← All insights

High-Risk AI Is Now Regulated in the EU. Compliance Isn’t the Point.

This month, the strictest parts of the EU AI Act came into force. If your organization uses AI to make decisions about people, the rules now apply to you — whether or not you realized you were in scope.

The rules that just took effect

The EU AI Act sorts artificial-intelligence systems by risk. The heaviest obligations fall on the applications with the greatest influence over people’s lives — and from this month, those obligations apply.

The high-risk category is not abstract. It covers systems most large organizations already run:

  • Hiring and HR — screening candidates, ranking applicants, evaluating employees.
  • Education — scoring and assessment that affect a person’s access or progression.
  • Credit scoring — deciding who gets access to finance, and on what terms.
  • Insurance — risk pricing and eligibility for life and health cover.
  • Critical infrastructure — systems that keep essential services running safely.

Here is the uncomfortable part: many companies already operate systems like these without knowing they now fall within the Act’s scope. The model was bought as a feature, embedded in a vendor’s product, or built quietly by an internal team. Nobody filed it under “high-risk AI.” The regulation does not care how it arrived.

The trap: treating it as paperwork

It is easy to read all of this as one more administrative burden — a compliance file to assemble, a box to tick, a cost to absorb and forget.

But documentation was never the goal. The goal is artificial intelligence you can actually rely on — sovereign, secure, and resilient. Systems whose decisions you can explain, whose data you control, and whose behavior holds up under scrutiny. Companies that treat the Act as a formality miss that point entirely. They produce the paperwork and remain exactly as exposed as before — and unprepared for the phases still to come.

What the rules are really asking for

Strip away the legal language and the high-risk requirements describe something a serious operator would want regardless of any regulation: know what your models do, control the data they run on, and be able to stand behind the decisions they make.

That is difficult when your AI is a black box rented from someone else — when the model, the data, and the compute all sit outside your control. It becomes tractable when the system is yours: an architecture where data stays inside your boundary, models are chosen and adapted deliberately, and governance is built in rather than bolted on afterward. Compliance stops being a document you chase and becomes a property of how the system was built.

This is the same conviction behind everything we build at Cortex Labs: own your intelligence. AI is far easier to trust — and far easier to defend to a regulator — when you control the data, the models, and the infrastructure they run on.

You are not navigating this alone

Rules on paper still have to become workable practice. That is where industry alliances matter. Bodies such as AURIII connect business, research, and the state to translate the regulation into something organizations can actually apply — and to represent their members’ interests before national and European institutions as the framework evolves. Turning the Act from text into practice is a shared effort, not a burden each company carries alone.

Where to start

If artificial intelligence is already making decisions about people inside your organization, now is the moment to find out where you stand — not after an audit, and not once the next phase of obligations lands.

The first questions are simple: Which of our systems fall into the high-risk category? Whose data do they run on, and where does it live? Could we explain their decisions if we were asked to tomorrow? If those answers are not clear, the gap is not a paperwork gap — it is an architecture gap. And that is a far better problem to discover now than to be told about later.