EU AI Act Explained for Product Teams (2026)
AI Governance

The EU AI Act, explained for product and engineering teams

7 min read · Certifyi research team · Updated July 2026

Short answer

The EU AI Act regulates AI by risk tier rather than by technology. Unacceptable-risk uses are banned, high-risk uses carry heavy obligations around data governance, documentation, human oversight and monitoring, and limited-risk uses mainly require transparency. Your first job is to classify each AI system you ship.

The risk tiers

Everything follows from classification, so do this before any remediation work.

TierExamplesObligation level
UnacceptableSocial scoring, certain biometric categorisationProhibited
High riskEmployment screening, credit decisions, critical infrastructure, some medical usesExtensive: risk management, data governance, documentation, oversight, logging
Limited riskChatbots, emotion recognition, synthetic contentTransparency: tell people they are interacting with AI
Minimal riskSpam filters, recommendation featuresNo specific obligations

Who it applies to

Scope is extraterritorial, in the same way GDPR is. If your AI system is placed on the EU market or its output is used in the EU, the Act can reach you regardless of where you are incorporated.

Obligations also differ by role. Providers who build and place a system on the market carry more than deployers who use one, but deployers are not exempt.

What high-risk actually demands

If any of your systems land in the high-risk tier, plan for a substantial programme.

  • A documented risk management system across the lifecycle
  • Data governance covering training, validation and testing datasets
  • Technical documentation sufficient for a regulator to assess conformity
  • Automatic logging of events during operation
  • Meaningful human oversight with defined intervention capability
  • Accuracy, robustness and cybersecurity commensurate with intended purpose

A practical first 90 days

  1. Inventory every AI system, including third-party models and embedded vendor AI
  2. Classify each against the risk tiers and write down the reasoning
  3. Identify whether you are provider, deployer, or both, for each system
  4. Gap-assess high-risk systems against the obligation list
  5. Stand up governance: approval gates, monitoring, documented human oversight

How this connects to ISO 42001

The Act tells you what outcomes are required; it does not hand you an implementation framework. ISO 42001 provides one. Teams commonly use an AIMS as the operating model that generates the evidence the Act expects.

Do not wait for perfect clarity

  • Classification and inventory work is valuable regardless of how guidance evolves.
  • The documentation burden for high-risk systems cannot be produced retroactively with any credibility.

Key takeaways

  • Obligations follow risk tier, so classify first.
  • Scope is extraterritorial, like GDPR.
  • High-risk systems carry documentation and oversight duties you cannot backfill.
  • ISO 42001 is a practical implementation route.

Frequently asked questions

Does the Act apply to us if we are not in the EU?

Potentially yes. If your system is placed on the EU market or its output is used in the EU, it can apply regardless of where you are based.

Are we a provider or a deployer?

If you build and place the system on the market you are a provider. If you use someone else's system in your operations you are a deployer. Many companies are both across different systems.

Does using an off-the-shelf model exempt us?

No. Integrating a third-party model into a product you ship generally carries obligations, and you may become a provider for that system.

What is the first thing to do?

A complete AI inventory and risk classification. Every other obligation depends on knowing what you run and which tier it falls into.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.

Book a 20-min deal readiness call

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top