AI Safety & Guardrails

Course Content

AI Safety & Guardrails

5 sections · 50 lessons

How do emerging regulations impact AI development practices?


EU AI Act risk tiersMinimal: spamfilters, no new dutiesLimited:chatbots must discloseHigh-risk:hiring, credit, medicalUnacceptable:banned outrighttopbottomGeneral-purpose models carry separate duties on top of these tiers.
The same model can sit in different tiers depending on use — a chatbot is limited risk until it screens job applicants.

What you need to know

EU AI Act risk tiers

TierExamplesObligations
Unacceptable (banned)Social scoring; manipulation that exploits vulnerabilities; untargeted scraping of face images to build databases; emotion recognition at work or school (with narrow exceptions)Prohibited
High-riskAI in hiring and worker management, credit scoring, access to essential services, education, critical infrastructure, law enforcement, migration; AI in regulated products like medical devicesRisk management, data governance, technical documentation, automatic logs, human oversight, accuracy and robustness, conformity assessment, registration
Limited risk (transparency)Chatbots, deepfakes, AI-generated contentTell people they are talking to AI; label deepfakes; mark synthetic content in a machine-readable way
Minimal riskSpam filters, game AINo new obligations

General-purpose AI (GPAI) models have their own duties: technical documentation, a copyright policy, and a public summary of training content. Models above a compute threshold (presumed at 10^25 training FLOPs) are treated as having systemic risk and must also do evaluations and adversarial testing, report serious incidents and ensure cybersecurity. A voluntary Code of Practice published in 2025 describes how to meet these.

Timeline (check before quoting): the Act entered into force in August 2024; prohibitions applied from February 2025; GPAI duties from August 2025; most high-risk duties were scheduled for August 2026, with product-embedded systems later. In late 2025 the Commission proposed delaying some high-risk deadlines. Always check the current dates. Penalties for prohibited practices can reach 7% of global annual turnover.

Other rules

  • GDPR and India's DPDP Act 2023 for personal data.
  • US: no single federal AI law; state and city rules such as New York City's bias-audit law for automated hiring tools and Colorado's AI Act for high-risk decisions (whose start date has already been pushed back). Federal policy has shifted between administrations.
  • India: no dedicated AI statute; MeitY's AI governance guidelines, sector regulators such as the RBI, and changes to the IT Rules on labelling synthetic content.
  • Sector rules: medical-device rules, financial suitability and lending rules.

Capabilities that transfer across laws

  • Data inventory with provenance and lawful basis.
  • Automatic, retained decision logs.
  • Versioned models, prompts, datasets and indexes.
  • A designed human-oversight point.
  • Per-decision explanations and an appeal route.
  • Labelling of AI-generated content and AI interactions.

A real-life example

An Indian HR-tech startup sells an AI screening assistant to employers, including three in Germany. Under the EU AI Act, AI used to filter job applications is high-risk, and the startup is the provider. The employers are deployers with their own duties, such as assigning trained people to oversee the tool.

The startup's roadmap changes: a risk-management file per release; documented training-data sources and bias testing; automatic logs of every score with model and prompt versions; a recruiter-facing explanation of each score; a "human decides" design where the tool ranks but never rejects; and technical documentation for conformity assessment. Most of this also helps with New York City's bias-audit rule for a US prospect, and with DPDP for Indian clients.

Follow-up questions to expect

  • "Does the EU AI Act apply to a company outside the EU?" — Yes, if it places an AI system on the EU market or its output is used in the EU.
  • "What is the difference between a provider and a deployer?" — The provider develops the system and places it on the market; the deployer uses it under its own authority. Providers carry most high-risk obligations; deployers have duties like human oversight and monitoring.
  • "Is a general chatbot high-risk?" — Usually not; it has transparency duties. It becomes high-risk if used for a listed purpose such as screening job applicants.