Glossary
EU AI Act
European legislation that regulates AI according to how risky the use is rather than what the technology is, so the same tool can be treated very differently depending on the job.
In plain terms
European legislation that grades AI by how much is at stake in what it is being used for, with the most serious applications carrying the most. The part worth internalising as a buyer is the grading unit: it is the use, not the product. A model that summarises meeting notes and the same model helping decide who gets hired are not the same proposition, and nothing about the software distinguishes them.
Why it matters
Because it moves the question a buyer has to answer. Software purchasing habitually asks what a tool is and whether it is any good. This framing asks what you intend to do with it. That is a question about your own organisation, and no vendor can answer it for you. That is why the same tool passes review in one department and stalls in another. It is also why a vendor asking about your use case is doing something more substantial than qualifying a lead.
How it works
The unit of assessment is the application rather than the technology, which is the idea everything else follows from. A general-purpose tool is not sorted into a category on its own; what it is being used for is. That is why two organisations can buy the same product and reach opposite conclusions in review without either of them having made a mistake.
It follows that scope can change without the tool changing. A deployment that was uncontroversial for drafting becomes a different question when somebody points it at decisions affecting people, and nothing in the software or the contract will have altered. Organisations that treat approval as a property of the tool are unprepared for that; treating it as a property of the use is what keeps a review current.
It explains why vendors ask what you will use something for, and why the answer belongs in your own records. The vendor cannot know your use and the assessment turns on it, so the exchange is genuinely necessary rather than commercial curiosity. Writing down what you said, and revisiting it when the use expands, is the part organisations skip.
It distinguishes broadly between those who build these systems and those who deploy them, and most organisations are the second. That matters because it locates where the assessment sits: with the people who decided to point a tool at a particular job, not only with whoever made it. Buying carefully does not move that, and it is the reason the question arrives at buyers at all.
Higher-stakes uses attract more of everything: more documentation, more human oversight, more explanation of how a decision was reached. What exactly is required is legal detail and turns on the grade and the circumstances. The direction is stable enough to plan against. It argues for knowing early which side of that line a use sits on, rather than discovering it late.
For most ordinary business AI, drafting, summarising, searching internal material and automating routine steps, the framing is orienting rather than onerous, and saying so plainly is more useful than implying everything is fraught. The uses that attract serious attention are recognisable: they are the ones where a decision meaningfully affects a person's life.
Where this page stops is where the advice starts. Whether you are in scope, which grade a use falls into, and what follows are all specifics. They turn on facts about your situation and on legal text a glossary should not approximate. The useful thing understood here is the shape: assessment attaches to use, so the question is about you.
One tool, several uses
Seen in the wild
The same assistant used for internal drafting in one team and proposed for screening applications in another, which are different propositions.
ChatGPTAn automation that summarises and routes incoming records, where the question is whether anything downstream decides something about a person.
n8nInternal search answering questions from company material, which is the ordinary end of the range rather than the contested one.
GleanA CRM assisting with contact records, where the use is administrative rather than deciding anything about anybody.
Attio
Common misconceptions
People assume
It regulates AI models.
In fact
It grades applications. A model is not assessed in the abstract; what somebody is doing with it is, which is why the same product can be routine in one deployment and closely examined in another. Buyers who look for a compliant tool are looking for a property that does not sit in the tool.
People assume
We approved it once, so we are covered.
In fact
Approval of a use is not approval of a tool. Pointing an approved deployment at a materially different job is a new question, even though nothing about the software or the contract has changed. That is the commonest way an organisation drifts out of what it actually assessed.
People assume
It is only a concern for European companies.
In fact
Reach here works similarly to the data protection regime that preceded it, and many vendors and buyers found it simpler to work one way everywhere. Whether any particular organisation is in scope is a specific legal question, and the vocabulary has already spread well beyond Europe regardless.
Telling them apart
EU AI Act vs GDPR
EU AI Act
Grades what an AI application is being used for.
Governs what may be done with information about people.
A use can raise one, the other, both or neither. They ask different questions about the same deployment.
Questions
- Why does a vendor ask what we will use it for?
- Because the assessment depends on it and they cannot know it. That makes the question substantive rather than sales qualification. The answer is worth writing down in your own records, because the useful version is the one you can revisit when somebody proposes a new use.
- Does this affect ordinary business use?
- For drafting, summarising, internal search and routine automation the framing is mostly orienting rather than burdensome. The uses that attract serious attention are recognisable by a common feature: a decision that meaningfully affects somebody's life. Knowing which side of that a use sits on is the practical step.
- What should we keep a record of?
- What each deployment is used for, who decided that, and what human involvement there is in anything it affects. Those are worth having for ordinary management reasons, and they are the things you will be asked to describe if a use ever turns out to sit higher up the range than anybody assumed.
- Why does this page not list the risk categories and their rules?
- Because that is legal detail whose consequences turn on specifics, and an approximation would be confidently wrong for most readers who arrived by searching. The shape of the idea is stable, genuinely useful and safe to explain; the requirements need somebody qualified reading your actual situation.
Key takeaways
- It grades the use, not the tool, so no product is compliant on its own.
- Scope can change while the software and the contract stay identical.
- Most organisations are deploying rather than building, and the question still arrives at them.
- A vendor asking about your use case is doing something necessary, not commercial.
- Record what each deployment is for; it is the thing you will be asked to describe.
Last checked July 2026