SkarpSkarp

Chapter 1 of 11

From Legal Text to Business Reality: What the EU AI Act Actually Is

Instead of wading through hundreds of pages of legalese, step into a clear big-picture view of the EU AI Act: what it covers, why it exists, and how it will reshape the way businesses build and use AI in and beyond Europe.

15 min readen

Step 1 – Why the EU AI Act Exists and Where It Stands Today

What Is the EU AI Act?

Regulation (EU) 2024/1689, the EU AI Act, is the world’s first broad, horizontal AI law. It creates a single rulebook for AI across the EU to protect people and support trustworthy innovation.

Why It Was Adopted

The Act aims to protect fundamental rights, ensure safety, and give businesses a predictable legal environment. It responds to rapid AI advances and concerns about bias, surveillance, and opaque decision-making.

A Risk-Based Framework

The AI Act sorts AI uses into four buckets: prohibited (unacceptable risk), high-risk (strict rules), limited-risk (transparency), and minimal risk (no specific AI Act duties). Most AI falls into the last two.

A Regulation With Direct Effect

Unlike a directive, this regulation applies directly in all EU countries. It sits alongside GDPR and sector laws, adding AI-specific duties rather than replacing existing protections.

Step 2 – The Architecture of the AI Act: How It Is Structured

Four Big Layers

The AI Act’s logic can be seen in four layers: (1) definitions and scope, (2) risk categories and prohibited practices, (3) obligations and governance, and (4) enforcement and innovation support.

Risk Categories

The Act defines prohibited AI, high-risk AI, limited-risk with transparency duties, and minimal-risk AI. High-risk categories are largely listed in annexes, tied to sensitive use areas.

Obligations and Governance

Detailed duties apply mainly to high-risk AI and certain general-purpose AI models. Oversight is handled by the EU AI Office plus national authorities and notified bodies.

From Text to Business Questions

To apply the Act, businesses ask: What type of AI system is this? What role do we play? The answers determine which chapters and annexes of the Act actually apply.

Step 3 – What Counts as AI and Who Is Covered (Scope)

Territorial Reach

The AI Act applies to EU organizations and to non-EU companies that place AI systems on the EU market or whose AI outputs are used in the EU. Physical presence in the EU is not required.

AI System Definition

An AI system is a machine-based system that operates with some autonomy and generates outputs (predictions, recommendations, decisions) that influence environments. It covers many techniques, not just deep learning.

General-Purpose AI Models

GPAI models are versatile models usable for many tasks, such as large language or multimodal models. Their providers face dedicated obligations, especially when models pose systemic risk.

What Is Out of Scope?

Purely non-AI software and certain military or national security uses are outside the AI Act. But many business tools marketed as AI or using ML will fall in scope.

Step 4 – The Risk-Based Approach: From Prohibited to Minimal Risk

Four Risk Levels

The AI Act escalates duties with risk: prohibited AI (unacceptable), high-risk AI (strict rules), limited-risk AI (transparency), and minimal-risk AI (no specific AI Act duties).

Prohibited Practices

Certain manipulative AI, harmful social scoring by public bodies, and some uses of real-time biometric identification in public are banned, with only narrow exceptions for law enforcement.

High-Risk Systems

High-risk AI includes safety components of regulated products and systems used in sensitive fields like education, employment, credit, law enforcement, and public services.

Limited vs Minimal Risk

Limited-risk AI has transparency duties (for example, chatbots, deepfakes). Minimal-risk AI like many recommendation tools has no extra AI Act duties, though good practice is encouraged.

Step 5 – Key Operator Roles: Who Does What in the AI Value Chain

Roles, Not Just Companies

The AI Act regulates roles in the AI lifecycle: provider, deployer, importer, distributor, and product manufacturer. One company can hold multiple roles for the same or different systems.

Provider vs Deployer

A provider builds and markets the AI system under its name. A deployer uses the AI system under its authority, such as a bank using a third-party AI tool to decide on loans.

Importer and Distributor

Importers bring non-EU AI systems into the EU market. Distributors resell or make AI systems available but do not develop them. Both must check that basic compliance elements are in place.

Product Manufacturer

A product manufacturer integrates AI into physical products, especially where AI is a safety component. They may inherit or share obligations similar to AI system providers.

Why Role Classification Matters

Each role has different legal duties. Knowing your role for each AI system is the starting point for understanding what documentation, testing, and oversight you must provide.

Step 6 – Role Mapping in Real Businesses (Scenarios)

Scenario A: Recruitment SaaS

A US company offers an AI CV-screening tool to EU employers. It is the provider of a high-risk system. EU resellers act as distributors, and EU employers act as deployers using the system.

Scenario A: Obligations

The provider must ensure risk management, data quality, and documentation. Deployers must use the tool as instructed, keep human oversight in hiring, and maintain records of use.

Scenario B: Medical Device

An EU manufacturer embeds AI into a medical imaging device. It is both product manufacturer and provider of a high-risk AI system, combining AI Act duties with medical device rules.

Scenario C: GPAI Model

A lab develops a large language model usable for many tasks. It is a GPAI model provider. A start-up that fine-tunes it into a legal assistant becomes a provider of a downstream AI system.

Stacked Responsibilities

Across these scenarios, roles and duties stack along the value chain: foundation model provider, system provider, distributors, and deployers all carry different compliance pieces.

Step 7 – Classify the Role: Quick Thought Exercise

Use this short exercise to practice mapping business activities to AI Act roles.

Imagine you are analyzing three companies. For each one, decide which AI Act role(s) best fit and why.

  1. Company X: CloudVision
  • Builds an image recognition model.
  • Sells API access directly to EU retailers for product recognition in stores.
  • Does not control how retailers integrate the API.

Your task:

  • Which role does CloudVision have? Provider, deployer, importer, distributor, product manufacturer, or several?
  • Does it likely have high-risk systems, or more limited/minimal risk? Why?
  1. Company Y: SmartHire Agency
  • Buys a third-party AI recruitment tool.
  • Uses it for pre-screening candidates for its clients (companies across the EU).
  • Does not modify the AI, but configures scoring thresholds.

Your task:

  • Which role does SmartHire play? Is it a deployer, provider, or something else?
  • What might its main obligations be under the AI Act?
  1. Company Z: RoboHome Appliances
  • Manufactures home vacuum robots.
  • Integrates a simple navigation algorithm that is not safety-critical and does not rely on learning.
  • Markets the robots worldwide, including in the EU.

Your task:

  • Does the navigation feature likely qualify as an AI system under the AI Act definition? Why or why not?
  • If it does not, what does that mean for AI Act obligations?

Hint for self-check:

  • Providers develop and place AI systems on the market.
  • Deployers use AI systems under their authority.
  • Importers and distributors sit in the supply chain but do not build the AI.
  • Not every algorithmic feature is necessarily an AI system under the Act.

Write down your answers in bullet points. Then compare them to a model answer from your instructor or course notes, focusing on your reasoning, not just the labels.

Step 8 – Quick Check: Scope and Roles

Answer this multiple-choice question to test your understanding of scope and roles under the EU AI Act.

A Canadian company develops an AI tool that predicts loan default risk and sells it as SaaS to banks in several EU countries. The banks use the tool’s scores when deciding whether to grant loans. Under the EU AI Act, which statement is most accurate?

  1. The Canadian company is outside the AI Act because it has no office in the EU; only the EU banks are covered.
  2. The Canadian company is a provider in scope of the AI Act because it places an AI system on the EU market, and the EU banks are deployers using a likely high-risk AI system.
  3. The Canadian company is only a distributor because it does not manufacture a physical product; the EU banks are providers because they make final decisions on loans.
  4. Neither the Canadian company nor the EU banks are in scope because credit scoring is not covered by the AI Act.
Show Answer

Answer: B) The Canadian company is a provider in scope of the AI Act because it places an AI system on the EU market, and the EU banks are deployers using a likely high-risk AI system.

Credit scoring is one of the classic high-risk use cases under the AI Act. The Canadian company develops and markets the AI system to EU clients, so it is a provider in scope despite being outside the EU. The EU banks use the system under their authority, so they are deployers. Physical presence in the EU is not required for the Act to apply.

Step 9 – How the AI Act Interacts With GDPR and Other EU Laws

AI Act and GDPR

GDPR regulates personal data; the AI Act regulates AI systems. When AI uses personal data, both apply. You must design systems that satisfy data protection and AI-specific requirements together.

AI and Product Safety Laws

For products like medical devices or machinery, AI Act duties are integrated into existing conformity assessments, rather than creating a separate parallel process.

Fundamental Rights Focus

The AI Act is built around protecting fundamental rights and preventing discrimination. It may require impact assessments and documentation of how harms and biases are mitigated.

Multi-Layer Compliance

In practice, AI projects often sit at the intersection of the AI Act, GDPR, sector rules, and human rights law. Cross-functional teams are needed to manage this combined compliance landscape.

Step 10 – Key Term Flashcards

Flip through these flashcards to reinforce core EU AI Act concepts.

AI Act (Regulation (EU) 2024/1689)
An EU regulation establishing a risk-based framework for the development, placement on the market, and use of AI systems and general-purpose AI models in and affecting the EU.
AI system
A machine-based system with varying levels of autonomy that, for explicit or implicit objectives, generates outputs (predictions, recommendations, decisions) influencing physical or virtual environments.
General-purpose AI model (GPAI)
A model that can be used for a wide range of tasks, such as large language or multimodal models, and that may be integrated into many downstream AI systems.
Provider
An organization that develops an AI system or GPAI model and places it on the market or puts it into service under its own name or trademark.
Deployer
An organization that uses an AI system under its authority, for example a bank using an AI credit scoring tool or an employer using an AI hiring assistant.
Importer
An EU-based operator that places on the EU market an AI system from a provider established outside the EU.
Distributor
An operator in the supply chain, other than the provider or importer, that makes an AI system available on the EU market without modifying its intended purpose.
High-risk AI system
An AI system that poses a significant risk to health, safety, or fundamental rights, such as AI used in credit scoring, employment, law enforcement, or as a safety component of regulated products.
Prohibited AI practice
AI uses banned under the AI Act, such as certain manipulative systems, harmful social scoring by public authorities, and some real-time remote biometric identification in public spaces.
Risk-based approach
The AI Act’s design principle where regulatory obligations scale with the level of risk posed by an AI use case, from prohibited to high-risk, limited-risk, and minimal-risk categories.

Key Terms

Deployer
An operator that uses an AI system under its authority, such as an organization using AI tools in its operations.
Importer
An EU-based operator that places on the EU market an AI system supplied by a provider outside the EU.
Provider
An operator that develops an AI system or GPAI model and places it on the market or puts it into service under its name or trademark.
AI system
A machine-based system that can operate with some autonomy and produce outputs like predictions, recommendations, or decisions that influence physical or virtual environments.
Distributor
An operator in the supply chain that makes an AI system available on the EU market without being the provider or importer.
Material scope
The types of technologies and activities covered by the AI Act, focusing on AI systems and GPAI models as defined in the regulation.
Territorial scope
The geographical reach of the AI Act, including EU-based operators and non-EU operators whose AI systems or outputs affect the EU market or people in the EU.
High-risk AI system
An AI system classified by the AI Act as posing significant risks to health, safety, or fundamental rights, and therefore subject to strict obligations.
Risk-based approach
A regulatory strategy where the level of legal obligations increases with the potential risk an AI use case poses to individuals and society.
Product manufacturer
A manufacturer of a product that integrates an AI system as a component, especially where the AI affects safety or regulatory classification.
Prohibited AI practice
An AI use that the AI Act bans entirely because it is considered incompatible with EU values and fundamental rights.
General-purpose AI model (GPAI)
A versatile AI model that can be used for a broad range of tasks and integrated into many downstream systems, such as large language or multimodal models.
AI Act (Regulation (EU) 2024/1689)
The EU’s comprehensive regulation on artificial intelligence, establishing a risk-based framework for AI systems and general-purpose AI models in and affecting the EU market.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself