american asian black brainstorming

The EU AI Act in 1,200 words for non-lawyers

Insights  ·  Governance

The EU AI Act in 1,200 words for non-lawyers.

A plain-English read for VP Eng, COO, CISO, or compliance leads who need to know what the Act actually requires of a mid-market AI deployment in 2026.

By Hussain, Founder · About

Draft outline — founder to write. The structure below is locked. The narrative under each heading will be written by Hussain to keep voice authentic. Estimated final length: ~1,200 words.

1. What the Act actually does

[TODO: founder to write — ~200 words. Risk categories: minimal, limited, high, prohibited. Why a risk-based regime rather than a sector regime. Who it applies to (provider, deployer, importer, distributor). Geographic scope: any system that puts output on the EU market, regardless of where the system is built.]

2. Which AI deployments fall into which category — concrete examples

[TODO: founder to write — ~250 words. Working examples for a mid-market reader: lead scoring (minimal/limited), chatbot triage (limited), document summarisation for compliance (limited), CV ranking (high), credit-decision support (high), biometric ID (high), social-scoring (prohibited). The categorisation is workload-specific, not vendor-wide.]

3. The transparency obligations most CRM, marketing, and support AI triggers

[TODO: founder to write — ~200 words. For limited-risk systems: users must be told when interacting with an AI; AI-generated content must be labeled; deepfake disclosure; emotion-recognition disclosure; training-data summary on request. What this means in product UX terms — how we surface these obligations in the rep’s view, the customer-facing chat, etc.]

4. What “high risk” really means — and which mid-market deployments touch it

[TODO: founder to write — ~250 words. Annex III categories: employment, credit, essential services, education, law enforcement, migration, justice, biometrics. Mid-market workflows that quietly touch these: recruiting screens, performance management, financial-services underwriting, healthcare patient prioritisation. Conformity assessment requirements: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity. Why we decline these builds without the infrastructure already in place.]

5. The vendor questions every buyer should ask

[TODO: founder to write — ~200 words. A checklist a buyer can put to any AI vendor: under which risk class does the proposed system fall, who is the provider vs. deployer, what conformity artifacts will I receive, what audit logs will the system produce, where does the training data come from, what is the DPA position, what happens at end-of-contract for the data. Tone: practical, not lawyerly.]

6. The lawyer-engineer view

[TODO: founder to write — ~100 words. Personal close from Hussain: lawyer-engineer angle, why the Act is a forcing function not a blocker, what mid-market companies should plan for in the next 12 months.]

Related: AI governance defaults we ship with · Case studies · How we engage

Need help classifying your AI deployment?

The founder takes governance calls personally. Twenty-five years of engineering plus an LLB means the conversation moves fast.