← All resourcesPlain-English guide / Not legal advice
/15

The EU AI Act, Plain English

A practical map of what the EU AI Act is, who it affects, what is already live, and what the main risk levels mean.

Start here

10 min

Open +

The EU AI Act is not one giant rule for every AI tool. It is a risk-based law. The first useful question is not “Are we compliant?” It is “What are we doing with AI, what role are we playing, and which rules apply to that use?”

Leave knowing / Know the map before reading the legal text

The simple version

Start with the use, not the model.

The AI Act sorts obligations by what an AI system does, how risky that use is, and which role your organisation plays in the chain. Most everyday AI uses are not treated like high-risk systems.

Some rules are already applicable. The Act entered into force on 1 August 2024. Prohibited practices started applying on 2 February 2025. General-purpose AI obligations started applying on 2 August 2025. The Act became broadly applicable on 2 August 2026, with later dates for the main high-risk system requirements.

Following the 2026 AI Omnibus changes, the main rules for stand-alone high-risk use cases apply from 2 December 2027. High-risk AI embedded in regulated products has a later date of 2 August 2028.

Do not start with a compliance checklist. Start with an inventory of actual AI uses.

The risk map

Four buckets are enough to orient yourself.

Prohibited

Some AI practices are banned because the law considers the risk unacceptable. Treat this as a “do not build or deploy” category, not a controls problem.

High risk

Certain systems used in areas such as employment, education, critical infrastructure, migration and other sensitive decisions can carry stricter requirements.

Transparency risk

Some AI interactions or generated content need clear disclosure or technical marking so people are not misled about what they are seeing or interacting with.

Minimal or no risk

Most AI systems fall here. The AI Act does not impose the high-risk system regime on ordinary low-risk uses just because AI is involved.

Your first hour

Ask these questions before you ask a lawyer for a 40-page memo.

01

What AI systems or AI-enabled workflows are actually in use today?

02

What does each system do in the real world, not just what does the vendor call it?

03

Who is affected by the output or decision?

04

Are we the provider, deployer, importer, distributor, or simply a customer using a service?

05

Does the use touch employment, education, essential services, biometrics, safety, law enforcement, migration, justice, or another sensitive area?

06

Does the system generate synthetic content that people could mistake for human or authentic content?

07

What records would we need later if somebody asked what happened?

Dates

The timeline that matters right now.

DateWhat it means
2 Feb 2025Prohibited-practice rules began applying.
2 Aug 2025Governance and general-purpose AI model obligations began applying.
2 Aug 2026The Act became broadly applicable, including the transparency regime.
2 Dec 2027Main rules for stand-alone high-risk AI systems apply under the updated timeline.
2 Aug 2028Main rules for high-risk AI embedded in regulated products apply.

Official sources

We simplify the map here. For a real legal decision, use the law, current guidance and qualified counsel.

Notes / Subscribe

Get the next note.

No schedule. No content calendar. A note goes out only when there is something worth understanding.