EU AI Act
Who needs it
Any organization that provides or deploys AI systems whose output is used within the EU, with obligations scaling sharply based on which risk tier your specific AI system falls into.
Key requirements
Risk-tier classification for every AI system in scope, and for high-risk systems specifically: a risk management system, data governance controls, technical documentation, human oversight mechanisms, and a conformity assessment before market placement.
Cyber/privacy implications
Technical documentation and human-oversight requirements mean AI system architecture decisions, logging, and approval gates need to be defensible to a regulator, not just to your own engineering team.
Assessment methodology
AI system inventory and risk-tier classification against the Act's defined categories, gap assessment against applicable obligations for your tier, and a phased compliance roadmap matched to the Act's staggered deadlines.
Implementation phases
Classify
Inventory AI systems and classify each against the Act's risk tiers.
Remediate
Build risk management, documentation, and human-oversight controls for high-risk systems.
Sustain
Ongoing conformity assessment and monitoring as systems and deadlines evolve.
Evidence & documentation requirements
AI system risk-tier classification records, technical documentation for high-risk systems, human-oversight process documentation, and conformity assessment records where required.
Common mistakes
Assuming a system is low-risk without a documented classification exercise, which leaves no defensible record if a regulator disagrees; missing that obligations phase in on different dates depending on the requirement, prohibited-practice bans, GPAI obligations, and high-risk system obligations each have separate deadlines.
Related standards
Expert review
FAQ
Request an AI Governance Readiness Check
Classify your AI systems against the Act's risk tiers before a regulator does it for you.
Request a Readiness Check →