AI regulation isn't abstract policy anymore. If you're building systems that touch hiring, credit, healthcare, or law enforcement, there are now legal requirements attached to your model's behavior — and the penalties are real. Here's what actually matters for practitioners, without the fluff.

The EU AI Act: risk tiers, not blanket rules

Adopted in 2024, the EU AI Act is the first comprehensive AI law, and it works by classifying systems into four risk tiers:

Unacceptable risk — banned outright. Government social scoring, real-time biometric ID in public spaces (with narrow exceptions), manipulative AI targeting vulnerable people.

High risk — hiring, credit scoring, healthcare diagnostics, law enforcement, critical infrastructure, education. These require a conformity assessment, a documented risk management system, data governance controls, transparency, human oversight, and accuracy/robustness testing.