The EU AI Act came into force at the start of August, and since then I've watched data teams react in two unhelpful ways. One is to ignore it as a legal problem that lives in someone else's department. The other is to panic, as if every model and dashboard is now a compliance emergency. Both are wrong, and both come from the same place: the actual text is long, lawyerly, and written for regulators, so almost nobody building data systems has read what it really asks of them. I wrote recently about translating AI risk so a board can govern it; this is the companion piece pointed the other way — down at the data team, in the language of the people who build the things the Act is about.
The one idea that unlocks the whole Act
If you remember nothing else, remember this: the AI Act is risk-tiered. It does not treat all AI the same. It sorts AI uses into a small number of risk categories and applies obligations proportional to the tier. So the first and most important question for any AI system you touch is not "are we compliant" — it's "which tier is this," because the tier determines everything that follows.
The tiers, in plain terms:
- Unacceptable risk — banned outright. A short list of uses the Act simply prohibits (things like social scoring and certain manipulative or exploitative systems). For most data teams this is a quick check: are we doing any of the handful of forbidden things? Almost always no — but you confirm it, you don't assume it.
- High risk — heavily regulated, still allowed. AI used in consequential domains — think recruitment, credit, education, essential services, safety components. Permitted, but with real obligations: risk management, data governance, documentation, human oversight, transparency, logging. This is the tier that will cost you work if you're in it, and the tier most worth knowing whether you're in.
- Limited risk — transparency obligations. Systems that interact with people or generate content, where the main duty is disclosure — telling people they're dealing with AI, labelling AI-generated content. Lighter, but not nothing.
- Minimal risk — essentially unregulated. The large majority of ordinary analytics, BI, and internal tooling lands here, and the Act mostly leaves it alone.
The panic dissolves the moment you tier your systems, because most of what a typical data team runs is minimal or limited risk. The work concentrates almost entirely in the high-risk tier — so knowing precisely what's in it is the whole game.
What "high risk" actually asks of a data team
If you do have a high-risk system, here's what the obligations mean in build-and-run terms, stripped of the statute language:
- Data governance you can evidence. The training and input data has to be relevant, representative, and managed for bias and gaps — and you have to be able to show that, not just assert it. For data people this is the most natural obligation in the Act: it's data quality and lineage, with a regulator now asking to see your working.
- Documentation and traceability. You need records of how the system was built, what data fed it, what it's for, and how it behaves — technical documentation kept current, plus logging that lets you reconstruct what happened. If you already document properly, this is an extension; if you don't, this is the wake-up call.
- Human oversight, designed in. A high-risk system has to be built so a human can meaningfully understand, oversee, and intervene — not a rubber-stamp human, a genuinely-able-to-intervene one. That's an architecture and UX requirement, not a policy sentence bolted on afterwards.
- Transparency to the people affected. Clear information about the system's capabilities, limitations, and intended use, so the humans in the loop and the people on the receiving end aren't operating blind.
None of that is exotic to a team that already takes data governance seriously. The Act largely codifies practices good data people already believe in — and turns the ones you were doing informally into ones you now have to do demonstrably.
The timeline — because "in force" doesn't mean "all due now"
A crucial calming point, because "the Act is in force" gets misheard as "everything is required immediately." It isn't. The obligations phase in over the next couple of years:
- First come the bans on the prohibited uses — those apply well before the rest.
- Then the obligations on general-purpose AI models arrive.
- The full high-risk obligations phase in last, over a longer runway into the following years.
So the honest posture right now is not frantic remediation. It's: work out which of your systems land in which tier, confirm you're doing nothing prohibited, and identify anything high-risk so you have a real runway to meet its obligations before they bite. Preparation, not panic — and the preparation is mostly clarity about what you actually have.
The AI Act isn't asking most data teams to change much. It's asking all of them to know something they mostly don't: which of their AI systems is high-risk, and whether they could prove their data governance to someone who's allowed to ask.
What I'd actually do on Monday
Concretely, if I ran a data function, my near-term move wouldn't be a compliance programme. It'd be an inventory — the same unglamorous move that fixes half the problems in this field. List the AI and automated-decision systems you build or run, and tier each one honestly against the categories above. That single exercise tells you the truth: almost everything is minimal or limited risk and needs little, a small number of systems are high-risk and need real attention, and — most valuable of all — you now know which is which instead of guessing. From there the work is scoped and finite rather than a formless dread.
The teams that come out of the AI Act era well won't be the ones who panicked, and definitely not the ones who ignored it. They'll be the ones who treated it as what it mostly is for data people: a legal reason to finally do the data governance you always knew you should — the classification, the lineage, the documentation, the honest look at bias — and to be able to show your work when someone asks. The Act didn't invent those obligations. It just made them enforceable, and put a date on them.