← All articlesAI ActConformitéEurope7 min read

EU AI Act: where to start when you don't know where you stand

The first question the EU AI Act asks is not "what must I do?" but "what risk tier am I in?". How to answer it with articles, dates and sources.

Most companies approach Regulation (EU) 2024/1689 from the wrong end: they look for the list of their obligations. That is the reverse of how the text works. The regulation does not hand obligations to everyone — it classifies, then obliges according to the class.

Until the classification is settled, no list of obligations means anything: it is either far above or far below what actually applies.

The pyramid, and the rule that matters

INACCEPTABLE interdit — art. 5 HAUT RISQUE obligations lourdes — annexe III RISQUE LIMITÉ transparence — art. 50 RISQUE MINIMAL formation des équipes — art. 4 un seul critère du haut de la pyramide suffit à vous y placer
Classification works downward: first check whether any criterion at the top applies.

A single criterion from the top of the pyramid places you there, whatever your intentions and whatever the rest of the system does. That is why quick self-assessments get it wrong so often: they reason in averages, while the text reasons in maximums.

Describe a use, not a technology

"We use AI" cannot be classified. "A scoring model that filters job applications" can. The difference is not technical depth — it is the presence of the three things the regulation needs:

  • who puts the system into service, and in what capacity — provider, deployer, importer, distributor: the obligations differ;

  • on whom it has an effect — customers, employees, applicants, the general public;

  • which decision it informs or automates, and how much human intervention remains.

Those three decide the risk tier. Everything else — the model, the hosting, the language — comes afterwards.

Date it and source it, because the calendar moves

The regulation applies in stages, and its calendar has already been amended. An undated claim on this subject has a shelf life of a few months. That is why our compliance team runs a dedicated watcher agent that verifies texts and deadlines against EUR-Lex, the Union's official database, rather than reciting them from memory — and why every claim in the report carries its article and its date.

An audit that does not date its claims is not an audit. It is a photograph with no timestamp.

The report contains the reasoned classification, each applicable obligation handled individually, a deadline calendar and an action plan. A legal agent then challenges it before delivery — which does not replace your lawyer, and does not claim to.

What the tool will not do for you

It will not sign your declaration of conformity, it does not know about undocumented uses inside your teams, and it is not legal advice. What it does: turn a vague question into a dated, sourced, arguable file — the document you bring to a lawyer, rather than the question you ask one.

You can try the swarm online, no credit card.

Launch my first mission →
Read next