The EU AI Act Masterclass
Nobody signs anything. Nobody buys anything. By Friday the company may be carrying the heaviest obligations in the EU AI Act.
Executive brief
You can take on the heaviest obligations in the Act without buying a tool or signing a contract
Article 25 is the trapdoor between deployer and provider: rename it, rewire it, or repurpose it, and you own it
Four risk tiers, and the one companies skip past is limited risk, which went live under Article 50 in August 2026
The prohibitions have been in force since February 2025 and none were deferred, including emotion recognition at work
"Delayed" only ever applied to the high-risk chapter, and everything outside it is enforceable now
Episode conversation
A team points a general-purpose AI tool at a stack of CVs on a Tuesday. Nobody buys anything. Nobody signs anything. By Friday the company may be carrying the heaviest obligations in the EU AI Act. Jamal Ahmed walks Jeff Carson through the three questions that decide it, the four risk tiers a business owner can actually use, and what is enforceable right now.
Watch the episode
How a company becomes an AI provider without signing anything
Ahmed’s example starts on a Tuesday morning. HR gets hold of one of the general-purpose AI tools already floating around the business and decides it would save everyone time to run a stack of CVs through it.
Nobody signs anything. Nobody buys anything. No procurement process fires, because nothing was procured.
By Friday, that company may be the deployer of a high-risk use case. Transparency duties, human oversight expectations and AI literacy obligations have all attached, and nobody in the building agreed to any of them. If somebody rebranded or tweaked the tool along the way, the company is not the deployer at all. It is the provider, carrying the heaviest obligations in the Act.
Ahmed’s explanation for why this keeps happening is the sharper part. Nobody has changed how they do business. The vendor process still runs the way it always ran. Due diligence, the ISO 27001 certificate, the boxes ticked, approved, handed to the business to use however it likes. That was good enough for software that does one thing. It is not good enough for a tool whose obligations change depending on what you point it at.
What Article 25 of the EU AI Act actually does
Article 25 has been called the bombshell clause, and Ahmed’s reason is that it promotes you silently.
Build it and you are the provider. Use it under your own authority and you are the deployer. Article 25 is the trapdoor between the two, and a deployer can fall through it into being a downstream provider without anybody deciding to.
His analogy is a car. Buy a Ford and drive it around and it stays a Ford, with Ford’s obligations attached to Ford. Put your own badge on it, or remap the engine, and the obligations land on you as though you built it.
The three questions that decide whether you are a provider
Ahmed reduces the Article 25 test to three questions. Say yes to any one of them and the provider obligations apply.
# | The question | What it catches |
1 | Have you put your name or brand on it? | Rebranding or white-labelling. If it is your badge on the outside and somebody else’s engine underneath, you are the provider. |
2 | Have you substantially modified it? | A manufacturer is responsible for a car meeting the safety standard. Remap it so it performs well outside that standard and the responsibility moves to whoever modified it. |
3 | Have you changed its intended purpose? | Taking a general-purpose tool and giving it a high-risk job. These tools were never intended to screen CVs for employability. |
Say no to all three and you are most likely still a deployer.
Ahmed’s own way of remembering it: if you rename it, rewire it, or repurpose it, you own it.
The four risk tiers, explained for a business owner
Ahmed frames these as a traffic light with a banned tier sitting above it.
Tier | Signal | What it means |
Unacceptable | Banned | Prohibited outright. You cannot do this at all. |
High | Red | Allowed, heavily regulated, proceed with extreme caution. Hiring, credit, education, and other essential services. |
Limited | Amber | Allowed, but you have to tell people. Chatbots and AI-generated content. The obligation is that a person knows they are dealing with a machine, not a person. |
Minimal | Green | Carry on. |
One company, two tools, classified live
Take a 400-person company running a customer chatbot and an AI hiring tool.
The chatbot sits in the limited-risk tier. The company has to disclose that it is AI, and that obligation is live now under Article 50 for new systems.
The hiring tool is high risk. Those obligations were deferred to December 2027, but the classification is real today, the prohibitions are already in force, and the AI literacy duty already applies.
One of those two tools carries live obligations right now. Working out which one is the company’s job, not the vendor’s.
What the EU AI Act bans outright
The one that surprises people is emotion recognition at work and in education. Sentiment scoring of call centre staff, engagement tracking in meetings. That can walk a company straight into a prohibited practice.
The rest of the list companies stumble into: social scoring, scraping faces to build recognition databases, and exploiting vulnerabilities.
These have been in force since February 2025. None of it is deferred, and the penalties for the banned practices sit right at the top of the scale.
What the delay actually covers
A lot of people heard the EU AI Act was delayed and stopped reading. Ahmed is blunt that the communication has been poor enough that even people inside Europe are confused.
What the Digital Omnibus did was stagger the enforcement dates on part of the Act. The delay covers the high-risk chapter. Bringing a new high-risk system to market means complying now. A system already on the market has until December 2027.
Everything outside that chapter is live. The prohibitions are enforced. The AI literacy duty applies. The general-purpose AI rules are in place. And the Article 50 transparency obligations went live in August 2026 alongside the penalty regime.
The question to ask before Monday
Ahmed’s test is one line, and it runs before anyone points an AI tool at a decision about people.
Whose name is on this? Ours, or the vendor’s?
Most companies have never asked it. The clause in the contract that says who carries the liability when something goes wrong goes unread, and the exposure sits there unmeasured.
Questions answered in this episode
How can a company become an AI provider under the EU AI Act without buying anything?
By changing what an existing tool does. Point a general-purpose AI tool at a high-risk task such as screening CVs and the company becomes the deployer of a high-risk use case. Rebrand or modify that tool and it becomes the provider, which carries the heaviest obligations in the Act. No contract is signed and no procurement process fires, which is why most companies cannot tell you whether it has already happened.
What is Article 25 of the EU AI Act?
Article 25 sets out responsibilities along the AI value chain. In practice it is the clause that moves a company from deployer to downstream provider. Ahmed describes it as the trapdoor between the two, because it promotes you silently: the obligations change without anyone deciding to take them on.
What are the three questions that decide whether you are a provider?
Have you put your name or brand on it, have you substantially modified it, and have you changed its intended purpose. Yes to any one of the three and the provider obligations apply. No to all three and you are most likely still a deployer. Ahmed’s shorthand is that if you rename it, rewire it, or repurpose it, you own it.
What are the four risk tiers of the EU AI Act?
Unacceptable, high, limited, and minimal. Unacceptable is banned outright. High risk is allowed but heavily regulated, and covers hiring, credit, education and other essential services. Limited risk is allowed provided people are told they are dealing with AI, which is where chatbots and AI-generated content sit. Minimal risk carries no additional obligations.
What does the EU AI Act ban outright?
Emotion recognition in the workplace and in education, social scoring, scraping facial images to build recognition databases, and exploiting vulnerabilities. These prohibitions have been in force since February 2025 and were not deferred. Penalties for them sit at the top of the scale.
Was the EU AI Act delayed, and what is still enforceable?
Only the high-risk chapter moved. The Digital Omnibus deferred high-risk obligations for systems already on the market to December 2027, while a new high-risk system brought to market has to comply now. The prohibitions, the AI literacy duty, the general-purpose AI rules and the Article 50 transparency obligations are all live.
Chapters
00:00 A Tuesday decision, a Friday liability
00:23 Why the loudest voices in AI are often the least qualified
01:20 Meet Jamal Ahmed
02:54 How a company takes on risk just by using ChatGPT
04:47 Why vendor due diligence stopped being enough
06:03 Article 25, the trapdoor clause
06:56 The Ford badge analogy
07:33 Rename it, rewire it, repurpose it
10:25 The four risk levels as a traffic light
11:50 One company, two tools, classified live
12:32 The practices banned outright
13:51 What the omnibus delayed, and what is live now
Sources
The EU AI Act
Regulation (EU) 2024/1689. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
The Digital Omnibus on AI
Regulation (EU) 2026/1744, in force 27 July 2026.
The clauses referenced in this episode
Article 4 on AI literacy, Article 5 on prohibited practices, Article 25 on responsibilities along the AI value chain, Article 50 on transparency, and Annex III on high-risk use cases.
Jamal Ahmed’s guide
The Easy Peasy Guide to the EU AI Act. amazon.co.uk/dp/1917534175