Guide

The EU AI Act, without the legalese

What the regulation covers, which role your organisation holds for each system it uses, how the risk tiers work, and when each set of obligations starts to apply. Written for teams who have to act on it rather than litigate it.

Published 2026-08-22 · Last reviewed 2026-08-22 · Dates verified against source 2026-08-22

What the AI Act actually regulates

The AI Act is a product-safety style regulation applied to artificial intelligence. It does not regulate AI as a technology. It regulates what a given system is used for, and it scales the obligations to how much harm that use could cause. The same underlying model can be unregulated in one deployment and high-risk in another.

That is why an inventory is the starting point rather than a formality. You cannot answer any question the regulation asks until you can say what each system does, who uses it, and who it affects.

It also reaches organisations outside the EU. If the output of a system is used in the Union, the regulation can apply regardless of where the organisation running it is established.

The four tiers

Almost everything in the regulation follows from which tier a particular use falls into.

Unacceptable risk

Practices that are prohibited outright

A small set of uses is banned rather than regulated - the regulation treats them as incompatible with fundamental rights regardless of how carefully they are built. The Digital Omnibus extended this list. These prohibitions are already in application.

High risk

Systems that carry substantive obligations

Two routes into this tier: systems used in the sensitive areas listed in Annex III, such as biometrics, employment, education, essential services, and migration; and AI built into products that already require third-party conformity assessment under the legislation listed in Annex I. Article 6(3) provides a narrow route out for systems that do not pose a significant risk, but it has to be justified and documented.

Transparency obligations

Tell people what they are dealing with

Some systems carry duties regardless of risk tier: making it clear when somebody is interacting with an AI system, and marking synthetic or manipulated content. These have applied since the regulation became generally applicable.

Minimal risk

Most systems, most of the time

The majority of AI in ordinary business use falls outside the tiers above and carries no specific obligation under the regulation. Knowing which of your systems these are is the point of doing the assessment.

Which role are you in?

The regulation assigns obligations by role, not by organisation. You can hold different roles for different systems, and more than one role for the same system. Getting this wrong is the most common way an assessment goes astray, because it changes everything downstream.

Provider

You develop an AI system or have one developed, and place it on the market or put it into service under your own name or trademark. This role carries the heaviest obligations.

Deployer

You use an AI system under your own authority in a professional capacity. Most organisations are deployers of tools somebody else built, and this is the role people most often overlook.

Importer

You place on the EU market an AI system bearing the name or trademark of an organisation established outside the EU.

Distributor

You are in the supply chain and make an AI system available on the EU market without being the provider or importer.

Authorised representative

You are established in the EU and have a written mandate from a provider outside it to carry out obligations on their behalf.

GPAI model provider

You place a general-purpose AI model on the market. Separate obligations attach to the model itself, distinct from any system built on top of it.

One trap worth naming: a deployer can become a provider. If you put your own name on a system, or change what it is used for in a substantial way, the heavier set of obligations can follow.

When each part applies

The obligations phase in rather than landing at once, and the timetable has already been rebased once by the Digital Omnibus on AI, which moved the high-risk dates out. Treat the later dates as current rather than final.

  1. In application

    The AI Act entered into force

    The regulation became law, with its obligations phased in over the following four years rather than all at once.

  2. In application

    Prohibited practices and AI literacy

    The bans on certain AI practices began to apply, alongside the duty to make sure staff dealing with AI systems have an adequate level of AI literacy.

  3. In application

    General-purpose AI models and governance

    Obligations for providers of general-purpose AI models began to apply, together with the governance rules covering the AI Office and national authorities.

  4. In application

    General application and transparency duties

    The AI Act became generally applicable, including the transparency duties that attach to systems people interact with directly or that generate synthetic content.

  5. Upcoming

    Two further prohibited practices

    The Digital Omnibus added prohibitions covering non-consensual intimate imagery and child sexual abuse material generated or manipulated by AI.

  6. Upcoming

    High-risk rules for stand-alone systems

    Obligations for high-risk systems in areas such as biometrics, critical infrastructure, education, employment, migration, asylum, and border control begin to apply.

  7. Upcoming

    High-risk rules for systems inside products

    Obligations for high-risk AI built into products that already require third-party conformity assessment, such as lifts and toys, begin to apply.

What to do first

None of the following requires a decision about classification, which is what makes it a sensible place to start.

  1. 1

    Write down what you're using

    Including the tools that arrived through a subscription somebody expensed, and the AI features switched on inside software you already had.

  2. 2

    Name an owner for each one

    Somebody who can answer what it does and who uses it. Without this, every later question stalls.

  3. 3

    Work out your role for each system

    Provider, deployer, importer, distributor. It is per system, not per organisation.

  4. 4

    Note what you can't answer

    The gaps are the useful output of a first pass. Most of them are questions for a supplier rather than for you.

  5. 5

    Ask your suppliers early

    Vendor responses are the long pole. Requests raised now are answered while there is still time to act on the answer.

This guide is general information, not legal advice. EmberHound supports AI discovery, assessment, documentation, and governance. It does not provide legal advice or guarantee compliance. Organisations should obtain specialist advice where an AI system presents significant regulatory, safety, or fundamental-rights risks.

Sources & references

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) - EUR-Lex
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) - EUR-Lex
  3. Regulation (EU) 2024/1689 - consolidated text as at 27 July 2026 - EUR-Lex
  4. AI Act - regulatory framework for artificial intelligence - European Commission

Doing this properly, rather than in a spreadsheet

The EmberHound AI Act Workspace turns the steps above into a repeatable process: an inventory, a guided assessment, the obligations that follow, and a governance record that holds up.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy