Module 4: EU AI Act Deep Dive

1. Module introduction: EU AI Act Deep Dive

Capsule description

Up to now, "ethics" and "privacy" were good engineering practices. Things you should do.

This module changes that.

The EU AI Act turns many of those practices into legal obligations. Things you MUST do, or you face fines of up to:

  • €35M or 7% of your global revenue (whichever is greater) for prohibited systems.
  • €15M or 3% for violations of the requirements for high-risk systems.
  • €7.5M or 1.5% for supplying incorrect information to regulators.

This is not future theory. It's in force. The prohibitions started in February 2025. The obligations for general-purpose systems in August 2025. The full requirements for high-risk systems in August 2026.

This capsule introduces the module: why the EU AI Act matters, its risk-based structure, its extraterritorial reach, and what you'll learn.

Welcome to Phase 2: Regulatory Compliance of the guide. We're entering the territory where regulation is leverage, not optional.


Why the EU AI Act matters (even if you're not in the EU)

Reason 1: extraterritorial reach

The EU AI Act applies to you if:

  • You operate in the EU (obviously).
  • You sell AI products to users in the EU (even if your company is elsewhere).
  • Your output is used in the EU (even if it was produced outside).

Concrete examples:

  • Your startup in Argentina sells a product with AI to customers in Spain → the EU AI Act applies.
  • Your company in the US processes European citizens' data with AI → it applies.
  • Your global API with AI has users in the EU → it applies.

Like GDPR before it, the EU AI Act has extraterritorial effect. You can't "dodge" it by simply not being in the EU.

Reason 2: a global regulatory precedent

Historically, EU regulation influences global regulation:

  • GDPR → CCPA (California), LGPD (Brazil), PIPL (China), etc.
  • EU AI Act → likely a similar pattern.

The US already has multiple state-level proposals influenced by the EU AI Act. The UK, Canada, Australia, and Japan are following a similar approach.

What you comply with for the EU will probably be similar to what you'll need to comply with in other markets in the coming years.

Reason 3: the consequences are real

Fines of up to 7% of global revenue are existential for startups and expensive for large companies.

Real GDPR fine cases (a template for the AI Act):

  • Meta: €1.2B (2023).
  • Amazon: €746M (2021).
  • Google: €50M (2019, Spain).

The EU AI Act follows the same enforcement model. The precedents are established.


The risk-based structure

The EU AI Act's central innovation is: it doesn't regulate all AI equally.

Instead, it classifies systems into 4 risk categories and applies proportional requirements:

┌─────────────────────────────────────────┐
│  CATEGORY           │ TREATMENT         │
├─────────────────────┼───────────────────┤
│ Unacceptable Risk   │ PROHIBITED ❌      │
│ High Risk           │ Strict obligations │
│ Limited Risk        │ Transparency only  │
│ Minimal Risk        │ Voluntary codes    │
└─────────────────────┴───────────────────┘

Why this approach

The reasoning: regulating everything equally would be:

  • Unworkable: too much overhead for low-risk apps (unnecessary burden).
  • Insufficient: not enough enforcement for high-risk ones.

A risk-based proportional model = enforcement strength matches actual harm potential.

The trade-off: correct classification is critical

Misclassify too low → under-comply → fine. Misclassify too high → over-invest in compliance → unnecessary cost.

The central skill of this module is: correctly classifying any AI system.


The 4 categories in detail (preview)

We cover them in the following capsules, but here's an overview for context:

Unacceptable Risk

Prohibited. Don't deploy.

Systems:

  • Subliminal manipulation that causes material harm.
  • Social scoring (by government or a private company).
  • Real-time biometric identification in public spaces (with limited exceptions for law enforcement).
  • Predictive policing based solely on profiling.
  • Emotion recognition in the workplace or school (with exceptions).
  • Biometric categorization based on sensitive attributes.
  • Untargeted scraping of facial recognition databases.

If your system falls here → you can't deploy it in the EU. Period.

High Risk

Strict obligations.

Systems that affect fundamental rights or safety:

  • Employment and recruitment (hiring, performance evaluation).
  • Education (admission, evaluation, exam scoring).
  • Essential services (credit, insurance, social benefits).
  • Law enforcement (limited predictive policing, evidence assessment).
  • Migration and asylum (visa decisions).
  • Administration of justice (judicial decisions).
  • Critical infrastructure (utilities, transport).
  • Safety components of products (medical devices with AI).
  • Biometric identification (except real-time public).

If you land here: 6 major obligations (capsule 04 details them).

Limited Risk

Transparency obligations.

Systems that interact with humans:

  • Chatbots: must identify themselves as AI.
  • Deepfakes: must be labeled as AI-generated content.
  • Emotion recognition (where permitted).
  • Biometric categorization (where permitted).

The main obligation: disclosure. Users must know they're interacting with an AI.

Minimal Risk

Voluntary codes of conduct.

Most AI: spam filters, video games, recommendations, etc.

No legal requirements. Best practices encouraged voluntarily.


The central skill: classifying correctly

When you work on a new AI system, the first step is:

Which of the 4 categories does this system fall into?

That classification determines:

  • Which requirements apply.
  • How much compliance effort is necessary.
  • Which deadlines you have.
  • What your financial risk is.

Examples:

1. A customer support chatbot

  • Does it manipulate subliminally? No.
  • Does it make high-stakes decisions? No.
  • Does it interact with humans? Yes.
  • Limited Risk. Disclosure requirement: "you're chatting with an AI."

2. A hiring algorithm scoring résumés

  • Employment? Yes.
  • High Risk. Full obligations.

3. A recommendation engine for e-commerce products

  • Employment, education, justice, etc.? No.
  • A chatbot? No (typically).
  • Minimal Risk. Voluntary codes.

4. A government scoring system for social benefits eligibility

  • A decision about access to essential services? Yes.
  • High Risk.
  • Also social scoring? Maybe. If it's a comprehensive ranking of citizens based on behavior →
  • Unacceptable Risk. Prohibited.

Each requires different treatment. Misclassify one → exposure.


Compliance timelines

2024 ────────────── 2025 ──────────────── 2026 ──────────── 2027
  │                   │                     │                │
  │                February: prohibitions   │                │
  │                of unacceptable risk     │                │
  │                                          │                │
  │                August: GP AI rules      │                │
  │                                          │                │
  │                                       August: high-risk  │
  │                                       requirements full  │
  │                                          │                │
  │                                          │             August:
  │                                          │             pre-existing
  │                                          │             systems comply
  │                                          │                │

Implications:

  • Feb 2025: prohibitions in effect. Unacceptable systems cannot be deployed.
  • Aug 2025: General Purpose AI rules (foundation models): documentation, evaluation, etc.
  • Aug 2026: High-Risk full requirements: 6 obligations enforceable.
  • Aug 2027: existing high-risk systems (deployed before Aug 2026) must also comply.

For your planning:

  • Today: classify your systems.
  • Now–Aug 2026: implement the high-risk obligations.
  • Aug 2026 onward: enforcement begins for new deployments.

What you'll learn

8 capsules:

  1. Introduction (this capsule).
  2. Unacceptable Risk — the prohibited ones.
  3. High Risk — categories and requirements.
  4. High Risk obligations — the 6 obligations in detail.
  5. Limited Risk and transparency — chatbots, deepfakes.
  6. Minimal Risk and General Purpose AI — the rest.
  7. Compliance timelines and penalties — planning.
  8. Mini-project: Risk Classification — classifying a real system.

By the end:

  • You classify any AI system into the 4 categories.
  • You identify the specific requirements.
  • You understand the timelines and plan compliance.
  • You know the penalties and the ROI of compliance vs. non-compliance.
  • You produce a professional Risk Classification document.

The mindset shift in this module

Before:

"Ethics matters because we want to do the right thing."

After:

"Ethics matters because (a) we want to do the right thing AND (b) there are concrete fines if we don't. Here are the numbers."

Compliance isn't in conflict with ethics — it's the enforcement of ethical principles. But that enforcement requires precision: correct classification, complete documentation, specific requirements.

This is the transition from "good ideas" to "execution with legal consequences."


How it relates to M1-M3

M1 Ethics Impact Analysis    ↘
M2 Bias Audit                  ↘  Inputs to ─→ M4-M6 Compliance
M3 Privacy Assessment        ↗

The Phase 1 frameworks (M1-M3) feed Phase 2 (M4-M6):

  • Risk Classification (this module, M4) uses the outputs of the Ethics Impact Analysis (M1) to identify stakeholders and risks.
  • GDPR Compliance (M5) uses the outputs of the Privacy Assessment (M3).
  • NIST AI RMF (M6) integrates everything.

Without Phase 1, Phase 2 would be legal memorization with no foundation. With Phase 1, the legal modules connect to your engineering thinking.


Traps in learning the EU AI Act

1. Treating it as "just another GDPR"

The EU AI Act is different from GDPR. GDPR covers data; the EU AI Act covers AI systems specifically. They overlap in certain areas (data quality) but they're separate frameworks. Both apply simultaneously.

2. Memorizing articles instead of classifications

You're not going to recite the Act at deploy time. You're going to classify your system and derive the requirements. Practical skill > theoretical knowledge.

3. Assuming your system is "minimal risk"

Many engineers assume their system is "just" a chatbot or a recommendation engine. But context matters: a chatbot for medical advice ≠ a chatbot for FAQs.

Always classify carefully, with context. Default conservatively.

4. Forgetting updates to the Act

The EU AI Act will have amendments and delegated acts (regulator clarifications). What's true today may shift. Set calendar reminders to check the official sources annually.

5. Ignoring the General Purpose AI rules

If you use OpenAI, Anthropic, or Google APIs, those providers are under the GP AI rules. Your system inherits some of their obligations. Check the provider's compliance + your own use.


Self-check

1. Why does the EU AI Act have extraterritorial reach?

The EU AI Act applies if:

  1. You operate in the EU: an EU company developing or deploying.
  2. You sell AI products to users in the EU: a company from any country with EU customers.
  3. Your AI output is used in the EU: a product built outside, used in the EU.

The reason: protecting the fundamental rights of people in the EU, not territorial protection of EU companies. If a person in the EU is affected by AI, the regulation applies regardless of where the AI was developed.

The same pattern as GDPR. There's already legal precedent: non-EU companies fined for violations.

Implication: if you have any presence or users in the EU, the Act applies. The only way to "avoid" it is to block EU users entirely — operationally costly.

For most companies, they're already in scope. Better to comply than to dodge.

2. Why is the risk-based approach the Act's key innovation?

The alternative approach (uniform regulation): all AI systems get the same requirements. Problems:

  • Over-regulates low-stakes systems (spam filters get the same scrutiny as healthcare).
  • Under-regulates high-stakes ones (no special protections where they matter most).
  • Compliance costs are uniformly high → discourages low-stakes innovation.

The risk-based approach:

  • Unacceptable: prohibited (no compliance is possible).
  • High-risk: strict requirements (justified by the stakes).
  • Limited: transparency only (proportional).
  • Minimal: voluntary (encouraged but not mandated).

Benefits:

  • Proportional: regulation matches harm potential.
  • Innovation-friendly: low-stakes apps don't carry heavy compliance.
  • Targeted enforcement: regulators focus on high-stakes systems.
  • Clear: companies know which tier they're in.

The trade-off: classification matters. Misclassify:

  • Too low → liability.
  • Too high → unnecessary cost.

The skill: classify correctly. Which is what this module teaches.

3. How does this module relate to M1-M3 (Ethics Foundations)?

M1-M3 are technical principles: impact analysis, bias detection, privacy assessment.

M4-M6 are regulation: EU AI Act, GDPR, NIST AI RMF, etc.

The relationship is bidirectional:

Phase 1 feeds Phase 2:

  • The Ethics Impact Analysis (M1) → identifies the stakeholders and risks that classify the system under the EU AI Act.
  • The Bias Audit (M2) → its outputs are evidence of compliance with bias requirements.
  • The Privacy Assessment (M3) → its outputs are evidence of compliance with the Act's GDPR/privacy requirements.

Phase 2 validates Phase 1:

  • Systems prepared with Phase 1 are naturally aligned with the Phase 2 obligations.
  • If you did Phase 1 well, Phase 2 compliance is a matter of translating it into legal artifacts.

Without Phase 1: Phase 2 is empty legal memorization. With Phase 1: Phase 2 is a formalization of your already well-grounded thinking.

That's why the guide does Phase 1 before Phase 2 — fundamentals before regulation.

4. What's the priority order of the timelines?

Immediate: the prohibitions (Feb 2025).

If your system is potentially Unacceptable Risk: stop immediately. Don't deploy in the EU. Re-architect or don't enter the market.

2025: the GP AI rules (Aug 2025).

If you use foundation models (LLMs via API), understand which requirements apply to your use. Verify provider compliance. It may affect contracts.

2026 (most critical): the full high-risk requirements (Aug 2026).

If your system is high-risk, you have from now until Aug 2026 to:

  • Document risk management.
  • Establish data governance.
  • Build technical documentation.
  • Implement human oversight.
  • Ensure accuracy/robustness/cybersecurity.
  • Register in the EU database.

This is substantial work. Plan months ahead. Don't wait until 2026.

2027: existing systems (deployed before Aug 2026) must comply.

If you have legacy AI deployed in the EU, retrofit compliance by Aug 2027.

The practical sequence:

  1. Today: classify your systems.
  2. Q3 2025: identify your GP AI dependencies, work with providers.
  3. 2025-2026: implement the high-risk obligations for new + existing systems.
  4. Ongoing: monitor regulator updates.

Not planning is the biggest risk. Plan now.


Summary and next step

  • The EU AI Act is comprehensive regulation for AI with extraterritorial effect.
  • A risk-based approach: 4 categories (unacceptable, high, limited, minimal).
  • Classification is the central skill. Misclassify = exposure.
  • Significant penalties: up to 7% of global revenue or €35M.
  • Timelines: prohibitions 2025, high-risk 2026, existing systems 2027.
  • The connection to M1-M3: technical principles feed regulatory compliance.

Checkpoint: you should be able to articulate why correct classification is the takeaway skill, not memorizing the Act.

Bridge to the next capsule: capsule 02 covers Unacceptable Risk — the prohibited systems. You'll learn exactly what's prohibited, why, and how to avoid accidentally landing in the prohibited category. Important: even bona-fide use cases can trigger a prohibition — knowing the exact criteria protects your deploy.


Resources

  1. EU AI Act — Official Text (Regulation 2024/1689) — the official text.
  2. EU AI Act — Plain Language Guide — community-maintained.
  3. European Commission — AI Office — the regulator.
  4. Future of Life Institute — AI Act Tracker — implementation status.

Next: 02-unacceptable-risk-prohibitions.md — Prohibited systems.

Capsule 01 of 08 — Module 4 — AI Ethics & Compliance Guide