The EU AI Act is a risk ladder — classify first, then comply by design
AI regulation, EU AI Act, GDPR, IP, and compliance-by-design
The question: How do firms comply without freezing innovation?
Regulation is no longer abstract: the EU AI Act is in force with phased obligations, GDPR still governs personal data, and IP questions touch every generated asset. Leaders must classify systems, know their role (provider vs deployer), and build compliance into design — because retrofitting is the expensive path.
What the lesson covers
The EU AI Act (Regulation 2024/1689) is risk-based: unacceptable-risk practices are banned (social scoring, manipulative techniques, most real-time biometric ID in public); high-risk systems (employment, credit, education, essential services, safety components…) carry strict obligations; limited-risk systems carry transparency duties (tell people they are talking to AI; label deepfakes); minimal risk is unregulated. Your obligations follow your TIER and your ROLE: providers (who place systems on the market) carry more than deployers (who use them) — but deployers still owe human oversight, monitoring, and AI literacy.
The timeline is phased: bans and AI-literacy duties applied from Feb 2025; GPAI (general-purpose AI model) obligations from Aug 2025 with the GPAI Code of Practice as the compliance vehicle; most high-risk obligations bite Aug 2026–2027. Penalties scale to 7% of global turnover for prohibited practices. "We'll see how enforcement goes" is a strategy with a price tag.
High-risk obligations are a management system, not paperwork: risk management across the lifecycle, data governance (representative, error-checked data), technical documentation, logging, transparency to users, human oversight designed-in, accuracy/robustness/cybersecurity, and post-market monitoring. ISO/IEC 42001 (AI management systems) and the NIST AI RMF are the scaffolding standards firms use to operationalise it.
GDPR runs in parallel wherever personal data appears: lawful basis, purpose limitation, minimisation, and Article 22 rights around solely-automated decisions with significant effects (a human review that merely rubber-stamps does not count). Cross-border transfer rules apply to AI vendors like to any processor — residency and DPAs belong in procurement (Lesson 8).
IP in both directions: training data (text-and-data-mining exceptions with opt-outs in the EU; live litigation elsewhere), and outputs (purely AI-generated content generally lacks copyright protection in most jurisdictions — human creative contribution matters; vendor indemnities vary). Contracts must say who owns prompts, outputs, and fine-tuned artefacts. Compliance-by-design closes the loop: classify at intake, document as you build, assign owners, set review dates — the AI Compliance Canvas in one page.
Key points
- Risk ladder: banned → high-risk (strict) → transparency → minimal; obligations follow tier AND role (provider vs deployer).
- Phased timeline is live: bans + literacy (Feb 2025), GPAI (Aug 2025), most high-risk (Aug 2026–27); fines up to 7% of turnover.
- High-risk compliance = a management system (risk, data governance, docs, logging, oversight, monitoring) — ISO 42001 / NIST RMF scaffold it.
- GDPR runs in parallel: lawful basis, minimisation, Article 22 for automated decisions.
- IP both ways: training-data rights and output ownership belong in contracts; pure AI output is generally uncopyrightable.
Framework — AI Compliance Canvas
use case · your role (provider/deployer) · risk tier · affected persons · personal data (lawful basis) · obligations triggered · evidence/documentation · owner · review date. One page per system; the inventory of canvases IS your AI register.
The lab
Classify real systems, then build one compliance canvas properly.
Open this lesson, its lab and its quiz
Sources and further reading
- EU AI Act — full text + timeline explorer — FLI
- AI Act implementation timeline — European Commission
- ISO/IEC 42001 — AI management systems — ISO