EU AI Act, ethics, security: the triangle every manager must know
tier III · strategist · 10 min · interactive article ✦
While your teams were testing ChatGPT, Europe was legislating. The EU AI Act, the world's first comprehensive legal framework on artificial intelligence, has been applying gradually since 2025. For a manager, knowing it is no longer a lawyer's topic: it's a managerial skill, just as GDPR became one.
The logic of the text: classify by risk
The AI Act doesn't regulate “AI” as a block — it classifies uses by risk level. The same model can be harmless for summarizing a meeting and “high risk” for screening résumés. It's the use that counts, not the tool:
the AI Act pyramid: the more a use touches decisions about people, the higher it rises
The practical question for you: “does this use touch decisions about people — hiring, evaluating, granting, sanctioning?” If yes, you're probably in high risk, and improvisation stops there.
Ethics: before compliance, trust
The text sets a legal floor; ethics sets your reputational ceiling. Two reflexes are worth almost any charter: bias — a model trained on historically biased data reproduces those biases with industrial confidence; any HR or customer use deserves an adversarial test. Transparency — your employees and customers have the right to know when an AI takes part in a decision that concerns them.
Security: three hygiene rules
What you type can leave: no confidential data in a consumer tool without a company agreement.
Check the contractual status of your AI tools: is your data used to train the vendor's models?
Beware of prompt injection: a booby-trapped document can manipulate an assistant that reads it. Any external content processed by an AI is an attack surface.
test yourself — just like in the path
Your HR director wants to use AI to pre-screen applications. Under the AI Act, this use is:
✓ High risk: not banned, but governed — documentation, human oversight, informing candidates, audits. Being able to say this in a meeting is precisely the strategist manager's role.
Look at the pyramid: recruitment = decision about people. Try again.
Going deeper
Who is responsible if something goes wrong?
The AI Act distinguishes the provider (who develops the system) from the deployer (who uses it — you). Using a compliant tool doesn't exempt you: the deployer has its own obligations, notably human oversight and use consistent with the intended purpose. “It's the vendor's tool” is not a defense.
Where to start in my team?
With an inventory: list the real AI uses in your scope (including the unofficial ones — there are some). Place them on the pyramid. In most teams, 90% of uses are minimal risk… and the remaining 10% deserve a real conversation with legal.
The triangle, one sentence each
AI Act: classify your uses by risk, treat high-risk ones seriously. Ethics: test for bias, say when AI decides. Security: what goes into the tool can come out of it. The manager who masters this triangle innovates without accidents.
Frequently asked questions
Does the EU AI Act ban AI in Europe?
No. The regulation classifies uses by risk level and imposes proportionate obligations. It's not a general ban on AI.
How many risk levels does the AI Act distinguish?
Four, from minimal risk to unacceptable risk. Obligations increase with the risk level of the use.
Is screening résumés with AI covered?
Yes. This use is generally “high risk,” with reinforced obligations (documentation, human oversight, transparency).
Who is responsible for an AI-assisted decision?
A human must always be designated as responsible. “The tool's fault” doesn't exist legally: governance sets accountability.
This notion is a full level of the IAPLC path.
In the course, you practice it on YOUR context: lessons generated for your job, interactive exercises, gamified progression.