Skip to content
AI Act: the compliance nobody reads until it matters 🤖

AI Act: the compliance nobody reads until it matters 🤖

10 September 2026·Sandro Lain
Sandro Lain

AI Act and regulation

The public debate on the AI Act has been dominated by the wrong question: “will it block innovation?”. The honest answer is: no, it won’t block anything — but it changes where your systems end up, and therefore what you must demonstrate. The right question is another one: “which box does my system fall into, and who has to sign?”

Want the full picture? Who is in scope, how to classify systems, obligations for providers and deployers, penalties and deadlines are in the practical guide: AI Act — Practical guide.

The world’s first regulation on what AI can do 🌍

Regulation (EU) 2024/1689 is the world’s first comprehensive legal framework for artificial intelligence. It entered into force on 2 August 2024 and applies in full from 2 August 2026. But the most debated part — the prohibitions — has been operational since February 2025.

Here’s the point few grasp: the AI Act doesn’t regulate “AI” as an abstract thing. It regulates use cases. The same foundation model can be harmless in one context and heavily regulated in another. A customer-support chatbot and a CV-screening tool are the same technology with radically different obligations.

It’s a mindset shift the tech sector struggles to accept: the risk is not in the technology, but in the use you make of it. And who uses or integrates, decides.

The political idea: risk is not “ethical”, it’s systemic 🎯

The reasoning behind the AI Act is the same that drove NIS 2 and GDPR: when a technology can distribute harm on an industrial scale, leaving everything to individual discretion is a political choice, not a technical one.

Subliminal manipulation, social scoring, biometric scraping, crime prediction by profiling: the list of prohibited practices (Art. 5) is not a list of “bad things”. It’s the declaration that certain uses cross a line that no consent can legitimise. It’s not about ethics: it’s law.

And the penalty sends a clear signal: up to €35 million or 7% of worldwide turnover for those who violate the prohibitions. We’re not talking about a parking fine. We’re talking GDPR-level, and above.

The real revolution: risk-based classification 🗂️

The operational heart of the AI Act is the three-tier model. Almost nobody talks about it, but that’s where almost everything is decided:

  • Unacceptable risk → prohibited, period.
  • High risk → the bulk of the obligations: risk management, data governance, documentation, human oversight, robustness, cybersecurity, registration in the EU database.
  • Everything else → transparency (chatbots, deepfakes, synthetic content) and, for foundation models, a dedicated regime.

The most interesting part is the Art. 6.3 exception: a system that falls into a high-risk sector can not be one if it doesn’t materially impact decisions. But if it profiles, it’s high-risk always, no exceptions. And if you declare “not high-risk”, you must document it.

In practice: you don’t get to decide by voice that your system isn’t risky. You have to demonstrate it. And when in doubt, a conservative classification protects you.

The knot for developers: the contrast between “make it work” and “prove it” ⌨️

For those who write code, the most real tension is between two cultures. On one hand, speed: ship fast, iterate, improve. On the other, documentation: bias-free representative datasets, automatic logs, robustness tests, evidence of human oversight, 10 years of retention.

They’re not incompatible — but they require documentation to become part of the deliverable, not a document to fill in at audit time. It’s the same lesson as NIS 2: measures aren’t just applied, they’re demonstrated.

And there’s a concrete detail that touches many teams: open-source foundation models (GPAI) get preferential treatment, but whoever integrates those models into their own systems assumes the downstream obligations. The application developer’s box is the most populated one, and it doesn’t always notice.

The real cost is not the fine 💸

As with NIS 2, the penalties are the most visible but not the heaviest part of the bill.

The real cost is operational: if a high-risk system has no logs, no evidence, no human oversight, it’s not just “non-compliant” — it’s incredibly hard to debug when things go wrong. The documentation the Regulation asks for is, in large part, the documentation you’d want anyway when the model produces a wrong result and someone asks “how is that possible?”.

Then there’s the commercial side: those operating in regulated sectors (finance, healthcare, credit, HR) will see customers and auditors ask for evidence of classification and compliance. Those who already have the inventory and gap analysis in hand start ahead. The others will run to catch up.

Conclusion: it’s no longer the Wild West, and that’s good news 🏛️

The AI Act isn’t the end of innovation. It’s the end of “I did it because I could”. For those working with AI, the value is no longer just “it works”, but “it works, I know why, and I can prove it at the limit”.

Take it as a provocation: AI regulation probably won’t block anything worth building. But it will force you to know exactly what you’re building, and which box it falls into.

Want the operational details — who’s in scope, how to classify, obligations and deadlines? They’re in the practical guide: AI Act — Practical guide.

Last updated on