GRAIL
What we do Why GRAIL Essays Industry Briefings Book a call

The EU AI Act, in practice

The EU AI Act, turned into a checklist you can use.

Skip the fear and the framework. Here is what the Act asks of you, how to sort your own AI uses in ten minutes, and what to do this week.

The EU AI Act sorts each AI use, not each tool, into four tiers. A few uses are prohibited. High-risk uses, mainly hiring, worker management, and decisions about access to essential services, require human oversight with a named owner, monitoring, and an audit trail. Uses that generate content a person interacts with require a disclosure that it is AI. Everything else is minimal-risk, with a general AI-literacy duty that is already live. Most companies are deployers, not builders, so in practice the job is to triage your uses, name who oversees each consequential one, and keep evidence that the controls work.

iA practical guide, not legal advice. It gets you to the right questions and a defensible first move. The final call on any specific use still goes past your own counsel.

Ten-minute triage

Sort one AI use in ten minutes

Classify the use, not the tool. The same tool can be minimal-risk in one workflow and high-risk in another. Take one use and describe it as department + tool + what it does + the data it touches. Then answer three questions.

Your AI use

Question 1 of 3

Does the use do anything on the banned list?

Scoring or rating people socially, inferring the emotions of staff at work, scraping faces from the web to build a recognition database, or nudging people in ways that exploit or manipulate them.

Question 2 of 3

Does it help decide about a person?

Screening or ranking job candidates, allocating or evaluating work, managing staff, biometric categorisation, or gating access to an essential service. In short, does it make or materially shape a decision about someone's job or access?

Question 3 of 3

Does it create or change content a person will see or talk to?

A chatbot people interact with, or generated or edited text, image, audio, or video that reaches an audience.

Prohibited

Stop. This use is not allowed.

It falls under an Article 5 prohibition. There is no version of it that ships with conditions. Do not soften it into a "high-risk with controls" case.

Do this: record it as rejected with the reason, tell the requesting team why, and escalate to management if it comes back. Look for a different way to reach the goal that does not rely on a banned technique.
High-risk

Allowed, with real obligations.

Uses that decide about people carry the Act's heaviest deployer duties. This is the tier to slow down on and get right before go-live.

Do this: name a person who can oversee it and the exact point where they can intervene, use it only for its stated purpose, monitor it and log issues, keep the input data relevant, inform the people it affects, and hold an audit trail. If personal data is involved, add a data-protection impact assessment. This is the one to run past counsel.
Limited transparency

Allowed. Just disclose it.

The obligation is honesty: the person must know they are dealing with AI or with AI-generated content.

Do this: add a clear disclosure that the content or chat is AI, and name who owns that disclosure. If the content touches your editorial output or a person's likeness, treat it as more than a checkbox and bring in the rights owner.
Minimal risk

The fast lane. Most uses land here.

Drafting, summarising, searching internal knowledge, meeting prep. No specific Act obligation beyond the general AI-literacy duty that is already live.

Do this: record it as approved, name the data category, and move on. Keep it in the register so it is visible, and let the AI-literacy baseline cover it.

AI use register

0 uses

No uses yet. Run one through the triage above, name it, and add it here. It stays on this device.

Classify the use, not the tool. A use is high-risk mainly when it helps decide about people: screening or ranking job candidates, allocating work, managing or evaluating staff, or gating access to essential services, plus biometric categorisation. Most everyday uses, drafting, summarising, searching internal knowledge, are not high-risk. The quick test: does this use make or materially shape a decision about a person's job or access to a service? If yes, treat it as high-risk and apply oversight, monitoring, and an audit trail. If it only generates content someone reads, it needs an AI disclosure. If neither, it is minimal-risk.

The four tiers

What each tier asks of you

The whole Act, for a company that uses AI, comes down to these four. Keep the reference next to your use register.

Prohibited

You're here if

the use does social scoring, infers staff emotions at work, scrapes faces to build recognition databases, or manipulates behaviour.

The Act asks

Nothing. It is banned.

Do this

reject it, record why, find another route to the goal.

High-risk

You're here if

the use helps decide about people: hiring, worker management, biometric categorisation, or access to essential services.

The Act asks

human oversight with a named owner, monitoring, relevant input data, information to people affected, and an audit trail.

Do this

name the overseer and the override point before go-live; add a DPIA if personal data is in scope.

Limited transparency

You're here if

the use is a chatbot people talk to, or it generates or edits content an audience sees.

The Act asks

a clear disclosure that it is AI or AI-generated.

Do this

add the disclosure, name who owns it; escalate if it touches editorial or a person's likeness.

Minimal risk

You're here if

it is drafting, summarising, internal search, meeting prep. The large majority of everyday uses.

The Act asks

nothing specific, beyond the general AI-literacy duty that is already live.

Do this

record it as approved, note the data category, keep it visible in the register.

Do this now

Your day-one checklist

None of these need a law firm. They are the moves that turn the Act from a worry into a set of decisions you own. Tick them off, this page remembers where you got to.

Day-one checklist
0 of 8 done

Start with five moves, none of which need a law firm. Name one owner for AI governance who is not only Legal. List your live AI uses described as the use, not the tool. Triage each into a tier. For every consequential use, name a person who can intervene and the point where they do. Flag the three things that carry obligations: uses that decide about people, uses that generate content people see, and uses that touch personal data. Then start AI literacy for everyone who deploys or decides on AI, which is already required, and keep a short evidence record per consequential use.

Govern the use, not the tool.

Ownership

Who owns what

The one failure mode is collapsing all of this onto Legal. It sits across four seats, and the board keeps the piece it cannot delegate.

The board

owns the risk posture: how much AI risk the company will carry, and for what return. This is the piece that cannot be delegated.

The AI-policy owner

holds the framework and the register: the standing policy, the list of uses, and the triage. One accountable seat, not a committee.

The use-case owner

runs the controls on their own use: the overseer, the override point, the monitoring, the evidence. Where the work actually happens.

Legal

advises on the hard classifications and the high-risk cases. It cannot make the business judgment about which uses are worth the risk.

Yes. If you use third-party AI systems you are a deployer, and deployers carry real obligations, they are just lighter than a builder's. For consequential uses you need a named person who can oversee and intervene, you must use the system for its intended purpose, monitor it, keep input data relevant, and inform people where a high-risk use affects them. The AI-literacy duty applies to every organisation. So the common belief that the Act is only for AI companies is wrong: almost every company that uses AI is a deployer with duties to meet.

Straight Answers

What does the EU AI Act require of companies?

The EU AI Act sorts each AI use, not each tool, into four tiers. A few uses are prohibited. High-risk uses, mainly hiring, worker management, and decisions about access to essential services, require human oversight with a named owner, monitoring, and an audit trail. Uses that generate content a person interacts with require a disclosure that it is AI. Everything else is minimal-risk, with a general AI-literacy duty that is already live. Most companies are deployers, not builders, so in practice the job is to triage your uses, name who oversees each consequential one, and keep evidence that the controls work.

How do I know if my AI use is high-risk under the EU AI Act?

Classify the use, not the tool. A use is high-risk mainly when it helps decide about people: screening or ranking job candidates, allocating work, managing or evaluating staff, or gating access to essential services, plus biometric categorisation. Most everyday uses, drafting, summarising, searching internal knowledge, are not high-risk. The quick test: does this use make or materially shape a decision about a person's job or access to a service? If yes, treat it as high-risk and apply oversight, monitoring, and an audit trail. If it only generates content someone reads, it needs an AI disclosure. If neither, it is minimal-risk.

What should a company do first to comply with the EU AI Act?

Start with five moves, none of which need a law firm. Name one owner for AI governance who is not only Legal. List your live AI uses described as the use, not the tool. Triage each into a tier. For every consequential use, name a person who can intervene and the point where they do. Flag the three things that carry obligations: uses that decide about people, uses that generate content people see, and uses that touch personal data. Then start AI literacy for everyone who deploys or decides on AI, which is already required, and keep a short evidence record per consequential use.

Does the EU AI Act apply to companies that only use AI, not build it?

Yes. If you use third-party AI systems you are a deployer, and deployers carry real obligations, they are just lighter than a builder's. For consequential uses you need a named person who can oversee and intervene, you must use the system for its intended purpose, monitor it, keep input data relevant, and inform people where a high-risk use affects them. The AI-literacy duty applies to every organisation. So the common belief that the Act is only for AI companies is wrong: almost every company that uses AI is a deployer with duties to meet.

Governing AI well is an advantage, not a cost. Want it built into your team?