What is the EU AI Act?
By Identra · Updated
The EU AI Act is a European Union regulation that governs AI systems according to their intended purpose and the risks they pose to health, safety and fundamental rights. What a company owes under it depends on the system, how it is used and whether the company is that system's provider or its deployer.
How does the EU AI Act classify AI risk?
Roughly four ways. Some practices are banned outright. High-risk systems carry heavy requirements. Certain interactions and generated content need disclosure, such as telling people they are talking to a chatbot. Most other uses pick up few AI Act duties, though other laws still apply. General-purpose AI models get a separate set of provider obligations. The European Commission's overview lays this out.
The categories overlap. A high-risk system can carry transparency duties too.
Classification follows the Act's criteria and the system's intended purpose. Your security team's internal risk rating does not decide it. A drafting assistant and a tool that ranks job candidates can run on the same model and land in very different places. Feed the result into AI risk management, but keep the legal reasoning in its own record.
Prohibited practices
- Question to answer for each use
- Does this use fall inside a prohibition and its specific conditions?
High-risk systems
- Question to answer for each use
- Does the intended purpose meet the legal criteria for high-risk treatment?
Transparency duties
- Question to answer for each use
- Does this interaction or output need notice, marking or disclosure?
Everything else
- Question to answer for each use
- Which general obligations and other laws, such as GDPR, still apply?
Is my company a provider or a deployer?
A deployer uses an AI system under its own authority for professional purposes. A provider develops a system, or has one developed, and places it on the market or puts it into service under its own name. Buy ChatGPT Enterprise for your staff and you are usually a deployer. Build a claims-triage model and run it internally and you may be a provider. The Commission's AI Act questions and answers walk through the distinctions.
Assign roles per system and per use. Plenty of companies are both at once. Rebranding a system, substantially modifying it or changing its intended purpose can move you into the provider role under conditions the Act sets out. Make each of those a review trigger in your AI governance process.
Put a named business owner next to every role. Someone who can say what the system does, who relies on it and who can approve a change.
What do deployers of high-risk AI have to do?
Providers carry the heavy items, like risk management and conformity assessment. Deployers have a shorter list. Use the system according to the provider's instructions, assign human oversight to people with the competence and authority to do it, monitor how it runs and act on the risks you find. The Act applies in phases, so check which duties are already in force for your deployment. The Commission's explanation of responsibilities has the detail.
Human oversight has to be a real job. Name the reviewer. Say what they check. Give them the power to stop or override the system. A recruiter who clicks approve on every ranking is not oversight.
From suppliers, get intended-use limits, operating instructions, compliance documentation and an incident contact. The vendor's paperwork covers the product. Your deployment is still yours to assess.
How would the EU AI Act apply to an AI recruiting tool?
Say an employer buys a service that ranks job applicants. Recruitment and candidate evaluation appear among the high-risk use cases listed in Annex III, subject to the Act's classification rules. So the tool gets assessed before launch. It does not get waved through as office software.
HR explains how the rankings feed the shortlist. Legal works out classification and which duties apply. Security looks at who can reach applicant data and what the tool connects to, the applicant tracking system for a start, while the supplier states which uses it supports. One named reviewer checks recommendations and can push back on them.
Months later someone wants to switch on automatic rejection. That reopens the assessment before the feature goes live. Record the new purpose, who it affects, how oversight changes and what the supplier says about it.
How should an enterprise prepare for the EU AI Act?
Start from what people actually use. The procurement list will be incomplete. ChatGPT and Gemini in the browser, desktop assistants, coding agents like Claude Code and AI features inside Microsoft 365 or Google Workspace all count. Shadow AI is usually where the inventory comes up short. Record the business purpose and the people affected next to each product name.
- Give each system an owner. Write down its intended purpose, users, data categories and your role.
- Have legal assess scope, prohibited uses, classification and which duties apply from which date.
- Collect supplier instructions, permitted uses and escalation contacts.
- Put new purposes, new data access, substantial modifications and supplier changes behind an approval gate.
- Rehearse a failure. A wrong recommendation that a busy reviewer is tempted to accept is a good one to start with.
- Keep assessments, approvals, relevant logs, incidents and fixes for as long as your duties and retention policy require.
What AI literacy training and records does the Act expect?
As adopted, Article 4 asks providers and deployers to take measures to ensure a sufficient level of AI literacy among the people who operate AI on their behalf. Amendments to the Act have been proposed, so check the current text. In practice that means people understand the systems they use, their limits and their possible impact, with training fitted to role and experience. The Commission's AI literacy guidance explains the approach. A recruiter needs to know how to question a ranking. A developer using GitHub Copilot needs to review generated code and keep secrets out of prompts.
Tie the training to an AI acceptable use policy that names approved tools, permitted data and who to ask.
Keep an AI audit trail that lets a reviewer rebuild approvals, changes and how problems were handled. Collecting every prompt anyone ever typed is not governance. Decide which records serve a defined purpose, who can read them and when they get deleted.
How Identra thinks about it
Identra discovers the AI apps and accounts people use in the browser, the AI clients, coding agents and MCP servers on macOS and Windows endpoints, and the AI agents in Microsoft 365 Copilot, Google Workspace and Anthropic, each with its owner. That gives provider and deployer role reviews, oversight assignments and AI literacy planning a starting list built from the AI actually in use.
Go deeper: AI security, built on identity
Frequently asked questions
Does the EU AI Act apply to companies outside the EU?
It can. Organizations outside the EU are covered when they place AI on the EU market or meet the Act's other territorial scope conditions. Where the company is headquartered does not settle it. See the Commission's scope explanation.
Is every generative AI tool high-risk?
No. Being generative does not make a system high-risk. Intended purpose and the legal criteria decide that, and separate transparency or model-provider obligations may still apply.
Does the EU AI Act replace GDPR?
No. GDPR still applies whenever AI processes personal data. An AI Act review does not settle lawful basis, data minimization or individual rights.
Does every employee need the same AI training?
No. Training should match the person's work, experience and the systems they use. Someone overseeing candidate rankings needs different preparation from someone drafting routine emails.
Does an AI inventory prove compliance?
No. It tells you which systems and responsibilities exist. Compliance depends on the obligations that apply and evidence that you meet them.
