The penalties are severe
Up to €35M or 7% of global annual turnover for prohibited practices, and €15M / 3% for other breaches — among the steepest in EU digital law. This is board-level risk.
The world's first comprehensive law for AI.
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive, risk-based law governing artificial intelligence. It sorts AI systems into risk tiers — from banned practices to high-risk systems with strict obligations, to light transparency duties — and its requirements scale with both the risk of the system and the role you play in the AI value chain.
The standard
EU AI Act — Regulation (EU) 2024/1689
Who needs it
Any organisation that builds, sells, deploys, imports or distributes AI systems touching the EU — whether you're a provider putting an AI product on the market or a company deploying a high-risk AI system (e.g. in hiring or credit decisions). Extraterritorial reach means non-EU companies are firmly in scope.
€35M
or 7% turnover — max penalty
The basics
The EU AI Act is a regulation, not a certification — you don't 'pass' it, you comply with it. It classifies every AI system by risk: a small set of practices are prohibited outright, a defined list of high-risk uses (in areas like employment, credit, education, biometrics and critical infrastructure) carry the bulk of the obligations, and most other AI faces only light transparency duties or none at all.
Your duties also depend on your role — provider, deployer, importer or distributor — with providers of high-risk systems carrying the heaviest load: a risk-management system, data governance, technical documentation, logging, human oversight, robustness and cybersecurity, a conformity assessment, CE marking and registration in an EU database. General-purpose AI (GPAI) models carry their own transparency, copyright and (at the largest scale) systemic-risk obligations.
It applies extraterritorially — to anyone placing AI on the EU market or whose AI output is used in the EU — and it lands in phases: prohibitions from February 2025, GPAI rules from August 2025, and most high-risk obligations from August 2026.
Why it matters
Up to €35M or 7% of global annual turnover for prohibited practices, and €15M / 3% for other breaches — among the steepest in EU digital law. This is board-level risk.
Prohibitions applied in Feb 2025 and GPAI rules in Aug 2025; the big high-risk obligations hit Aug 2026. Programmes started now avoid a scramble later.
Like GDPR before it, the AI Act is shaping AI governance worldwide. Getting ahead of it is a market signal to enterprise buyers that your AI is trustworthy.
Unacceptable (prohibited, Art. 5), high-risk (Art. 6 + Annex III), limited (transparency, Art. 50) and minimal — obligations scale with risk.
Articles 9–15: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity.
Provider, deployer, importer, distributor duties (Art. 16–27), plus conformity assessment, EU Declaration of Conformity, CE marking and EU-database registration.
Chapter V obligations for GPAI models — technical docs, copyright policy, training-data summary, and systemic-risk duties for the largest models.
The AI Act is mostly a documentation-and-process regime — technical files, risk assessments, a fundamental-rights impact assessment, post-market monitoring — that most teams have never produced. Working out which of the hundreds of obligations even apply to you, by role and risk tier, and then assembling the evidence by hand, is where AI-Act programmes stall.
Do it once, reuse it everywhere. Evidence you collect for EU AI Actis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps EU AI Act to your environment in a 30-minute walkthrough — and how much of it we handle for you.