All resources
Guide 9 min read

The EU AI Act, explained without the legalese

C1The Compliance One team26 August 2026

The EU AI Act (Regulation (EU) 2024/1689) is the first law to govern artificial intelligence end to end. Like GDPR before it, it applies extraterritorially — if you place an AI system on the EU market, or your AI's output is used in the EU, you're in scope, wherever you're based. And it carries GDPR-scale teeth: up to €35M or 7% of global turnover for the worst breaches.

The good news: it's risk-based. Most AI faces little or nothing. The obligations concentrate on a defined set of higher-risk uses — and on the role you play. Here's the map.

Four risk tiers

Every AI system sorts into one of four buckets, and your duties scale with the bucket:

  • Unacceptable (prohibited, Art. 5): a short list of banned practices — social scoring, manipulative or exploitative systems, most real-time public biometric identification, untargeted face-scraping, workplace/school emotion recognition.
  • High-risk (Art. 6 + Annex III): permitted, but only with the full set of obligations — used in areas like employment, credit and insurance, education, biometrics, critical infrastructure, law enforcement and justice.
  • Limited (Art. 50): transparency only — tell people they're dealing with AI, and label chatbots, deepfakes and AI-generated content.
  • Minimal: everything else — no obligations, voluntary codes only.

It also depends on your role

The same system carries different duties depending on whether you're a provider (you build it and put it on the market), a deployer (you use it under your own authority), an importer or a distributor. Providers of high-risk systems carry the heaviest load: a risk-management system, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity (Articles 9–15), plus a conformity assessment, CE marking and registration in an EU database.

Deployers have a lighter but real set (use per instructions, human oversight, monitoring, logs) — and public bodies and certain high-risk deployers must complete a Fundamental Rights Impact Assessment. General-purpose AI (GPAI) models get their own transparency, copyright and (at the largest scale) systemic-risk rules.

The timeline is already running

  • 2 Feb 2025 — prohibited practices and AI-literacy duties apply.
  • 2 Aug 2025 — GPAI obligations, the governance bodies and penalties apply.
  • 2 Aug 2026 — most high-risk (Annex III) and transparency obligations apply.
  • 2 Aug 2027 — high-risk AI embedded in regulated products, and pre-2025 GPAI, must comply.

How Compliance One makes it manageable

The Act is mostly a documentation-and-process regime, and the hardest part is simply working out which of the hundreds of obligations apply to you. Compliance One ships a full control library covering every Article and Annex, each tagged by role and risk tier so you only see what's relevant. It separates the clear, ready-to-adopt obligations from the ones that need a legal-review call, pre-fills the mandatory documents (technical file, Declaration of Conformity, FRIA, quality management system, post-market monitoring plan and more), and cross-maps everything to your ISO 42001 and ISO 27001 work so you're not starting from zero.

This is scaffolding, not legal advice — but it turns a daunting regulation into a tracked, evidenced programme you can actually run.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.