AI Act: what your IT
department must anticipate
The European regulation on AI — the AI Act — doesn't classify technologies, but uses, by risk level. Knowing where yours falls has become a basic skill for any IT professional. Test a use case below: the classifier gives you the level and the associated obligations.
● minimal risk
No specific obligation. The vast majority of professional uses (summarizing, writing, non-determining decision support) fall here. Recommended good practice: verify outputs, protect data, inform users.
◐ limited risk — transparency
Transparency obligation. The user must know they're interacting with an AI (and generated content must be identifiable). That's the case for chatbots. Light, but not to be forgotten.
▲ high risk
Strong obligations. Anything touching employment, credit, education, health, justice: risk management, data quality and governance, technical documentation, human oversight, traceability and informing individuals. To frame from design.
✕ unacceptable risk — banned
Purely banned. General social scoring, behavioral manipulation, sensitive biometric categorization: these uses are prohibited in the EU, in any sector. Rule them out from the start.
The 4 levels at a glance
the obligation follows the risk of the use — not the technology employed
take it with you · free
The AI Act audit checklist as a PDF
The 4 levels, the typical uses of each, and a checklist to place and document your use cases. Ideal for a first internal audit. Leave your email to receive it, or download directly.
or download directly, no email →✓ Thanks — your download is starting.
This article is an educational overview and does not constitute legal advice. For a high-risk use, have your analysis validated by your DPO or a lawyer.
Frequently asked questions
What is the AI Act?
The AI Act is the European regulation on artificial intelligence. It classifies AI uses into four risk levels — unacceptable, high, limited, minimal — and imposes obligations proportional to each level.
Which AI uses are banned?
Unacceptable-risk uses: general social scoring, behavioral manipulation, sensitive biometric categorization, among others. They are purely banned, in any sector.
Is my AI use high-risk?
Often yes if it touches employment (CV screening), credit, education, health, justice or critical infrastructure. These uses require risk management, data quality, documentation, human oversight and traceability.
AI governance is something you steer.
In IAPLC, you learn to place your uses, set a framework and govern AI — on YOUR cases, through 30 levels generated for your IT role.
Explore the course →