The thing with the EU AI Act is this: for you as a deployer, what matters is your use case. The model itself is regulated too, but those obligations (technical documentation, copyright, training-data summaries) sit with the vendor like OpenAI or Anthropic, not with you. And in most day-to-day uses of these chats, it might not even be applicable. Think of use cases like:
- Grammar, spelling, and stylistic help, like writing a blog post using ChatGPT
- Inventory management algorithms, predicting supply vs demand
- AI code autocompletion, using Claude Code, Codex, and Cursor
- UI/UX design prototyping, teams using AI tools to instantly generate wireframe layouts
These are all low-risk uses. They carry just the obligation of basic training (AI literacy, similar to how companies run cybersecurity training when you first onboard). But that does not mean all use cases are low risk. Some specific high-risk ones include:
- Algorithmic employee evaluation & performance trackers, software used to autonomously allocate tasks, score productivity, or recommend promotions and terminations
- Critical infrastructure safety components, AI used as a safety component running power grids, water supply, or road traffic, where a malfunction could threaten public safety
- FinTech credit scoring, software using predictive machine-learning algorithms to assess an individual's credit risk
Why these examples? The core philosophy of the EU AI Act is that an AI system becomes high-risk the moment its failure or bias can directly destroy a person's livelihood, jeopardize public safety, or lock someone out of the economy.
Being high-risk doesn't instantly mean it's forbidden; it just means there are more hoops to jump through to get it to a state where you won't have problems with the law.
Here is the risk spectrum you can save for later:
