All frameworks
EURegulation · risk-based

EU AI Act compliance

The world's first comprehensive law for AI.

The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive, risk-based law governing artificial intelligence. It sorts AI systems into risk tiers — from banned practices to high-risk systems with strict obligations, to light transparency duties — and its requirements scale with both the risk of the system and the role you play in the AI value chain.

Start from the basics

The standard

EU AI Act — Regulation (EU) 2024/1689

Who needs it

Any organisation that builds, sells, deploys, imports or distributes AI systems touching the EU — whether you're a provider putting an AI product on the market or a company deploying a high-risk AI system (e.g. in hiring or credit decisions). Extraterritorial reach means non-EU companies are firmly in scope.

€35M

or 7% turnover — max penalty

The basics

What is EU AI Act?

The EU AI Act is a regulation, not a certification — you don't 'pass' it, you comply with it. It classifies every AI system by risk: a small set of practices are prohibited outright, a defined list of high-risk uses (in areas like employment, credit, education, biometrics and critical infrastructure) carry the bulk of the obligations, and most other AI faces only light transparency duties or none at all.

Your duties also depend on your role — provider, deployer, importer or distributor — with providers of high-risk systems carrying the heaviest load: a risk-management system, data governance, technical documentation, logging, human oversight, robustness and cybersecurity, a conformity assessment, CE marking and registration in an EU database. General-purpose AI (GPAI) models carry their own transparency, copyright and (at the largest scale) systemic-risk obligations.

It applies extraterritorially — to anyone placing AI on the EU market or whose AI output is used in the EU — and it lands in phases: prohibitions from February 2025, GPAI rules from August 2025, and most high-risk obligations from August 2026.

Why it matters

What EU AI Act does for your business

The penalties are severe

Up to €35M or 7% of global annual turnover for prohibited practices, and €15M / 3% for other breaches — among the steepest in EU digital law. This is board-level risk.

The clock is already running

Prohibitions applied in Feb 2025 and GPAI rules in Aug 2025; the big high-risk obligations hit Aug 2026. Programmes started now avoid a scramble later.

It's becoming the global benchmark

Like GDPR before it, the AI Act is shaping AI governance worldwide. Getting ahead of it is a market signal to enterprise buyers that your AI is trustworthy.

What it covers

Four risk tiers

Unacceptable (prohibited, Art. 5), high-risk (Art. 6 + Annex III), limited (transparency, Art. 50) and minimal — obligations scale with risk.

High-risk requirements

Articles 9–15: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity.

Roles & conformity

Provider, deployer, importer, distributor duties (Art. 16–27), plus conformity assessment, EU Declaration of Conformity, CE marking and EU-database registration.

General-purpose AI

Chapter V obligations for GPAI models — technical docs, copyright policy, training-data summary, and systemic-risk duties for the largest models.

The hard way

The AI Act is mostly a documentation-and-process regime — technical files, risk assessments, a fundamental-rights impact assessment, post-market monitoring — that most teams have never produced. Working out which of the hundreds of obligations even apply to you, by role and risk tier, and then assembling the evidence by hand, is where AI-Act programmes stall.

The easier way, with Compliance One

  • Ships a full, 360° control library covering every Article and Annex — with each obligation tagged by role, risk tier and GPAI applicability, so you only work the controls that apply to you.
  • Separates the clear, ready-to-implement obligations from those needing a legal-review call, and lets you promote them into your Statement of Applicability once confirmed.
  • Pre-fills the mandatory documents — technical documentation (Annex IV), Declaration of Conformity, FRIA, quality management system, post-market monitoring plan and more.
  • Cross-maps to your ISO 42001 and ISO 27001 work, so evidence you already have counts toward the AI Act instead of starting over.

Do it once, reuse it everywhere. Evidence you collect for EU AI Actis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is the EU AI Act a certification?
No — it's a law you comply with, not a certificate you earn. For high-risk systems you run a conformity assessment (often internal), draw up a Declaration of Conformity, CE-mark the system and register it in the EU database. Compliance One structures all of that and stores the evidence.
When does it actually apply to us?
In phases: prohibited practices from 2 Feb 2025, GPAI rules from 2 Aug 2025, most high-risk obligations from 2 Aug 2026, and embedded-product high-risk from 2 Aug 2027. The platform tracks these dates against your systems.
How do we know which obligations apply to us?
It depends on your role (provider/deployer/importer/distributor) and each system's risk tier. Compliance One tags every control by role, tier and GPAI so it surfaces only what's relevant — and flags the judgment calls for your legal counsel.
We're already doing ISO 42001 — does that help?
Substantially. ISO 42001's AI-management controls overlap with much of the AI Act's governance expectations, and Compliance One cross-maps the two so your existing evidence carries over.

Ready to tackle EU AI Act?

See exactly how Compliance One maps EU AI Act to your environment in a 30-minute walkthrough — and how much of it we handle for you.