AI

The EU AI Act, Explained for Product Teams

By Tom Bore · 6 August 2026 · 7 min read

The EU AI Act sorts AI systems by how much harm they could do and sets rules to match. If you build or use AI, the first job is to work out which tier you're in. Most products land in the low-risk bands and carry light obligations. A few don't, and those carry real ones.

This is a plain-English overview for product teams, not legal advice. The Act is detailed and your specifics matter, so treat this as a map and take the exact route with counsel.

The four risk tiers

  • Unacceptable risk. Banned outright. Things like social scoring and certain manipulative or biometric uses.
  • High risk. Allowed with strict duties: risk management, data governance, documentation, human oversight, transparency. Covers uses like hiring, credit and access to essential services.
  • Limited risk. Transparency duties. If people are talking to a chatbot or looking at AI-generated content, tell them.
  • Minimal risk. Most software. No specific obligations under the Act.

It applies even if you're not in the EU

The Act reaches beyond EU borders. If your AI system's output is used in the EU, the rules can apply wherever your company sits. A studio in London or a startup in Dubai serving EU users is in scope, the same as an EU provider. Global reach cuts both ways.

The timeline in brief

The Act came into force in 2024 and applies in phases. The bans and AI-literacy duties landed first, in early 2025. Obligations for general-purpose AI models followed in August 2025. The bulk of the high-risk rules apply from August 2026, with a further set for certain regulated products in 2027. As of now, the high-risk obligations are the ones to take seriously.

What to do now

None of this needs a panic. It needs an inventory:

  • List every place you use or ship AI, including features built on third-party models.
  • Put each one in a tier. Be honest about the high-risk uses.
  • For limited-risk features, add the disclosure that users are dealing with AI.
  • For high-risk uses, plan the documentation, oversight and data governance early, not at launch.

Penalties scale with the breach, and the top band reaches into the millions or a slice of global turnover, so the classification step earns its keep. If you're adding AI to a product, fold this into how you scope the feature from the start, and lean on the same buy-first instinct from build vs buy when you pick a model provider, since their compliance work becomes part of yours.

In short

Classify first, disclose where required, and treat high-risk uses with the care they demand. If you want help mapping your product to the tiers and building compliance into the work, get in touch. For the exact legal position, speak to a qualified adviser.