1Actors and risk levels
The AI Act distinguishes several actors along the chain: provider (places on the market), deployer (uses), importer, distributor. Obligations differ by role — Article 10 targets only the provider, but a deployer has its own duties (human oversight, information…).
It also classifies systems by risk level:
2Risk management frameworks
Governance relies on structured frameworks. The NIST AI RMF proposes four functions in a loop:
- Govern — culture, roles, policies;
- Map — context and identified risks;
- Measure — evaluate, test, measure;
- Manage — prioritize, address, monitor.
And cross-cutting responsible AI principles: fairness, transparency, accountability, robustness, human oversight, privacy protection.
Human oversight refers to humans' ability to understand, supervise and, if needed, interrupt or correct the system — neither manually validating every prediction, nor removing all automation.
3Obligations and lifecycle
Proportionate regulation
The AI Act scales requirements to the risk level: light for minimal, demanding for high risk, prohibited for unacceptable. Some practices are restricted or banned depending on context — for example emotion recognition in the workplace.
What the provider owes (high risk)
Beyond Article 10 on data, the provider must put in place:
- a risk management system;
- technical documentation demonstrating compliance;
- logging of events;
- the required transparency (e.g. disclosing that content is AI-generated);
- post-market monitoring and the reporting of serious incidents.
The importer and the distributor, for their part, verify that the provider is compliant (conformity, documentation) before the system enters the EU market. And governance covers the whole lifecycle — through to the system's decommissioning / withdrawal.