The EU AI Act for Engineers Who Just Want to Ship
You can read the EU AI Act as 400 pages of legal text, or you can read it as a triage system. For engineers the triage version covers most decisions you will actually face.
The law sorts AI systems by risk. A small set of uses is banned outright, social scoring, scraping faces off the internet for recognition databases, manipulation targeting vulnerable groups. If your product is not doing those, and it had better not be, the question becomes whether you are "high risk," and here is the part engineers miss: high risk is defined by use case, not by model size or cleverness. A tiny logistic regression screening job applicants is high risk. A frontier model writing marketing copy is not. The list of high risk domains is roughly the list you would guess, hiring, credit, education access, medical devices, critical infrastructure, law enforcement.
High risk means real homework. Risk management process, documented. Training data governance, documented. Logging sufficient to reconstruct why the system did what it did. Human oversight that can actually intervene, not a rubber stamp. Accuracy and robustness testing, documented. None of it is exotic, most of it is what a mature ML team half does already, the delta is doing it consistently and being able to show your work.
Below high risk, obligations get light. Transparency, mostly. If people are talking to a bot, they should know. If content is synthetic, it should be labeled.
The engineering takeaway that survives all the legal detail: keep records like you might be asked to justify the system later, because you might. Data lineage, eval results, decision logs. Teams that already have that discipline will find compliance annoying. Teams that don't will find it existential. Choose which team you're on before the deadline chooses for you.