AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Foundations of AI governance · Lesson 2 of 17

How the EU AI Act is built: scope, roles and risk tiers

Article · 16 min · 9 min lecture

Video lecture

How the EU AI Act is built: scope, roles and risk tiers

12 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 12

Same model, different rules

  • Product descriptions: minimal risk
  • Ranking job applicants: high risk
  • It's the use that counts

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Not legal advice. This course explains regulations and standards so you can ask better questions and build sensible controls. Laws change and apply differently to each organization. For decisions with legal consequences, confirm with qualified counsel in the relevant jurisdiction.

The regulation in one paragraph

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is a product-safety style regulation for AI. It sets rules for placing AI systems and general-purpose AI models on the EU market, putting them into service and using them. It classifies AI uses by risk, bans a short list of practices, places heavy duties on "high-risk" systems, adds transparency duties for certain systems, and creates specific obligations for general-purpose AI models. In 2026 it was amended by the "Digital Omnibus on AI" (Regulation (EU) 2026/1744), which, among other things, pushed back the high-risk deadlines. You will study those dates in Module 2.

Scope: when does it apply to you?

The Act reaches beyond EU borders. It can apply to:

  • Providers placing AI systems or GPAI models on the EU market or putting them into service in the EU, wherever the provider is established.
  • Deployers established or located in the EU.
  • Providers and deployers outside the EU where the output produced by the AI system is used in the EU.
  • Importers, distributors, product manufacturers that integrate AI, and authorized representatives of non-EU providers.

So a Lahore software house selling an AI recruitment tool to a company in Ireland is in scope as a provider. A Riyadh brand that runs an AI chatbot for customers in France should assume the transparency rules apply to that chatbot.

Key exclusions include AI used exclusively for military, defence or national security purposes, AI used for scientific research and development as such, and purely personal non-professional use. Open-source releases get some carve-outs, but not for prohibited or high-risk uses or for certain transparency duties.

The roles ("operators")

RoleWhoTypical burden
ProviderDevelops the system or model, places it on the market or puts it into service under its own name or trademarkHeaviest: design, documentation, conformity
DeployerUses it under its authority in a professional capacityUse as instructed, oversight, transparency to affected people
ImporterEU entity placing a non-EU provider's system on the marketVerify conformity before placing
DistributorMakes it available in the supply chainCheck markings and documentation
Authorized representativeEU-based entity mandated by a non-EU providerActs on the provider's behalf with authorities

Roles can shift. Under Article 25, a deployer, distributor or importer is treated as a provider of a high-risk system if they put their name or trademark on it, make a substantial modification, or change its intended purpose so that it becomes high-risk. Example: you buy a general-purpose chatbot and re-purpose it to rank job applicants. You may now be the provider of a high-risk system.

The risk pyramid

  1. Unacceptable risk: prohibited (Article 5). For example social scoring, manipulative techniques causing significant harm, emotion recognition in workplaces and schools. Lesson 2.1.
  2. High risk (Article 6 and Annexes I and III). AI in regulated products (such as medical devices, machinery, toys) and in listed sensitive areas such as employment, education, credit scoring and essential services. Lesson 2.2.
  3. Transparency risk (Article 50). Chatbots, synthetic content, deepfakes, emotion recognition and biometric categorization carry disclosure duties. Lesson 2.4.
  4. Minimal risk. Everything else: spam filters, most content tools, recommendation of blog topics. No specific AI Act obligations beyond AI literacy, though other laws still apply.

Alongside the pyramid sits a separate track for general-purpose AI models (Lesson 2.3), with extra duties for models posing "systemic risk".

A single product can touch several layers. A recruitment chatbot that screens candidates is high-risk (employment) and also subject to chatbot transparency.

Who enforces it

  • The AI Office, inside the European Commission, supervises general-purpose AI models and coordinates implementation.
  • The European AI Board (Member State representatives) supports consistent application, alongside a scientific panel and an advisory forum.
  • National market surveillance authorities enforce most rules on AI systems in each Member State.
  • Data protection authorities remain in charge of GDPR, which keeps applying in parallel.

Worked example: classifying five uses at a UK retailer selling into the EU

UseClassificationWhy
Product description generatorMinimal risk (check Art. 50 if content is published as news-like public-interest text)Ordinary content creation
Customer service chatbotTransparency riskMust inform people they are interacting with AI unless obvious
CV screening for warehouse jobsHigh riskAnnex III, employment
Dynamic pricing modelUsually minimal risk under the AI ActConsumer and competition law still apply
Staff emotion-detection from webcamsProhibitedEmotion recognition in the workplace (limited medical and safety exceptions)

Hands-on: a classification decision tree

Use this for every entry in your AI inventory.

1. Is it an "AI system" (infers outputs from inputs with some autonomy)?   No -> out of AI Act scope (other laws still apply)
2. Is it used in the EU, or is its output used in the EU?                  No -> likely out of scope; record reasoning
3. What is our role? Provider / Deployer / Importer / Distributor
   Did we rebrand, substantially modify, or change intended purpose?      Yes -> treat as Provider for that system
4. Does it match an Article 5 prohibited practice?                          Yes -> STOP. Escalate to legal.
5. Is it a safety component of an Annex I product, or an Annex III use?    Yes -> High-risk candidate. Check Art. 6(3) exceptions.
6. Does it interact with people, generate synthetic content, recognize
   emotions, or categorize people biometrically?                           Yes -> Article 50 transparency duties
7. Otherwise -> minimal risk: AI literacy + good practice + other laws

Record the answer and the reasoning for each step. The reasoning is what an auditor or client will want to see.

Pitfalls

  • Assuming "we're not in the EU, so it doesn't apply" while serving EU customers.
  • Classifying the vendor's product instead of your use of it. The same model can be minimal risk in marketing and high-risk in hiring.
  • Forgetting that GDPR, consumer protection and sector rules apply regardless of the AI Act tier.

Key takeaways

  • The AI Act regulates uses by risk tier: prohibited, high-risk, transparency and minimal, plus a separate track for general-purpose AI models.
  • It applies extraterritorially, including when an AI system's output is used in the EU.
  • Article 25 can make a deployer the provider of a high-risk system if it rebrands, substantially modifies or repurposes it.
  • Classification depends on the specific use; GDPR and other laws apply regardless of tier.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. A Karachi-based company sells an AI tool that scores loan applicants to a bank in Spain. What is the company's most likely status?
  2. A marketing team buys a general chatbot and reconfigures it to shortlist job applicants. What changes?
  3. Which statement about the risk tiers is correct?

Put it into practice

Run each tool in your inventory through the seven-step decision tree. Record role, tier and a one-sentence rationale for each.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.