The EU AI Act introduces a risk-based framework for artificial intelligence. For innovators, the productive response is not to label every system high risk or low risk from a headline. It is to define the intended purpose, actors, context and evidence, then verify the applicable obligations.
What matters most
Classification depends on the system’s intended purpose and use context.
The same underlying model can create different obligations for providers, deployers and other actors.
Data governance, technical documentation, monitoring and human oversight should be designed early where relevant.
Standards, common specifications and official guidance can affect implementation detail.
Rules phase in over time and may be amended or clarified.
This site provides educational orientation, not legal or conformity-assessment advice.
Questions to answer before acting
Use these questions to turn a broad topic into a defined decision, test or work package:
- What is the defined intended purpose?
- Who is the provider, deployer, importer or distributor?
- Which risk category and sector rules may apply?
- What evidence can be generated during development?
A practical sequence
- Step 1. Document the system, actors and intended use.
- Step 2. Screen prohibited and regulated categories.
- Step 3. Map likely obligations and sector rules.
- Step 4. Build documentation and testing into development.
- Step 5. Verify current official guidance and obtain specialist advice where needed.
Common traps
- Classifying from marketing language
- Assuming the model alone determines obligations
- Waiting until launch to create evidence
Where this fits in the wider system
This topic belongs to the site’s Digital rules for innovators pillar. The strongest route normally connects several pillars: a research result may need a testbed, a consortium, an appropriate programme, standards work and a scale-up plan.
Use the planning tools to identify the next uncertainty, then verify the route through the official-source directory.