Compliance · EU · AI
EU Regulation 2024/1689Phased applicability through 2027
EU AI Act
Plain-English definition
The EU AI Act is a risk-based regulation covering AI systems placed on the EU market or whose output is used in the EU, regardless of where the provider is based. It bans certain 'unacceptable risk' AI practices outright, imposes strict obligations on 'high-risk' systems (risk management, data governance, technical documentation, human oversight, conformity assessment), and requires transparency disclosures for limited-risk systems like chatbots. Obligations are phased in through 2027.
Extraterritorial scope mirrors GDPR: your AI system's output being used in the EU can bring you into scope even without an EU office.
Who needs it
Any organization that provides or deploys AI systems whose output is used within the EU, with obligations scaling sharply based on which risk tier your specific AI system falls into.
Key requirements
Risk-tier classification for every AI system in scope, and for high-risk systems specifically: a risk management system, data governance controls, technical documentation, human oversight mechanisms, and a conformity assessment before market placement.
Cyber/privacy implications
Technical documentation and human-oversight requirements mean AI system architecture decisions, logging, and approval gates need to be defensible to a regulator, not just to your own engineering team.
Assessment methodology
AI system inventory and risk-tier classification against the Act's defined categories, gap assessment against applicable obligations for your tier, and a phased compliance roadmap matched to the Act's staggered deadlines.
Implementation phases
01
Classify
Inventory AI systems and classify each against the Act's risk tiers.
02
Remediate
Build risk management, documentation, and human-oversight controls for high-risk systems.
03
Sustain
Ongoing conformity assessment and monitoring as systems and deadlines evolve.
Evidence & documentation requirements
AI system risk-tier classification records, technical documentation for high-risk systems, human-oversight process documentation, and conformity assessment records where required.
Common mistakes
Assuming a system is low-risk without a documented classification exercise, which leaves no defensible record if a regulator disagrees; missing that obligations phase in on different dates depending on the requirement, prohibited-practice bans, GPAI obligations, and high-risk system obligations each have separate deadlines.
Expert review
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA
FAQ
Are we in scope if we're based outside the EU?
Yes, if your AI system's output is used within the EU, extraterritorial scope applies regardless of where your organization is headquartered.
What counts as 'high-risk'?
The Act defines specific categories, including AI used in employment decisions, credit scoring, critical infrastructure, and law enforcement contexts; classification requires mapping your specific system against the Act's annexes.
How does this relate to our AI Red Teaming and AI Risk Assessment services?
Those services test and assess your AI systems technically; EU AI Act readiness translates those findings into the specific legal and documentation obligations the regulation requires.
Request an AI Governance Readiness Check
Classify your AI systems against the Act's risk tiers before a regulator does it for you.
Request a Readiness Check →