A risk-tiered rulebook, not a blanket ban
The EU AI Act is widely described as the first comprehensive AI-specific regulatory framework adopted by a major economic bloc. Rather than writing one set of rules that applies equally to every AI system, it sorts systems into risk tiers and attaches obligations that scale with the tier. That structure matters more than any single provision, because it means the honest answer to 'does the AI Act apply to me' is almost always 'it depends which tier your system falls into,' not a flat yes or no.
At the top sits 'unacceptable risk': a short list of uses the Act prohibits outright rather than regulates. Categories commonly cited include social scoring by governments, certain forms of real-time biometric identification in public spaces (with narrow carve-outs for law enforcement), and manipulative systems designed to exploit vulnerabilities in specific groups, like children or people with disabilities. If a system falls in this bucket, compliance paperwork doesn't help, the use case itself is off the table in the EU.
Below that is 'high-risk,' which is where most of the Act's real compliance machinery lives, and below that, 'limited risk' (mainly transparency duties, covered in a later lesson) and 'minimal risk' (largely unregulated, which covers the bulk of everyday AI applications like spam filters or recommendation widgets). The Act has been rolled out in phases rather than all at once, with different provisions taking effect on different timelines after its adoption. Anyone building against it should check the current state of implementation rather than assume a single effective date covers everything, since phased rollouts are exactly where 'as of writing' hedging matters most.
