EU AI Act
The EU AI Act is the first comprehensive AI regulation: a risk-tiered regime that entered into force in 2024 with obligations phasing in through 2026–2027. Prohibited practices (social scoring, manipulative systems) are banned outright; high-risk systems (employment decisions, credit, essential services, and other Annex III categories) carry heavy obligations — risk management, data governance, human oversight, conformity assessment; limited-risk systems face transparency duties (disclose the chatbot is a chatbot); minimal-risk systems are untouched.
Who’s in scope
Like GDPR, reach is extraterritorial: providers and deployers whose AI output is used in the EU. B2B SaaS companies most often enter as deployers of general-purpose models or as providers whose features drift into Annex III territory — an HR-tech scoring feature, a fintech credit signal. The classification question is the whole game: the same model is minimal-risk in one product context and high-risk in another.
What to do now
Inventory your AI systems and classify each against the tiers; document the reasoning (this is the AI analogue of a DPIA, and the two often pair); implement transparency notices where required; and if anything plausibly touches high-risk categories, start the conformity groundwork early — an ISO 42001-shaped management system is the emerging vehicle for it.
Enterprise procurement is ahead of the deadlines: EU customers already ask vendors for AI Act positioning, so the inventory-and-classification document earns its keep in security reviews today.
DPIA — A DPIA is GDPR's structured risk assessment for high-risk processing — increasingly triggered by AI features. What it covers and when you must run one.
ISO 42001 — ISO 42001 certifies an AI management system (AIMS) — governance for how you build and use AI. The emerging answer to 'prove your AI is responsible.'