7 Regulation and Compliance
This chapter covers
- Preparing for your discussions with Legal, although it does not provide legal advice.
- An overview of high-risk systems under the EU AI Act
- Legal roles (provider, deployer, or GPAI provider) and how they can change
- Mapping best practices from Chapters 3 through 6 to specific regulatory obligations
- What evidence you need before your system goes live
Does our RAG pipeline count as an AI system? We fine-tuned a vendor model on our data and deployed it internally, but our vendor says they handle compliance. Can we rely on that? Is my AI-driven personalized marketing system a high risk one? What about my internal agent that talks to my colleagues on a Slack channel and can run sensitive SQL queries?
When the European Commission published its AI Act proposal in April 2021, the accompanying Impact Assessment estimated that only 5-15% of AI systems would qualify as high-risk[1]. However, a 2023 study of 106 enterprise systems found that 18% of the systems could be categorized as high-risk, while 40% could not be clearly classified into a risk tier at all, meaning they could eventually end up in the high-risk category[2]. The Act’s first prohibitions took effect in February 2025[3]. GPAI provider obligations followed in August[4]. Many teams developing AI systems still aren’t sure what legal obligations they have for their AI system.