EU AI ACT

Understand your obligations under Regulation (EU) 2024/1689.

The EU AI Act introduces a risk-based regulatory framework for artificial intelligence systems and general-purpose AI models. Compliance depends on the system, intended purpose, regulatory role and deployment context.

RISK-BASED REGULATION

Not every AI system is regulated in the same way.

The EU AI Act applies different obligations depending on the nature, risk profile and use of an AI system.

01

Prohibited AI Practices

Certain AI practices are prohibited because of their unacceptable risks to individuals and society.

02

High-Risk AI Systems

High-risk AI systems are subject to extensive governance, technical, documentation and lifecycle obligations.

03

Transparency Obligations

Certain AI systems and AI-generated content require specific transparency and disclosure measures.

04

General-Purpose AI

Providers of GPAI models have specific documentation, copyright, transparency and systemic-risk obligations.

05

Deployers & Providers

Compliance responsibilities differ depending on whether an organization develops, provides, deploys, imports or distributes AI.

06

Continuous Compliance

Compliance continues after deployment through monitoring, incident reporting, corrective actions and documentation updates.

HIGH-RISK AI

Core requirements for high-risk AI systems.

Organizations responsible for high-risk AI systems may need to demonstrate compliance across multiple interconnected areas.

01

Risk Management

Establish and maintain an iterative AI risk management system.

02

Data Governance

Address data quality, relevance, representativeness and bias.

03

Documentation

Maintain technical documentation demonstrating compliance.

04

Record-Keeping

Enable and retain appropriate system logs and records.

05

Human Oversight

Ensure effective oversight, intervention and escalation.

06

Security & Performance

Maintain appropriate accuracy, robustness and cybersecurity.

COMPLIANCE LIFECYCLE

EU AI Act compliance is not a one-time exercise.

Organizations should maintain governance and evidence throughout the lifecycle of each relevant AI system.

1. Scope & Classification

Determine territorial scope, regulatory roles, prohibited practices and risk classification.

2. Requirements Assessment

Identify applicable legal and operational obligations for the AI system and organization.

3. Evidence & Controls

Document policies, procedures, technical evidence, governance controls and implementation records.

4. Conformity & Registration

Complete conformity, declaration, CE marking and registration activities where required.

5. Monitoring

Monitor performance, risks, incidents, complaints and operational changes after deployment.

6. Remediation

Track identified gaps, corrective actions and compliance improvements through completion.

YOUR REGULATORY ROLE MATTERS

Provider, deployer, importer, distributor or GPAI provider?

The obligations that apply depend heavily on the role your organization performs in the AI value chain.

Provider Organizations developing or placing AI systems on the market under their name or trademark.
Deployer Organizations using AI systems under their authority in professional activities.
Importer / Distributor Organizations making third-party AI systems available within the Union market.
GPAI Provider Providers of general-purpose AI models subject to dedicated model-level obligations.
START WITH APPLICABILITY

Find out which EU AI Act requirements apply to your AI system.

A structured assessment can help determine your regulatory role, system classification and priority compliance obligations.