The EU AI Act explained in plain language comes down to one core idea: AI systems are regulated based on how much risk they pose, not based on what technology they use. A chatbot that helps you draft an email faces almost no special rules; an AI system used to screen job candidates or score creditworthiness faces strict obligations. This guide walks through the four risk tiers, what’s actually banned, the compliance timeline, and what it means in practice if you’re a business using AI tools rather than building them.
The Act is EU law, adopted by the European Parliament and Council and published by the European Commission, and it applies to any provider or user of AI systems affecting people in the EU — not just companies headquartered there. The official source for the regulation and its rollout is the European Commission’s own page, the EU’s regulatory framework for AI, which is worth bookmarking directly since guidance continues to be published as different obligations take effect.
The Four Risk Tiers, Explained
| Risk tier | What it covers | What’s required |
|---|---|---|
| Unacceptable risk | Practices considered too harmful to allow at all | Banned outright — nine prohibited practices |
| High risk | AI in sensitive areas: employment, credit scoring, law enforcement, critical infrastructure, education access | Risk assessment, quality datasets, logging, documentation, human oversight, cybersecurity measures |
| Limited/transparency risk | Systems that interact with people or generate content, like chatbots and deepfakes | Disclosure that AI is involved; labeling of AI-generated content |
| Minimal or no risk | Most everyday AI systems — spam filters, recommendation features, general chat assistants | No specific regulatory requirements |
What’s Actually Banned Under “Unacceptable Risk”
The Act prohibits nine specific categories of AI practice: harmful manipulation or deception, social scoring of individuals, AI used to assess an individual’s risk of committing a crime based on profiling, untargeted scraping to build facial recognition databases, emotion recognition in workplaces and schools, biometric categorization to infer protected characteristics like race or religion, real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions), and non-consensual generation of intimate imagery including child sexual abuse material. Eight of these nine prohibitions already took effect on February 2, 2025; the ninth applies from December 2026. If your business isn’t doing any of these things — and the overwhelming majority of everyday AI use, like drafting text, generating images, or researching with an assistant, is nowhere near this category — this tier isn’t something you need to actively manage, just be aware exists.
High-Risk AI: What It Means for Businesses
The high-risk category is where most of the Act’s real compliance burden sits, and it’s narrower than people often assume — it applies to specific use cases in areas like employment decisions (hiring, firing, performance evaluation), access to essential services (credit scoring, insurance pricing), law enforcement, migration and border control, education (exam scoring, admissions), and critical infrastructure. If your business builds or deploys an AI system that makes or materially influences a decision in one of these areas, it faces obligations including risk assessment and mitigation, use of high-quality training data, detailed technical documentation, activity logging, human oversight requirements, and cybersecurity measures. These obligations become effective December 2, 2027, with an extension to August 2, 2028 for AI systems embedded in already-regulated products like medical devices.
For most small and medium businesses using AI assistants for writing, coding, design or general research — not building automated hiring or credit-scoring systems — this tier simply doesn’t apply. It’s worth understanding mainly so you can correctly recognize when it does: if you’re evaluating an AI tool specifically to screen job applicants or make lending decisions, that’s exactly the scenario where high-risk obligations kick in and deserve real legal review.
Transparency Obligations: The Tier Most People Actually Encounter
The limited-risk or transparency tier is the one most businesses and individuals actually interact with day to day. It requires that people be told when they’re interacting with an AI system rather than a human, and that AI-generated content — including deepfakes and AI-written text published on matters of public interest — be clearly labeled as such. These transparency obligations became applicable in August 2026. In practice, this is why you’ll increasingly see disclosure language like “this response was generated by AI” or labeling on AI-generated images and video, particularly on public-facing content and customer-facing chatbots.
General-Purpose AI Model Obligations
Separately from the risk-tier system for AI applications, the Act also regulates general-purpose AI models themselves — the underlying models that power many downstream products, including chat assistants. Providers of these models must ensure transparency about their models and comply with EU copyright law, and must publish a summary of the training data used. Models classified as having systemic risk — broadly, the most capable models with the widest potential impact — face additional risk assessment and mitigation obligations. These governance rules for general-purpose AI models became applicable August 2, 2025, alongside a voluntary Code of Practice that providers can use to demonstrate compliance.
Compliance Timeline at a Glance
| Date | What takes effect |
|---|---|
| February 2, 2025 | Eight of nine prohibited practices banned |
| August 2, 2025 | General-purpose AI model governance rules applicable |
| August 2026 | Transparency obligations (AI disclosure, content labeling) applicable |
| December 2026 | Ninth prohibited practice takes effect |
| December 2, 2027 | High-risk system obligations apply in sensitive use cases |
| August 2, 2028 | High-risk obligations extend to AI embedded in already-regulated products |
Penalties for Non-Compliance
The Act sets tiered fines depending on the severity of the violation. Engaging in a prohibited practice from the unacceptable-risk category carries the steepest penalties, structured as a percentage of global annual turnover or a fixed maximum amount, whichever is higher — the same enforcement approach GDPR uses, which businesses already familiar with EU data law will recognize. Violations of high-risk system obligations or transparency requirements carry lower, but still meaningful, penalty tiers. The exact figures and enforcement mechanics are set out in the regulation text itself and in guidance published by the European Commission and national supervisory authorities, so any business with real exposure in the high-risk category should review the current official figures directly rather than relying on a secondhand summary, since enforcement guidance continues to be refined as each compliance deadline arrives.
Practical Steps for a Business Evaluating AI Compliance
A useful first step for any business, regardless of size, is a simple classification exercise: list every AI system you use or provide, then ask whether it falls into a prohibited practice (almost certainly not, for standard business tools), a high-risk use case (only if it materially affects hiring, credit, law enforcement, education access or similar sensitive decisions), or the much larger minimal/transparency category most tools fall into. For the systems that land in minimal or transparency risk — which covers the overwhelming majority of AI assistants used for chat, writing, coding, design and research — the main practical obligation is disclosure: telling users when they’re interacting with an AI system, and labeling AI-generated content shared publicly. For anything that might touch the high-risk category, that’s the point to involve legal counsel with EU regulatory expertise rather than relying on a general guide like this one, since the specific documentation and oversight requirements are detailed and consequential to get right.
What This Means for a Typical Business Using AI Assistants
For most businesses using AI for chat, writing, coding, design or research — rather than building automated decision systems for hiring, lending or law enforcement — the practical impact of the EU AI Act is limited but not zero. The transparency obligations mean being clear with customers when they’re talking to an AI-powered support system rather than a human, and labeling any AI-generated content published for public consumption. Checking that your AI provider is compliant with the general-purpose AI model rules — publishing what it needs to about training data and safety — is also a reasonable due-diligence step when choosing a vendor, alongside checking data residency and privacy practices, which the Act doesn’t cover directly but which are commonly evaluated together under GDPR.
Ask Mio’s approach to this is straightforward: chats and files belong to the user, are not used to train models, and are hosted on EU servers in Germany, which is directly relevant to the GDPR side of this picture even though it sits outside the AI Act’s own scope — a data posture that sits alongside, though isn’t itself dictated by, the AI Act’s separate transparency and general-purpose model obligations. For businesses specifically weighing whether an AI vendor’s practices align with EU expectations, checking both the AI Act obligations relevant to your use case and the underlying GDPR data handling is the more complete picture.
How the AI Act Fits Alongside Other EU Digital Regulation
The AI Act doesn’t exist in isolation — it’s one part of a broader EU digital regulatory framework that includes GDPR for data protection, the Digital Services Act for online platform accountability, and the Digital Markets Act for competition in digital markets. A business evaluating AI tool compliance in the EU context typically needs to think across at least the AI Act and GDPR together, since an AI system that processes personal data triggers GDPR obligations regardless of which AI Act risk tier it falls into. This is why data residency and training-data policies — where a provider hosts data, whether it trains models on customer conversations — matter as much in practice as the AI Act’s own risk classification, even though they’re technically governed by a separate piece of legislation.
Frequently Asked Questions
Does the EU AI Act apply to businesses outside the EU?
Yes, if the AI system affects people located in the EU, regardless of where the provider is headquartered. It’s based on where the impact occurs, not where the company is based.
Is using a chatbot like Ask Mio considered high-risk under the Act?
No. General chat, writing, coding, design and research assistants fall well outside the high-risk category, which is reserved for specific sensitive use cases like automated hiring, credit scoring and law enforcement. Transparency obligations, like disclosing that a response is AI-generated, are the relevant tier for most everyday AI use.
What are the nine prohibited AI practices?
They include harmful manipulation, social scoring, criminal risk profiling, untargeted facial recognition scraping, emotion recognition in workplaces and schools, biometric categorization by protected characteristics, real-time public biometric identification by law enforcement, and non-consensual intimate imagery generation including CSAM. Most already apply; the last takes effect December 2026.
When do the EU AI Act’s high-risk obligations take effect?
December 2, 2027 for high-risk use cases in sensitive areas, with an extension to August 2, 2028 for AI systems embedded in products already regulated under other EU product safety law.
Do AI companies have to disclose their training data under the Act?
Providers of general-purpose AI models must publish a summary of the training data used and ensure compliance with EU copyright law, obligations that became applicable in August 2025.
How is the EU AI Act different from GDPR?
GDPR governs how personal data is collected, processed and stored. The AI Act governs the risk and behavior of AI systems themselves, including transparency, safety and prohibited uses. They overlap but address different things, and an AI product can need to comply with both.
Where can I read the official EU AI Act text?
The European Commission publishes the regulatory framework, guidance and timeline directly at its digital strategy site, which is the authoritative source rather than third-party summaries, including this one.
The Bottom Line
The EU AI Act sorts AI systems by risk, bans a narrow set of clearly harmful practices, imposes real compliance obligations on high-risk use cases like hiring and credit decisions, and requires transparency for AI-generated content and AI-powered interactions more broadly. Most everyday AI use — chat, writing, code, design, research — sits in the minimal-risk or transparency tier, not the high-risk one. For businesses choosing an AI vendor, checking both AI Act relevant obligations and a provider’s data practices together gives the fuller picture before you commit.
