Skip to content
Tekoälli

Cross-cutting

Rules and responsibility

What the law requires, what ethics requires, and what has to be written down.

On this page

Regulation is not a layer of its own; it cuts across all of them. A system can be technically faultless and still unlawful if it is used for the wrong decision, on the wrong material, or without telling the person involved what is happening. For an organisation adopting AI, the question worth answering is which category its own use falls into and what follows from that.

What matters in this area

  1. 01

    Obligations follow the use, not the technology

    The EU AI Act classifies systems by what they are used for. The same language model is close to unregulated in marketing copy and a high-risk system in recruitment.

  2. 02

    Using someone else's system still makes you responsible

    A deployer has obligations of its own even when somebody else built the model. Staff competence and telling customers what is going on are the deployer's job, not the vendor's.

  3. 03

    Some obligations are already in force

    Prohibited practices and the AI literacy requirement have applied since February 2025, and transparency obligations since August 2026. High-risk obligations were pushed further out in the summer of 2026.

  4. 04

    Ethics is not the same thing as law

    The law says what is forbidden. It does not say whether something is worth doing. Bias, copyright, environmental load and the changing shape of work are questions the Act does not answer.

  5. 05

    A written playbook is cheaper than sorting it out afterwards

    Writing down what may be fed in, who approves adoption and how an incident is handled costs a few working days. Not having it usually costs more than that.

A common misconception

AI Act
The EU regulation that classifies AI by the risk of its intended use and sets obligations accordingly.
High-risk system
A use of AI that the AI Act places in the category carrying the most obligations.
Provider
Whoever develops an AI system or places it on the market under their own name.
Deployer
An organisation that uses an AI system in its own operations.
Transparency obligation
The duty to say when a person is dealing with AI, or when content is artificial.
AI literacy
The duty to take measures that support the development of skills among those who use AI.
General-purpose AI model (GPAI)
A model that suits many tasks and that others build their own applications on top of.
Human oversight
A named person with the competence, the time and the authority to intervene in a decision the machine has made.
Fundamental rights impact assessment (FRIA)
An assessment made in advance of which human rights a high-risk system affects.
Bias
The model repeats the systematic differences in its material and carries them into decisions.

Articles on this topic

AI ethics without the sermon

Lists of principles settle nothing. Seven places where the harm actually happens, and the questions that turn them into decisions.

5 min

The AI Act: what applies, and when

The high-risk deadline moved in the summer of 2026, but most guides still quote the old dates. What an organisation using AI actually needs to know.

8 min