Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

EU AI Act compliance guide showing the four risk tiers and key obligations

The EU AI Act Explained: A Complete Compliance Guide

The EU AI Act is the world’s first comprehensive law governing artificial intelligence — and if your organization builds, sells, or even uses AI systems that touch the European market, it now sets the rules you play by. Formally Regulation (EU) 2024/1689, it entered into force on 1 August 2024 and applies in phases through 2027.

This guide explains what the EU AI Act is, who it applies to, how its risk-based approach works, the obligations it creates, the deadlines you need to plan around, and the practical steps to get compliant. Whether you develop AI in-house or simply deploy a third-party tool, this is your starting point.

EU AI Act compliance guide showing the four risk tiers and key obligations

What is the EU AI Act?

The EU AI Act is a horizontal regulation that governs how AI systems are developed, placed on the market, and used across the European Union. Rather than regulating the technology itself, it regulates risk: the same AI capability faces very different obligations depending on how it is used and who it could harm.

Because it is a regulation rather than a directive, it applies directly and uniformly in every EU member state — there is no national transposition to wait for. And like the GDPR before it, its reach is extraterritorial: a company headquartered anywhere in the world falls in scope if it places an AI system on the EU market or if the system’s output is used within the EU. In practice, that pulls a very large share of global AI vendors and enterprise adopters into its remit.

Who does the EU AI Act apply to?

The Act assigns obligations by role, not just by company. A single organization can hold more than one role at once, so the first step in any compliance effort is to map which hat you wear for each AI system.

  • Providers — those who develop an AI system (or have one developed) and place it on the market or put it into service under their own name or trademark. Providers carry the heaviest obligations.
  • Deployers — those who use an AI system under their own authority in a professional capacity. Most businesses adopting third-party AI are deployers, and they carry real duties of their own, including human oversight and using systems as instructed.
  • Importers and distributors — those who bring an AI system from outside the EU to the market, or make it available along the supply chain. They must verify that upstream compliance obligations have been met.
  • Product manufacturers — those who place an AI system on the market together with their product and under their own name.

A crucial and often-missed point: even if you only use AI rather than build it, you are a deployer and you have obligations. Assuming the Act is “a vendor problem” is one of the most common early mistakes.

The four risk categories

The Act sorts every AI system into one of four tiers. Your obligations flow almost entirely from which tier applies.

1. Unacceptable risk (prohibited)

A small set of uses is banned outright because they are considered a clear threat to people’s safety, livelihoods, and rights. These include social scoring by public authorities, manipulative or exploitative techniques that cause harm, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, and — with narrow law-enforcement exceptions — real-time remote biometric identification in publicly accessible spaces. These prohibitions have applied since February 2025.

2. High risk

This is the heart of the Act. AI systems are high-risk when they are used in sensitive domains — such as biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services, law enforcement, migration and border control, and the administration of justice — or when they act as a safety component of a regulated product. High-risk systems are not banned, but they face a demanding set of obligations before and after they reach the market.

3. Limited risk (transparency)

Some systems carry specific transparency duties. Chatbots must let people know they are interacting with a machine; AI-generated or manipulated content (including deepfakes) must be labelled as such; and where emotion-recognition or biometric-categorization systems are permitted, people must be informed they are exposed to them.

4. Minimal risk

The vast majority of AI systems — spam filters, recommendation engines, AI in video games — fall here and face no new mandatory obligations under the Act, though voluntary codes of conduct are encouraged.

Obligations for high-risk AI systems

If any of your systems land in the high-risk tier, this is where the real work sits. Providers of high-risk AI must, among other things:

  • Establish and maintain a risk management system across the entire lifecycle.
  • Apply strong data governance — training, validation, and testing data must be relevant, representative, and appropriately vetted for bias.
  • Produce and keep technical documentation demonstrating conformity.
  • Enable automatic record-keeping (logging) of events over the system’s lifetime.
  • Provide clear instructions for use so deployers can operate the system correctly.
  • Design for effective human oversight.
  • Achieve appropriate levels of accuracy, robustness, and cybersecurity.
  • Operate a quality management system, undergo the required conformity assessment, affix the CE marking, and register the system in the EU database.

Deployers of high-risk systems have their own duties too: using the system in line with instructions, ensuring meaningful human oversight, monitoring operation, keeping logs, and — in several cases — carrying out a fundamental rights impact assessment. Meeting these obligations is fundamentally a documentation and evidence exercise, which is exactly where a structured template set earns its keep.

General-purpose AI (GPAI) models

The Act also sets rules for general-purpose AI models — the large, adaptable models that power a wide range of downstream applications. All GPAI providers must maintain technical documentation, publish a sufficiently detailed summary of training content, and put a policy in place to respect EU copyright law. Models deemed to carry systemic risk (identified partly by the scale of compute used to train them) face additional duties, including model evaluation, systemic-risk assessment and mitigation, serious-incident reporting, and cybersecurity protection. These GPAI obligations began to apply in August 2025.

EU AI Act timeline and key deadlines

The Act applies in stages, so compliance is a roadmap rather than a single deadline:

  • 1 August 2024 — the Act enters into force.
  • 2 February 2025 — prohibitions on unacceptable-risk AI and AI-literacy obligations apply.
  • 2 August 2025 — governance rules and obligations for general-purpose AI models apply.
  • 2 August 2026 — the bulk of the Act applies, including obligations for high-risk systems listed in Annex III.
  • 2 August 2027 — obligations apply for high-risk AI that is a safety component of products already regulated under EU product-safety law.

The direction of travel is clear: the earliest, easiest wins (mapping your systems, stopping prohibited uses, building AI literacy) are already due, and the heavier high-risk obligations arrive in 2026–2027. Organizations that start their inventory and documentation now will not be scrambling later.

Penalties for non-compliance

The Act is enforced with GDPR-scale fines, tiered by the seriousness of the breach:

  • Up to €35 million or 7% of global annual turnover (whichever is higher) for breaching the prohibitions on unacceptable-risk AI.
  • Up to €15 million or 3% of turnover for breaching most other obligations, including the high-risk requirements.
  • Up to €7.5 million or 1% of turnover for supplying incorrect or misleading information to authorities.

Lower caps apply to SMEs and start-ups, but the message is unambiguous: this is a board-level compliance obligation, not a technicality.

How to prepare: a compliance roadmap

You do not need to solve everything at once. A pragmatic sequence looks like this:

  • Build an AI inventory. List every AI system you provide or deploy, including embedded third-party features.
  • Classify each system by risk tier and confirm your role (provider, deployer, or both).
  • Stop any prohibited uses immediately — these are already unlawful.
  • Close the gaps on high-risk systems: risk management, data governance, technical documentation, human oversight, logging, and a quality management system.
  • Assign accountability and raise AI literacy across the teams that build and use these systems.
  • Document everything. Conformity ultimately rests on the evidence you can produce.

Skip the blank page.

Our EU AI Act Toolkit gives you the risk assessments, technical-documentation templates, policies, and records you need to demonstrate conformity — fully editable in Word and Excel, mapped to the Act’s requirements.

Explore the EU AI Act Toolkit →

The EU AI Act and ISO 42001: better together

The EU AI Act tells you what you must achieve; ISO 42001, the international AI management system standard, gives you a management framework to achieve it repeatably. Building an AI Management System (AIMS) to ISO 42001 creates the governance structure, roles, risk processes, and documentation trail that map directly onto the Act’s high-risk obligations. For most organizations, the smartest path is to treat ISO 42001 as the operating system and the EU AI Act as the specific legal requirements it must satisfy. If you are weighing your options, our which toolkit do I need? guide can help you map obligations to the right starting point.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies to any provider that places an AI system on the EU market and to providers or deployers whose AI system output is used in the EU — regardless of where the company is based. Non-EU organizations serving European customers are squarely in scope.

What is the difference between a provider and a deployer?

A provider develops an AI system and places it on the market under its own name; a deployer uses an AI system under its own authority in a professional context. Providers carry the majority of obligations, but deployers still have duties such as human oversight and using the system as instructed.

Is ChatGPT or a general-purpose AI model covered?

Yes. General-purpose AI models have their own obligations — technical documentation, a training-content summary, and a copyright policy — with additional requirements for models judged to carry systemic risk. Those rules began applying in August 2025.

What are the penalties for breaching the EU AI Act?

Fines reach up to €35 million or 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for most other breaches, and up to €7.5 million or 1% for providing misleading information to authorities, whichever amount is higher.

When do I need to comply?

Prohibitions have applied since February 2025 and GPAI rules since August 2025. The bulk of the high-risk obligations apply from August 2026, with product-embedded high-risk systems following in August 2027. Starting your AI inventory and documentation now is the safest way to stay ahead.

How do I demonstrate compliance in practice?

Compliance rests on evidence: a documented risk management system, data governance records, technical documentation, logs, instructions for use, and a quality management system. A ready-made template set — such as our EU AI Act Toolkit — gives you that documentation structure out of the box so you can adapt rather than author from scratch.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.