The nine pages in the series
Nine rules, nine sourced pages
Each page takes one official text, states who it applies to, what it allows, what it does not, and links back to the source document.
The EU AI Act does not merely sort uses by level of risk: it rules eight of them out altogether. These are not uses to be «framed» with paperwork — no compliance file rescues them. This page takes each in turn, with the text as written, the real scope of each prohibition, and an example drawn from the guidelines published by the European Commission.
Since 2 August 2026, European law requires in principle that a person knows they are interacting with an artificial intelligence system. The announcement must be clear, accessible and made no later than the first interaction. This transparency replaces neither the identification of the trader nor the information owed on personal data.
An AI agent often processes personal data without that data sitting in a conventional file: voice, emails, prompts, call notes, tickets, customer history or a score can identify a person. The GDPR requires a purpose, a legal basis and safeguards to be defined before collection — and then proved to work.
An AI agent benefits from no exemption when it carries out direct marketing. The channel, the status of the person contacted and the source of their contact details determine the rule. Since 11 August 2026, telephone canvassing of consumers rests in principle on strict prior consent, and no longer on a check against Bloctel alone, the French opt-out register for telephone canvassing.
A sales agent may explain an offer, qualify a need or prepare a quotation. It may not invent a discount, hide an essential limitation, pile up follow-ups until the other party is worn down, or lock the customer into a journey they do not understand. Automation increases the risk of scale; it does not reduce the liability of the trader.
AI can search for a document, explain a general rule or prepare a file. It does not turn the organisation running it into an avocat, a doctor, an expert-comptable or a financial investment adviser. As soon as the answer applies law, medicine, accounting technique or financial advice to an individual situation, it must be checked whether the line into an activity reserved to a regulated profession has been crossed.
A text, an image or a message generated automatically can defame, insult, harass, steal an identity or mislead through a doctored image or recording. The rules and the liabilities differ according to the role of the organisation — publisher of its own output, hosting provider for third-party content, or platform. Moderation must be designed before publication, not improvised after a report.
Being technically able to reach a piece of content does not mean being allowed to copy it, extract it, train on it or republish it. An AI agent must respect copyright, the database maker’s right, privacy, image rights, personal data, contracts and trade secrets alike.
An AI system is not “high-risk” because it is powerful or generative. It becomes high-risk when it meets the criteria of Article 6 of the AI Act ↗(opens in a new tab), in particular for certain purposes listed in Annex III: recruitment, credit, access to essential services, biometrics, justice, migration or critical infrastructure. The timetable was amended in July 2026.