SkyCircle

AI Governance

The EU AI Act,
in plain language

A short guide for teams working between Europe and Asia — what the Act asks of you, and where to start without panicking.

Most conversations about the EU AI Act start with a worried question: "Does this apply to us?" Usually, the answer is yes — at least in part. If your AI touches people in the EU, the Act follows the users, not your head office.

The reassuring part is that the Act is built around risk. Once you know which of your use cases carry real risk, most of the fog clears. Here is the short version.

Risk tiers

Four tiers, four responses

Banned outright

Social scoring, emotion recognition at work or school, manipulative systems that exploit vulnerable people. If something here sounds close to what you do, stop and redesign.

High risk

Hiring, credit, education, healthcare, essential services. This is where the real work sits: documentation, data governance, human oversight, monitoring. Not impossible — but it needs owners and time.

Limited risk

Chatbots and generated content. Mostly a transparency job: tell people they are talking to an AI, and label what a machine made.

Minimal risk

Most everyday tools. Nothing mandatory — as long as you are honest about which tier you are really in.

Timeline

What applies when

  • Already in force: the bans, and the duty to make sure your people understand AI.
  • August 2025: rules for general-purpose AI models.
  • August 2026: transparency for chatbots and generated content.
  • December 2027: the full high-risk regime.

Cross-border

If you work between Asia and Europe

Teams in Hong Kong and the Greater Bay Area usually ask three things at once: what Europe wants, what local law wants, and what can actually be built. The Act does not replace GDPR or local frameworks — it sits on top of them.

In practice, one shared map of overlapping obligations saves months. It is far easier than three teams each solving the same problem in a different direction.

Where to start

Five honest first steps

1

List every place AI is actually used — including the tools nobody officially approved.

2

Sort each one into a risk tier. When in doubt, go one tier higher.

3

Decide who you are for each system: provider or deployer. Your duties change completely.

4

Start the paperwork for anything high risk. It takes longer than anyone expects.

5

Give your teams a real AI literacy session, not a slide deck.

Next step

Not sure where you stand?

That is a normal place to be. Our AI Compliance Assessment maps your use cases against the Act and GDPR, and gives you a short, ranked list of what to fix first.