The regulatory approach that has emerged in most places writing AI law shares a common logic. Rather than regulating the technology, it regulates the application — sorting uses into tiers and attaching heavier obligations to the tiers where a mistake does more damage. The European Union's AI Act is the most developed example, and its structure has been widely echoed.
The tiers, in plain terms
At the top sit uses considered unacceptable and prohibited outright. Below that, a "high risk" band covering systems used in employment, education, credit, essential services, law enforcement and similar consequential decisions. These carry real obligations: risk management, documentation, data governance, human oversight, accuracy and robustness testing, and record-keeping.
Below that, a transparency tier — largely a requirement to tell people they are interacting with a machine, and to mark synthetic media. Everything else is essentially unregulated by the instrument.
The consequence people miss
The same model can sit in three tiers at once depending on deployment. A general-purpose language model used to draft marketing copy attracts almost nothing; the same model screening job applications is high risk. Obligations attach to the use, which means they attach to the deploying organisation as much as to the developer.
That is why "we just use the API" is not an answer to a compliance question. The company deciding what the output is used for carries obligations regardless of who trained the model.
Why it matters outside the jurisdictions writing it
Large vendors tend to build one compliance posture and apply it everywhere, because maintaining several is expensive. Documentation, model cards and transparency features produced for the strictest regime end up available to everyone. The practical effect is that rules written in one place shape products used everywhere — which is worth understanding whether or not your own regulator has written anything yet.