EU AI Act
In shortThe AI Act reaches mid-sized companies mainly through recruitment and worker monitoring.
At a glance
- Instrument
- Regulation (EU) 2024/1689, in force since August 2024, applying in stages
- Approach
- Risk-based: prohibited practices, high risk, transparency duties, minimal risk
- Who is covered
- Providers and deployers of AI systems — including those who merely use somebody else's system
- Relevant for mid-sized firms
- Recruitment, and evaluation or monitoring of workers, fall into the high-risk tier
- Transparency duties
- Chatbots, synthetic content and emotion recognition must be labelled
- Practical preparation
- An inventory of the systems in use with purpose and data categories; a one-page usage rule
The AI Act does not regulate technology but purposes of use. The same language model can fall under minimal risk in one application and become a high-risk system in another — it depends on what it is used for and whom the decision affects.
For companies that is the regulation's most important property. It does not answer "may we use AI?" in the abstract, but per use case.
The tier that reaches mid-sized companies
Prohibited practices concern very few companies. The transparency duties are inconvenient but manageable: chatbots and synthetic content must be recognisable as such.
The tier that actually creates work is high risk — and it contains two applications long since common in mid-sized business: candidate selection, and evaluation or monitoring of workers.
Anyone using an applicant tracking system with automatic pre-sorting, or analysing performance data, is covered — even where the system comes from a third party.
What deployers must do
For high-risk applications that includes human oversight with a genuine ability to intervene, logging, informing the people affected, control over input data, and following the provider's instructions.
Those duties presuppose something many services do not supply: information on how the system works, where processing happens and what data flows out. That is exactly where the regulation meets the sovereignty question — not through the provider's registered office, but through traceability.
The pragmatic starting point
Compile a list of the AI tools actually in use, with purpose and data categories. In most organisations that list is longer than expected, and it incidentally uncovers part of the Shadow IT.
Add a one-page rule on which data categories never go into an external tool. A ban with no usable replacement fails against the tools' usefulness; a clear boundary plus an approved tool works.
Common questions
- Does the regulation apply if we only use third-party tools?
- Yes. Deploying an AI system carries its own duties, depending on the risk tier. For high-risk applications these include human oversight, logging and informing the people affected.
- Which typical applications are high risk?
- In companies, above all use in hiring and candidate selection, and in evaluating, allocating and monitoring workers. Both are more widespread than the debate suggests.
- What does this have to do with sovereignty?
- The duties presuppose traceability: where does the model come from, where is processing done, what data flows out? With a service that will not answer those questions, meeting your own duties is barely possible — regardless of where the provider sits.
- What is the pragmatic first step?
- A list of the AI tools actually in use, their purpose and the data categories going into them. In most organisations that list is longer than expected — and it uncovers part of the shadow IT at the same time.
Sources
See also
Related terms
- Digital sovereigntySovereignty is not a state but the answer to four questions: law, operations, data, capability.
- Sovereign cloudSovereign cloud is not a protected term. Ask which of the four layers the provider actually means.
- NIS2NIS2 may not cover you, but it covers your biggest customer — who passes the duties on.