Pixel Myth
← Field notes
Regulation

The AI Act passed: what to do on Monday

Regulation field note

Classifying your systems by risk takes an afternoon. Discovering that one is high-risk takes six months of work.

The EU AI Act passed. Enforcement is three to four years away. That's plenty of time and no time at all. Classifying your systems by risk takes an afternoon. Discovering that one is high-risk and already in production takes six months of work.

The framework creates four categories: prohibited, high-risk, limited risk and minimal risk. Prohibited systems are rare. Most AI work falls into one of the lower brackets. The compliance burden scales with the risk category.

The inventory comes first: which systems use AI, for which decision, about whom. An analytics dashboard is minimal risk. A hiring recommender is high-risk. A credit scoring model is high-risk. You need to know which is which.

Most of what we see falls into limited risk, with transparency obligations you can absorb. You have to tell the user they're interacting with a system. You need to have a person who can explain decisions. That's manageable.

The ones to worry about are hiring and credit. These trigger explicit requirements: training data documentation, bias testing, human oversight and a process for appeals. Start the documentation now, not when enforcement arrives. Building it in is cheaper than bolting it on.

The companies ahead will have catalogues of their AI systems and clear risk classifications. The ones behind will be scrambling six months before enforcement to understand what they've built. The work is boring. Start this week.