Skip to content
AI ConnectPowered by VELENTIS

The EU AI Act at a Glance: Risk Tiers, Deadlines, and How to Implement It

28 min reading + quiz

In the previous lessons you learned why the training obligation exists, how AI tools work, and where the opportunities and risks lie. This final lesson puts the frame around it all: the logic of the EU AI Act, the key deadlines and fines — and a concrete roadmap your company can follow to put the requirements into practice.

A Law That Sorts by Risk

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law on artificial intelligence. As an EU regulation it applies directly in every member state — no separate national implementation law is needed. And it doesn't just cover companies that build AI systems; it explicitly applies to companies that merely use them.

The core idea: the law regulates not the technology as such, but the specific use case — graded by the risk it poses to health, safety, and fundamental rights. The higher the risk, the stricter the obligations. This produces four tiers:

  • Unacceptable risk: prohibited (e.g., social scoring)
  • High risk: permitted but strictly regulated (e.g., AI in candidate selection)
  • Limited risk: transparency obligations (e.g., labeling chatbots)
  • Minimal risk: no special obligations (e.g., spam filters) — the vast majority of applications

Red Lines: What Has Been Banned Since February 2025

Since 2 February 2025, certain AI practices have been completely banned in the EU because they violate fundamental rights. These include social scoring (rating people based on their social behavior with detrimental consequences), manipulative or deceptive techniques that materially distort people's behavior and can cause them significant harm, and the untargeted scraping of facial images from the internet to build recognition databases.

Particularly relevant for everyday working life: AI-based emotion recognition in the workplace and in educational institutions is prohibited — for example, software that continuously infers employees' emotional state from their voice or facial expressions. The only exceptions are medical and safety reasons, such as fatigue detection for professional drivers.

These prohibitions are absolute: there is no remaining transition period, and they cannot be lifted by obtaining the affected people's consent. So whenever you evaluate a new tool — especially from vendors outside the EU — always check whether it includes such features before you deploy it.

High Risk, Transparency, Minimal: Where Your Day-to-Day Work Happens

High-risk systems are permitted but subject to strict requirements. Annex III of the regulation lists the fields of use — especially relevant for mid-sized companies: AI in employment decisions (such as automatically pre-sorting job applications or software supporting promotion and dismissal decisions) and assessing the creditworthiness of natural persons. The main obligations fall on the providers of such systems, but deployers also have duties: use the system in line with its instructions, monitor its operation, and ensure effective human oversight by trained staff.

Limited risk is about transparency: anyone interacting with a chatbot must be able to tell they are talking to a machine. AI-generated or AI-manipulated content — deepfakes, for instance — must be labeled as such. For a customer service team this means, concretely: the chatbot on your website needs a clear notice that an AI is answering.

The vast majority of AI applications fall into the minimal-risk category: spam filters, spell checkers, most internal writing and research assistants. The AI Act imposes no special requirements here. The due-diligence rules from Lesson 4 — check outputs, keep sensitive data out of open tools — still apply, because data protection and liability law continue to operate independently.

Deadlines and Fines: The Legislator's Timetable

The AI Act does not apply all at once but in stages. The key dates:

The fines are deliberately painful: deploying prohibited practices can cost up to 35 million euros or 7 percent of worldwide annual turnover — whichever amount is higher. Most other violations (such as breaches of deployer or transparency obligations) carry fines of up to 15 million euros or 3 percent, and supplying false information to authorities up to 7.5 million euros or 1 percent. For small and medium-sized enterprises, the lower of the two amounts serves as the cap.

For context: the fine catalogue in Article 99 contains no separate penalty for the training obligation in Article 4. But a lack of AI literacy can count against you in other violations and in liability cases — which is why documented training is your best safeguard, as described in Lesson 1.

  • 1 August 2024 — the regulation entered into force
  • 2 February 2025 — the prohibitions and the AI literacy obligation (Art. 4) apply; the basis of this course
  • 2 August 2025 — obligations for general-purpose AI models (e.g., large language models) and the penalty regime apply
  • 2 August 2026 — the core obligations for high-risk systems and most remaining rules apply; certain transition periods run until 2027

What Your Company Should Do Now

For most mid-sized companies, the AI Act is not a mega-project but well-organized groundwork. Four steps form the foundation:

Also anchor clear ownership: one person or a small team that keeps the inventory current, vets new tools before use, and tracks the deadlines. AI literacy is not a one-off project — Article 4 requires a sufficient level on an ongoing basis, and the tool landscape changes fast.

This closes the loop on the course: you know why the training obligation exists, how the tools work, where they create value, and which risks you need to keep under control — and now also the legal framework all of this operates in. If you implement the four steps above, you are not just fulfilling an obligation; you are laying the foundation for using AI safely and productively in your company.

  • Build an AI inventory: Which AI tools are in use — including unofficially on individual machines? Record per tool: purpose, data processed, risk category.
  • Clarify roles: Are we only a deployer (we use third-party AI) or also a provider (we develop or market AI under our own name)? The obligations differ substantially.
  • Document training: Who was trained, when, on what content? Keep written records of participation and topics — this course is one building block.
  • Introduce an AI policy: Which tools are approved, which data is off-limits, when is human review mandatory, and how is AI-generated content labeled?

Key takeaways

  • The AI Act regulates by use case and risk: prohibited, high, limited, minimal — most everyday tools fall into the lowest tier.
  • Since 2 February 2025 the prohibitions (including social scoring and workplace emotion recognition) and the AI literacy obligation apply; the core obligations for high-risk systems follow from 2 August 2026.
  • High risk begins where AI makes decisions about people — above all candidate selection and creditworthiness assessment; strict requirements and human oversight apply there.
  • Violating the prohibitions costs up to 35 million euros or 7 percent of worldwide annual turnover (whichever is higher); for SMEs the lower amount is the cap.
  • Your roadmap: build an AI inventory, clarify roles, document training, introduce an AI policy — and assign clear ownership.

Knowledge check

Question 1 of 3

A company wants to use AI to continuously assess its customer service employees' mood from their voice and facial expressions. How does the EU AI Act treat this?

Questions about this lesson? Your tutor

Answers based on this lesson — explains, gives examples, helps you understand.

The tutor answers exclusively based on the reviewed lesson content and is not legal advice. Please do not enter personal data of third parties.