The Act is now operational, not theoretical
For two years the EU AI Act was a thing to prepare for. After the Reset, it is a thing to comply with, and the gap between the two is where the fines live.
The AI Act entered into force in 2024 and now applies in phases: the prohibited-practice ban and AI-literacy duties first, general-purpose-model obligations next, and the heavy high-risk obligations landing across 2026 and 2027. An operator's playbook exists to stop treating this as a legal-department abstraction and start treating it as an engineering and deployment constraint, because that is what it now is.
The Act is risk-tiered, not technology-banning. It does not forbid frontier models; it forbids deploying them into certain uses without documentation, logging, human oversight, and data governance. Read that way, the Act is less a compliance burden than a placement instruction: the heavier the obligations on a use case, the stronger the argument for running it on infrastructure you control and can prove.
The four tiers, and what each demands
Every AI use case in your organisation sits in one of four tiers. Knowing which is most of the work.
Prohibited practices, social scoring, certain biometric categorisation, manipulative systems, must be audited out entirely; there is no compliant way to run them. High-risk uses, named in Annex III, include creditworthiness assessment, life and health insurance pricing, recruitment and worker management, and a range of essential public services. These carry the full weight: risk management, data governance, technical documentation, logging, transparency, human oversight, and conformity assessment.
Limited-risk systems, chatbots, generative content, owe transparency: people must know they are dealing with AI or AI-generated material. Minimal-risk uses are largely unencumbered. The trap is mis-tiering, assuming a use is limited-risk when an Annex III reading makes it high-risk. HR and credit are where this happens most, and where a wrong call is most expensive.
Share of typical enterprise AI deployments that fall under high-risk obligations (Annex III) per function.
Why the Act rewards sovereignty
The obligations are easier to meet, and cheaper to prove, on infrastructure you govern end to end.
Documentation, logging, and human-oversight evidence are far simpler to produce when the model, the data, and the audit trail live inside your perimeter than when they are mediated by a third-country API you cannot inspect. DORA and NIS2 reinforce the same instinct from the operational-resilience side. The Act never says self-host, but its evidentiary demands consistently make sovereign deployment the path of least resistance for high-risk uses.
This is the quiet synergy at the heart of Rindogatan's thesis: the same architecture that satisfies the European regulator, local, auditable, minimised, is the one that protects your data and your strategic autonomy. Compliance, sovereignty, and security stop being three budgets and become one decision.
“The Act does not ban frontier models. It bans deploying them without a paper trail your DPO can sign.”
The 90-day compliance sprint
Four moves that turn the Act from a looming deadline into a standing capability.
Inventory and tier every AI use case, live, piloted, and shadow, against the four tiers, with special attention to anything touching credit, insurance pricing, recruitment, or public services. The shadow uses are usually the finding.
For each high-risk use, decide placement before you build the paperwork: a use you run on sovereign infrastructure is one whose documentation, logging, and oversight you can actually deliver. Then stand up a standing AI-governance process so new use cases are tiered and placed by default, turning the Act from a project into an operating system.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.