What it means in practice
Think of the EU AI Act as traffic rules for artificial intelligence. A bicycle (a chatbot that summarises text) needs no complicated certification, but if you want to drive a lorry carrying dangerous goods (AI assessing credit risk at a bank, or reading X-rays), you have to pass strict tests and hold specific permissions. The law sorts AI applications into four categories, from unacceptable risk (banned outright) down to minimal risk (a spam filter, where almost no rules apply).
Why companies need to know this
- Heavy fines. Breaching the rules can mean fines in the millions of euros, or up to a set percentage of global turnover.
- Transparency. If an AI chatbot talks to customers on your shop or your helpline, you must tell the customer plainly that they are not speaking to a person.
- New documentation duties. Companies building their own high-risk AI systems (software that assesses employees, say) will have to meet strict standards for data quality and documentation.
- Protection from unfair competition. The law sets boundaries so the technology cannot be used to manipulate customers.
An example from practice
A recruitment agency wants to deploy an AI tool that would automatically reject job applicants based on analysing their face during a video interview. Under the EU AI Act, emotion recognition in the workplace falls into the banned category (unacceptable risk). Deploying it would expose the company to enormous fines. Using AI only to summarise the interview notes, on the other hand, is minimal risk with no bureaucracy attached.
In our company AI workshops we show how to bring AI into your processes so you get the most out of it and stay on the right side of the law.