Artificial intelligence
The AI Act, risk classification, human oversight and the obligations that actually apply to you.
Most conversations about AI inside a company start with "are we allowed to", when they should start with "what is the thing we are deploying, and who are we in this configuration". Provider, deployer and user carry entirely different obligations, and most companies are the third while talking like the first.
The practical consequence is a pleasant one: if you are not building a high-risk system, a large share of what you read online about the AI Act does not apply to you. To know that for certain, though, you have to run the classification once instead of assuming the answer.
A common argument
„If the system can be tightly controlled and a human is in the loop, it is not AI.”
How it actually is
Human oversight is an obligation towards an AI system, not a criterion for what an AI system is. How easy the control is tells you how hard the obligation will be to meet — not whether it arises.
Questions I hear most often
- ? Is our tool a high-risk system?
- ? Are we a provider or a deployer — and what changes when we add our own layer?
- ? What must we document, and what is merely good practice?
- ? Who answers when the model suggests something harmful?
Materials in this area
See allThe AI Act in a small company: what applies to you and what does not
Most companies are not high-risk system providers and do not need a risk management system. How to check which side of that line you are on.
Checklist: rolling out an AI tool in a team
Twenty questions to answer before signing with a vendor — from the legal basis to how you get out of the tool.