The EU AI Act, explained without the legalese
The EU AI Act (Regulation (EU) 2024/1689) is the first law to govern artificial intelligence end to end. Like GDPR before it, it applies extraterritorially — if you place an AI system on the EU market, or your AI's output is used in the EU, you're in scope, wherever you're based. And it carries GDPR-scale teeth: up to €35M or 7% of global turnover for the worst breaches.
The good news: it's risk-based. Most AI faces little or nothing. The obligations concentrate on a defined set of higher-risk uses — and on the role you play. Here's the map.
Four risk tiers
Every AI system sorts into one of four buckets, and your duties scale with the bucket:
- Unacceptable (prohibited, Art. 5): a short list of banned practices — social scoring, manipulative or exploitative systems, most real-time public biometric identification, untargeted face-scraping, workplace/school emotion recognition.
- High-risk (Art. 6 + Annex III): permitted, but only with the full set of obligations — used in areas like employment, credit and insurance, education, biometrics, critical infrastructure, law enforcement and justice.
- Limited (Art. 50): transparency only — tell people they're dealing with AI, and label chatbots, deepfakes and AI-generated content.
- Minimal: everything else — no obligations, voluntary codes only.
It also depends on your role
The same system carries different duties depending on whether you're a provider (you build it and put it on the market), a deployer (you use it under your own authority), an importer or a distributor. Providers of high-risk systems carry the heaviest load: a risk-management system, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity (Articles 9–15), plus a conformity assessment, CE marking and registration in an EU database.
Deployers have a lighter but real set (use per instructions, human oversight, monitoring, logs) — and public bodies and certain high-risk deployers must complete a Fundamental Rights Impact Assessment. General-purpose AI (GPAI) models get their own transparency, copyright and (at the largest scale) systemic-risk rules.
The timeline is already running
- 2 Feb 2025 — prohibited practices and AI-literacy duties apply.
- 2 Aug 2025 — GPAI obligations, the governance bodies and penalties apply.
- 2 Aug 2026 — most high-risk (Annex III) and transparency obligations apply.
- 2 Aug 2027 — high-risk AI embedded in regulated products, and pre-2025 GPAI, must comply.
How Compliance One makes it manageable
The Act is mostly a documentation-and-process regime, and the hardest part is simply working out which of the hundreds of obligations apply to you. Compliance One ships a full control library covering every Article and Annex, each tagged by role and risk tier so you only see what's relevant. It separates the clear, ready-to-adopt obligations from the ones that need a legal-review call, pre-fills the mandatory documents (technical file, Declaration of Conformity, FRIA, quality management system, post-market monitoring plan and more), and cross-maps everything to your ISO 42001 and ISO 27001 work so you're not starting from zero.
This is scaffolding, not legal advice — but it turns a daunting regulation into a tracked, evidenced programme you can actually run.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.