Skip to content

4.10 — Compliance: the EU AI Act (and GDPR)

After the technical guardrails (4.3-4.7), here come the legal ones. Deploying AI in your company also means following the law. Europe passed the AI Act — the first major legal framework for AI. Good news: most business uses face light obligations.

🟢 In plain terms — the AI Act ranks AI systems by their risk level for people. The higher the risk, the heavier the obligations. The vast majority of everyday uses fall into the lowest tier (no new obligation).

🚦 The 4 risk levels.

  • Unacceptable → banned (since February 2025): social scoring, subliminal manipulation, emotion recognition at work…
  • High risk → heavy obligations: hiring AI, credit scoring, biometrics… → documentation, human oversight, testing, logging.
  • Limited risk → transparency: chatbots, generative AI → you must say it’s an AI (and label generated content).
  • Minimal risk → nothing: the vast majority (spam filters, product suggestions…).

🧩 Concrete example — your customer-support agent (a chatbot) = limited risk → one simple obligation: tell the user they’re talking to an AI. But an agent that screens job applications = high risk → serious obligations (documentation, human oversight, non-discrimination).

📅 The timeline (freshness note ⏳). The bans apply since February 2025; obligations for general-purpose models (GPAI, the large models like GPT/Claude) since August 2025; high-risk obligations phase in over 2026-2027. ⚠️ These deadlines are regularly adjusted — check the official source before any decision (links below).

⚠️ Common mistake — thinking “the AI Act makes AI illegal” or “it only concerns big companies”. False: most uses face light obligations. In practice the real day-to-day topic is often GDPR: as soon as your AI processes personal data (customer emails, CVs, contact details…), it applies — legal basis, minimisation, and never send sensitive personal data to a model without care (recall: the “lethal trifecta”, 4.4).

Check your understanding — your agent screens job applications for a role. What risk level under the AI Act, and what consequence?

See the answer

High risk (hiring is explicitly covered). Consequence: serious obligations — documentation, human oversight (a human decides, not the machine alone), non-discrimination testing, logging. This is exactly the kind of use where Human-in-the-Loop (4.6) is not optional.

In short

  • The AI Act ranks AI into 4 levels: unacceptable (banned) · high risk (heavy) · limited (transparency) · minimal (nothing).
  • Most business uses = limited or minimal risk → light obligations.
  • Sensitive uses (hiring, credit…) = high risk → documentation + human oversight.
  • GDPR applies as soon as there’s personal data — often the real day-to-day topic.

🔎 Going further. Possible penalties (large fines), official text and timeline: digital-strategy.ec.europa.eu and artificialintelligenceact.eu. The field moves fast: treat these as a starting point, not legal advice.

How would you rate this lesson?
📝 My note

A training byBaxIA