The EU AI Act sorts AI systems by risk rather than regulating the technology as a single category. A small set of uses, such as social scoring or manipulative subliminal techniques, are banned outright. A larger set, including most AI used in hiring, credit, law enforcement, and critical infrastructure, is classed as high-risk and comes with binding obligations: documented risk management, data governance, technical robustness, and, under Article 14, human oversight that the provider or deployer can actually demonstrate, not just assert. Everything else carries lighter transparency duties or none at all.
Its obligations phase in on a staggered timeline rather than all at once, which makes it easy to assume there’s more runway than there is. The prohibited-practices rules and the human-oversight requirements for high-risk systems apply years apart, with different deadlines again for systems already on the market versus new ones, so “we’re not affected yet” is a date-specific claim that needs checking against the actual system category, not a general assumption.
The Act’s real influence extends well past the companies it directly binds, because it’s becoming the reference design for what “adequate human oversight” means globally, the way GDPR became the reference design for data protection language well outside the EU. A board asking “could we show a regulator our oversight was real” is, in substance, already testing against this standard, whether or not the Act applies to them directly.