The EU AI Act, read the week it leaked: Flick Fisher on risk tiers, providers, and the compliance clock
The EU AI Act is the first serious legislative attempt anywhere to regulate artificial intelligence, and the useful news for most companies is that the heavy obligations land on a smaller group than the headlines suggest.
This episode was recorded days after the final text leaked in late January 2024, while the law was still awaiting formal approval. The Act was subsequently adopted and entered into force later that year. What follows is a specialist's read of the final text at the moment it became readable, which holds up well as an explanation of how the law is structured.
Flick Fisher is a European privacy specialist and a partner in Fieldfisher's top-ranked Privacy, Security and Information group, and one of Global Data Review's top 40 under 40 data privacy lawyers.
She is also the show's first returning guest. Michael's episode with her on GDPR and data privacy turned out to be among the most popular the podcast has published, despite not being with a COO, which is why this became the first instalment of a recurring segment called The Legal Opinion.
What happened, and when
The Act traces its origins to 2021, well before generative AI arrived in public consciousness.
Which created the central complication. Substantial agreement had been reached on the original framework, and then ChatGPT arrived and regulators concluded they needed provisions specifically addressing the privacy and societal risks that generative AI presents to European consumers. Much of the last-minute negotiation was about exactly that.
A provisional agreement was reached in December, after long and complex discussions between the European Parliament, Council and Commission. Everyone was waiting for the final draft.
Then somebody leaked it on a Sunday, which, as Fisher puts it, sent the privacy lawyers into a frenzy reading several hundred pages.
How the law is structured
The AI Act is horizontal legislation, which means it applies to all AI. But it does so on the explicit premise that not all AI carries equal risk, so it takes a risk-based approach.
That produces distinct buckets.
Prohibited. Systems the legislators decided present unacceptable risk and will simply be banned.
High risk. Systems that pose potential threats to fundamental rights, safety or the environment, and therefore attract substantial additional requirements.
Limited or minimal risk. Everything else, with light provisions rather than a compliance programme.
The bulk of the law falls on providers of high-risk AI systems. Fisher's summary of the intent: Europe wants to lead in requiring that people design AI that is transparent, ethical, safe and mindful of environmental cost.
What is actually high risk
The categories Fisher lists are concrete, and the first one affects a large number of ordinary companies.
Using AI systems to make employment or workplace decisions. Who gets promoted, who does not, which candidates are selected.
Biometric systems. AI used for immigration and asylum cases. Critical infrastructure. And systems already covered by existing European product safety legislation, which brings in categories like toys and aviation.
What is prohibited outright
The banned list is where the law makes a values statement.
Emotion recognition systems in the workplace or in educational settings. Biometric categorization systems using sensitive characteristics. Scraping large volumes of facial images to build a facial recognition database, which she references as the Clearview scenario.
And manipulative systems, meaning products using subliminal or deceptive techniques. Her example is a toy directed at a child designed to manipulate them.
Why this matters outside Europe
Michael makes the point for listeners who assume this is a European problem: Europe moves faster than the US and places a higher value on personal privacy, so what happens there becomes a template, and US companies selling into the EU are bound by it regardless.
Fisher's term for this is the Brussels effect.
GDPR was the landmark case. Its extraterritorial reach effectively created a global privacy standard, with other jurisdictions passing similar laws and companies raising their compliance to meet it because it became the default definition of good practice.
The AI Act has the same extraterritorial structure. Even if you are not based in Europe, if you design systems that will be used in Europe by European consumers, or whose outputs will be used there, the Act applies to you.
By contrast, the US has no federal equivalent. There is a New York City law focused on bias assessments for certain monitoring in recruitment, and various state laws addressing insurance, credit monitoring, healthcare use, and elections. Nothing horizontal.
The definition fight
The provision everyone focused on first is what counts as AI.
The original proposals used a very broad definition that potentially captured almost any software with an analytical or statistical function. The final text reflects the OECD formulation instead: machine-based systems designed to operate with varying levels of autonomy, which in practice points at machine learning.
The nuances are where the argument started. The definition was clearly shaped to capture generative AI. Critics responded that it may now fail to capture everything it should, with rule-based AI systems potentially falling outside it.
The open source carve-out
The leaked text confirmed that open source software is exempt from a substantial set of requirements, which was welcomed.
Specifically, general purpose models provided free and openly escape a lot of the model evaluation, data governance, incident reporting and transparency requirements.
With an important exception. The exemption disappears if the model is used in the high-risk scenarios, meaning employment, immigration, critical infrastructure, or within products already governed by product safety legislation.
The reasoning Fisher gives is sensible: much of the transparency about how those models were developed is already public, which is the point of open source.
Two tiers of foundation model
General purpose AI, meaning the foundation models, gets its own two-tier treatment.
Ordinary foundation models face basic rules, including adherence to codes of practice.
Models classified as involving systemic risk face considerably more: model evaluations, assessment and mitigation of systemic risk, testing designed to probe for failure, and information provided to the organizations that will build on them, so those organizations can do their own risk assessments. Plus energy efficiency requirements.
The classification threshold is defined by the computational scale used in training, which Fisher cites as ten to the power of twenty-five floating point operations. Cross it and you are automatically in the riskier bucket. Separately, a model can end up in the high-risk category through use, if it is deployed in one of the listed scenarios.
Provider or deployer, and how to accidentally become a provider
This is the distinction that matters most for the average company.
A provider develops the AI system. Google, Microsoft, Meta, OpenAI, Anthropic.
A user, also called a deployer, is a company that operates, implements or integrates that system. Anyone under whose authority the system is used.
Fisher's worked example: if you use Copilot in your organization, Microsoft is the provider and you are the deployer. And deployer obligations are relatively light, focused on transparency and good governance.
Then the trap, which is worth reading twice.
If you make substantial changes to a model, building something genuinely bespoke, you can yourself become a provider of that model and inherit the heavier obligations. So the depth of the work you do on someone else's model is a compliance decision, not just an engineering one.
The clock, and the fines
The implementation is phased, which Fisher notes gives organizations time to work out what compliance actually looks like.
Six months from entry into force to stop using prohibited AI systems.
Twelve months to comply with the general purpose AI provisions.
Thirty-six months if you are a provider of, or using, a high-risk AI system.
The penalties scale with the risk category, and the prohibited systems attract the heaviest. Failing to identify prohibited systems in your organization, or building and deploying them as a provider, exposes you to fines of up to 35 million euros or 7% of global turnover.
Was this fast?
Michael's instinct is that this moved much faster than GDPR. Fisher confirms it, with context.
GDPR took roughly six years to negotiate, and many companies are still working on compliance with it. The AI Act traces to a framework published in 2021, so by comparison it moved quickly. Many observers doubted it would be agreed before the end of the year, and there was a visible rush to get it done.
Behind that is momentum in Europe to be first, to lead globally on regulating AI, and simultaneously to be an innovation hub. Whether those two objectives are compatible is the open question she keeps returning to.
What is genuinely uncertain
Asked how OpenAI and Anthropic feel reading this, Fisher is balanced. Those companies have publicly supported good regulation of AI. There is also genuine concern that Europe may stifle innovation, that this came too soon, that it is not flexible enough, and that there may not be enough freedom to train and develop models.
She notes there are exemptions for work done on models before they are placed on the market, so the pre-market development work is not necessarily caught. But both companies face a considerable amount of work to comply.
The more fundamental uncertainty is structural. The law refers to codes of conduct and risk assessment frameworks that do not exist yet. And there is no collective agreement on how to assess the risks the law now requires people to assess.
Her conclusion is that this may require a genuinely global effort to agree standardized frameworks for the risk assessments the law mandates.
Her stated fear for the alternative: fragmentation, with every organization grappling with a different set of governance frameworks and requirements as they emerge. She would rather this inspire a shared standard.
The social media comparison
Michael's framing is that you cannot put the toothpaste back in the tube with social media, and that regulators appear to want a second attempt with AI, an area with the potential to do more damage.
Fisher does not dispute the motivation. There are real-world harms here, and in Europe the frame is protecting residents' fundamental rights, with transparency, ethics and environmental considerations built in. The intent is a law that forces people to think about the risks that arise from using these systems in particular scenarios.
Her caveat is honest. The law will always be trying to keep up, given how fast the technology is evolving. The hope is that a risk-based approach is flexible enough to remain relevant as systems change.
What high-risk providers actually have to do
Fisher's characterization is the clearest framing in the episode: in many ways this is product safety legislation for AI systems.
Which means conformity testing. Risk assessments. Data governance, including the quality of the data used for training. Human oversight by suitably qualified people during development. Technical documentation maintained across the development lifecycle and provided to the organizations using the system so they can perform their own assessments. And registration on a European database flagging that you have a high-risk system.
Plus designing with transparency, energy consumption and ethical considerations in mind. All of which, she notes, is good for consumers. The open question remains what it does to the pace of development.
There will also be new bodies established to oversee the Act, produce guidance and help define what risk assessment looks like, supported by codes of conduct and standardized contract templates. New regulators, or new responsibilities for existing ones. And internally, new compliance roles for people who understand AI governance.
Michael raises Sam Altman's suggestion of something like the International Atomic Energy Agency for assessing foundation models, and Fisher confirms the Act moves in that direction.
What to do if you are an employer
The practical implication for most listeners is narrow and clear.
If you use AI systems for employee monitoring, recruitment activity, sifting candidates, or determining who is promoted, those systems are high risk.
Which means significantly more transparency to your employees about the fact that you are using them, your own risk assessments behind the scenes, and consideration of your obligations under existing privacy law.
And if you are a vendor helping AI providers develop those systems, expect additional contractual obligations flowing down to you.
Her legal opinion
Fisher's closing verdict is the most useful part for anyone deciding how alarmed to be.
The AI Act is important and will reshape the field. But it will not affect everyone the way GDPR did.
If you are in the high-risk category, you have a great deal of work ahead. If you are not, the requirements are genuinely light touch, and the work is tweaking governance and transparency, thinking about best practices, and considering whether the forthcoming codes of practice make sense for your organization.
Her instruction is to work out whether you are caught. If you are doing anything prohibited, act quickly, because that clock is six months. If you are high risk, you have three years. Everyone else should be aware rather than afraid.
The 5 things I took away from this conversation
1. Find out which bucket you are in before doing anything else. The single most useful thing in this episode is that the compliance burden is wildly uneven. Most companies are deployers facing light-touch transparency and governance requirements. A minority are high-risk providers facing something closer to a product safety programme. Everything follows from which one you are.
2. Employment and recruitment AI is high risk. This is the category that catches ordinary companies who do not think of themselves as AI companies at all. If a system is helping decide who gets hired or promoted, it is in scope, and that brings transparency obligations to employees and your own risk assessments.
3. You can accidentally become a provider. Flick's warning about substantially modifying a model is the one I had not considered. Use Copilot and you are a deployer with modest obligations. Do enough bespoke work on someone else's model and you become the provider of it, with everything that entails.
4. The frameworks the law requires do not exist yet. The Act mandates risk assessments and codes of conduct that nobody has written and nobody has collectively agreed how to perform. That gap is where the practical difficulty of the next few years lives, and it may need an international effort to close.
5. Prohibited has a six month clock and the largest fines. Everything else has a year or three. If there is anything in your organization that falls into the banned categories, emotion recognition in the workplace being the most likely candidate, that is the item that cannot wait.
FAQ
What is the EU AI Act? The first comprehensive attempt anywhere to regulate artificial intelligence. It applies horizontally to all AI but sorts systems by risk, banning some outright, imposing substantial obligations on high-risk systems, and applying only light transparency and governance requirements to everything else.
What are the EU AI Act risk categories? Four levels in practice. Prohibited systems presenting unacceptable risk, such as workplace emotion recognition and untargeted facial image scraping. High-risk systems including employment decisions, biometrics, immigration and critical infrastructure. Limited-risk systems with transparency obligations. And minimal-risk systems attracting almost nothing.
Does the EU AI Act apply to companies outside the EU? Yes. Like GDPR, it has extraterritorial effect. If you design systems that will be used in Europe by European consumers, or whose outputs will be used there, the Act applies regardless of where your company is based.
What is the difference between a provider and a deployer? A provider develops the AI system, which typically means the large model companies. A deployer, also called a user, is any organization operating or integrating that system. Deployer obligations are relatively light, but making substantial modifications to a model can convert a deployer into a provider.
What are the penalties under the EU AI Act? Fines scale with the severity of the breach. The heaviest apply to prohibited systems, at up to 35 million euros or 7% of global turnover, with lower tiers applying to other categories of non-compliance.
Also mentioned
- Fieldfisher, its data podcast and Silicon Valley webinar series
- The EU AI Act, the legislation itself
- GDPR, the precedent for extraterritorial reach and the Brussels effect
- The OECD definition of an AI system, which the final text adopts
- New York City's bias audit law for automated employment decision tools
- Sam Altman's proposal for an international agency to assess foundation models
Listen to the full episode
Flick Fisher on Between Two COO's
Between Two COO's is hosted by Michael Koenig. Subscribe on Apple Podcasts, Spotify, or wherever you listen.
The COO's Execution Playbook
Frameworks, templates, and hard-won lessons from operators who've been in the chair. Every Tuesday.
No spam. Unsubscribe anytime.