The EU AI Act in plain English
What the new European AI law means for you and your colleagues. No legal jargon. Everything you need to know about AI literacy at work, on one page.
The EU AI Act is the world’s first major law that regulates how artificial intelligence may be used. Europe wants AI to be safe, to work fairly and to not harm people. The law has been in force since 1 August 2024 and is being introduced step by step.
The idea is simple: the bigger the impact an AI system can have on people, the stricter the rules. A spam filter can do almost anything. AI that decides whether you get a job or a loan has to meet heavy requirements. And some AI is not allowed at all.
The law sorts AI by risk. That tells you straight away how strict the rules are.
Banned
AI that is a clear danger to people. Not allowed. Think of social scoring or AI that secretly manipulates people.
High risk
AI with a big impact on your life, such as in hiring, exams or credit. Allowed, but with strict requirements and oversight.
Limited risk
AI where you need to know you are dealing with AI, such as chatbots and deepfakes. The rule: be transparent.
Minimal risk
By far most AI, such as spam filters and recommendations. Free to use, no extra rules.
Not just tech companies
The law applies to every organisation that uses AI. From the bakery with a smart stock tool to a hospital or a local council. Do you use AI in your work? Then your organisation falls under it. You do not need to build software to be affected.
Provider or deployer
The law has two main roles: those who make AI (the provider) and those who use AI (the deployer). Most companies are deployers, for example of ChatGPT or an AI tool inside their software. As a deployer you have duties too, and AI literacy is one of them.
AI literacy means that everyone who works with AI understands enough to use it safely and sensibly. What AI can and cannot do, where it goes wrong, and when you need to step in yourself.
Since 2 February 2025 this is no longer a nice-to-have. Article 4 of the EU AI Act requires every employer that uses AI to actively build these skills in their staff. Not with a thick report nobody reads, but with real knowledge that fits the work people actually do.
This is exactly what our AI Literacy Essentials training is for. In half a day your whole team gets the basics down and you meet the AI literacy obligation. Explore the Claude for Business training →
Do
- Always check what AI gives you back. AI sounds confident, even when it makes things up (hallucinations).
- Be open: let people know when something was made with AI.
- Keep a human in charge of decisions about people.
- Watch for bias: AI copies the skew in its training data.
Don’t
- Copy or forward AI output blindly without checking it.
- Paste personal data or company secrets into a public chatbot.
- Let AI decide about applicants, customers or colleagues without oversight.
- Pretend AI content was made by a human when you are required to disclose it.
Some AI is banned outright, including at work. The most important ones for employers:
Emotion recognition at work
AI that measures the mood, stress or emotions of employees is banned, except for medical or safety reasons.
Social scoring
Giving people a score and disadvantaging them based on their behaviour or traits. Not allowed.
Manipulation
AI that steers people, without them noticing, into choices that harm them. Banned.
Scraping faces
Grabbing photos from the internet or cameras at random to build a facial database. Not allowed.
The law enters into force
The EU AI Act is officially in effect. The rules are then phased in over time.
Banned AI + AI literacy
The banned AI practices are now truly prohibited. And every employer that uses AI must ensure AI literacy among staff.
General-purpose AI models and oversight
Rules for large AI models (like the tech behind ChatGPT) and the supervisory authorities take effect.
High-risk AI
The strict requirements for high-risk AI start to apply, for example in hiring, education and credit scoring.
Final parts
The remaining rules for high-risk AI built into products take effect.
The 2026 and 2027 dates are indicative. Europe may still adjust the rollout of some high-risk rules. The AI literacy obligation already applies regardless.
The fines are steep. For banned AI practices they can reach 35 million euro or 7% of global annual turnover, whichever is higher. For other breaches it is up to 15 million or 3%. But the real risk is usually not the fine: it is losing the trust of customers and employees when AI is used badly. Good AI literacy is, above all, just smart business.
How to get AI literacy sorted in your organisation
We take your team from zero to confident and compliant in half a day. Practical, jargon-free, and directly applicable to your own work.