GLOSSARY · LEADERSHIP & GRC
EU AI Act
The EU AI Act is the European Union's regulation for artificial intelligence, in force since August 2024, which imposes obligations on AI systems in tiers based on risk.
It bans a short list of practices, sets strict requirements for high-risk uses, adds transparency duties for general-purpose models, and applies in phases through 2027. Like the GDPR, it reaches organizations outside the EU whose AI outputs are used inside it.
The structure that matters operationally is the risk tiering. A small set of practices is prohibited outright, including social scoring and certain kinds of biometric categorization. A larger set is classified high risk, and this is where most compliance work lands: AI used in employment, education, credit, essential services, law enforcement, and as a safety component in regulated products. High-risk systems carry obligations for risk management, data governance, technical documentation, logging, human oversight, and accuracy. Everything else falls into limited or minimal risk, where the duties are largely about telling people they are interacting with AI.
The second structural point is that obligations attach to roles rather than to companies. The Act distinguishes providers, who develop a system or place it on the market, from deployers, who use one under their own authority. Most organizations are deployers of somebody else’s high-risk system rather than providers of their own. Deployer duties are lighter but real: human oversight, monitoring, retaining logs, and using the system according to its instructions.
For a CISO the practical first move is not a compliance program but an inventory mapped to tiers. You cannot assess exposure to a risk-tiered regulation without knowing which AI systems you run and what each is used for, and that inventory is the one AI governance needs anyway. The official text is the authority worth reading; vendor summaries of it vary considerably in quality.