The EU AI Act, explained for product and engineering teams
7 min read · Certifyi research team · Updated July 2026
The EU AI Act regulates AI by risk tier rather than by technology. Unacceptable-risk uses are banned, high-risk uses carry heavy obligations around data governance, documentation, human oversight and monitoring, and limited-risk uses mainly require transparency. Your first job is to classify each AI system you ship.
The risk tiers
Everything follows from classification, so do this before any remediation work.
| Tier | Examples | Obligation level |
|---|---|---|
| Unacceptable | Social scoring, certain biometric categorisation | Prohibited |
| High risk | Employment screening, credit decisions, critical infrastructure, some medical uses | Extensive: risk management, data governance, documentation, oversight, logging |
| Limited risk | Chatbots, emotion recognition, synthetic content | Transparency: tell people they are interacting with AI |
| Minimal risk | Spam filters, recommendation features | No specific obligations |
Who it applies to
Scope is extraterritorial, in the same way GDPR is. If your AI system is placed on the EU market or its output is used in the EU, the Act can reach you regardless of where you are incorporated.
Obligations also differ by role. Providers who build and place a system on the market carry more than deployers who use one, but deployers are not exempt.
What high-risk actually demands
If any of your systems land in the high-risk tier, plan for a substantial programme.
- A documented risk management system across the lifecycle
- Data governance covering training, validation and testing datasets
- Technical documentation sufficient for a regulator to assess conformity
- Automatic logging of events during operation
- Meaningful human oversight with defined intervention capability
- Accuracy, robustness and cybersecurity commensurate with intended purpose
A practical first 90 days
- Inventory every AI system, including third-party models and embedded vendor AI
- Classify each against the risk tiers and write down the reasoning
- Identify whether you are provider, deployer, or both, for each system
- Gap-assess high-risk systems against the obligation list
- Stand up governance: approval gates, monitoring, documented human oversight
How this connects to ISO 42001
The Act tells you what outcomes are required; it does not hand you an implementation framework. ISO 42001 provides one. Teams commonly use an AIMS as the operating model that generates the evidence the Act expects.
Do not wait for perfect clarity
- Classification and inventory work is valuable regardless of how guidance evolves.
- The documentation burden for high-risk systems cannot be produced retroactively with any credibility.
Key takeaways
- Obligations follow risk tier, so classify first.
- Scope is extraterritorial, like GDPR.
- High-risk systems carry documentation and oversight duties you cannot backfill.
- ISO 42001 is a practical implementation route.
Frequently asked questions
Does the Act apply to us if we are not in the EU?
Potentially yes. If your system is placed on the EU market or its output is used in the EU, it can apply regardless of where you are based.
Are we a provider or a deployer?
If you build and place the system on the market you are a provider. If you use someone else's system in your operations you are a deployer. Many companies are both across different systems.
Does using an off-the-shelf model exempt us?
No. Integrating a third-party model into a product you ship generally carries obligations, and you may become a provider for that system.
What is the first thing to do?
A complete AI inventory and risk classification. Every other obligation depends on knowing what you run and which tier it falls into.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call