The EU AI Act regulates artificial intelligence according to the risk a use case creates, not the technology behind it. The same model can be unregulated in one application and heavily regulated in another - which means classification starts with what the system does, and to whom.
The risk tiers
- Prohibited - practices considered unacceptable, such as certain manipulative techniques, social scoring by public authorities, and specified biometric practices. These are banned outright rather than regulated.
- High risk - the heart of the regime. Includes AI used in defined areas such as employment and worker management, access to essential services including credit, education, critical infrastructure, law enforcement, and as a safety component in regulated products.
- Limited risk - transparency obligations. People should know when they are interacting with AI, and certain generated or manipulated content requires disclosure.
- Minimal risk - the large majority of business applications, with no specific obligations beyond general law.
General-purpose AI models carry their own layer of obligations, with additional requirements where a model is considered to present systemic risk.
Provider or deployer - your role changes everything
- Providers develop an AI system or have it developed and place it on the market under their own name. They carry the heaviest obligations for high-risk systems: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, and conformity assessment.
- Deployers use an AI system under their own authority. Obligations are lighter but real - use the system as instructed, ensure human oversight, monitor operation, and in some cases inform affected people.
Roles can shift. Substantially modifying a high-risk system, or putting your own name on it, can turn a deployer into a provider - with the full obligation set attached. Check this before white-labelling anything.
Classify your AI systems now
GRC Copilot inventories your AI systems, assesses them against EU AI Act expectations and ISO 42001, and shows which obligations attach to each based on how it is used.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Extraterritorial reach
Like the GDPR, the Act reaches beyond the EU. It can apply to providers placing systems on the EU market regardless of establishment, and where output produced by a system is used in the EU. Being outside Europe is not, by itself, an exemption.
What to do now, regardless of classification
- Build an AI inventory. You cannot classify what you have not catalogued - and this includes AI features inside tools you already buy.
- Determine your role per system - provider or deployer. It is per system, not per organisation.
- Classify by use case, focusing on anything affecting people's access to employment, credit, education or essential services.
- Assess data governance - what the system was trained or grounded on, and whether you had rights to use it.
- Define human oversight that is meaningful: a reviewer with the authority, information and time to override.
- Enable logging sufficient to reconstruct how a decision was reached.
- Prepare transparency notices where people interact with AI or see generated content.
- Update vendor due diligence to capture AI role, model provenance and change notification.
How ISO 42001 helps
ISO 42001 is not the Act and does not confer compliance with it. What it provides is the management system - inventory, accountability, impact assessment, monitoring and improvement - that makes demonstrating Act obligations feasible. Organisations building an AI management system now are substantially better placed than those treating the Act as a future legal project.
Obligations phase in over time and guidance continues to develop. Confirm current requirements and timelines with qualified counsel for your specific systems - this article is orientation, not legal advice.
Frequently asked questions
Does the Act apply to us if we only use AI tools?
Potentially, as a deployer - with lighter obligations than a provider. If you substantially modify a system or place it under your own name, you may become a provider.
Is most business AI high risk?
No. The majority of internal productivity uses fall into minimal risk. High risk is defined by specific areas, most of which involve decisions affecting people.
Does ISO 42001 certification make us compliant?
No. It gives you the governance structure and evidence to demonstrate obligations, but the Act is law with its own requirements and conformity processes.
Where should we start?
The AI inventory. Every subsequent decision - role, tier, obligations - depends on knowing which systems exist and what they are used for.
Key takeaways
- Risk tiers attach to the use case, not the technology.
- Provider and deployer obligations differ sharply - and roles can shift.
- The Act reaches organisations outside the EU.
- Start with an AI inventory; everything else depends on it.