AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Foundations of AI governance · Lesson 2 of 17
How the EU AI Act is built: scope, roles and risk tiers
Video lecture
How the EU AI Act is built: scope, roles and risk tiers
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Same model, different rules
Imagine two companies using exactly the same AI model. One uses it to write product descriptions. The other uses it to rank job applicants. Under the EU AI Act, the first has almost no specific obligations. The second is running a high-risk AI system. Same model, completely different rules. By the end of this lesson, you will be able to work out whether the Act applies to you, which role you play, and which risk tier each of your AI uses falls into.
0:36 The AI Act in one breath
Start with the big picture. The AI Act, formally Regulation twenty twenty-four slash sixteen eighty-nine, works like product safety law for AI. It sets rules for placing AI systems and general-purpose models on the EU market, putting them into service, and using them. It bans a short list of practices, puts heavy duties on high-risk systems, adds transparency duties for things like chatbots and deepfakes, and has a separate track for general-purpose models. In twenty twenty-six it was amended by the Digital Omnibus on AI, which moved some deadlines. We'll cover those dates in the next module.
1:18 Analogy: road rules
Here's an analogy for the whole structure. Think of the AI Act like road rules for vehicles. Some vehicles are banned outright from public roads. Heavy trucks, the high-risk category, need inspections, logbooks and licensed drivers. Ordinary cars need lights and number plates so others can see and identify them, that's the transparency layer. And bicycles in your own garden face almost no rules at all. Crucially, the rules depend on how and where you drive, not just what you bought. A van used for deliveries and the same van used as a school bus are treated differently.
2:01 Who is in scope
Now, scope. The Act reaches well beyond Europe. It applies to providers placing AI on the EU market wherever they are based, to deployers in the EU, and even to providers and deployers outside the EU when the output of the AI system is used in the EU. So a software house in Lahore selling an AI recruitment tool to a company in Ireland is in scope as a provider. A brand in Riyadh running a chatbot for customers in France should assume the chatbot rules apply. There are exclusions: military and national security uses, scientific research as such, and purely personal use.
2:46 Operators
Next, roles. The Act calls them operators. The provider develops the system and puts it on the market under its own name. The deployer uses it professionally. Importers and distributors move it through the supply chain, and an authorized representative acts in the EU for a non-EU provider. Here is the trap. Under Article twenty-five, you can become the provider of a high-risk system without building anything. If you put your brand on it, substantially modify it, or change its purpose so it becomes high-risk, the provider duties land on you. Buying a general chatbot and repurposing it to screen job applicants is the classic example.
3:32 The risk pyramid
Now the risk pyramid. At the top, unacceptable risk: prohibited practices such as social scoring or emotion recognition in workplaces. Below that, high risk: AI in regulated products like medical devices and machinery, and AI in sensitive areas listed in Annex three, such as employment, education, credit scoring and access to essential services. Then transparency risk: chatbots, synthetic content, deepfakes, emotion recognition and biometric categorization carry disclosure duties. And at the base, minimal risk, which is most AI. One product can sit in two layers at once. A recruitment chatbot is both high-risk and subject to chatbot disclosure.
4:15 Enforcement
Who enforces all this? The AI Office inside the European Commission supervises general-purpose models and coordinates everything. The European AI Board brings Member States together, with a scientific panel and an advisory forum. National market surveillance authorities enforce the rules on AI systems in each country. And your data protection authority still enforces GDPR in parallel. That last point matters. Even minimal-risk AI can breach privacy, consumer or advertising law.
4:45 Worked example: UK retailer
Let's classify five uses at a UK retailer that sells into the EU. The product description generator is minimal risk. The customer chatbot carries transparency duties. The CV screening tool for warehouse jobs is high risk, because employment is in Annex three. The dynamic pricing model is usually minimal risk under the AI Act, although consumer and competition law still bite. And the webcam tool that detects staff emotions is prohibited. In the lesson text you'll find a seven-step decision tree. Run every tool in your inventory through it, and write down your reasoning, because the reasoning is what clients and auditors will ask for.
5:31 Example 2: Karachi designer, French client
Now a simpler example. A freelance designer in Karachi uses an image generator to create illustrations for a French client's brochure. Is she in scope? Her output is used in the EU, so the Act can reach her work. But what applies? She's a deployer of a general-purpose image tool. The illustrations are stylized, not realistic depictions of real people or events, so they aren't deepfakes. Her main practical duties come from the client contract, copyright and the tool's terms. The lesson: scope doesn't automatically mean heavy obligations. Classification tells you how much actually applies.
6:12 Common mistakes
Three mistakes come up again and again. First, assuming we're not in the EU, so it doesn't apply, while serving EU customers or sending outputs into the EU. Second, classifying the vendor's product instead of your use of it. The vendor's marketing page might say low risk, but if you use the tool to rank job applicants, you're in high-risk territory. Third, forgetting that everything else still applies. Even minimal-risk AI must respect GDPR, consumer protection and advertising law. Classification under the AI Act is one question, not the only question.
6:52 Watch me do it: classify rows
Watch me do it. I'm taking the register from the last lesson and adding three columns: In scope, Role, and Tier, plus a Reasoning column. Row one, the chat assistant used for drafting. Is it an AI system? Yes. Is output used in the EU? Yes, we have a German client. Role: deployer, because we use it under our authority and haven't rebranded it. Prohibited? No. Annex three use? No, it's drafting marketing copy. Interacts with the public? No, staff only. So tier: minimal, reasoning: internal drafting, AI literacy applies. Row two, the help desk reply suggestions. Deployer again. Customers don't talk to it directly, agents do, so minimal, but I note: if we ever switch on auto-replies to customers, Article fifty disclosure applies. Row three, a new pilot: a CV screening add-on in our HR tool. Employment is Annex three, so tier: high-risk candidate. I check Article six three: it ranks candidates, which is profiling, so no exemption. I mark it amber and write escalate before rollout. Notice what just happened: three minutes of structured questions turned a vague worry into one clear decision for leadership.
8:13 Recap and next step
Recap. The AI Act regulates uses, not models, so classify what you do with a tool, not the tool itself. It reaches outside the EU whenever your AI or its output touches the EU. Know your role, and watch for Article twenty-five, which can turn a deployer into a provider. Your next step: take the AI tool list you started last lesson and run each entry through the decision tree in the lesson text. Mark each one prohibited, high-risk candidate, transparency, or minimal, and note why.
Not legal advice. This course explains regulations and standards so you can ask better questions and build sensible controls. Laws change and apply differently to each organization. For decisions with legal consequences, confirm with qualified counsel in the relevant jurisdiction.
The regulation in one paragraph
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is a product-safety style regulation for AI. It sets rules for placing AI systems and general-purpose AI models on the EU market, putting them into service and using them. It classifies AI uses by risk, bans a short list of practices, places heavy duties on "high-risk" systems, adds transparency duties for certain systems, and creates specific obligations for general-purpose AI models. In 2026 it was amended by the "Digital Omnibus on AI" (Regulation (EU) 2026/1744), which, among other things, pushed back the high-risk deadlines. You will study those dates in Module 2.
Scope: when does it apply to you?
The Act reaches beyond EU borders. It can apply to:
- Providers placing AI systems or GPAI models on the EU market or putting them into service in the EU, wherever the provider is established.
- Deployers established or located in the EU.
- Providers and deployers outside the EU where the output produced by the AI system is used in the EU.
- Importers, distributors, product manufacturers that integrate AI, and authorized representatives of non-EU providers.
So a Lahore software house selling an AI recruitment tool to a company in Ireland is in scope as a provider. A Riyadh brand that runs an AI chatbot for customers in France should assume the transparency rules apply to that chatbot.
Key exclusions include AI used exclusively for military, defence or national security purposes, AI used for scientific research and development as such, and purely personal non-professional use. Open-source releases get some carve-outs, but not for prohibited or high-risk uses or for certain transparency duties.
The roles ("operators")
| Role | Who | Typical burden |
|---|---|---|
| Provider | Develops the system or model, places it on the market or puts it into service under its own name or trademark | Heaviest: design, documentation, conformity |
| Deployer | Uses it under its authority in a professional capacity | Use as instructed, oversight, transparency to affected people |
| Importer | EU entity placing a non-EU provider's system on the market | Verify conformity before placing |
| Distributor | Makes it available in the supply chain | Check markings and documentation |
| Authorized representative | EU-based entity mandated by a non-EU provider | Acts on the provider's behalf with authorities |
Roles can shift. Under Article 25, a deployer, distributor or importer is treated as a provider of a high-risk system if they put their name or trademark on it, make a substantial modification, or change its intended purpose so that it becomes high-risk. Example: you buy a general-purpose chatbot and re-purpose it to rank job applicants. You may now be the provider of a high-risk system.
The risk pyramid
- Unacceptable risk: prohibited (Article 5). For example social scoring, manipulative techniques causing significant harm, emotion recognition in workplaces and schools. Lesson 2.1.
- High risk (Article 6 and Annexes I and III). AI in regulated products (such as medical devices, machinery, toys) and in listed sensitive areas such as employment, education, credit scoring and essential services. Lesson 2.2.
- Transparency risk (Article 50). Chatbots, synthetic content, deepfakes, emotion recognition and biometric categorization carry disclosure duties. Lesson 2.4.
- Minimal risk. Everything else: spam filters, most content tools, recommendation of blog topics. No specific AI Act obligations beyond AI literacy, though other laws still apply.
Alongside the pyramid sits a separate track for general-purpose AI models (Lesson 2.3), with extra duties for models posing "systemic risk".
A single product can touch several layers. A recruitment chatbot that screens candidates is high-risk (employment) and also subject to chatbot transparency.
Who enforces it
- The AI Office, inside the European Commission, supervises general-purpose AI models and coordinates implementation.
- The European AI Board (Member State representatives) supports consistent application, alongside a scientific panel and an advisory forum.
- National market surveillance authorities enforce most rules on AI systems in each Member State.
- Data protection authorities remain in charge of GDPR, which keeps applying in parallel.
Worked example: classifying five uses at a UK retailer selling into the EU
| Use | Classification | Why |
|---|---|---|
| Product description generator | Minimal risk (check Art. 50 if content is published as news-like public-interest text) | Ordinary content creation |
| Customer service chatbot | Transparency risk | Must inform people they are interacting with AI unless obvious |
| CV screening for warehouse jobs | High risk | Annex III, employment |
| Dynamic pricing model | Usually minimal risk under the AI Act | Consumer and competition law still apply |
| Staff emotion-detection from webcams | Prohibited | Emotion recognition in the workplace (limited medical and safety exceptions) |
Hands-on: a classification decision tree
Use this for every entry in your AI inventory.
1. Is it an "AI system" (infers outputs from inputs with some autonomy)? No -> out of AI Act scope (other laws still apply)
2. Is it used in the EU, or is its output used in the EU? No -> likely out of scope; record reasoning
3. What is our role? Provider / Deployer / Importer / Distributor
Did we rebrand, substantially modify, or change intended purpose? Yes -> treat as Provider for that system
4. Does it match an Article 5 prohibited practice? Yes -> STOP. Escalate to legal.
5. Is it a safety component of an Annex I product, or an Annex III use? Yes -> High-risk candidate. Check Art. 6(3) exceptions.
6. Does it interact with people, generate synthetic content, recognize
emotions, or categorize people biometrically? Yes -> Article 50 transparency duties
7. Otherwise -> minimal risk: AI literacy + good practice + other lawsRecord the answer and the reasoning for each step. The reasoning is what an auditor or client will want to see.
Pitfalls
- Assuming "we're not in the EU, so it doesn't apply" while serving EU customers.
- Classifying the vendor's product instead of your use of it. The same model can be minimal risk in marketing and high-risk in hiring.
- Forgetting that GDPR, consumer protection and sector rules apply regardless of the AI Act tier.
Key takeaways
- The AI Act regulates uses by risk tier: prohibited, high-risk, transparency and minimal, plus a separate track for general-purpose AI models.
- It applies extraterritorially, including when an AI system's output is used in the EU.
- Article 25 can make a deployer the provider of a high-risk system if it rebrands, substantially modifies or repurposes it.
- Classification depends on the specific use; GDPR and other laws apply regardless of tier.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Run each tool in your inventory through the seven-step decision tree. Record role, tier and a one-sentence rationale for each.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.