The EU AI Act and the Two Classes

EU AI Act: a profile, EU stars and scales of justice beside four goals: a stronger single market, trustworthy AI, fundamental rights and innovation.

The EU names four official objectives for the EU AI Act: strengthening the internal market, promoting trustworthy AI, protecting fundamental rights and supporting innovation. That is how it presents itself. What the regulation actually distributes is best seen in a recent judgment.

Higher Regional Court of Hamm, May 12, 2026, case number 4 UKl 3/25. On the website of Aesthetify GmbH, an aesthetic medical practice, an AI chatbot answered patients’ questions and booked appointments. Asked about the managing directors’ qualifications, it invented three specialist medical titles that do not exist under Germany’s medical training regulations.

The Consumer Advice Centre of North Rhine-Westphalia brought a claim. The practice defended itself with two arguments: the chatbot was an independent third party whose statements could not be attributed to the company. And the hallucination had not been foreseeable; the bot had been fed correct data.

The court disagreed on both points. The chatbot is part of the business organization, not a third party. Its statements are directly attributable to the company, including hallucinations. Whether training was carried out carefully is irrelevant. An appeal to the Federal Court of Justice has been allowed.

Sixteen days later, reading the judgment, one sees an answer to a question the EU began asking with the AI Act in 2024, but did not answer. Who is liable when AI misleads?

The EU AI Act regulates how AI may be developed, sold and used in Europe. German case law fills in what it leaves open.

What the regulation actually does

113 articles, 13 annexes, 180 recitals. Entry into force on August 1, 2024. Full effect on August 2, 2027.

Before reading the risk classes, it is worth looking at the definition. Article 3(1) describes AI as

a machine-based system designed to operate with varying levels of autonomy and to exhibit adaptiveness after deployment, and which, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

Four characteristics: machine-based, autonomous to varying degrees, adaptive after it enters operation, and deriving outputs from inputs with an effect on a real or virtual environment.

The definition presupposes two things without proving them. First, that it is a machine. Second, that AI has neither consciousness nor initiative of its own. Anyone who defines AI as a machine regulates it like a product. Anyone defining a subject would have to talk about rights, not just obligations. The EU chooses the product logic.

Four risk classes.

On this definitional basis, the regulation sorts AI into risk classes.

Class 1: Unacceptable risk (Article 5). Eight configurations, prohibited since February 2025. Social scoring by public authorities. Manipulation below the threshold of consciousness. Exploiting vulnerabilities in children or people with disabilities. Predicting individual criminal offences based solely on profiling. Untargeted creation of facial recognition databases through scraping. Emotion recognition in workplaces and educational institutions. Biometric categorization based on sensitive characteristics. Real-time biometric identification in public spaces.

Class 2: High risk (Article 6, Annexes I and III). Strictly regulated, but permitted. AI in medical devices, recruitment and promotion, creditworthiness assessments, critical infrastructure, law enforcement and the justice system, and educational scoring. Obligations under Articles 8 to 21 and Article 26: CE marking, technical documentation, risk management, human oversight, logging and conformity assessment.

Class 3: Limited risk (Article 50). Labelling obligations where confusion may arise. Chatbots must identify themselves as AI. Deepfakes must be labelled. Emotion recognition in non-sensitive contexts must be disclosed.

Class 4: Minimal risk. No special obligations under the AI Act. Spam filters. AI opponents in video games. Simple recommendation systems.

The four risk classes of the EU AI Act, from top to bottom: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (transparency obligations), minimal risk (no special requirements).
The four risk classes of the EU AI Act, from top to bottom: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (transparency obligations), minimal risk (no special requirements).

The regulation takes the product logic as its foundation. Anyone regulating products regulates market access. What is not allowed into the market does not enter it. What is allowed in comes with obligations. Anyone who fails to fulfil them pays. Up to 7 percent of worldwide annual turnover for prohibited practices.

What the regulation does not do

It leaves the meaning of central terms open.

  • “Material impairment”, Article 5(1)(a). Not defined.
  • “Disproportionate harm”, Article 5(1)(c). Not defined.
  • “Significantly influence”, Article 6 and Annex III. Not defined.
  • “Reasonably foreseeable misuse”, Article 9. No threshold established.
  • “Substantial modification of an AI system”, Article 3(23). No threshold established.

The text of the regulation provides the shell. Interpretation comes later.

It comes from Court of Justice of the European Union case law. From national courts. From harmonized standards developed by CEN-CENELEC JTC 21, which have been under negotiation since 2021 and are still not all in place in 2026. From administrative practice. From associations writing position papers.

Whoever helps write the code writes the playing field

General-purpose AI models (GPAI) follow a logic of their own. Articles 51 to 56 regulate them. At 10^25 FLOPs of training compute, a model is considered to pose systemic risk. To put that in perspective: a modern Nvidia H100 delivers around 10^15 FLOPs per second. It would need 317 years for 10^25. In practice, tens of thousands of GPUs run in parallel for three to six months, at training costs of USD 100 million to 1 billion. GPT-4, Claude 3 Opus, Gemini Ultra, Llama 3 405B and Mistral Large 3 are above the threshold.

Those above it have additional obligations. Those below it still have basic obligations: documentation, copyright and a training-data summary.

The operational steering instrument is called the Code of Practice. Published on July 10, 2025. Signatories receive a presumption of compliance. The authority presumes that the obligations are met and does not examine every requirement individually. Those who do not sign must demonstrate each obligation separately.

As of May 2026, 26 providers have signed all three chapters in full: Transparency, Copyright, and Safety and Security. They include Anthropic, OpenAI, Microsoft, Google, Amazon, IBM, Mistral and Aleph Alpha. xAI has signed only the Safety and Security chapter. Meta has refused. Chinese providers are not among the signatories. From August 2, 2026, the Commission activates its full enforcement powers: audits, investigations and fines.

The code is negotiated between the European Commission, the AI Office and industry. The big players are represented there, with legal departments and public policy teams. Small providers, the open-source community and EU start-ups are effectively not at the table. The big players help shape the standards by which they will later be measured. They then sign a code that largely reflects their own practices and are compliant by definition.

Operationally, this is not regulatory protection but a mild form of regulatory capture.

The first risk: compliance as a fixed cost

The AI governance team a high-risk system needs consists of four senior roles. A compliance officer, a product owner, a data scientist and a legal expert. Plus a training budget, a monitoring budget and an implementation project.

The operational burden is the same everywhere. The capacity to carry it is not.

A DAX corporation spreads the costs across billions in revenue. A 50-person medium-sized company with EUR 3 million in revenue spreads them across EUR 3 million. A small business with fewer than ten people spreads them across its equity. The maximum fines are not the problem here. Seven percent of Meta amounts to billions. Seven percent of the medium-sized company is around EUR 200,000, manageable or not depending on revenue. The real weight lies elsewhere. Compliance documentation. Risk management. Technical documentation. Logging. Audits. Continuous monitoring. A lawyer’s billable hour versus a legal department.

Even in the lowest risk class, compliance is already a question of definition. AI literacy under Article 4 has been mandatory since February 2, 2025. It applies to providers and deployers across all classes, without exception. What “basic understanding” means in practice is difficult to say. An AI system changes faster than any curriculum. The definition comes from a logic in which competence can be tested like a construction plan. Living systems work differently. The regulation assumes an object, not a subject.

An obligation in the text. A promise in enforcement.

The two classes

AI is a democratizing technology. With LLMs and tools, individual citizens or tiny teams can reach a scale that once required corporations. Regulation takes back precisely this democratization. The compliance burden is a fixed cost, not a cost that scales.

The EU AI Act does not kill the technology. It kills the non-established user.

That is the first class. Those who can afford an AI governance team see competitive advantages in compliance. Proof of conformity in tenders. Audit readiness. Reputation protection. Consulting slides list seven such advantages. They sound convincing at first glance, but they do not apply to everyone.

The second class sees compliance as a question of survival. A person with a good idea, a programming environment and an LLM account pays the compliance burden out of a pittance, or abandons the idea, or does not bring it to the European market. As of May 2026, Mistral, with Mistral Large 3, is the only European frontier player in the LLM field. Heidelberg-based Aleph Alpha and Canada’s Cohere announced a USD 20 billion merger on April 24, 2026; regulatory completion is pending. The corporate world can withstand that. Medium-sized businesses do not exist at this scale.

Where this leaves smaller businesses

Anyone who understands the mechanism of the AI Act sees it beyond AI regulation too. Germany’s Federal Chancellor regularly asks why the German economy is not growing. Why people supposedly no longer want to work. Part of the answer lies in the same logic the EU AI Act makes visible. Anyone who regulates innovation before it emerges protects what already exists, not what is new. Anyone who places a block of fixed compliance costs in front of every market entry has already decided who can reach the market at all.

Where does that leave smaller businesses when the obligations scale as if they were corporations, but their shoulders do not?

These questions are not answered in the EU AI Act. But it reproduces the pattern. Germany has no social media platform of its own with global reach. No search engine of its own. No frontier LLM of its own any more since Aleph Alpha was acquired by Cohere. That is the consequence of a policy that protects what exists and regulates innovation, if not deliberately blocks it.

The concluding thesis

Democratic legislation stands or falls on whether the rules apply to everyone. Including those who write them. The EU AI Act punishes a private provider’s breach of duty more severely than state use of data justified on national security grounds. Military, defence and national security are entirely outside its scope under Article 2(3). Law enforcement is exempt from the transparency obligations under Article 50(1), (2) and (4). And under Article 99(8), each member state decides for itself whether public authorities can be fined at all. Private actors pay up to EUR 35 million or 7 percent.

Those who write the rules soften their application to themselves.

One thing should be kept in mind, though: whoever builds surveillance infrastructure does not build it for their own government. They build it for every future one. The infrastructure outlives the government that built it.

That is the imbalance.

In Germany, a good idea faces an uphill struggle. That is not a necessity but the result of political decisions. These decisions are not openly framed as protecting the established from the new, but as protecting citizens. Both can be true at the same time. Either way, the result is that regulation entrenches market positions.

Anyone who reads the EU AI Act and thinks only of compliance has understood one part. Anyone who reads it and thinks of playing fields has understood another.

The paper is here

This reading became a paper: “Der EU AI ACT, von außen gesehen”. Six chapters, 25 pages, with my annotations.

Sources, image credits and method

Case law

  • Higher Regional Court of Hamm, judgment of May 12, 2026, case no. 4 UKl 3/25 (Consumer Advice Centre of North Rhine-Westphalia v Aesthetify GmbH). Press release. Legal analysis in Legal Tribune Online.

Regulation text and Code of Practice

European competition, as of May 2026

  • Mistral AI overview: Wikipedia.
  • Cohere acquires Aleph Alpha, announced April 24, 2026, combined valuation USD 20 billion: TechCrunch.

Scholarly context

  • Shoshana Zuboff (2019): The Age of Surveillance Capitalism. Profile Books.
  • Bruce Schneier (2015): Data and Goliath. W.W. Norton.

Images (header, risk-class graphic)

  • Header image: concept and composition: Elfie Schürfeld-Todor. Image generation with ChatGPT based on my own briefing.
  • Risk-class graphic: concept and design: Elfie Schürfeld-Todor in collaboration with Claude and ChatGPT, based on Regulation (EU) 2024/1689.

Method

  • This article was created in collaboration with Claude. Specifically: my own reading of the regulation, my own positions, my own arguments. In exchange with the model, wording was refined, legal clarifications checked and sources verified.