The AI Act came into force in stages, and most companies we meet overestimate its constraints as much as they underestimate the documentation it demands.
The logic of the text: four risk tiers
The regulation does not regulate "AI" — it regulates uses, classified by risk. Prohibited practices (social scoring, manipulation) do not concern a normal business. High risk covers specific domains: hiring, credit, education, critical infrastructure. Limited risk mostly demands transparency: a chatbot must declare itself. Everything else — the vast majority of business uses — is minimal risk, with no new obligations.
The accidental high-risk trap
The case that surprises: an internal tool that screens CVs or evaluates employees is a high-risk system, even if it "only" pre-filters. The obligations are then real: documented risk management, demonstrable data quality, effective human oversight, logging, technical documentation.
If you use AI anywhere in hiring or HR evaluation, that is the first area to audit. Not because it is forbidden — because it is regulated.
What we build in by default
The good news: the regulation's requirements largely overlap with what a well-built system already does. A register of AI systems and their classification. Decision traceability — which model version, which data, which confidence score. Human oversight with genuine power to intervene, not a rubber stamp. And documentation that states what the system can and cannot do.
These four cost little when designed in from the start, and a great deal as retrofit.
Where to start
A one-page inventory: every existing or planned AI use, its risk tier, the compliance gap. For most SMEs the exercise takes a day and yields three concrete actions. Far less frightening than reading the regulation — and defensible the day a customer or auditor asks.


