Applied AI Academy

The EU AI Act is a risk ladder — classify first, then comply by design

AI regulation, EU AI Act, GDPR, IP, and compliance-by-design

The question: How do firms comply without freezing innovation?

Regulation is no longer abstract: the EU AI Act is in force with phased obligations, GDPR still governs personal data, and IP questions touch every generated asset. Leaders must classify systems, know their role (provider vs deployer), and build compliance into design — because retrofitting is the expensive path.

What the lesson covers

The EU AI Act (Regulation 2024/1689) is risk-based: unacceptable-risk practices are banned (social scoring, manipulative techniques, most real-time biometric ID in public); high-risk systems (employment, credit, education, essential services, safety components…) carry strict obligations; limited-risk systems carry transparency duties (tell people they are talking to AI; label deepfakes); minimal risk is unregulated. Your obligations follow your TIER and your ROLE: providers (who place systems on the market) carry more than deployers (who use them) — but deployers still owe human oversight, monitoring, and AI literacy.

The timeline is phased: bans and AI-literacy duties applied from Feb 2025; GPAI (general-purpose AI model) obligations from Aug 2025 with the GPAI Code of Practice as the compliance vehicle; most high-risk obligations bite Aug 2026–2027. Penalties scale to 7% of global turnover for prohibited practices. "We'll see how enforcement goes" is a strategy with a price tag.

High-risk obligations are a management system, not paperwork: risk management across the lifecycle, data governance (representative, error-checked data), technical documentation, logging, transparency to users, human oversight designed-in, accuracy/robustness/cybersecurity, and post-market monitoring. ISO/IEC 42001 (AI management systems) and the NIST AI RMF are the scaffolding standards firms use to operationalise it.

GDPR runs in parallel wherever personal data appears: lawful basis, purpose limitation, minimisation, and Article 22 rights around solely-automated decisions with significant effects (a human review that merely rubber-stamps does not count). Cross-border transfer rules apply to AI vendors like to any processor — residency and DPAs belong in procurement (Lesson 8).

IP in both directions: training data (text-and-data-mining exceptions with opt-outs in the EU; live litigation elsewhere), and outputs (purely AI-generated content generally lacks copyright protection in most jurisdictions — human creative contribution matters; vendor indemnities vary). Contracts must say who owns prompts, outputs, and fine-tuned artefacts. Compliance-by-design closes the loop: classify at intake, document as you build, assign owners, set review dates — the AI Compliance Canvas in one page.

Key points

Framework — AI Compliance Canvas

use case · your role (provider/deployer) · risk tier · affected persons · personal data (lawful basis) · obligations triggered · evidence/documentation · owner · review date. One page per system; the inventory of canvases IS your AI register.

The lab

Classify real systems, then build one compliance canvas properly.

Deliverable: Risk-tier classification of the 8 systems + one completed compliance canvas.

Open this lesson, its lab and its quiz

Sources and further reading