In Depth
Adopted as Regulation (EU) 2024/1689, the Act sorts AI systems into tiers by the risk they pose. A small set of uses is prohibited outright. A larger set is high-risk. These are systems used in areas like employment, credit, essential services, medical devices, and other consequential decisions, and they carry the heavy obligations. Below that sit limited-risk systems, which mainly owe transparency duties, and minimal-risk systems, which are largely unregulated. The tier determines the burden, and misclassifying your own system is itself a risk.
For high-risk systems the obligations are concrete and ongoing: a risk-management process, data governance over training and input data, technical documentation, record-keeping, human oversight, and post-market monitoring once the system is live. These aren't one-time certifications. They are operational duties that have to be maintained and evidenced for as long as the system is on the market, which means a vendor needs the governance machinery to produce that evidence on demand.
The enforcement backstop is serious. Penalties run up to €35 million or 7% of global annual turnover for engaging in prohibited practices, with lower tiers for other violations. The Act applies in phases between 2025 and 2027, and prohibitions and obligations switch on at different dates. So the relevant question is rarely "does the Act apply" but "which obligations apply to this system, and from when."
What It Looks Like
A U.S. vendor sells an AI agent that ranks job candidates, and a European customer wants to deploy it for hiring in the EU. Employment screening is a high-risk use under the Act. Overnight, the vendor's agent needs documented risk management, governed training data, logged decisions, demonstrable human oversight, and post-market monitoring. The vendor also has to be able to produce that documentation for the customer and, if asked, for a regulator. The product didn't change. Its regulatory classification did, and with it the entire compliance burden.
Why It Matters For AI Vendors
The Act has extraterritorial reach. If your AI system is used in the EU, it can bind you even from outside Europe. For any vendor with European ambitions, the high-risk obligations become a gating requirement that enterprise buyers will check before they deploy. They don't want to inherit your non-compliance.
The trap is treating the Act as a single yes/no question. Obligations differ by tier, by role (provider versus deployer), and by phase-in date. A vendor who can't say precisely which duties attach to their agent, and prove they're met, looks unmanaged to both regulators and customers, regardless of how good the underlying product is.