A chatbot giving you a wrong recipe is an inconvenience. A model deciding whether you get the job, the loan, the visa, or a police visit is a different category, and the law has started to treat it that way.
Why these three keep appearing
Hiring, lending and policing share features that make automation both attractive and dangerous.
They are high volume — thousands of decisions, so even small per-decision savings are large. They involve scarce goods — one job, limited credit. They have long feedback loops — you learn whether a hire was good in a year, whether a loan was good in five. And crucially they are self-confirming: reject someone and you never learn whether you were right. The model's mistakes never come back to correct it. Only its accepted cases generate data, so it gets more confident about the group it already favours.
Policing adds the sharpest version. Predict more crime in a district, send more officers, they record more incidents, that becomes training data showing more crime in that district. The loop closes and tightens, and what it measures is police attention, not crime.
What "high risk" means in the EU AI Act
The EU AI Act, in force since 2024 with obligations phasing in through 2026 and 2027, sorts systems by risk rather than by technology.
Prohibited. A short list, banned outright: social scoring by public authorities, exploiting vulnerabilities of children or disabled people, untargeted scraping of facial images to build recognition databases, and emotion recognition in workplaces and schools. Real-time remote biometric identification in public spaces is banned for law enforcement with narrow, authorised exceptions.
High risk. This is the important tier, and it is defined by *use*, not by how clever the model is. A simple scoring formula used for hiring is high risk. A sophisticated model used to recommend films is not. The listed areas include employment (recruitment, promotion, termination), access to essential services including credit scoring, education access and grading, law enforcement, migration and border control, and administration of justice.
High-risk systems carry real obligations: risk management, data governance including examination for bias, technical documentation, logging, accuracy and robustness requirements, human oversight designed in, and registration in an EU database. Penalties reach into the tens of millions of euros or a percentage of global turnover.
The Act reaches beyond Europe. If your system's output is used in the EU, it applies, wherever you sit.
India: a different shape
India has no AI Act. The relevant instruments are the Information Technology Act, 2000 with the IT Rules, 2021 (amended since), and the Digital Personal Data Protection Act, 2023.
The IT Rules govern intermediaries — platforms — with due diligence duties, grievance officers, takedown timelines, and traceability requirements for large messaging services. In 2025 the government moved to require labelling of synthetically generated information carried by platforms. The DPDP Act governs personal data: notice, consent, purpose limitation, and rights to access, correction and erasure.
So the Indian approach regulates the *data* and the *platform* rather than the *model*, and advisories have carried more weight in practice than statute. Note also the DPDP Act's absence of a general automated-decision provision comparable to the GDPR's Article 22 — which is the clause giving Europeans a right not to be subject to purely automated decisions with legal or similarly significant effects, and a right to obtain human intervention.
What to actually do
If a decision about you was automated, three questions are worth asking in writing: *Was this decision made by an automated system? What information about me was used? How do I request human review?* In the EU, and increasingly elsewhere, an organisation has to answer. Even where it does not, the questions on record change how the conversation goes.
If you build such a system, the human oversight requirement is where most implementations quietly fail. A human who approves 200 recommendations an hour is not oversight; they are a rubber stamp with a job title. Oversight means the reviewer has the information, the time and the actual authority to disagree — and that someone tracks how often they do.
Before you move on