the tiers sits a separate regime for general-purpose AI models, the foundation models that power many downstream applications. GPAI providers face transparency and documentation duties, with stricter requirements for the most capable models judged to carry systemic risk. This layer was added precisely because a single general-purpose model can flow into countless high-risk and limited-risk uses, so regulating only the end application would leave a gap.

Limited-risk obligations are lighter but real. They centre on transparency: people should know when they are interacting with an AI system, and certain synthetic or manipulated content should be marked as artificially generated. The Act enters force and applies in phases, with prohibitions, GPAI rules and high-risk obligations switching on at different points through to 2027, which gives organisations a runway but also a sequence of hard deadlines to plan against.

How practitioners operationalise it

In practice the Act is a checklist of legal obligations, not a management method, so teams pair it with a system that can carry those obligations day to day. ISO/IEC 42001 is the common answer: an AI management system gives you the risk assessments, data governance, human-oversight and post-market monitoring routines the Act expects, run as a repeatable system rather than improvised under deadline. The NIST AI Risk Management Framework is often used alongside as a voluntary structure for identifying and treating AI risk. None of these makes a system legally compliant on its own. They make compliance achievable and auditable, which is the difference between demonstrating due diligence and hoping no one asks.

Frequently asked questions

01Does the EU AI Act apply to companies outside the EU?

Yes, it can. The Act reaches providers and deployers established outside the Union when their AI system is placed on the EU market or when the system's output is used inside the EU. Location of the company is not the deciding factor; the market and the use are.

02What makes a system high-risk?

Broadly, AI used as a safety component of a regulated product, or AI used in sensitive areas listed by the Act such as critical infrastructure, employment, education, essential services, law enforcement and justice. High-risk classification triggers the full set of obligations and a conformity assessment before market entry.

03How does the AI Act relate to ISO 42001?

The AI Act sets the legal obligations; ISO/IEC 42001 gives you a certifiable management system to meet them in a structured way. Holding 42001 does not equal legal compliance, but it institutionalises the risk management, data governance, oversight and monitoring the Act expects.

04What is GPAI and why is it regulated separately?

GPAI means general-purpose AI models, the foundation models that feed many downstream applications. They get their own transparency and documentation rules, with extra obligations for the most capable models carrying systemic risk, because one model can propagate into many regulated uses.

05When does the AI Act take effect?

It applies in phases rather than all at once. Prohibited practices, general-purpose AI rules and the high-risk obligations switch on at staggered points after the regulation enters into force, giving organisations time to prepare but a clear sequence of deadlines through to 2027.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.