HS08

Europe classified your AI without telling you

A company buys software to sort job applications, a productivity gadget, it thinks. In Brussels, that exact use has just been filed under a category called high-risk, with its long list of obligations. No one warned the company. The law classified its AI the day it chose what to do with it.

AILawComplianceSeptember 9, 2026

The director does not think of themselves as concerned by the regulation of artificial intelligence. They built no model, they have no machine-learning engineers, they simply bought a tool that ranks CVs by relevance, or flags suspicious credit files. Ordinary software, in their eyes. What they do not know is that it is not the software that decides their legal fate, it is the use they put it to. And that precise use, screening people for a job or a loan, has been placed by the European regulation in its most demanding category, with no letter to announce it, no inspection to make it felt. The classification does not live in the code, it lives in the destination, and therein lies the whole matter.

Here is the thesis. The real move of the European regulation on artificial intelligence is not to regulate AI, it is to regulate it by use, not by technology. The same model, the same algorithm, is free as a spam filter and high-risk as a hiring filter. So you do not choose your risk class, your use case chooses it for you, silently and automatically. And because AI has slipped in everywhere, into recruitment tools, credit scoring, medical devices, safety components, thousands of firms that never called themselves AI companies find themselves bound by AI law, for adopting a use that crossed a line drawn without them.

The law does not regulate the knife, it regulates what you cut

The regulation builds a pyramid of risk. At the very top, a handful of uses are forbidden, deemed incompatible with fundamental rights. Below, high-risk uses carry a heavy apparatus of obligations, documentation, human oversight, bias testing, registration. Lower down, limited-risk uses owe only transparency, warning the user they are speaking to a machine. At the bottom, the vast majority of uses, free. But the decisive point is not the height of the pyramid, it is what the category clings to. It clings not to the technology, but to the use.

The forbidden uses give the measure of what Europe deems intolerable, the generalized social scoring of citizens by public power, certain forms of real-time mass biometric surveillance, techniques that manipulate by exploiting people's vulnerabilities. This top of the pyramid is not an abstraction, it draws a moral boundary, the one beyond which no economic usefulness redeems the use. In tracing this limit, the regulation asserts something rare, that certain applications of AI must not exist whatever the benefit, and that assertion, even more than the technical obligations imposed on high-risk uses, is the true political gesture of the text.

The right image is the knife. The law does not regulate the blade, it regulates what you cut with it. The same blade is a kitchen tool or a weapon depending on the hand that holds it and the target it faces. This choice makes the regulation technology-neutral, and therefore durable, it will not be struck obsolete when the next model arrives, and it aims at harm where it actually occurs, a chatbot is harmless as a game and dangerous as a medical adviser. But this choice carries a hidden price. The legal status of an AI ceases to be a property of its code and becomes a property of its context, and a context changes. Deploy the same system for a new purpose, and you have, without a single line of code altered, changed your legal obligations.

The regulation moreover does not only target those who build AI, it reaches those who deploy it. Whoever buys and puts into service an automated recruitment system, a credit-scoring tool, a biometric-identification device or a diagnostic aid takes on, as a user, part of the obligations, human oversight, data control, vigilance over bias. This is what makes the trap so quiet, it is enough to buy a tool and point it at a decision that affects people to become, without meaning to, the operator of a high-risk system. Responsibility follows not only the creator of the model, it follows the hand that uses it to settle the fate of an individual, and that hand is often a company that does not even know the regulation exists.

The AI Act does not regulate your AI, it regulates what you do with it. The same model is harmless as a spam filter and high-risk as a hiring filter. You do not choose your risk class, your use chooses it for you.

The flaw of the do-everything models

Regulating by use is a brilliant idea that carries its own instability, and here the analysis must go further than praise. The first problem is drift, a system can change category as its use slides, so a company can alter its legal obligations without even noticing, simply by finding a new job for its tool. The second is the border, the line between categories is contestable and will be litigated, each actor having an interest in defining its use as narrowly as possible to escape the higher class, opening a game of arbitrage over definitions. The third problem is the gravest, and it touches the very heart of the technology.

For the most powerful models, the general-purpose models, have no single use. They do a hundred things, they write, summarize, translate, code, advise, and by nature refuse to enter a box defined by purpose. The regulation therefore had to graft onto them a separate regime, an implicit admission that its central logic, classification by use, does not work for them. And this is the sharpest observation in the whole scheme, the most capable AI is precisely the one that resists classification by use, so the regulation's master idea weakens exactly where the stakes are highest. The law files specialized tools perfectly and finds itself helpless before generalist systems, which are the very ones whose power gives concern.

This game over definitions is anything but theoretical. A vendor may argue that its tool merely assists a human decision rather than taking it, to escape the high-risk category, or that it counts as mere entertainment where the real use touches health or employment. Each border of the pyramid thus becomes a terrain of legal qualification, where considerable stakes will play out, because falling on one side of the line or the other separates a light obligation from a heavy, costly compliance apparatus. AI law will therefore be, in good part, a law of the border, a permanent battle over which side of a line a use belongs on.

The filing cabinet and the fleeing substance

To these flaws is added the underlying debate, familiar since NIS2. The heavy obligations fall on companies that lack the means of the large technology players, which risks concentrating the ability to make compliant AI in a few hands and smothering the rest under documentation. Defenders reply that the harm targeted, the automated decision that affects a human life, deserves this care, and that a neutral, graduated framework is infinitely better than a blanket ban or a void. Both are right, and that is what makes the subject insoluble, one cannot at once protect without constraining and innovate without risk.

The very timetable of the regulation betrays this difficulty. It enters into application in waves, the forbidden uses first, then the obligations on general-purpose models, then, later still, the bulk of the requirements on high-risk uses, staggered over several years. This slow rollout tries to give companies time to adapt, but it also creates a moving target, because the categories, thresholds and guidance keep being clarified while actors are already trying to comply with them. Companies are asked to file themselves into boxes whose outlines are still shifting, and this regulatory instability adds to the technological one, as though the filing cabinet itself changed shape while one tries to place the folders in it.

There remains a question the text struggles to resolve, that of enforcement. How does a regulator know what use you actually put your AI to. The classification rests largely on the declaration of the actors themselves, on their honesty in recognizing which box they fall into. This is at once what makes the scheme applicable to tens of thousands of companies, no authority being able to inspect them one by one, and what weakens it, because the temptation to declare oneself in the lower, cheaper category will be constant. The regulation therefore bets on a largely voluntary compliance, backed by the threat of sanctions where a breach is exposed, a classic wager of the law, but a perilous one before a technology whose real use is so hard to observe from the outside.

But the deepest knot is neither cost nor concentration, it is temporal. A law that classifies by use assumes that uses are stable, legible, declarable. Yet the very nature of AI is to be reconfigurable, the same system performs a hundred tasks and its uses multiply faster than any classification can follow. The regulation is a filing cabinet built for a substance that refuses to stay in its folder. It faces a permanent race between its categories and the fluidity of what AI is used for, and the more powerful AI becomes, the more it slips between the boxes. The cabinet is solid, the substance is alive, and nothing guarantees the first keeps pace with the second.

You are already classified

The European AI regulation is a filing cabinet built for a substance that will not stay put. It orders uses in a world where AI's defining trait is to be repurposed faster than any category updates. Its bet is that one can govern AI by governing its uses, while AI's own nature is to invent uses beyond all counting. This bet is not absurd, it is brave, but it rests on a fragile assumption, that the map will keep up with the territory.

The open question is therefore not whether your AI is classified, it already is, from the day you chose what to do with it. It is whether a map drawn by use can keep pace with a technology whose genius is never to stay in its place. The director who bought a simple sorting tool may discover they operate a high-risk system, bound to obligations they never saw coming, not because their software changed, but because Brussels decided, without telling them, the meaning of what they were doing with it. In a world where use defines the law, to choose a tool is already, unknowingly, to choose a law.

There is, in this way of governing by use, a lesson that reaches beyond AI. It heralds a law that no longer attaches to objects but to intentions, not to what a thing is but to what one does with it, and which must therefore run endlessly after shifting practices. This is perhaps the only way to regulate versatile technologies, but it is also a law condemned to permanent discomfort, always one use behind, always forced to redraw its boxes. The AI Act is the first major text to take on this wager at such a scale, and its success or failure will tell whether one can truly hold in law what technology works to make ungraspable, or whether the map will forever stay one step behind the territory.

Further reading, the text of the European regulation on artificial intelligence, the European Commission's guidance on high-risk uses and on the general-purpose AI regime, and the legal analyses of its phased entry into application set out the actual content of the scheme.

In echo, AlgoPolis foundational article 11, the AI Act and the risk-based classification of systems, details the categories, obligations and timetable of the text.

Related articles
11

The EU AI Act and Liability for High-Risk Systems

The AI Act is a safety code, not a liability regime. Yet the withdrawal of the dedicated directive has made it, by default, the keystone of liability for artificial intelligence, and compliance with the regulation has become the new frontier of insurability.

EU AI ActAI
Read →
08

The NIS2 Directive and Its Insurance Implications

NIS2 does not mention insurance even once, and it does not directly regulate insurers. Yet by raising the cybersecurity baseline of fifteen to twenty thousand French entities and by making executives personally liable, this directive profoundly reshapes the risk that insurers underwrite.

NIS2Cyber Insurance
Read →
01

The Firm Facing Agentic AI

Cognitive labor substitution, organizational hyper-flattening and the emergence of new operational risks

Agentic AIOperational Risk
Read →
Editorials you might enjoy
HS05

NIS2, the directive no one has read but that binds you anyway

A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.

LawCyber
Read →
HS06

Why bosses insure themselves against their own decisions

A leader makes a decision, a merger, a launch, a restructuring. It fails, the shareholders lose money and sue them, personally. Their house, their savings are on the line. And yet they sleep soundly, because an insurance exists that covers them against the consequences of their own judgment.

Financial LinesFinance
Read →
Stay informed

Follow the research

One analysis with every new publication, on insurance, reinsurance, cyber and AI. No account, no noise.

No spam, one-click unsubscribe, no data ever sold.