Glossary

EU AI Act

The EU AI Act is the first comprehensive AI regulation: a risk-tiered regime that entered into force in 2024 with obligations phasing in through 2026–2027. Prohibited practices (social scoring, manipulative systems) are banned outright; high-risk systems (employment decisions, credit, essential services, and other Annex III categories) carry heavy obligations — risk management, data governance, human oversight, conformity assessment; limited-risk systems face transparency duties (disclose the chatbot is a chatbot); minimal-risk systems are untouched.

Who’s in scope

Like GDPR, reach is extraterritorial: providers and deployers whose AI output is used in the EU. B2B SaaS companies most often enter as deployers of general-purpose models or as providers whose features drift into Annex III territory — an HR-tech scoring feature, a fintech credit signal. The classification question is the whole game: the same model is minimal-risk in one product context and high-risk in another.

What to do now

Inventory your AI systems and classify each against the tiers; document the reasoning (this is the AI analogue of a DPIA, and the two often pair); implement transparency notices where required; and if anything plausibly touches high-risk categories, start the conformity groundwork early — an ISO 42001-shaped management system is the emerging vehicle for it.

Enterprise procurement is ahead of the deadlines: EU customers already ask vendors for AI Act positioning, so the inventory-and-classification document earns its keep in security reviews today.

Related Terms

DPIA — A DPIA is GDPR's structured risk assessment for high-risk processing — increasingly triggered by AI features. What it covers and when you must run one.

ISO 42001 — ISO 42001 certifies an AI management system (AIMS) — governance for how you build and use AI. The emerging answer to 'prove your AI is responsible.'