Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
The risk-based structure
The AI Act is built around risk. Some practices are banned, some AI systems are high-risk and subject to strict obligations, some systems mainly require transparency, and many ordinary systems remain minimal or low risk. This means your first operational task is not buying software; it is classifying what your AI system actually does and who it affects.
The four practical buckets
- Unacceptable risk: practices that are prohibited, such as harmful manipulation, social scoring, and certain biometric or emotion-recognition uses.
- High-risk: AI used in sensitive areas such as employment, education, essential services, critical infrastructure, law enforcement, migration, justice, and regulated product safety.
- Transparency-risk: use cases where people need to know they are interacting with AI or seeing AI-generated content.
- Minimal or no risk: most everyday AI use, such as spam filtering or productivity support, provided it does not move into sensitive decision-making.
What businesses should document
Create a simple AI register. For each system, record the use case, owner, vendor, model type, data used, affected people, decision impact, human review process, transparency notices, risk controls, monitoring plan, and review date. This register becomes the foundation for policies, risk assessments, training, and legal review.
Common mistakes
- Assuming the AI Act only affects AI vendors and not deployers.
- Using AI in HR, scoring, eligibility, or customer decisions without a documented risk review.
- Allowing employees to paste confidential or personal data into unapproved tools.
- Skipping user notices for chatbots, AI-generated media, or automated interactions.
- Treating AI governance as a one-time project instead of a monthly operating process.
FAQ
When did the AI Act enter into force?
The AI Act entered into force in 2024 and applies in phases, with key obligations applying on different dates.
What is the first thing a company should do?
List all AI systems and use cases, then classify them by risk and role.
Can internal productivity AI be low risk?
Often yes, but it still needs policies for data protection, security, confidentiality, human review and acceptable use.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.