Skip to content

Latest commit

 

History

History
41 lines (30 loc) · 2.76 KB

File metadata and controls

41 lines (30 loc) · 2.76 KB
title EU AI Act — Essentials for Enterprise Deployers
source-id eu-ai-act-2024
wiki-page (02_References/enterprise-ai/wiki/frameworks/eu-ai-act-risk-classification.md)
last-synced 2026-06-07

EU AI Act — Essentials for Enterprise Deployers

What this reference contains

The EU AI Act 2024 provisions most directly relevant to enterprise AI deployers: risk classification, AI literacy obligations, and the governance requirements triggered by high-risk deployments.

Key provisions (with citations)

  • Article 4 — AI Literacy obligation (in force February 2025). Organizations must ensure their staff and agents using AI systems "possess an adequate level of AI literacy." This is a mandatory workforce obligation, not optional training. Source: EU AI Act, Art. 4.
  • Risk-tiered system classification:
    • Unacceptable risk: prohibited (social scoring, subliminal manipulation)
    • High risk: extensive governance requirements (HR decisions, safety systems, critical infrastructure)
    • Limited risk: transparency obligations (chatbots must disclose they are AI)
    • Minimal risk: no mandatory requirements
  • High-risk systems (selected HR/enterprise examples): AI used in employment decisions, AI used to evaluate creditworthiness, AI managing critical infrastructure, biometric identification.
  • High-risk deployer obligations (Art. 26): Human oversight designation (a named person), technical documentation maintained, fundamental rights impact assessment, post-market monitoring.
  • GPAI provider obligations: General-purpose AI model providers must document capabilities/limitations, comply with copyright law, disclose training data summaries.
  • Governance from day 1, not deployment gate. The Act's compliance requirements are triggered at design, not at deployment. Risk classification, documentation, and oversight designation must happen before deployment.

The compliance-as-contributor principle

The Act is designed to be integrated into project design, not applied at a final checkpoint. Organizations that build legal, risk, and ethics into project kickoff:

  • Avoid 6-month post-build compliance audits
  • Reduce rework (changing a deployed system to meet Art. 26 requirements is expensive)
  • Are 1.7× more likely to be AI leaders (PwC ROI 2026 finding)

When to consult

  • For skill tech-agent-guardrail: EU AI Act obligations run alongside IMDA's four dimensions — particularly Art. 4 (literacy) and Art. 26 (deployer oversight).
  • For skill people-readiness-conversation: the AI literacy obligation (Art. 4) is a named governance requirement; ask whether the organization has addressed it.

Source

EU AI Act 2024. Articles 4, 26, and risk-classification framework. In force August 2024; Art. 4 (literacy obligation) effective February 2025.