← Glossary

EU AI Act

The EU AI Act is the world's first comprehensive AI law, regulating AI systems by risk level and placing duties on organizations that deploy AI as well as those that build it.

Updated

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law: it regulates AI systems by risk level and places duties not only on those who build AI but on organizations that deploy it. That second part is what most companies underestimate: using AI in certain ways triggers obligations, whether or not you develop anything. Official implementation guidance is published on digital-strategy.ec.europa.eu.

Key facts:

  • Four risk tiers: prohibited practices (banned outright), high-risk systems (strict requirements), limited risk (transparency duties) and minimal risk (most everyday AI).
  • Obligations phase in over several years from entry into force in 2024; verify currently applicable dates against official sources.
  • Deployers of high-risk AI (for example in recruitment, credit or essential services) carry duties like human oversight and monitoring, and general AI literacy obligations reach ordinary workplaces.
  • The Act works alongside GDPR: the AI Act governs the system's use, GDPR governs the personal data flowing through it.

The risk pyramid

TierExamplesObligation
Unacceptable riskSocial scoring, manipulative techniques, most real-time biometric surveillance in publicProhibited
High riskAI in hiring, credit scoring, critical infrastructure, education, law enforcementRisk management, data governance, human oversight, conformity assessment
Limited riskChatbots, deepfakes, AI-generated contentTransparency: people must know they are dealing with AI or AI-generated content
Minimal riskSpam filters, AI in games, most productivity featuresNo new obligations; voluntary codes of conduct

Why it lands on your desk anyway

Even organizations far from "high-risk AI" inherit two practical problems. First, classification requires inventory: you cannot assess which tier your AI use falls into if you do not know which AI tools are in use, and shadow AI makes that inventory fiction. Second, employees deploying AI in HR-adjacent or customer-affecting workflows can create high-risk use unofficially. AI governance, with real visibility underneath it, is how the Act's abstractions become manageable. For financial services, coordinate with NIS2 obligations on the same underlying systems.

Where email security fits, honestly

Sentaro is not a compliance tool for the AI Act. Its contribution is the inventory reality: Sentaro discovers AI services adopted across the organization via signup trails and OAuth grants in Google Workspace and Microsoft 365, so classification, literacy efforts and deployer assessments start from what is actually in use rather than what was approved.

This page is general guidance, not legal advice.

Questions we get asked.

What is the EU AI Act in simple terms?

The EU's law regulating AI by risk level: some uses are banned, high-risk uses carry strict duties, and transparency rules apply to chatbots and synthetic media. It applies to organizations using AI, not just building it.

Does the AI Act apply to companies that just use ChatGPT?

Everyday productivity use is generally minimal-risk, but obligations can arise depending on how AI is used (for example in hiring decisions), and general duties like AI literacy reach ordinary organizations. Knowing what AI is in use is the prerequisite for any assessment.

How does the AI Act relate to GDPR?

They stack: the AI Act governs the AI system and its use; GDPR governs personal data processed by it. A single workplace AI tool can trigger duties under both.

What are the penalties under the AI Act?

Tiered administrative fines, with the highest bracket for prohibited practices reaching into percentages of global turnover (verify current figures against official sources before publishing specifics).

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.