Prohibited AI Practices
Certain AI practices are prohibited because of their unacceptable risks to individuals and society.
The EU AI Act introduces a risk-based regulatory framework for artificial intelligence systems and general-purpose AI models. Compliance depends on the system, intended purpose, regulatory role and deployment context.
The EU AI Act applies different obligations depending on the nature, risk profile and use of an AI system.
Certain AI practices are prohibited because of their unacceptable risks to individuals and society.
High-risk AI systems are subject to extensive governance, technical, documentation and lifecycle obligations.
Certain AI systems and AI-generated content require specific transparency and disclosure measures.
Providers of GPAI models have specific documentation, copyright, transparency and systemic-risk obligations.
Compliance responsibilities differ depending on whether an organization develops, provides, deploys, imports or distributes AI.
Compliance continues after deployment through monitoring, incident reporting, corrective actions and documentation updates.
Organizations responsible for high-risk AI systems may need to demonstrate compliance across multiple interconnected areas.
Establish and maintain an iterative AI risk management system.
Address data quality, relevance, representativeness and bias.
Maintain technical documentation demonstrating compliance.
Enable and retain appropriate system logs and records.
Ensure effective oversight, intervention and escalation.
Maintain appropriate accuracy, robustness and cybersecurity.
Organizations should maintain governance and evidence throughout the lifecycle of each relevant AI system.
Determine territorial scope, regulatory roles, prohibited practices and risk classification.
Identify applicable legal and operational obligations for the AI system and organization.
Document policies, procedures, technical evidence, governance controls and implementation records.
Complete conformity, declaration, CE marking and registration activities where required.
Monitor performance, risks, incidents, complaints and operational changes after deployment.
Track identified gaps, corrective actions and compliance improvements through completion.
The obligations that apply depend heavily on the role your organization performs in the AI value chain.
A structured assessment can help determine your regulatory role, system classification and priority compliance obligations.