The EU AI Act is a risk-tiered rulebook for systems that infer, recommend, or generate. If you ship a product used in the Union — including a Turkish studio selling into Europe, which we do — it is not optional reading for counsel. It changes what you log, what you disclose, and which features you are allowed to turn on by default.
We treat it the way we already treat KVKK and GDPR: a constraint on architecture. The lawyers tell us the tier. Engineering makes the tier true in code. A “limited risk” chatbot that quietly starts scoring job applicants is no longer limited risk, no matter what the landing page says.
Classify the feature, not the company
Gidysoft as a studio is not “high-risk”. A specific feature can be. An EduPick placement test that decides a child’s school track is a different conversation from a Limy copy assistant that rewrites a heading. We keep a living inventory: feature name, purpose, data in, human oversight, and the Act tier we claim. If the inventory and the code disagree, the inventory is wrong — and that is a bug.
Logging that would survive an audit
For anything above minimal risk we store model version, prompt template hash, retrieved document IDs, and the operator who overrode a suggestion. We do not store raw learner essays longer than we must. Retention is a product decision with a delete job, not a folder called ai-logs-final-FINAL.
Human oversight is a UI problem
The Act’s “human in the loop” fails when the override is a tiny checkbox under a wall of generated text. Our rule: high-impact actions render as a draft the human must accept, with the model’s confidence and sources visible. If the reviewer rubber-stamps, the design failed — we measure override rate the same way we measure conversion.
Questions we keep getting
Does a general SaaS chatbot need a conformity assessment? Usually no, if it is limited risk and you disclose it. The moment it makes a consequential decision about a person, get counsel and freeze the feature until the inventory is updated.
We are in Izmir — does this apply? If EU users are in scope, yes. Market location follows the user, not the office.
What is the first engineering ticket? The inventory table and a kill switch per AI feature. Everything else is detail.