Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/AI Essentials/Responsible & trustworthy AI/Privacy, ethics and governance/Governance and the EU AI Act: the topline
3/3+140 XP

Privacy, ethics and governance

1Privacy and confidential data: what not to paste+1502Ethics and responsible use at work+1303Governance and the EU AI Act: the topline+140

Governance and the EU AI Act: the topline

# Governance and the EU AI act: the topline

In 2025, a company shipped an AI tool that scored job applicants partly on facial expressions during video interviews. Under the EU AI Act, that kind of "emotion recognition in the workplace" is now effectively banned. Not "fined." Banned.

The EU AI Act is the world's first major law that regulates artificial intelligence directly. If you work with AI tools, build with them, or even just buy them for your team, the topline matters. You do not need to read 100 pages of legal text. You need the shape of the law: what is forbidden, what is heavily controlled, and when the rules bite.

Let's get you that shape.

What the law actually does

The EU AI Act sorts AI systems into risk tiers. The higher the risk to people's rights and safety, the heavier the rules. Think of it like a traffic-light system with four levels.

  • Unacceptable risk: banned outright.
  • High risk: allowed, but tightly controlled (paperwork, testing, human oversight).
  • Limited risk: allowed, with transparency duties (you must tell people).
  • Minimal risk: basically free to use (spam filters, AI in video games).

One key point: the law applies based on where the AI is *used*, not where the company is based. A US startup whose chatbot serves EU customers is on the hook. This is the same "long " that made the GDPR (Europe's privacy law) a global standard.

reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.Voir la définition complète →

A quick definition: a "provider" is whoever builds or sells the AI system. A "deployer" is whoever uses it in their organisation. Both have duties, but providers carry the heavier load.

Tier 1: What is prohibited

These uses are off the table in the EU. Most took effect in February 2025. Concrete examples:

  • Social scoring by governments: ranking citizens' trustworthiness and then denying them services. (Picture a national "good behaviour" score.)
  • Emotion recognition at work or in schools: software claiming to detect if you are angry, bored, or lying from your face or voice.
  • Untargeted face scraping: building facial recognition databases by hoovering images off the internet or CCTV.
  • Manipulative AI that exploits people's vulnerabilities (age, disability) to distort their behaviour and cause harm.
  • Predictive policing based purely on profiling a person to guess they will commit a crime.
  • Biometric categorisation that infers sensitive traits like race, sexual orientation, or political views.

If your product idea touches any of these, stop. There is no compliance checklist that makes it legal in the EU.

Tier 2: What is high-risk

This is the tier most professionals will actually bump into. High-risk does not mean "evil." It means the AI is used in a setting where a bad decision seriously affects someone's life. Examples:

  • AI that screens CVs or ranks job candidates.
  • AI used in credit scoring or deciding who gets a loan.
  • AI in medical devices and diagnostics.
  • AI that decides access to education (exam scoring, admissions).
  • AI used in critical infrastructure (power grids, water).
  • Certain AI used by law enforcement, border control, and courts.

If you deploy a high-risk system, you inherit real obligations: keep humans in the loop, log what the system does, use good-quality data, monitor for bias, and be transparent with the people affected. Providers must register these systems in an EU database before selling them.

A real scenario

Say your HR team buys an AI résumé-screener. You are now a deployer of a high-risk system. Your duties include:

  • Assigning a human to oversee its decisions (not rubber-stamp them).
  • Keeping logs of its outputs.
  • Informing candidates that AI is part of the process.
  • Checking the provider gave you proper instructions and a risk assessment.

The lesson: "we just bought it off the shelf" is not a defence. Buying high-risk AI makes you responsible for how you use it.

Tier 3: Limited risk (the transparency tier)

This is where everyday tools like ChatGPT, Claude, and Gemini mostly live for general use. The core rule is simple: people should know when they are dealing with AI.

  • Chatbots must make clear users are talking to a machine, not a human.
  • AI-generated or heavily edited images, audio, and video ("deepfakes") must be labelled as artificial.
  • AI-generated content should be marked in a machine-readable way where feasible.

So if you deploy a customer-service chatbot, a one-line "You're chatting with our AI assistant" disclosure goes a long way.

General-purpose AI: the models behind your tools

The big models powering ChatGPT, Claude, and Gemini are called General-Purpose AI (GPAI): models flexible enough to do many tasks. The Act adds a separate set of duties for the companies that make them, which kicked in around August 2025.

GPAI providers must publish summaries of their training data, respect EU copyright rules, and provide technical documentation. The most powerful models (those posing "systemic risk") face extra testing and security requirements. The EU published a voluntary General-Purpose AI Code of Practice to help these providers comply.

For you as a *user*, this mostly happens upstream. But it is why your AI vendor's documentation and "model cards" matter: they are partly there to satisfy these rules.

The timeline you should remember

The Act entered into force in August 2024, but the rules switch on in waves. The headline dates:

  • Feb 2025: Prohibited uses banned. AI literacy duties begin.
  • Aug 2025: Rules for general-purpose AI models apply.
  • Aug 2026: Most high-risk and transparency rules apply. This is the big one.
  • Aug 2027: Remaining high-risk rules (AI embedded in regulated products like medical devices) apply.

So 2026 is the year the bulk of the obligations land. If your organisation uses AI in hiring, lending, or other sensitive areas, this year is when "we should look into that" becomes "we needed this done."

Penalties, briefly

Fines are serious. Banned uses can cost up to 35 million euros or 7% of global annual revenue, whichever is higher. Other breaches scale down from there. The numbers are designed to make compliance cheaper than ignoring the law.

Vérification des acquis

1. What is the core organising principle the EU AI Act uses to decide how heavily an AI system is regulated?

2. A US-based startup with no EU offices offers a chatbot that serves customers in France and Germany. Why does the EU AI Act still apply to it?

3. In the vocabulary of the EU AI Act, what distinguishes a 'provider' from a 'deployer'?

CHOIX MULTIPLES

4. Select ALL uses of AI that fall under the 'unacceptable risk' tier and are prohibited in the EU.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL statements that correctly describe the difference between the risk tiers of the EU AI Act.

Sélectionnez toutes les réponses correctes.

A simple way to check where you stand

You do not need a lawyer to do a first-pass triage. Ask three questions about any AI system you use or build:

1. Is the use prohibited? (Social scoring, workplace emotion detection, etc.) If yes, stop.

2. Is it high-risk? (Hiring, credit, health, education, law enforcement.) If yes, you have real obligations.

3. Does it talk to or generate content for people? If yes, you owe them transparency.

Here is that triage as a tiny script you could adapt for an internal checklist:

python
def classify_ai_use(use_case):
    prohibited = {"social_scoring", "workplace_emotion_recognition",
                  "untargeted_face_scraping", "predictive_policing"}
    high_risk = {"cv_screening", "credit_scoring", "medical_diagnosis",
                 "exam_scoring", "border_control"}

    if use_case in prohibited:
        return "PROHIBITED: do not deploy in the EU."
    if use_case in high_risk:
        return "HIGH-RISK: human oversight, logging, bias checks required."
    return "LIMITED/MINIMAL: add a clear 'this is AI' disclosure."

print(classify_ai_use("cv_screening"))
# HIGH-RISK: human oversight, logging, bias checks required.

This is a starting filter, not legal advice. But it forces the right first question every time.

What this means for non-EU readers

Even if you are in the US, UK, or elsewhere, three reasons to care:

  • Reach: if any of your users are in the EU, the Act may apply to you.
  • Template effect: like the GDPR, this law is shaping rules elsewhere. Many companies adopt one global standard rather than juggle several.
  • Trust signal: following these practices (human oversight, transparency, data qualitydata qualityThe degree to which data is fit for purpose: accurate, complete, consistent, timely, valid and unique. Poor quality data undermines analytics, reporting and AI.Voir la définition complète →) is simply good AI hygiene, regulation or not.

You can read the official summary on the EU's own AI Act page if you want the primary source in plain-ish language.

Key Takeaways

  • Memorise the four tiers: prohibited, high-risk, limited (transparency), minimal. Most of your daily AI use is "limited," meaning: just tell people it's AI.
  • Know the banned list. Social scoring, workplace and school emotion recognition, untargeted face scraping, and certain predictive policing are off-limits in the EU, full stop.
  • If you use AI for hiring, lending, health, or education, treat it as high-risk now. Assign human oversight, keep logs, and demand documentation from your vendor.
  • Mark August 2026 on your calendar. That is when most high-risk and transparency rules fully apply. Start your internal review this year, not next.
  • Run the three-question triage (prohibited? high-risk? talking to people?) on every AI tool before you roll it out. It catches the biggest issues in minutes.

À faire, tiré de cette leçon

Ces actions sont compilées dans le plan d'action du rôle.

  • Never clone a real person's voice, face, or likeness without documented consent
  • Run three-question triage—prohibited, high-risk, talking to people—before rolling out any tool
Voir le plan d'action complet →

Précédent

Ethics and responsible use at work

Retour au parcours