The EU AI Act is the first broad regulation of AI. Here's how it works and who it affects.
The short answer
The EU AI Act regulates AI systems by risk tier — from prohibited uses, through high-risk systems with strict obligations, down to limited and minimal risk with lighter duties.
Who's affected?
Providers (who build AI systems) and deployers (who use them) operating in the EU. The heaviest obligations fall on high-risk use cases.
What do higher-risk systems require?
- Risk-management and data-governance processes.
- Technical documentation and record-keeping.
- Transparency and human oversight.
- Accuracy, robustness and security.
One AI governance programAn ISO 42001 AI management system and the NIST AI RMF help you satisfy many AI Act obligations, with shared evidence. Run it self-hosted — even on a private model. See AI Governance.
General guidance, not legal advice. Confirm your EU AI Act obligations with your compliance and legal teams.