The EU AI Act, in practice
The EU AI Act, turned into a checklist you can use.
Skip the fear and the framework. Here is what the Act asks of you, how to sort your own AI uses in ten minutes, and what to do this week.
The EU AI Act sorts each AI use, not each tool, into four tiers. A few uses are prohibited. High-risk uses, mainly hiring, worker management, and decisions about access to essential services, require human oversight with a named owner, monitoring, and an audit trail. Uses that generate content a person interacts with require a disclosure that it is AI. Everything else is minimal-risk, with a general AI-literacy duty that is already live. Most companies are deployers, not builders, so in practice the job is to triage your uses, name who oversees each consequential one, and keep evidence that the controls work.
iA practical guide, not legal advice. It gets you to the right questions and a defensible first move. The final call on any specific use still goes past your own counsel.
Ten-minute triage
Sort one AI use in ten minutes
Classify the use, not the tool. The same tool can be minimal-risk in one workflow and high-risk in another. Take one use and describe it as department + tool + what it does + the data it touches. Then answer three questions.
Question 1 of 3
Does the use do anything on the banned list?
Scoring or rating people socially, inferring the emotions of staff at work, scraping faces from the web to build a recognition database, or nudging people in ways that exploit or manipulate them.
Question 2 of 3
Does it help decide about a person?
Screening or ranking job candidates, allocating or evaluating work, managing staff, biometric categorisation, or gating access to an essential service. In short, does it make or materially shape a decision about someone's job or access?
Question 3 of 3
Does it create or change content a person will see or talk to?
A chatbot people interact with, or generated or edited text, image, audio, or video that reaches an audience.
Stop. This use is not allowed.
It falls under an Article 5 prohibition. There is no version of it that ships with conditions. Do not soften it into a "high-risk with controls" case.
Allowed, with real obligations.
Uses that decide about people carry the Act's heaviest deployer duties. This is the tier to slow down on and get right before go-live.
Allowed. Just disclose it.
The obligation is honesty: the person must know they are dealing with AI or with AI-generated content.
The fast lane. Most uses land here.
Drafting, summarising, searching internal knowledge, meeting prep. No specific Act obligation beyond the general AI-literacy duty that is already live.
AI use register
No uses yet. Run one through the triage above, name it, and add it here. It stays on this device.
Classify the use, not the tool. A use is high-risk mainly when it helps decide about people: screening or ranking job candidates, allocating work, managing or evaluating staff, or gating access to essential services, plus biometric categorisation. Most everyday uses, drafting, summarising, searching internal knowledge, are not high-risk. The quick test: does this use make or materially shape a decision about a person's job or access to a service? If yes, treat it as high-risk and apply oversight, monitoring, and an audit trail. If it only generates content someone reads, it needs an AI disclosure. If neither, it is minimal-risk.
The four tiers
What each tier asks of you
The whole Act, for a company that uses AI, comes down to these four. Keep the reference next to your use register.
You're here if
the use does social scoring, infers staff emotions at work, scrapes faces to build recognition databases, or manipulates behaviour.
The Act asks
Nothing. It is banned.
Do this
reject it, record why, find another route to the goal.
You're here if
the use helps decide about people: hiring, worker management, biometric categorisation, or access to essential services.
The Act asks
human oversight with a named owner, monitoring, relevant input data, information to people affected, and an audit trail.
Do this
name the overseer and the override point before go-live; add a DPIA if personal data is in scope.
You're here if
the use is a chatbot people talk to, or it generates or edits content an audience sees.
The Act asks
a clear disclosure that it is AI or AI-generated.
Do this
add the disclosure, name who owns it; escalate if it touches editorial or a person's likeness.
You're here if
it is drafting, summarising, internal search, meeting prep. The large majority of everyday uses.
The Act asks
nothing specific, beyond the general AI-literacy duty that is already live.
Do this
record it as approved, note the data category, keep it visible in the register.
Do this now
Your day-one checklist
None of these need a law firm. They are the moves that turn the Act from a worry into a set of decisions you own. Tick them off, this page remembers where you got to.
Start with five moves, none of which need a law firm. Name one owner for AI governance who is not only Legal. List your live AI uses described as the use, not the tool. Triage each into a tier. For every consequential use, name a person who can intervene and the point where they do. Flag the three things that carry obligations: uses that decide about people, uses that generate content people see, and uses that touch personal data. Then start AI literacy for everyone who deploys or decides on AI, which is already required, and keep a short evidence record per consequential use.
Govern the use, not the tool.
Ownership
Who owns what
The one failure mode is collapsing all of this onto Legal. It sits across four seats, and the board keeps the piece it cannot delegate.
The board
owns the risk posture: how much AI risk the company will carry, and for what return. This is the piece that cannot be delegated.
The AI-policy owner
holds the framework and the register: the standing policy, the list of uses, and the triage. One accountable seat, not a committee.
The use-case owner
runs the controls on their own use: the overseer, the override point, the monitoring, the evidence. Where the work actually happens.
Legal
advises on the hard classifications and the high-risk cases. It cannot make the business judgment about which uses are worth the risk.
Yes. If you use third-party AI systems you are a deployer, and deployers carry real obligations, they are just lighter than a builder's. For consequential uses you need a named person who can oversee and intervene, you must use the system for its intended purpose, monitor it, keep input data relevant, and inform people where a high-risk use affects them. The AI-literacy duty applies to every organisation. So the common belief that the Act is only for AI companies is wrong: almost every company that uses AI is a deployer with duties to meet.
Straight Answers
What does the EU AI Act require of companies?
The EU AI Act sorts each AI use, not each tool, into four tiers. A few uses are prohibited. High-risk uses, mainly hiring, worker management, and decisions about access to essential services, require human oversight with a named owner, monitoring, and an audit trail. Uses that generate content a person interacts with require a disclosure that it is AI. Everything else is minimal-risk, with a general AI-literacy duty that is already live. Most companies are deployers, not builders, so in practice the job is to triage your uses, name who oversees each consequential one, and keep evidence that the controls work.
How do I know if my AI use is high-risk under the EU AI Act?
Classify the use, not the tool. A use is high-risk mainly when it helps decide about people: screening or ranking job candidates, allocating work, managing or evaluating staff, or gating access to essential services, plus biometric categorisation. Most everyday uses, drafting, summarising, searching internal knowledge, are not high-risk. The quick test: does this use make or materially shape a decision about a person's job or access to a service? If yes, treat it as high-risk and apply oversight, monitoring, and an audit trail. If it only generates content someone reads, it needs an AI disclosure. If neither, it is minimal-risk.
What should a company do first to comply with the EU AI Act?
Start with five moves, none of which need a law firm. Name one owner for AI governance who is not only Legal. List your live AI uses described as the use, not the tool. Triage each into a tier. For every consequential use, name a person who can intervene and the point where they do. Flag the three things that carry obligations: uses that decide about people, uses that generate content people see, and uses that touch personal data. Then start AI literacy for everyone who deploys or decides on AI, which is already required, and keep a short evidence record per consequential use.
Does the EU AI Act apply to companies that only use AI, not build it?
Yes. If you use third-party AI systems you are a deployer, and deployers carry real obligations, they are just lighter than a builder's. For consequential uses you need a named person who can oversee and intervene, you must use the system for its intended purpose, monitor it, keep input data relevant, and inform people where a high-risk use affects them. The AI-literacy duty applies to every organisation. So the common belief that the Act is only for AI companies is wrong: almost every company that uses AI is a deployer with duties to meet.