What the European regulation really says. And what remains unclear.
The AI Act came into force in August 2024. Since then, two camps have been at odds: those who see it as a regulatory disaster for European innovation, and those who brush it aside with a wave of the hand.
Both are wrong.
Most companies are only subject to light obligations. Those deploying AI in sensitive contexts have real deadlines approaching. And a few gray areas in the text itself will only be settled by case law.

I’ve had the same conversation a dozen times over the past year. Someone who works in tech, who came across the term “AI Act” in a newsletter or during a board meeting, asks me whether their team should worry about it.
The honest answer fits in one sentence: probably not much, unless you work on HR, credit or health tools.
Here is the summary of the AI Act for those who haven’t read it, and don’t want to.
Common-sense disclaimer: I am not a lawyer. What follows is the reading of an AI practitioner who has spent time on the original text, not the opinion of a specialized attorney. For real compliance decisions, that’s a different job.
1. What the regulation actually does
The most common misreading: believing that the AI Act regulates AI.
It does not regulate AI. It regulates certain uses of AI in high-risk contexts.
This distinction changes everything. The text contains no list of banned models, no list of prohibited technologies. What it contains is a classification of uses by level of risk. And the majority of everyday AI uses (writing assistants, recommendation tools, spam filters, internal chatbots) fall into the “minimal risk” category. No specific obligation.
The example to remember: if you take GPT-5 and use it to help your sales team write emails, you are at minimal risk. If you use the same model to automatically sort applications and decide who gets an interview, you are at high risk. Same LLM layer. But radically different regulation.
The regulation classifies by use and by context, not by technology.
2. The four levels, without the jargon

Prohibited. No placing on the market or deployment possible. A system already in production must be withdrawn.
High risk. The heavy regime: conformity assessment, technical documentation, traceable data, human oversight, logging and registration in the EU database before being placed on the market. The provider bears most of the burden; the deployer keeps oversight and log-keeping.
Limited risk. A single obligation, of transparency: telling users they are talking to an AI and labeling generated or manipulated content.
Minimal risk. No binding obligation. The regulation only encourages voluntary adherence to codes of conduct.
Most tech teams live in the last two lines.
3. The timeline — what is already behind us
The full timeline stretches to 2027, which creates an illusion of leeway. Yet several milestones have already passed.
February 2025: the prohibitions take effect. If you have deployed a tool that recognizes emotions in meetings or analyzes employees’ affective states, the question arises now.
August 2025: the rules apply to providers of foundation models, what the regulation calls GPAI (General Purpose AI), i.e. models trained at scale to perform multiple tasks. OpenAI, Google, Mistral, Anthropic. They have transparency obligations on the training data and the capabilities of their models. For companies that use these APIs, the direct impact is limited. But it creates traceability in the chain of responsibility.
August 2026: the main deadline for Annex III high-risk systems (see next section). That’s one month away.
4. Annex III — who is really in the crosshairs
Annex III lists eight high-risk areas. Four of them directly concern the companies that call me.
Critical infrastructure. The regulation targets AI systems used as safety components in the management of critical digital infrastructure: supervising a telecom network, orchestrating a data center, managing service continuity. A player that operates this type of infrastructure for European customers falls within scope.
Employment and human resources management. This is the area most directly relevant for many. Explicitly listed are: automated recruitment systems (CV screening, candidate scoring), employee performance evaluation, tools that assist promotion or dismissal decisions, monitoring of activity at work. And, a point that generates a lot of ambiguity, “monitoring and evaluating working conditions”.
Access to essential services. This is where banking and insurance come in. Three examples: creditworthiness assessment and credit scoring of individuals (fraud detection, for its part, remains out of scope), pricing and risk assessment in life and health insurance, and the processing of applications for social benefits.
Health. Medical devices with an AI component, diagnostic support.
Three other areas complete the list: law enforcement, migration management, the administration of justice. They fall to public actors and do not concern the companies I am talking about here.
A word on the AI Omnibus: a provisional agreement signed on May 7, 2026 brings several substantial changes. Two new prohibitions would be added to Article 5, effective as of December 2026: non-consensual intimate deepfakes and the generation of child sexual abuse material. This text has not yet been formally adopted, but these two prohibitions are rather a good thing.
5. What the text itself does not settle
This is where the summaries stop. And where the real operational questions begin. Let’s go back to some of the uses described above.
Monitoring working conditions. Annex III targets systems that evaluate employees’ performance and behavior. But does a tool that measures a team’s workload from aggregated data, without any automated decision about an individual, and where each employee can view their own data, fall into this category? The text does not say. The company deploying this tool must be able to justify its classification, and record it in its technical documentation before deployment, not on the day a client’s HR director asks the question during a due diligence.
Creditworthiness and fraud. Credit scoring is explicitly high risk, but financial fraud detection is excluded from it. Yet many banking tools do both with the same engine: a single model assesses a default risk and flags a suspicious transaction. The boundary becomes hard to draw when both functions share the same architecture. The regulation does not decide, and it is the company that will have to document where it draws the line.
Emotion recognition. The February 2025 prohibition covers inferring emotions from biometric data. Analyzing sentiment in written text probably remains allowed. Analyzing the tone and rhythm of someone’s voice during a meeting probably is not, because voice is behavioral biometric data. The truly open area concerns hybrid tools, which combine text analysis and voice analysis: no decision yet tells us how they will be classified.
Application to non-European players. A US vendor selling a credit scoring tool to a European bank falls within the scope of the regulation. The mechanism exists on paper. But no penalty has yet targeted a provider outside the EU, and no one knows how fast the first one will come.
To conclude without concluding
The AI Act is a tiered regulation. For most of the teams reading this article, the day-to-day impact is limited to chatbots that must identify themselves. For those building AI in HR, finance or health, the obligations are real and the deadlines close.
What the text does not yet resolve, case law will. The practical decision in the meantime: document your architecture choices and classification arguments now. Not once the line has been drawn by a judge, or a client has asked the question during a procurement process.
Reading the source text remains the best insurance.
It is shorter than people say.
Sources
artificialintelligenceact.eu• Official text and annotated articlesai-act-service-desk.ec.europa.eu• Official European Commission timelineGuidelines on Prohibited AI Practices (C(2025) 5052)• European Commission, July 2025EU AI Act Omnibus Agreement — Gibson Dunn• Analysis of the Digital Omnibus, May 2026