Book a Free Strategy Call
Skip the read: talk to Walid in 30 min.
Free strategy call. We map your AI engineering team, you keep the notes.
The EU AI Act is the first comprehensive AI-specific regulation of its kind, and its requirements scale directly with how risky a given AI system is judged to be, from essentially no obligations for minimal-risk systems to strict requirements for anything classified as high-risk. Understanding where a specific system falls in that risk tiering is the necessary first step before any compliance work makes sense, since the requirements that actually apply depend entirely on that classification.
This guide covers the Act's risk-based structure, what compliance actually requires at each tier, and a practical starting checklist. This is general information, not legal advice, and any organization with real compliance exposure should get qualified legal counsel for their specific situation.
The Act's risk-based structure
Unacceptable risk. A narrow category of AI applications the Act prohibits outright, including systems using manipulative techniques that cause harm, certain forms of biometric categorization, and social scoring by public authorities. If a system falls into this category, the answer isn't a compliance checklist, it's that the system can't be deployed in the EU market at all.
High-risk. Systems used in specific sensitive contexts explicitly listed in the Act, including employment and worker management, access to essential services (like credit scoring), education and vocational training, law enforcement, and migration and border control. These carry the most substantial compliance obligations: risk management systems, data governance requirements, technical documentation, human oversight, and conformity assessment before market placement.
Limited risk. Systems with specific transparency obligations, most notably that users need to be informed they're interacting with an AI system rather than a human, relevant for chatbots and similar interactive systems, without the full high-risk compliance burden.
Minimal risk. The large majority of AI applications, spam filters, AI-enabled video game features, and similar low-stakes systems, which face no specific obligations under the Act beyond general legal requirements that would apply regardless of AI involvement.
Related Reads
What compliance actually requires for high-risk systems
A risk management system. An ongoing, documented process for identifying, evaluating, and mitigating risks throughout the system's lifecycle, not a one-time assessment before launch, similar in spirit to the ongoing process covered in our guide to AI risk assessment frameworks.
Data governance requirements. Training, validation, and testing data need to meet quality criteria and be examined for possible biases, connecting directly to the bias testing discipline for systems affecting consequential decisions.
Technical documentation. Detailed documentation of the system's design, development process, and performance characteristics, conceptually related to but more extensive than the documentation covered in model cards.
Human oversight. High-risk systems need to be designed so a human can effectively oversee their operation, including the ability to intervene or halt the system, not deployed as a fully autonomous black box making consequential decisions unchecked.
Conformity assessment before market placement. High-risk systems generally need to undergo a conformity assessment confirming compliance with the Act's requirements before being placed on the market or put into service.
Free weekly brief
Steal our production automations
The exact n8n flows, Claude Code setups, and prompts we ship for clients, broken down step by step. No spam, unsubscribe anytime.
A comparison by risk tier
| Risk tier | Example | Compliance burden |
|---|---|---|
| Unacceptable | Manipulative or social-scoring systems | Prohibited outright |
| High-risk | Hiring tools, credit scoring, critical infrastructure | Risk management, data governance, documentation, human oversight, conformity assessment |
| Limited risk | Customer-facing chatbots | Transparency obligation (disclose AI interaction) |
| Minimal risk | Spam filters, low-stakes automation | No specific obligations |
A practical starting checklist
Determine which risk tier your system actually falls into. This is the foundational step, since it determines everything else. Review the Act's specific listed high-risk categories against your actual use case rather than assuming based on general impressions of how sensitive the application feels.
If high-risk, inventory what documentation and processes you already have versus what's required. Compare your existing risk assessment, data governance, and technical documentation practices against the Act's specific requirements to identify concrete gaps.
If limited risk, confirm your transparency obligations are actually met. Check that users interacting with an AI-driven interface are clearly informed of that fact, a comparatively lighter but still explicit requirement.
Build ongoing compliance into your development process, not a one-time review. The Act's risk management requirement for high-risk systems is explicitly ongoing, which means compliance needs to be embedded into how the system is maintained and updated, not treated as a single pre-launch gate.
Get qualified legal counsel for your specific situation. This checklist is a starting orientation, not a substitute for legal review, particularly for any system with real exposure under the high-risk category, given the direct consequences of getting classification or compliance wrong.
FAQ
What is the EU AI Act?
The EU AI Act is a comprehensive regulation governing AI systems in the EU market, structuring obligations around a risk-based tiering system, from prohibited unacceptable-risk applications to no specific obligations for minimal-risk systems.
How do I know if my AI system is classified as high-risk under the EU AI Act?
The Act lists specific categories considered high-risk, including employment and worker management, access to essential services like credit scoring, education, law enforcement, and migration control. Reviewing your specific use case against these listed categories, ideally with legal counsel, determines classification.
What does compliance require for a high-risk AI system?
An ongoing risk management system, data governance meeting quality and bias-examination criteria, detailed technical documentation, human oversight capability, and conformity assessment before the system is placed on the market.
What transparency obligations apply to limited-risk AI systems like chatbots?
Users need to be informed they're interacting with an AI system rather than a human, a specific but comparatively lighter obligation than the full compliance burden required for high-risk systems.
Does the EU AI Act apply to AI systems outside the EU?
The Act's scope can extend to providers and deployers outside the EU whose AI systems are placed on the EU market or affect people within the EU, which is a jurisdiction question worth confirming with legal counsel for any organization operating internationally.
Is EU AI Act compliance a one-time process?
No, particularly for high-risk systems, where the risk management requirement is explicitly ongoing throughout the system's lifecycle, not a single assessment completed before launch and never revisited.
For the ongoing risk-management process this connects to, see our AI risk assessment framework guide. For the bias-testing and documentation practices that support compliance, read AI bias testing and AI model card documentation. Our AI strategy consulting service helps organizations build the ongoing governance processes EU AI Act compliance requires; this is not a substitute for qualified legal counsel on your specific situation.
Sources: EU AI Act (Regulation (EU) 2024/1689) public text, internal AY Automate AI governance and strategy consulting practice.
Continue Reading
Shadow AI: The Enterprise Risk Hiding in Plain Sight (2026)
Why shadow AI spreads so easily inside organizations, the specific risks it creates, and how to address it without just banning tools that solve a real problem.
Responsible AI Framework for the Enterprise: How to Build One (2026)
What a responsible AI framework actually consists of, how it differs from scattered good practices, and how to build one that shapes real decisions.
Prompt Injection Attacks on AI Agents: How They Work, How to Defend (2026)
How prompt injection actually works, the difference between direct and indirect injection, and the practical defenses worth building into any agent processing untrusted content.
Book a Free Strategy Call
Building this in production?
Walid runs a 30-min call to map your AI engineering team. Free, no slides.
Free weekly brief
Steal our production automations
The exact n8n flows, Claude Code setups, and prompts we ship for clients, broken down step by step. No spam, unsubscribe anytime.

Ex-IBM AI engineer and enterprise architect. Adel owns the technical architecture behind every automation and AI agent system AY Automate ships.



