Course Content
AI Safety & Guardrails
5 sections · 50 lessons
How do emerging regulations impact AI development practices?
What you need to know
EU AI Act risk tiers
| Tier | Examples | Obligations |
|---|---|---|
| Unacceptable (banned) | Social scoring; manipulation that exploits vulnerabilities; untargeted scraping of face images to build databases; emotion recognition at work or school (with narrow exceptions) | Prohibited |
| High-risk | AI in hiring and worker management, credit scoring, access to essential services, education, critical infrastructure, law enforcement, migration; AI in regulated products like medical devices | Risk management, data governance, technical documentation, automatic logs, human oversight, accuracy and robustness, conformity assessment, registration |
| Limited risk (transparency) | Chatbots, deepfakes, AI-generated content | Tell people they are talking to AI; label deepfakes; mark synthetic content in a machine-readable way |
| Minimal risk | Spam filters, game AI | No new obligations |
General-purpose AI (GPAI) models have their own duties: technical documentation, a copyright policy, and a public summary of training content. Models above a compute threshold (presumed at 10^25 training FLOPs) are treated as having systemic risk and must also do evaluations and adversarial testing, report serious incidents and ensure cybersecurity. A voluntary Code of Practice published in 2025 describes how to meet these.
Timeline (check before quoting): the Act entered into force in August 2024; prohibitions applied from February 2025; GPAI duties from August 2025; most high-risk duties were scheduled for August 2026, with product-embedded systems later. In late 2025 the Commission proposed delaying some high-risk deadlines. Always check the current dates. Penalties for prohibited practices can reach 7% of global annual turnover.
Other rules
- GDPR and India's DPDP Act 2023 for personal data.
- US: no single federal AI law; state and city rules such as New York City's bias-audit law for automated hiring tools and Colorado's AI Act for high-risk decisions (whose start date has already been pushed back). Federal policy has shifted between administrations.
- India: no dedicated AI statute; MeitY's AI governance guidelines, sector regulators such as the RBI, and changes to the IT Rules on labelling synthetic content.
- Sector rules: medical-device rules, financial suitability and lending rules.
Capabilities that transfer across laws
- Data inventory with provenance and lawful basis.
- Automatic, retained decision logs.
- Versioned models, prompts, datasets and indexes.
- A designed human-oversight point.
- Per-decision explanations and an appeal route.
- Labelling of AI-generated content and AI interactions.
A real-life example
An Indian HR-tech startup sells an AI screening assistant to employers, including three in Germany. Under the EU AI Act, AI used to filter job applications is high-risk, and the startup is the provider. The employers are deployers with their own duties, such as assigning trained people to oversee the tool.
The startup's roadmap changes: a risk-management file per release; documented training-data sources and bias testing; automatic logs of every score with model and prompt versions; a recruiter-facing explanation of each score; a "human decides" design where the tool ranks but never rejects; and technical documentation for conformity assessment. Most of this also helps with New York City's bias-audit rule for a US prospect, and with DPDP for Indian clients.
Follow-up questions to expect
- "Does the EU AI Act apply to a company outside the EU?" — Yes, if it places an AI system on the EU market or its output is used in the EU.
- "What is the difference between a provider and a deployer?" — The provider develops the system and places it on the market; the deployer uses it under its own authority. Providers carry most high-risk obligations; deployers have duties like human oversight and monitoring.
- "Is a general chatbot high-risk?" — Usually not; it has transparency duties. It becomes high-risk if used for a listed purpose such as screening job applicants.