Skip to content
AISO Learn AISO Learn - Home
Part of AISO Group Take the Scorecard
AI Act

The EU AI Act, read for the person who has to do something about it.

This page is the landing point for our AI Act material - what the law says, what it means for a team like yours, which obligation is likely already live, and where the honest grey areas are. Written for the compliance lead, HR lead, or team leader who has read the summary and needs the next layer down.

What the AI Act is, in plain terms

The EU AI Act is a regulation that sorts AI systems into risk tiers and sets different obligations for each tier. Most of the public conversation has been about the high-risk tier - hiring tools, biometric systems, critical-infrastructure AI. That is not where most EU teams will spend their time.

For most professional-services teams, the obligation that actually binds is Article 4 - the literacy requirement. It applies to everyone who uses AI systems in the course of their work, and it sits on the employer to make sure the people doing the using know enough to use it responsibly.

That is the obligation this page is built around.

The three things worth knowing first

  • Article 4 is the one that applies to you. If your team uses AI tools in its work, this is the obligation to start with - not the high-risk tier, not transparency duties, not the general-purpose-AI rules.
  • “Sufficient literacy” is not defined. The text gives principles, not a checklist. That gap is deliberate on the regulator’s side, and it is where most compliance leads are currently stuck.
  • Review windows are short, not long. Member-state authorities will review SME readiness faster than most teams expect. Six months from “we should look into this” to “we need this documented” is a realistic planning horizon.

The sub-pages

Article 4 pillar

The deep read. What the text says, what guidance has been published, what “sufficient literacy” looks like in a real team, and the common mistakes we see.

Read the Article 4 pillar

AI Readiness Scorecard

A ten-question diagnostic that places your team in one of three bands - Starting, Practising, Evidence-ready - and produces a three-page action plan keyed to the band. Fifteen minutes.

Take the Scorecard

Risk tiers overview (coming)

A short reference page on the risk-tier structure - what is high-risk, what is limited-risk, what is minimal - for teams that want to rule out the tiers that do not apply to them.

Role-based obligations (coming)

Which obligations sit on the provider, which sit on the deployer, which sit on the user. Most SMEs are deployers or users - not providers - and that matters for what is expected of you.

Deadlines calendar (coming)

A practical timeline of the dates that matter for SME teams, separated from the dates that matter for providers of high-risk systems. Because most of the public timeline content mixes them up.

What we avoid on this hub

Three things this page is not, by design:

  • It is not legal advice. It is a reading of the law by teachers who work with compliance leads. For a formal opinion on your specific situation, talk to your counsel.
  • It is not a “survive the AI Act in ten minutes” promise. The obligations are not complicated, but they are not ten-minute work either. We do not pretend otherwise.
  • It is not a completion record mill. We do not sell AI Act completion records, and if a vendor offers you one, it is likely not doing the work the law actually asks for.

If you are the person in your team who has to act

Three honest paths, in order of speed:

  • Take the Scorecard if you want a read of your own team’s state before you commit to anything
  • Read the Article 4 pillar if you want the reference document
  • Book a discovery call if you want to talk to a teacher for thirty minutes about what a program would look like

The Scorecard is the fastest way to see where your team actually stands. The pillar is the deepest document on the site. The discovery call is the shortest way to know whether we are the right people to help.