EU AI Act: definition

The EU AI Act is the European regulation on artificial intelligence, adopted in 2024 and applied in stages. It governs the placing on the market and the use of AI systems within the European Union through a risk-tiered approach. Rather than applying the same rules to every system, the text scales obligations according to the risk each use presents. This page is descriptive and does not constitute legal advice.

The risk tiers

The regulation distinguishes four categories. Unacceptable risk covers prohibited uses, such as certain forms of social scoring. High risk applies to systems used in sensitive domains (for example employment, credit, safety): these carry the strongest obligations. Limited risk mainly triggers transparency duties, such as disclosing that content was generated by an AI. Minimal risk covers most everyday uses, with few specific obligations.

Most of the requirements therefore concentrate on high risk: documentation, traceability, transparency, human oversight and data quality management.

What it changes for memory and decisions

The EU AI Act does not regulate "memory" as such. Its impact is felt indirectly, through obligations around provenance and auditability, wherever an AI system feeds decisions classified as high risk. In that case, you need to be able to trace where the information used came from and to document how the system operates.

This connects to the question of data sovereignty and to the Cloud Act, which both concern where data sits and who controls it. A verifiable memory, whose provenance can be traced, makes this kind of requirement easier to meet. The reasoning is extended in the article why your memory should not live inside any AI.

FAQ

Does the EU AI Act ban the use of AI in business?

No. It only prohibits a narrow list of uses classified as unacceptable risk. The vast majority of uses fall under limited or minimal risk, with light obligations, mainly around transparency.

Do I have to document all company memory to be compliant?

No, not systematically. Documentation and traceability obligations apply mainly to high-risk systems. Still, a memory whose provenance is verifiable helps meet these requirements when they do apply.

Lire cet article en français