Langprotect

EU AI Act Compliance

Understand how the EU AI Act classifies AI systems, what obligations apply to providers and deployers, and how organizations can build the security, governance, and oversight needed for compliant AI adoption.

Entered Into Force: August 2024Type: European Union RegulationScope: Artificial Intelligence Systems & General-Purpose AI Models
EU AI Act Compliance

What Is the EU AI Act?

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) establishes a harmonized legal framework for artificial intelligence across the European Union. It aims to promote human-centric and trustworthy AI while protecting health, safety, fundamental rights, democracy, the rule of law, and the environment.

The regulation follows a risk-based approach, applying different requirements depending on the potential risks associated with an AI system. Certain AI practices are prohibited, while high-risk systems face extensive requirements around risk management, data governance, documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity.

The Act also introduces transparency obligations for certain AI systems and specific requirements for general-purpose AI (GPAI) models.

For organizations developing or using AI, compliance therefore begins with understanding which systems are in scope, how they are classified, and which obligations apply to their role in the AI value chain.

What Does the EU AI Act Require?

The EU AI Act establishes requirements based on the risk and intended use of an AI system. The following areas summarize key obligations under the regulation.

Article 4

AI Literacy

Providers and deployers must take measures to ensure an appropriate level of AI literacy among relevant staff and others using AI on their behalf.

Article 5

Prohibited AI Practices

Prohibits specified AI practices considered to pose unacceptable risks to individuals and society.

Article 6 + Annex I & III

High-Risk Classification

Defines when AI systems are considered high risk based on their role in regulated products or specified high-risk use cases.

Article 9

Risk Management

Establish a continuous and iterative risk-management system covering the lifecycle of high-risk AI systems.

Article 10

Data & Data Governance

Establish appropriate data-governance and management practices for training, validation, and testing data used by high-risk AI systems.

Article 11

Technical Documentation

Maintain technical documentation demonstrating how applicable requirements are addressed.

Article 12

Record Keeping

Enable automatic logging of events throughout the operation of high-risk AI systems to support traceability.

Article 13

Transparency & Information

Provide deployers with information necessary to understand the capabilities, limitations, and appropriate use of high-risk AI systems.

Article 14

Human Oversight

Design high-risk AI systems to allow effective human oversight and intervention appropriate to the risks involved.

Article 15

Accuracy, Robustness & Cybersecurity

Ensure appropriate levels of accuracy, robustness, and cybersecurity throughout the lifecycle of high-risk AI systems.

Article 50

AI-Generated Content Transparency

Establish transparency requirements for certain AI-generated or manipulated content and interactions with AI systems.

Articles 53–55

GPAI Obligations

Establish requirements for general-purpose AI model providers, including documentation, copyright policies, training-content summaries, and additional measures for systemic-risk models.

EU AI Act at a Glance

Get a quick overview of the EU AI Act, including its scope, risk-based approach, and phased application. Understand the key roles, risk categories, and obligations shaping AI governance in the European Union.

REGULATIONRegulation (EU) 2024/1689
JURISDICTIONEuropean Union
ENTERED INTO FORCEAugust 1, 2024
REGULATOREuropean Commission, EU AI Office & National Competent Authorities
APPROACHRisk-Based AI Regulation
RISK CATEGORIESProhibited, High Risk, Transparency, Minimal/No Risk
KEY SCOPEAI Systems & General-Purpose AI Models
HIGH-RISK ANNEXESAnnex I & Annex III

Who Should Consider EU AI Act Compliance?

The EU AI Act can apply to organizations both inside and outside the European Union depending on their role, activities, and connection to AI systems placed on the EU market or used in the Union.

AI Developers & Providers

AI Developers & Providers

Organizations developing AI systems or placing AI systems on the EU market under their name or trademark.

AI Deployers

AI Deployers

Organizations using AI systems under their authority for business, operational, or other professional purposes.

GPAI Providers

GPAI Providers

Organizations developing or placing general-purpose AI models on the EU market and subject to the Act's GPAI requirements.

Enterprise AI Users

Enterprise AI Users

Organizations deploying third-party AI applications, copilots, agents, or AI-powered platforms across internal workflows.

Regulated Organizations

Regulated Organizations

Organizations using AI in areas such as healthcare, education, employment, critical infrastructure, law enforcement, migration, or access to essential services.

Global Technology Companies

Global Technology Companies

Organizations outside the EU whose AI systems, products, or outputs fall within the Act's territorial scope.

EU AI Act Readiness Checklist

Create an inventory of AI systems and applications
Identify your organization's role for each AI system
Determine which systems fall within the Act's scope
Classify systems according to their applicable risk category
Identify prohibited AI practices and prevent their use
Assess whether systems qualify as high risk under Article 6 and the relevant Annexes
Establish AI risk-management processes for applicable high-risk systems
Review data governance and data-quality practices
Maintain appropriate technical documentation
Enable appropriate logging and traceability
Establish transparency and information practices
Implement appropriate human-oversight mechanisms
Evaluate AI accuracy, robustness, and cybersecurity
Review third-party AI models, applications, and components
Assess GPAI obligations where applicable
Implement applicable AI-generated-content transparency measures
Establish post-deployment monitoring and incident-management processes
Maintain appropriate AI literacy practices
Track regulatory guidance, standards, and applicable deadlines

How the EU AI Act Fits Into the AI Compliance Landscape

The EU AI Act provides legally binding requirements for AI within its scope. Organizations often need to implement it alongside standards and frameworks covering AI governance, privacy, information security, and risk management.

ISO/IEC 42001

ISO/IEC 42001

ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System (AIMS). Organizations can use it to structure AI governance, policies, responsibilities, risk management, and continual improvement alongside their EU AI Act obligations.

NIST AI Risk Management Framework

NIST AI Risk Management Framework

NIST AI RMF provides a voluntary approach to identifying and managing AI risks through Govern, Map, Measure, and Manage. It can complement the AI Act by providing practical risk-management processes.

GDPR

GDPR

GDPR governs the processing and protection of personal data in the European Union. AI systems may need to comply with both GDPR and the AI Act where they process personal data.

ISO/IEC 23894

ISO/IEC 23894

ISO/IEC 23894 provides guidance for managing risks associated with AI. It can complement the AI Act's risk-management requirements.

SOC 2

SOC 2

SOC 2 evaluates controls related to areas such as security, availability, processing integrity, confidentiality, and privacy. It can complement AI Act compliance by providing assurance around broader organizational controls.

Frequently Asked Questions