Skip to content
Piotr Kaniewski
Areas

Artificial intelligence

The AI Act, risk classification, human oversight and the obligations that actually apply to you.

Most conversations about AI inside a company start with "are we allowed to", when they should start with "what is the thing we are deploying, and who are we in this configuration". Provider, deployer and user carry entirely different obligations, and most companies are the third while talking like the first.

The practical consequence is a pleasant one: if you are not building a high-risk system, a large share of what you read online about the AI Act does not apply to you. To know that for certain, though, you have to run the classification once instead of assuming the answer.

A common argument

„If the system can be tightly controlled and a human is in the loop, it is not AI.”

How it actually is

Human oversight is an obligation towards an AI system, not a criterion for what an AI system is. How easy the control is tells you how hard the obligation will be to meet — not whether it arises.

Questions I hear most often

  • ? Is our tool a high-risk system?
  • ? Are we a provider or a deployer — and what changes when we add our own layer?
  • ? What must we document, and what is merely good practice?
  • ? Who answers when the model suggests something harmful?

Materials in this area

See all

Other areas