Go to main content Go to main navigation Go to footer
Back to overview

The EU AI Act: An Explanation, Risk Categories, and What It Means for Your Software.

The EU AI Act, formally known as Regulation (EU) 2024/1689, is the first comprehensive European law to regulate the development and use of AI. The law takes a risk-based approach: the greater the risk posed by an AI system, the stricter the requirements. The regulation entered into force on August 1, 2024, and the first obligations have been in effect since February 2, 2025. Below, you can read about what the AI Regulation means for your organization and software.

This explanation is for informational purposes only and does not constitute legal advice.

Bob ten Vergert - Security officer bij Cube - Oldenzaal
Author Test Engineer | Security & Privacy
Reading time
6 min

In short:

  • The EU AI Act takes a risk-based approach: the higher the risk, the stricter the requirements.

  • There are four risk categories: unacceptable, high, limited, and minimal.

  • The law identifies two key roles: the provider who develops AI and the deployer who uses AI.

  • The first obligations have been in effect since February 2, 2025. The stricter high-risk requirements are being pushed back to the end of 2027 and 2028 via the Digital Omnibus, though this is not yet final.

  • Virtually every organization that uses AI tools is covered, even if only as a deployer.

What the EU AI Act entails.

The EU AI Act is a regulation, not a directive. This means that the law applies directly in all 27 member states, without the Netherlands having to transpose it into national law. The goal is twofold: to facilitate responsible AI while setting limits where AI poses risks to health, safety, or fundamental rights. The basic principle is simple to explain. The law does not treat all AI equally, but looks at what a system does and who it affects. A spam filter and an algorithm that evaluates job applicants do not fall into the same category, and that is exactly the intention. The greater the potential impact on people, the more the law expects of you. Important to know: the AI Act has a long reach. If your organization is based outside the EU but the output of your AI system is used within the Union, you are still subject to the rules.

The four risk categories under the AI Regulation.

The AI Regulation classifies AI systems into four categories. Each category has its own obligations, ranging from a complete ban to no specific requirements at all.

Unacceptable risk: prohibited uses.

The most restrictive category. These are applications that the EU considers so harmful that they are banned. Examples include social scoring by governments, manipulative AI that subconsciously influences people’s behavior, and certain forms of remote biometric identification. These bans have been in effect since February 2, 2025, and violations result in the highest fines.

High risk: strict requirements.

AI used in areas with significant human impact is classified as high-risk. Examples include systems for recruitment and selection, credit assessment, education, and critical infrastructure. These systems are subject to the most stringent practical requirements: a risk management system, data quality requirements, technical documentation, logging, human oversight, and a conformity assessment before the system is placed on the market.

Limited risk: transparency requirement.

This includes chatbots, AI-generated content, and deepfakes. The key is transparency: users must know when they are interacting with AI or when content has been artificially created. Synthetic text, images, audio, and video must be marked as AI-generated in a machine-readable format.

Minimal risk: no specific requirements.

The largest group in practice. This includes spam filters, recommendation algorithms, and most everyday AI applications. The law does not impose any specific obligations in this regard.

Who is subject to the AI Act: provider versus deployer.

This is the part where many organizations get it wrong. The AI Act distinguishes between two roles, and those roles determine what you need to do.

An provider develops an AI system—or has it developed—and markets it under its own name. A deployer uses an AI system in its own business operations. If you use tools like ChatGPT or Copilot in your work processes, you are a deployer and therefore have certain obligations.

Here’s the catch. If you make significant changes to an existing AI system—for example, by fine-tuning it or altering its intended purpose—you legally become the provider yourself. With all the associated obligations. For organizations that integrate AI into custom software, this is a significant difference: the way you integrate AI helps determine the role you end up in.

The deadlines under the EU AI Act.

The law will be implemented in phases. This is the original timeline from the regulation:

  • August 1, 2024: the AI Act enters into force.

  • February 2, 2025: the ban on certain AI practices (Article 5) and the AI literacy requirement (Article 4) take effect.

  • August 2, 2025: the rules for general-purpose AI (GPAI) models and the penalty framework take effect.

  • August 2, 2026: most other obligations, including those for high-risk AI, would take effect.

  • August 2, 2027: full implementation is anticipated.

What the AI Act Means for Custom Software and AI Integration.

Whether your software falls under the AI Act does not depend on whether it is custom-built. It depends on what the AI function does and which risk category it falls into. If you’re building a function that evaluates people—for example, in a hiring process or during a credit application—you’ll likely fall into a higher-risk category. A smart search function or an in-product assistant typically falls into a much lower category.

The practical point: the law requires transparency, logging, human oversight, and documentation. These aren’t things you can just tack on afterward. They are design choices. Anyone who commissions custom software development and incorporates these requirements from the start will have significantly less work later on than those who have to squeeze them in later. Think of an AI feature that logs every decision, always provides feedback so a human can intervene, and can demonstrate its reasoning. That is exactly the kind of control the law requires, and it can be easily built into AI features within your existing software.

Preparing your organization for the AI Act.

You don’t have to wait for a deadline to get started. A few practical steps will take you a long way. First, identify which AI solutions you’re using and have them documented. Many organizations underestimate this: from the chatbot on the website to the Copilot in Microsoft 365, it all counts. Record this in a simple AI registry. Then determine for each application which risk category it falls into and what your role is—provider or deployer. Next, draft a light AI policy: who is allowed to do what, and under what conditions. And don’t forget about AI literacy. This requirement has been in effect since February 2, 2025, and requires that employees working with AI understand what it does, where the risks lie, and what the limitations are. Finally: be transparent with your users when they are dealing with AI.

Want to know what the EU AI Act means for your software? Schedule a no-obligation consultation.

Bob ten Vergert - Security officer bij Cube - Oldenzaal
Bob Test Engineer | Security & Privacy

Worth reading next...

How do you write a good RFP for custom software?

This guide covers the components of a strong software RFP, how to prioritize requirements using the MoSCoW method, and—perhaps most importantly—when an RFP isn't the best approach.

Software
Strategy

What is a configurator?

Which type of configurator fits your product? Cube builds custom product and 3D configurators with ERP integration. Discover the possibilities.

Software

Frequently Asked Questions About the EU AI Act.

The AI Act entered into force on August 1, 2024, and is being implemented in phases. The ban on certain AI applications and the AI literacy requirement have been in effect since February 2, 2025. Most obligations, including those for high-risk AI, were set to take effect on August 2, 2026, but may be postponed via the Digital Omnibus.

This applies to any organization that develops, markets, or uses AI within the EU. Organizations outside the EU are also covered if their products or services are used within the EU. In practice, this affects virtually every organization that uses tools such as ChatGPT or Copilot.

A provider develops an AI system or has it developed and markets it under its own name. A deployer uses an AI system in its business operations. Important: In the event of significant modifications, such as fine-tuning or changing the intended purpose, a deployer becomes a provider in legal terms.

Yes. Whether your custom software falls under this category depends on the AI functionality and the level of risk, not on the fact that it is custom-built. If you develop an AI feature that evaluates people, you will likely fall into a higher-risk category. This is not legal advice.

The obligation under Article 4 to provide employees who work with AI with sufficient knowledge about what AI does, its risks, and its limitations. This obligation has been in effect since February 2, 2025.