The EU AI Act and what it means for Pakistan
یورپی AI ایکٹ اور پاکستان کے لیے اس کے اثرات
40 min read
Three ways to see it
The EU AI Act came into force in August 2024, with most obligations becoming binding in stages through 2025 and 2026. It is the world's first horizontal AI law. Its design idea is risk tiering. Every AI system sold or operated in the EU is sorted into one of four buckets: prohibited, high-risk, limited-risk, and minimal-risk. Each bucket has its own obligations. General-purpose AI models, the foundation models like GPT-class systems, sit in a fifth track with their own rules. Pakistan is not in the EU, but Pakistani exporters and BPOs serving EU customers are inside the scope.
Way one to read the Act: by what it bans outright. Real-time biometric surveillance of public spaces by law enforcement (with narrow exceptions). Social scoring of citizens by public bodies. Manipulation of vulnerable groups in ways that cause harm. Untargeted scraping of facial images from the internet to build recognition databases. Emotion recognition in workplaces and schools. These prohibitions reflect a European bet that some AI use cases damage democracy faster than they help. Pakistani projects copying these patterns directly will be excluded from EU markets and increasingly from Gulf markets that follow the EU line.
Way two: by what counts as high-risk. Annex III of the Act lists the high-risk areas: critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, administration of justice, and democratic processes. For systems in these areas, providers must run a conformity assessment, maintain a risk management system, ensure data governance, keep technical documentation, log usage, ensure transparency and human oversight, and meet accuracy and cybersecurity standards. A Pakistani fintech selling credit-scoring AI to a German neobank lands here.
Quick check
Quick check: what makes modern AI different from a rule-based program?
The why-tree
Why-tree level one: why risk tiers, not blanket rules? Because AI is too heterogeneous for one rule. The risk of a chatbot recommending a recipe and the risk of an algorithm scoring asylum applicants are not comparable. Tiering lets the law match weight of obligation to weight of consequence.
Try this with Claude
AI-edge prompt to try: 'Acting as an EU AI Act notified body auditor, ask me 10 probing questions to decide whether the AI system I describe is high-risk under Annex III. After my answers, give a verdict with citations to specific Annex III categories.' Treat the answer as a draft, not gospel.
Sources
Sources and further reading. Regulation (EU) 2024/1689 of the European Parliament and of the Council, the AI Act (eur-lex.europa.eu). European Commission, AI Act explanatory materials (digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai). Future of Life Institute, EU AI Act Implementation Tracker (artificialintelligenceact.eu). Bird and Bird LLP, EU AI Act guides 2024 to 2026 (twobirds.com). Lewis Silkin, AI Act timeline notes. Pakistan Software Houses Association (P@SHA) export readiness papers.