Lesson 9 of 10 · 9 min read
EU AI Act basics for buyers and builders
In one paragraph
The EU AI Act regulates AI systems by risk: some practices are prohibited, high-risk uses such as credit scoring, hiring, education and insurance pricing carry strict obligations, and systems that interact with people must disclose they are AI. Under the 2026 Digital Omnibus agreement, Annex III high-risk obligations apply from 2 December 2027.
In this lesson
- Name the Act's risk tiers and where common business AI falls
- Know the key dates after the Digital Omnibus agreement
- List what a high-risk system must be able to show, and how deterministic logic makes that easier
The video version of this lesson is in production. The full lesson is below.
If your AI touches customers or decisions in the EU, or you sell to companies that operate there, the EU AI Act shapes what you must be able to show. This lesson is an orientation for buyers and builders, not a legal guide.
This lesson is a summary for orientation, not legal advice. Dates reflect the 2026 Digital Omnibus agreement; check current status with counsel.
Four tiers of risk
The Act sorts AI systems by the harm they could cause:
- Prohibited practices. A short list of uses banned outright, such as certain manipulative techniques and social scoring. These prohibitions already apply.
- High-risk systems. Uses listed in Annex III, including biometric identification, critical infrastructure, education, employment and hiring, access to essential private and public services (including credit scoring and life and health insurance pricing), law enforcement, migration and the administration of justice, plus AI that is a safety component of products regulated under Annex I. These carry the heaviest obligations.
- Transparency obligations. Under Article 50, people must be told when they are interacting with an AI system, and certain AI-generated content must be marked.
- Minimal risk. Most other AI systems, with voluntary codes of conduct.
Most business AI sits in tiers 3 and 4. The decisions this course focuses on (credit, collections, insurance, eligibility) are where tier 2 begins.
The dates that matter now
Under the 2026 Digital Omnibus agreement:
| Obligation | Applies from |
|---|---|
| Article 50 transparency | 2 August 2026 |
| Watermarking grace period for systems already on the market | until 2 December 2026 |
| Annex III high-risk obligations | 2 December 2027 |
| Annex I high-risk obligations (regulated products) | 2 August 2028 |
The extra time is planning time. Retrofitting documentation and logging into a live system is far harder than designing them in.
What a high-risk system must be able to show
Providers of high-risk systems must meet requirements including:
- Risk management across the system’s life.
- Data governance for training, validation and test data.
- Technical documentation describing how the system works and was tested.
- Record-keeping: automatic logs that allow decisions to be traced.
- Transparency to deployers about capabilities and limits.
- Human oversight built into the design.
- Accuracy, robustness and cybersecurity appropriate to the use.
Deployers, the businesses using these systems, also have duties, including using systems as instructed, assigning human oversight, monitoring operation and keeping logs.
Where deterministic logic helps
No design choice exempts a system from the Act. But a decision path that runs as versioned, tested code makes several obligations much easier to meet:
- Documentation: the logic is the documentation of how decisions are made.
- Logging: every decision can record which rule and which version applied.
- Oversight: reviewers can see exactly why a case was decided, and change rules through a controlled release.
- Accuracy testing: golden datasets and regression runs (lesson 5) give repeatable evidence.
Try it yourself: a 15-minute AI inventory
List every AI system your organisation builds or uses. For each, note:
- Does it interact with people? (Article 50 transparency.)
- Does it touch an Annex III area: hiring, credit, insurance pricing, education, essential services?
- Do EU residents use it, or is its output used in the EU?
- Who owns it, and who would answer a regulator’s question about it?
Anything with “yes” to questions 2 and 3 deserves a conversation with counsel well before December 2027.
What comes next
The final lesson brings the course together with patterns from real systems, and a five-step plan for where to start.
Key takeaways
- Obligations scale with risk: prohibited, high-risk, transparency, minimal.
- Article 50 transparency applies from 2 August 2026; Annex III high-risk obligations from 2 December 2027; Annex I from 2 August 2028.
- High-risk systems need risk management, documentation, logging, human oversight and accuracy testing.
- Conformity is the obligation of the provider or deployer. Vendors can support it but can't certify it on their behalf.
Check yourself
Pick an answer, then open the card to compare.
-
1. From when do Annex III high-risk obligations apply under the Digital Omnibus agreement?
- A.2 August 2025
- B.2 December 2027
- C.1 January 2030
Show the answer
B. 2 December 2027 The agreement moved Annex III high-risk obligations to 2 December 2027, and Annex I to 2 August 2028.
-
2. Which of these is an Annex III high-risk area?
- A.A spam filter
- B.Credit scoring of individuals
- C.A video game's opponent AI
Show the answer
B. Credit scoring of individuals Access to essential services, including creditworthiness assessment, is listed in Annex III.
-
3. Why does deterministic logic help with high-risk obligations?
- A.It exempts the system from the Act
- B.Versioned, testable logic makes documentation, logging, oversight and accuracy testing easier to provide
- C.Regulators prefer older technology
Show the answer
B. Versioned, testable logic makes documentation, logging, oversight and accuracy testing easier to provide No design exempts a system, but repeatable, traceable decisions are far easier to document and audit.
Common questions
Does the Act apply to companies outside the EU?
It can. It applies to providers placing AI systems on the EU market and to systems whose output is used in the EU, wherever the company is based. Check with counsel how it applies to you.
Is our chatbot high-risk?
Most customer-service chatbots aren't high-risk in themselves, but they carry transparency duties: people must be told they're dealing with AI. If the same system makes decisions in an Annex III area, such as credit or insurance pricing, that part may be high-risk.
Can a vendor certify our system under the EU AI Act?
No vendor can certify that on your behalf. Conformity is the provider's or deployer's obligation. A good vendor designs for readiness and gives you the documentation, logs and test evidence your conformity work needs.