Governance and the EU AI Act
The EU AI Act in plain English: what it means for your organisation
Lee, Co-founder and CEO · 9 September 2026 · 7 min read
The EU AI Act sorts AI systems by risk, and most business uses of AI fall into the lighter categories. What it asks of you is proportionate: know what you use, classify it, keep a human in charge and keep records.
A risk-based approach
The EU AI Act does not treat every AI system the same way. It sorts them by the risk they pose to people and applies obligations in proportion. The heavier the potential harm, the heavier the requirements.
In general terms there are four tiers: prohibited practices, high-risk systems, systems with transparency obligations, and minimal-risk systems. Where a given use of AI lands depends on what it is used for, not on which technology sits underneath.
The four tiers in general terms
This is a simplified picture. The text of the Act and its guidance are the authority, and your own case needs checking against them.
- Prohibited: a small set of practices judged to be unacceptable, which cannot be used at all.
- High-risk: uses in sensitive areas such as employment, education, essential services or law enforcement. These carry the most obligations, including risk management, data quality, documentation, human oversight and logging.
- Limited risk, with transparency duties: systems such as chatbots, where people should be told they are dealing with AI, or where generated content should be identifiable.
- Minimal risk: most everyday uses, such as spam filters or drafting assistance, where the Act asks for very little.
Where most organisations sit
Most businesses using AI for drafting, search, summarising or internal analysis fall into the lighter tiers. That does not mean you can ignore the Act. It means the work is mostly about knowing what you have and being able to show that you looked.
The harder questions tend to arise where AI feeds into decisions about people, such as recruitment, access to services or performance. Those are the cases to examine first.
What proportionate governance looks like
You do not need a large compliance programme to start. A practical baseline is enough for most organisations, and it builds toward anything heavier you may later need.
- Keep a register of the AI systems and tools in use, including those staff have adopted on their own.
- Classify each use against the risk tiers and record your reasoning.
- Name a person accountable for each system, and keep a human able to review and override its output.
- Keep records of how systems are configured, what data they use and how they have been tested.
- Tell people when they are interacting with AI where that is required.
Take advice on the detail
Timelines, definitions and how the Act applies to organisations outside the EU are detailed matters, and guidance continues to develop. Treat this article as orientation, not legal advice. Check your specific position with counsel before you rely on it.
What you can do now is the inexpensive part: find out what AI you use, classify it, and put the basic records in place. That makes any later conversation with a lawyer or regulator much easier.
