AI · Explainer
The AI Act stopped being a policy story this year. Here is what builders actually have to do.
Obligations for general purpose models and high risk systems are now operational. The practical burden falls on documentation and evaluation, not on model architecture.

Independent coverage
Published 5 September 2026
9 min read
Evidence: Analysis
Two years of commentary treated the European AI Act as a question of whether it would arrive. It arrived. For teams shipping software in Europe, the useful question now is which specific artefacts a regulator or a customer will ask to see.
The risk tier decides everything
Most business software is not a high risk system. A scheduling assistant, a marketing copy tool or an internal search product usually falls outside the high risk annex entirely, and the obligations reduce to transparency: tell people they are interacting with an AI system, and label synthetic media.
The high risk tier is where the real work sits, and it is defined by use rather than by technique. The same model that is unregulated in a marketing tool becomes high risk when it screens job applicants, scores creditworthiness, or supports a clinical decision.
What high risk actually requires
In practice, four artefacts. A risk management file that is maintained rather than written once. Documented data governance covering the training and evaluation sets. Technical documentation sufficient for a third party to understand the system. And logging that lets you reconstruct a decision after the fact.
Human oversight is the fifth requirement and the most commonly misread. It does not mean a person clicks approve. It means a named person has the authority, the information and the practical ability to override the system, and that this is demonstrable.
General purpose models
If you fine-tune an open weight model and ship it to others, you may be a provider of a general purpose model rather than merely a deployer. The dividing line is modification substantial enough to change the model's capabilities. Teams that assumed downstream use was always deployment have been the most surprised group this year.
The honest cost
For a mid-size European software company shipping one high risk feature, the compliance work observed in the field runs to a few months of one senior engineer plus legal review, front-loaded, then a recurring quarterly obligation. That is a real cost and a survivable one.
The teams struggling are not the ones with unusual models. They are the ones that never wrote down what their evaluation set contained.
Sources
Related reading