The European Union's Artificial Intelligence Act -- officially Regulation (EU) 2024/1689 -- is the most comprehensive piece of AI legislation ever enacted. It establishes a harmonized legal framework for the development, deployment, and use of artificial intelligence systems across the European Union, and its impact extends far beyond European borders. Any organization that places an AI system on the EU market, puts one into service within the EU, or whose AI system's output is used in the EU falls within its scope.

With the regulation's most consequential provisions taking effect in August 2026, the compliance window is closing rapidly. Organizations that have not yet begun preparing face significant legal, financial, and operational risks. This guide provides a thorough overview of the EU AI Act, its requirements, its timeline, and the concrete steps AI companies should take to achieve compliance.

What Is the EU AI Act?

The EU AI Act is the world's first comprehensive, binding regulatory framework dedicated specifically to artificial intelligence. Proposed by the European Commission in April 2021, negotiated over more than two years, and formally adopted by the European Parliament in March 2024, the regulation entered into force on August 1, 2024. It is structured around a risk-based approach to AI governance, meaning that the regulatory obligations imposed on an AI system are proportionate to the level of risk that system poses to health, safety, and fundamental rights.

The regulation builds on the EU's broader digital strategy and complements existing legislation including the General Data Protection Regulation (GDPR), the Digital Services Act (DSA), and the Digital Markets Act (DMA). It applies to providers, deployers, importers, distributors, and authorized representatives of AI systems, creating obligations at every stage of the AI value chain.

The EU AI Act is not merely a European regulation. It has extraterritorial reach: if your AI system's output is used within the EU, you are subject to its requirements regardless of where your organization is headquartered. This makes it a de facto global standard for AI governance.

The Act establishes the European Artificial Intelligence Office within the European Commission to oversee implementation, particularly for general-purpose AI models. Each member state is also required to designate national competent authorities and market surveillance authorities to enforce the regulation at the national level.

The Risk-Based Classification System

The foundational principle of the EU AI Act is its four-tier risk classification system. Every AI system that falls within the regulation's scope is categorized according to the level of risk it poses, and the obligations imposed on that system correspond directly to its risk tier.

Unacceptable Risk: Banned Practices

At the top of the risk pyramid are AI practices that the EU considers fundamentally incompatible with European values and fundamental rights. These are outright prohibited. The banned practices include:

The prohibitions on these practices became effective on February 2, 2025, making them the first provisions of the AI Act to apply. Organizations currently operating AI systems that fall into any of these categories must have already ceased those activities.

High-Risk AI Systems

The high-risk category is the most detailed and consequential tier of the regulation. AI systems classified as high-risk are permitted on the EU market but are subject to extensive compliance requirements. The Act identifies high-risk AI systems in two ways:

Annex I systems: AI systems intended to be used as a safety component of a product, or that are themselves a product, covered by Union harmonization legislation listed in Annex I (including machinery, medical devices, toys, civil aviation, motor vehicles, and other regulated products). These systems are subject to third-party conformity assessment under the relevant sectoral legislation.

Annex III systems: AI systems used in specific high-risk use cases listed in Annex III, including:

High-risk classification is not solely determined by the domain in which an AI system operates. The regulation includes an important exception: an Annex III system is not considered high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, provided it does not make profiles of natural persons, output decisions, or materially influence decisions that are already subject to human review. However, the provider must document and justify this assessment.

Limited Risk: Transparency Obligations

AI systems that present a limited risk are subject primarily to transparency requirements. These include:

These transparency obligations apply regardless of whether the AI system is classified as high-risk. Even a minimal-risk system that generates synthetic content must comply with the labeling requirements.

Minimal Risk

AI systems that do not fall into any of the above categories are classified as minimal risk. The vast majority of AI applications currently on the market -- spam filters, AI-enabled video games, inventory management systems, recommendation algorithms for non-essential services -- fall into this category. These systems are not subject to specific obligations under the AI Act, though providers are encouraged to voluntarily adopt codes of conduct aligned with the regulation's principles.

High-Risk AI System Requirements in Detail

The obligations imposed on providers of high-risk AI systems are comprehensive and technically demanding. They represent the core of the EU AI Act's regulatory framework and require significant investment in governance, documentation, and technical infrastructure.

Risk Management System

Providers must establish, implement, document, and maintain a risk management system that operates throughout the entire lifecycle of the high-risk AI system. This system must identify and analyze known and reasonably foreseeable risks, estimate and evaluate risks that may emerge when the system is used in accordance with its intended purpose and under conditions of reasonably foreseeable misuse, and adopt appropriate and targeted risk management measures. The risk management system must be regularly and systematically updated.

Data and Data Governance

Training, validation, and testing datasets must be subject to appropriate data governance and management practices. This includes specifications for data collection processes, data preparation operations (annotation, labeling, cleaning, enrichment), the formulation of relevant assumptions about the information the data is supposed to represent, and an assessment of the availability, quantity, and suitability of datasets. Training data must be relevant, sufficiently representative, and as free of errors as possible in light of the intended purpose.

Technical Documentation

Before a high-risk AI system is placed on the market or put into service, providers must draw up technical documentation demonstrating that the system complies with the regulation. This documentation must be kept up to date and must include a general description of the system, a detailed description of its elements and development process, information on monitoring, functioning, and control, a description of the risk management system, a description of any changes made during the lifecycle, a list of harmonized standards applied, and a copy of the EU declaration of conformity.

Record-Keeping and Logging

High-risk AI systems must be designed and developed with capabilities enabling the automatic recording of events (logs) throughout the system's lifetime. Logging capabilities must allow for the tracing of the system's operation, including the identification of the input data, the identification of situations in which the AI system may present risks, and monitoring of the system's performance.

Transparency and Information to Deployers

High-risk AI systems must be designed and developed to ensure that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately. Providers must supply deployers with concise, complete, correct, and clear instructions for use that include the provider's identity, the system's characteristics, capabilities, and limitations, the changes that have been pre-determined and assessed by the provider, human oversight measures, the expected lifetime and maintenance requirements, and the computational and hardware resources needed.

Human Oversight

High-risk AI systems must be designed and developed so that they can be effectively overseen by natural persons during the period in which they are in use. Human oversight measures must aim to prevent or minimize risks to health, safety, or fundamental rights that may emerge, particularly when such risks persist despite the application of other requirements. The system must allow the individual performing oversight to fully understand the system's capacities and limitations, to correctly interpret its output, to decide not to use the system or to disregard, override, or reverse its output, and to intervene or interrupt the system through a stop button or similar procedure.

Accuracy, Robustness, and Cybersecurity

High-risk AI systems must be designed and developed to achieve an appropriate level of accuracy, robustness, and cybersecurity, and to perform consistently in those respects throughout their lifecycle. Providers must declare the levels of accuracy and relevant accuracy metrics in the instructions for use. The systems must be resilient regarding errors, faults, or inconsistencies, and resilient against attempts by unauthorized third parties to alter their use, outputs, or performance by exploiting system vulnerabilities.

General-Purpose AI Model Obligations

One of the most significant additions to the EU AI Act during the legislative process was the introduction of obligations for providers of general-purpose AI (GPAI) models. These provisions were added in large part as a response to the rapid rise of foundation models and large language models such as GPT-4, Claude, Gemini, Llama, and Mistral.

A GPAI model is defined as an AI model -- including when trained with a large amount of data using self-supervision at scale -- that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way it is placed on the market, and which can be integrated into a variety of downstream systems or applications.

Obligations for All GPAI Model Providers

All providers of GPAI models, regardless of their size or the risk level of downstream applications, must meet baseline obligations:

Additional Obligations for Systemic Risk Models

GPAI models that pose systemic risk are subject to additional, more stringent obligations. A GPAI model is presumed to have systemic risk if it has high-impact capabilities, or if it was trained using a total computing power of more than 10^25 floating point operations (FLOPs). The Commission may also designate additional models as posing systemic risk based on other criteria.

Providers of GPAI models with systemic risk must, in addition to the baseline obligations:

The GPAI provisions became applicable on August 2, 2025, meaning providers of general-purpose AI models should already be in compliance with baseline obligations.

Penalties and Enforcement

The EU AI Act establishes a tiered penalty structure that reflects the severity of different types of non-compliance. The maximum fines are among the highest in EU regulatory law:

For SMEs and startups, the regulation provides that the fines shall be proportionate, and the lower of the two alternative amounts (fixed sum or percentage) shall apply. This provides some relief for smaller organizations but does not eliminate the compliance obligation itself.

The penalty regime under the EU AI Act is modeled on the GDPR's enforcement approach. Given that GDPR fines have exceeded 4 billion euros in aggregate since 2018, organizations should not treat AI Act penalties as theoretical. Enforcement will be real, and the financial consequences of non-compliance will be substantial.

Enforcement is shared between the European AI Office (which oversees GPAI models directly) and national market surveillance authorities designated by each member state. Member states must establish rules on penalties and enforcement mechanisms by August 2, 2025, and begin applying those rules by August 2, 2026.

Key Compliance Deadlines

The EU AI Act employs a phased implementation timeline, with different provisions becoming applicable at different points after entry into force on August 1, 2024. Understanding these deadlines is essential for planning your compliance program:

  1. February 2, 2025 -- Banned practices. The prohibitions on unacceptable-risk AI practices (Article 5) became applicable. Organizations must have already ceased any prohibited AI activities.
  2. August 2, 2025 -- GPAI obligations and governance. Obligations for providers of general-purpose AI models (Chapter V) became applicable. The European AI Office became fully operational. Rules on notified bodies, governance structure, penalties, and confidentiality also became applicable.
  3. August 2, 2026 -- High-risk AI systems and most remaining provisions. The bulk of the regulation becomes applicable, including all requirements for high-risk AI systems (Chapter III, Section 2), obligations on providers, deployers, importers, and distributors, transparency obligations for limited-risk systems, conformity assessment procedures, and market surveillance rules. This is the date by which organizations operating high-risk AI systems must be fully compliant.
  4. August 2, 2027 -- Annex I high-risk systems. Requirements for high-risk AI systems that are safety components of products covered by Annex I Union harmonization legislation become applicable. This extended timeline recognizes the additional complexity of integrating AI Act requirements with existing sectoral product safety legislation.

With the August 2026 deadline now fewer than four months away, organizations that have not yet begun their compliance journey face an extremely compressed timeline.

How the EU AI Act Relates to ISO 42001

ISO/IEC 42001:2023, the international standard for AI Management Systems, and the EU AI Act share a common goal: ensuring that AI systems are developed and used responsibly. However, they approach this goal from different angles and serve complementary purposes.

The EU AI Act is a binding legal regulation that imposes specific, mandatory requirements on AI systems based on their risk classification. ISO 42001 is a voluntary management system standard that provides a certifiable framework for governing AI activities across an organization. Together, they form a powerful combination.

Key areas where ISO 42001 directly supports EU AI Act compliance include:

While ISO 42001 certification does not automatically constitute EU AI Act compliance, the European Commission has recognized the role of harmonized standards in supporting conformity assessment. An organization with a mature, well-implemented AI Management System certified to ISO 42001 will find the path to EU AI Act compliance significantly shorter and less disruptive than an organization starting from zero.

Conformity Assessments and CE Marking

Before a high-risk AI system can be placed on the EU market or put into service, it must undergo a conformity assessment to demonstrate compliance with the regulation's requirements. The outcome of a successful conformity assessment is a declaration of conformity and the affixing of the CE marking to the AI system.

The EU AI Act provides for two types of conformity assessment procedures:

Internal Conformity Assessment (Self-Assessment)

For most high-risk AI systems listed in Annex III, providers may conduct an internal conformity assessment based on the procedure described in Annex VI of the regulation. This involves verifying that the quality management system is in compliance, examining the technical documentation, and verifying that the design and development process of the AI system and its post-market monitoring are consistent with the documentation. Providers who apply harmonized standards or common specifications referenced in the regulation benefit from a presumption of conformity with the requirements covered by those standards.

Third-Party Conformity Assessment

For certain categories of high-risk AI systems -- specifically, remote biometric identification systems and AI systems used for critical infrastructure, access to essential services, law enforcement, migration, and justice administration when designated by implementing acts -- the regulation requires third-party conformity assessment carried out by a notified body. This external assessment provides an independent verification that the AI system meets all applicable requirements.

For high-risk AI systems that are safety components of products covered by Annex I legislation (such as medical devices or machinery), the conformity assessment follows the procedures established under the relevant sectoral legislation, with the AI Act requirements integrated into that existing framework.

Regardless of the assessment type, providers must:

Steps AI Companies Should Take Now

With the August 2026 compliance deadline approaching, organizations need to act decisively. The following steps provide a structured approach to preparing for EU AI Act compliance:

1. Conduct an AI System Inventory

Begin by identifying and cataloging every AI system your organization develops, provides, deploys, or uses. For each system, document its intended purpose, the data it processes, the decisions or outputs it generates, the populations it affects, and the markets in which it operates. This inventory is the foundation of your compliance program because you cannot assess risk or determine obligations for systems you have not identified.

2. Classify Your AI Systems by Risk Level

Map each identified AI system to the appropriate risk tier under the EU AI Act. Determine whether any systems involve prohibited practices (which must be immediately discontinued), qualify as high-risk under Annex I or Annex III, are subject to limited-risk transparency obligations, or fall into the minimal-risk category. Document your classification rationale thoroughly, as you may need to justify it to regulators.

3. Perform a Gap Analysis

For each high-risk AI system, compare your current practices against the full set of requirements in the regulation: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. Identify the gaps between your current state and the target state required for compliance. This gap analysis will inform your implementation roadmap and resource allocation.

4. Establish Your Quality Management System

The regulation requires providers of high-risk AI systems to have a quality management system that includes policies and procedures covering risk management, data management, record-keeping, monitoring, resource management, accountability frameworks, and reporting structures. If you already operate under ISO 9001, ISO 27001, or ISO 42001, you have a head start. If not, now is the time to build these foundations.

5. Develop Technical Documentation

Begin drafting the technical documentation required for each high-risk AI system. This is often the most time-consuming aspect of compliance because it requires a thorough description of the system's design, development process, training methodology, validation and testing results, risk management measures, and post-market monitoring plan. Do not underestimate the effort required: technical documentation must be comprehensive, accurate, and maintained throughout the system's lifecycle.

6. Implement Logging and Monitoring Infrastructure

Ensure that your high-risk AI systems have the technical capability to automatically record events and enable traceability. This may require engineering work to add logging capabilities to existing systems, establish data retention policies, and build monitoring dashboards that support both operational oversight and regulatory reporting.

7. Establish Human Oversight Mechanisms

Design and implement human oversight measures appropriate to each high-risk AI system. This includes defining the roles and responsibilities of human overseers, ensuring they have the tools and training to understand system outputs, and implementing mechanisms that allow human operators to override, reverse, or shut down the system when necessary.

8. Prepare for Conformity Assessment

Determine which conformity assessment procedure applies to each of your high-risk AI systems. If third-party assessment is required, identify and engage with a notified body early, as demand for these services is expected to increase significantly as the August 2026 deadline approaches. If internal assessment is sufficient, ensure your processes are rigorous and well-documented.

9. Train Your Team

AI Act compliance is not solely a legal or compliance function. It requires collaboration across engineering, data science, product management, legal, risk management, and executive leadership. Invest in training programs that ensure all relevant personnel understand their obligations under the regulation and their role in the compliance framework.

10. Engage Expert Support

The EU AI Act is complex, and the interplay between the regulation, delegated acts, implementing acts, harmonized standards, and existing sectoral legislation creates a challenging compliance landscape. Working with experienced certification and compliance partners can accelerate your preparation and reduce the risk of costly oversights.

How AICerty Helps with EU AI Act Compliance

AICerty, the AI certification division of BALTUM, provides end-to-end support for organizations navigating the EU AI Act compliance journey. Our team combines deep expertise in AI governance, international standards, and European regulatory frameworks to deliver practical, actionable guidance tailored to your organization's specific needs.

Our EU AI Act compliance services include:

Our approach is practical, not theoretical. We work alongside your engineering, product, and legal teams to integrate compliance into your existing workflows rather than treating it as a separate, burdensome process. The result is a compliance program that is sustainable, efficient, and aligned with your business objectives.

Related Articles

What is ISO 42001? Complete Guide
Read article →
How to Prepare for AI Certification
Read article →
Why AI Companies Need ISO 27001
Read article →

Start Your EU AI Act Compliance Journey

The August 2026 deadline for high-risk AI system compliance is approaching fast. AICerty provides the expertise, frameworks, and hands-on support your organization needs to achieve compliance with confidence. Get in touch today to schedule your initial assessment.

Get Started with AICerty
← Back to Blog