EU AI Act global tech rules put product classification ahead of rollout
The EU AI Act sorts systems by risk, with bans already active and high-risk controls due in 2027 for companies serving EU use cases.
By Ingrid Halvorsen · Venture Capital Reporter
· 3 min read
The EU AI Act gives global technology companies a risk-based rulebook for AI products used in Europe, rather than a single compliance standard for every model or feature. The immediate task is operational: map EU-facing products and EU-used outputs, identify whether the company is a provider or professional deployer, then classify each use case before shipping.
Regulation (EU) 2024/1689 covers placing certain AI systems on the market, putting them into service and using them. The European Commission says its aim is to support trustworthy AI while protecting health, safety and fundamental rights. It does not make all AI applications high risk: limited-risk systems face lighter disclosure duties, while most minimal-risk systems are unregulated under the Act.
What does the EU AI Act mean for global tech companies?
Location alone does not decide coverage. A high-risk provider outside the EU can fall within the rules when its system’s output is used in the EU, according to the AI Act’s high-level summary. The same summary says the provision also reaches professional deployers outside the bloc in that circumstance. Most high-risk duties sit with providers, generally the developers bringing a system to market; deployers have fewer, though still material, responsibilities.
For product and legal teams, that makes classification a release gate. The European Commission identifies high-risk use cases across safety components, certain biometric systems, critical infrastructure, education, employment, essential public and private services, law enforcement, migration and border management, and justice or democratic processes. CV-screening software and credit-scoring tools are among the Commission’s examples.
What is already prohibited and what comes next?
Eight categories of prohibited AI practices took effect in February 2025, the Commission says. They include harmful manipulation or exploitation of vulnerabilities, social scoring, individual criminal-offence risk prediction, untargeted scraping of the internet or CCTV material to create or expand facial-recognition databases, emotion recognition in workplaces and education institutions, protected-trait biometric categorisation, and certain real-time remote biometric identification by law enforcement in public spaces.
A ninth prohibition, covering systems that generate non-consensual sexually explicit or intimate content or child sexual abuse material, is scheduled to take effect in December 2026. High-risk systems are due to face strict pre-market obligations from 2 December 2027, according to the Commission’s current guidance.
Those controls require risk assessment and mitigation, suitable data quality, activity logs, technical documentation, information for deployers, human oversight, and standards for robustness, cybersecurity and accuracy. The practical work is less about policy statements than building records, tests, data controls and product workflows that substantiate those requirements.
General-purpose models and transparency duties
Transparency obligations also affect products outside the high-risk bucket. The Commission says people should be told when they are interacting with systems such as chatbots, and providers of generative AI must make AI-generated content identifiable.
A non-official AI Act summary says general-purpose AI model providers must supply technical documentation and instructions for use, comply with the Copyright Directive and publish a summary of training content. It says providers of models presenting systemic risk must additionally evaluate and adversarially test models, track and report serious incidents, and maintain cybersecurity protections. Free and open-licence providers have narrower duties under that summary unless their models present systemic risk.
The result is a phased compliance program, not one deadline. Companies need a defensible view of their EU connection, their product category and the evidence each category requires. The Commission’s voluntary AI Pact may help firms prepare, but it does not replace the Act’s applicable obligations.
This story draws on original reporting from Tech Funding News.