The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law: it regulates AI systems by risk level and places duties not only on those who build AI but on organizations that deploy it. That second part is what most companies underestimate: using AI in certain ways triggers obligations, whether or not you develop anything. Official implementation guidance is published on digital-strategy.ec.europa.eu.
Key facts:
- Four risk tiers: prohibited practices (banned outright), high-risk systems (strict requirements), limited risk (transparency duties) and minimal risk (most everyday AI).
- Obligations phase in over several years from entry into force in 2024; verify currently applicable dates against official sources.
- Deployers of high-risk AI (for example in recruitment, credit or essential services) carry duties like human oversight and monitoring, and general AI literacy obligations reach ordinary workplaces.
- The Act works alongside GDPR: the AI Act governs the system's use, GDPR governs the personal data flowing through it.
The risk pyramid
| Tier | Examples | Obligation |
|---|---|---|
| Unacceptable risk | Social scoring, manipulative techniques, most real-time biometric surveillance in public | Prohibited |
| High risk | AI in hiring, credit scoring, critical infrastructure, education, law enforcement | Risk management, data governance, human oversight, conformity assessment |
| Limited risk | Chatbots, deepfakes, AI-generated content | Transparency: people must know they are dealing with AI or AI-generated content |
| Minimal risk | Spam filters, AI in games, most productivity features | No new obligations; voluntary codes of conduct |
Why it lands on your desk anyway
Even organizations far from "high-risk AI" inherit two practical problems. First, classification requires inventory: you cannot assess which tier your AI use falls into if you do not know which AI tools are in use, and shadow AI makes that inventory fiction. Second, employees deploying AI in HR-adjacent or customer-affecting workflows can create high-risk use unofficially. AI governance, with real visibility underneath it, is how the Act's abstractions become manageable. For financial services, coordinate with NIS2 obligations on the same underlying systems.
Where email security fits, honestly
Sentaro is not a compliance tool for the AI Act. Its contribution is the inventory reality: Sentaro discovers AI services adopted across the organization via signup trails and OAuth grants in Google Workspace and Microsoft 365, so classification, literacy efforts and deployer assessments start from what is actually in use rather than what was approved.
This page is general guidance, not legal advice.