The European Union AI Act came into staged force in 2024 and 2025. Its provisions on prohibited practices, transparency obligations and the obligations applying to general-purpose AI models have applied for some months. The high-risk obligations, the most operationally consequential, are entering force on a longer schedule running through 2026 and 2027. For tennis operations based in the European Union, or operating significantly within it, the Act is no longer a forthcoming consideration. It is a present compliance frame.
The Act is also, in many specific applications to sport, contested in interpretation. The text of the Act is general; the application to pose estimation in a junior academy, or to performance modelling in a Tour-level operation, is a matter of interpretation that the formal guidance has not yet fully resolved. This piece sets out what is settled, what is open, and what European tennis operations should document starting now to be in defensible position when the high-risk obligations are fully operational.
The primary reference for the Act’s text remains the consolidated version maintained at the official AI Act tracking site. The Council of Europe has published adjacent guidance on AI in sport that provides useful colour, though it does not have the binding force of the Act itself. Where this article makes interpretive claims, it states them as interpretive — the reader should not treat any specific call as settled legal advice.
The four-tier classification
The Act classifies AI systems into four tiers: unacceptable risk (prohibited), high risk (extensive obligations), limited risk (transparency obligations), and minimal risk (no specific obligations). The relevant question for tennis operations is where the systems they deploy or build land in this classification.
Unacceptable risk is unlikely to apply to any common tennis-operations system. The prohibited categories — social scoring, manipulative subliminal techniques, exploitation of vulnerabilities — do not have natural analogues in tennis-operations practice.
High risk is where most of the interpretive work lies. The Act lists eight categories of high-risk systems. Two are potentially relevant: biometric categorisation systems and systems used in critical decision-making about education or employment-equivalent. The intersection with tennis operations is partial and contested.
Limited risk covers systems with transparency obligations — particularly systems that interact with humans, where users must be informed they are interacting with AI, and systems that generate or manipulate content. Some tournament-facing chatbots and some content-generation pipelines fall here.
Minimal risk is where most current tennis-operations AI sits. Match analysis tools used internally by coaches, scheduling solvers, club retention models, audience analytics. These systems do not have specific obligations under the Act in their current configurations.
When pose estimation becomes biometric
The most operationally important interpretive question concerns pose estimation, as described in the biomechanics article. The Act treats biometric categorisation — the use of biometric data to categorise natural persons into specific groups — as high-risk. The question is whether pose estimation from match video constitutes biometric categorisation.
The argument for treating it as biometric: the skeleton estimate is derived from the player’s physical body, and the categorisation (high-fatigue, low-fatigue, technique-A, technique-B) is a clustering of natural persons based on that biometric input. Read strictly, this is biometric categorisation as the Act defines it.
The argument for treating it as performance analytics: the system is not categorising the person as a person. It is measuring her output in a performance context, the same way a stopwatch measures her sprint time. The skeleton is incidental to the measurement, not the basis of identity classification.
The current preponderance of professional interpretation, surveyed in adjacent regulatory commentary at SportBusiness and in the Italian AI professionals association discussions, leans toward the second reading for performance-context pose estimation. The qualifier — performance-context — matters. Pose estimation used for the same player across a season, with output that drives selection or contractual decisions, sits closer to the biometric-categorisation reading. Pose estimation used for technique feedback within a single session, with output that does not leave the coaching room, sits clearly in the performance-analytics reading.
Most operations are somewhere between the two. The Act’s full guidance documents may resolve this. Until they do, the prudent course is to document the use case clearly and design the data flows so they do not accidentally cross into categorisation in ways the operation did not intend.
What documentation is required now
Three categories of documentation are worth starting now, regardless of where any specific system lands in classification.
Use-case documentation. A short written specification of what each AI system in the operation is used for, what decision it informs, who reads the output, and who is responsible for the decision. The specification is not a marketing document. It is the operational baseline that the operation can present to a regulator or an audit if asked.
Data flow documentation. A diagram or written description of where the data comes from, where it is stored, who has access, and how long it is retained. For player-data systems, this includes a mapping to GDPR retention principles. For systems that may be reclassified as biometric, the data flow documentation is the foundation of any later compliance work.
Override and audit logs. The decision-rights and override log described in the periodisation article is also, conveniently, the kind of audit trail the high-risk provisions of the Act require for systems used in significant decision-making about individuals. The operational discipline of maintaining the log is the same discipline that makes the future regulatory case manageable.
These three categories of documentation are cheap to start. They are expensive to retrofit after a system has been operational for several years. Operations starting now build the documentation forward; operations retrofitting later have to reconstruct it.
Player-data and the GDPR layer
The EU AI Act sits on top of the General Data Protection Regulation, which has been in force since 2018. The GDPR layer is the older regulatory frame and the one that most tennis operations have been compliant with in some form for years.
The interaction matters. A player’s match video is personal data. The pose-estimation output derived from it is personal data, and possibly special-category personal data (biometric) depending on use. The retention, sharing, and processing of this data must satisfy GDPR. The Act’s provisions add a layer above GDPR, not a replacement.
Operations that have done their GDPR work properly are partly ready. Operations that have been informal about player data — academy footage stored on shared drives, coaches with informal access to wellness data, no formal retention policy — have older problems that pre-date the Act. The Act enforcement may surface these older issues before its own specific provisions bite.
The transparency obligations
For some systems, the Act requires transparency to the human subject. A player whose performance is being analysed by an AI system has, in some readings, a right to know the system is being used. The interpretation varies by use case.
The cleanest interpretation, from current practice: players should be informed in writing that AI tools are part of the operation’s analytical work. The written notice does not need to detail every model and every output. It does need to be specific enough that the player understands the broad categories of analysis being done on her performance, her video, her load data.
In practice, this is a one-page addendum to the player agreement. The addendum names the categories — match-video analysis, training-load monitoring, scheduling optimisation, audience analytics — and describes in general terms what each does and how the data is handled. The player signs it as part of normal onboarding. The administrative burden is light. The compliance benefit is significant.
The Council of Europe’s guidance on AI in sport covers this kind of transparency framework, though again not with the binding force of the Act itself.
The federation case
National federations operating in the EU have particular obligations because their decisions — squad selection, scholarship allocation, regional ranking — have material consequences for individual players. AI systems that materially inform these decisions are closer to the high-risk category than systems used for coaching feedback alone.
A federation deploying the kind of normalised scoring layer described in the federation talent pipelines article should treat the documentation discipline as more rigorous than an academy deploying a coaching tool. The use-case specification should name the decision categories the system informs. The override and audit log should record cases where the system’s ranking was overridden by human selection committee.
The federation that has done this work has, simultaneously, built operational documentation that strengthens its decisions internally — the same documentation that protects it externally serves it operationally. The work is dual-use in the best sense.
What is open
Three categories of open interpretation are worth tracking.
The first concerns where the line falls between performance-context pose estimation and biometric categorisation. The Act’s specific guidance documents may resolve this. Until they do, operations should document conservatively.
The second concerns the obligations on AI-system providers versus AI-system deployers. A federation that deploys a vendor’s system has different obligations from the vendor itself. The vendor relationship contracts need to address this, and most current vendor contracts do not.
The third concerns enforcement. The Act provides for substantial fines. The pattern of enforcement — which sectors first, which use cases first, what evidence will trigger investigation — will become clearer over 2026 and 2027. Operations should not assume early enforcement focus on tennis; they should also not assume the sector is permanently off the radar.
The Athletic’s reporting on regulation in sport and SportBusiness regulatory features are the most useful trackers of how the enforcement landscape develops, though both will continue to be supplemented by formal guidance from the European Commission as it appears.
This work sits inside the broader ethics-and-trends thread of the coaching analytics and player development cluster.
What this means for your operation
Three implications.
First, the documentation work — use cases, data flows, override logs — is worth starting now regardless of where specific systems land in classification. The work is cheap to do forward and expensive to retrofit.
Second, the player transparency addendum is small effort and substantial value. Most operations can implement it in a single onboarding cycle. The communication itself, done well, builds trust with players rather than eroding it.
Third, federations operating in the EU should expect that their AI-informed decisions face higher scrutiny than academy-internal tools. The documentation rigour should match.
To scope a compliance baseline for your specific operation, book a 60-minute call. We will work through use-case documentation, data flow mapping, and the gap between current practice and where you should be by the time the high-risk provisions are fully operational.