IOanyT Innovations

Lesson 9 of 10 · 9 min read

EU AI Act basics for buyers and builders

In one paragraph

The EU AI Act regulates AI systems by risk: some practices are prohibited, high-risk uses such as credit scoring, hiring, education and insurance pricing carry strict obligations, and systems that interact with people must disclose they are AI. Under the 2026 Digital Omnibus agreement, Annex III high-risk obligations apply from 2 December 2027.

In this lesson

  • Name the Act's risk tiers and where common business AI falls
  • Know the key dates after the Digital Omnibus agreement
  • List what a high-risk system must be able to show, and how deterministic logic makes that easier

The video version of this lesson is in production. The full lesson is below.

If your AI touches customers or decisions in the EU, or you sell to companies that operate there, the EU AI Act shapes what you must be able to show. This lesson is an orientation for buyers and builders, not a legal guide.

This lesson is a summary for orientation, not legal advice. Dates reflect the 2026 Digital Omnibus agreement; check current status with counsel.

Four tiers of risk

The Act sorts AI systems by the harm they could cause:

  1. Prohibited practices. A short list of uses banned outright, such as certain manipulative techniques and social scoring. These prohibitions already apply.
  2. High-risk systems. Uses listed in Annex III, including biometric identification, critical infrastructure, education, employment and hiring, access to essential private and public services (including credit scoring and life and health insurance pricing), law enforcement, migration and the administration of justice, plus AI that is a safety component of products regulated under Annex I. These carry the heaviest obligations.
  3. Transparency obligations. Under Article 50, people must be told when they are interacting with an AI system, and certain AI-generated content must be marked.
  4. Minimal risk. Most other AI systems, with voluntary codes of conduct.

Most business AI sits in tiers 3 and 4. The decisions this course focuses on (credit, collections, insurance, eligibility) are where tier 2 begins.

The dates that matter now

Under the 2026 Digital Omnibus agreement:

ObligationApplies from
Article 50 transparency2 August 2026
Watermarking grace period for systems already on the marketuntil 2 December 2026
Annex III high-risk obligations2 December 2027
Annex I high-risk obligations (regulated products)2 August 2028

The extra time is planning time. Retrofitting documentation and logging into a live system is far harder than designing them in.

What a high-risk system must be able to show

Providers of high-risk systems must meet requirements including:

  • Risk management across the system’s life.
  • Data governance for training, validation and test data.
  • Technical documentation describing how the system works and was tested.
  • Record-keeping: automatic logs that allow decisions to be traced.
  • Transparency to deployers about capabilities and limits.
  • Human oversight built into the design.
  • Accuracy, robustness and cybersecurity appropriate to the use.

Deployers, the businesses using these systems, also have duties, including using systems as instructed, assigning human oversight, monitoring operation and keeping logs.

Where deterministic logic helps

No design choice exempts a system from the Act. But a decision path that runs as versioned, tested code makes several obligations much easier to meet:

  • Documentation: the logic is the documentation of how decisions are made.
  • Logging: every decision can record which rule and which version applied.
  • Oversight: reviewers can see exactly why a case was decided, and change rules through a controlled release.
  • Accuracy testing: golden datasets and regression runs (lesson 5) give repeatable evidence.

Try it yourself: a 15-minute AI inventory

List every AI system your organisation builds or uses. For each, note:

  1. Does it interact with people? (Article 50 transparency.)
  2. Does it touch an Annex III area: hiring, credit, insurance pricing, education, essential services?
  3. Do EU residents use it, or is its output used in the EU?
  4. Who owns it, and who would answer a regulator’s question about it?

Anything with “yes” to questions 2 and 3 deserves a conversation with counsel well before December 2027.

What comes next

The final lesson brings the course together with patterns from real systems, and a five-step plan for where to start.

The EU AI Act sorts systems by risk Obligations grow with the potential for harm. Most business AI sits in the lower tiers. PROHIBITED: Unacceptable-risk practices, banned outright. HIGH RISK: Annex III: credit, hiring, education, insurance, from 2 Dec 2027. TRANSPARENCY: Tell people they are dealing with AI, Article 50. MINIMAL: Most other systems, voluntary codes. IOANYT ACADEMY / LESSON 9 The EU AI Act sorts systems by risk Obligations grow with the potential for harm. Most business AI sits in the lower tiers. PROHIBITED Unacceptable-risk practices banned outright HIGH RISK Annex III: credit, hiring, education, insurance from 2 Dec 2027 TRANSPARENCY Tell people they are dealing with AI Article 50 MINIMAL Most other systems voluntary codes summary for orientation, not legal advice

Key takeaways

  • Obligations scale with risk: prohibited, high-risk, transparency, minimal.
  • Article 50 transparency applies from 2 August 2026; Annex III high-risk obligations from 2 December 2027; Annex I from 2 August 2028.
  • High-risk systems need risk management, documentation, logging, human oversight and accuracy testing.
  • Conformity is the obligation of the provider or deployer. Vendors can support it but can't certify it on their behalf.

Check yourself

Pick an answer, then open the card to compare.

  1. 1. From when do Annex III high-risk obligations apply under the Digital Omnibus agreement?

    • A.2 August 2025
    • B.2 December 2027
    • C.1 January 2030
    Show the answer

    B. 2 December 2027 The agreement moved Annex III high-risk obligations to 2 December 2027, and Annex I to 2 August 2028.

  2. 2. Which of these is an Annex III high-risk area?

    • A.A spam filter
    • B.Credit scoring of individuals
    • C.A video game's opponent AI
    Show the answer

    B. Credit scoring of individuals Access to essential services, including creditworthiness assessment, is listed in Annex III.

  3. 3. Why does deterministic logic help with high-risk obligations?

    • A.It exempts the system from the Act
    • B.Versioned, testable logic makes documentation, logging, oversight and accuracy testing easier to provide
    • C.Regulators prefer older technology
    Show the answer

    B. Versioned, testable logic makes documentation, logging, oversight and accuracy testing easier to provide No design exempts a system, but repeatable, traceable decisions are far easier to document and audit.

Common questions

Does the Act apply to companies outside the EU?

It can. It applies to providers placing AI systems on the EU market and to systems whose output is used in the EU, wherever the company is based. Check with counsel how it applies to you.

Is our chatbot high-risk?

Most customer-service chatbots aren't high-risk in themselves, but they carry transparency duties: people must be told they're dealing with AI. If the same system makes decisions in an Annex III area, such as credit or insurance pricing, that part may be high-risk.

Can a vendor certify our system under the EU AI Act?

No vendor can certify that on your behalf. Conformity is the provider's or deployer's obligation. A good vendor designs for readiness and gives you the documentation, logs and test evidence your conformity work needs.