EU AI Act

The EU AI Act,
explained plainly

The EU AI Act is the first comprehensive law regulating artificial intelligence. Here is what it actually requires, from the four risk tiers and the obligations on high-risk systems and general-purpose AI models to the phased timeline and how conformity assessment works, plus how teams run the whole programme in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The regulation

What the EU AI Act actually requires.

Regulation (EU) 2024/1689 is a law, not a certification. It sorts AI systems into four risk tiers and loads the heaviest obligations onto high-risk systems, which undergo conformity assessment and carry CE marking. Separate rules apply to general-purpose AI models, and the whole thing arrives in phases.

Four risk tiers

Unacceptable risk is prohibited, high-risk carries heavy obligations, limited risk owes transparency duties, and minimal risk has no obligations at all.

High-risk obligations

Risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness — then conformity assessment and CE marking.

Providers and deployers

Who you are decides what you owe. Providers develop and place systems on the market; deployers use them under their own authority — plus importers and distributors.

A phased timeline

The bans applied first, general-purpose AI model rules followed, and most high-risk obligations land later — so the deadline that matters depends on your system.

The full picture

EU AI Act, explained in full.

A plain-language walkthrough — what it is, what it asks for, and what it takes to keep it current.

01

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689 — the first comprehensive law anywhere to regulate artificial intelligence. It entered into force on 1 August 2024 and takes a risk-based approach: rather than treating all AI the same, it sorts systems by the risk they pose to health, safety and fundamental rights, and scales the obligations accordingly. The riskier the use, the heavier the duties; some uses are banned outright.

It is important to be precise about what kind of instrument this is, because the language around it is often misused. The EU AI Act is a law, not a standard you certify against. There is no "EU AI Act certificate" to hang on the wall. Where the regulation requires it, for high-risk systems, you carry out a conformity assessment and affix CE marking, the same mechanism the EU already uses for regulated products. Throughout, the right words are "comply" and "conformity", not "get certified".

As a regulation rather than a directive, it applies directly across all EU member states without needing to be transposed into national law. Its reach is also extraterritorial: it can apply to providers and deployers outside the EU, including Swiss and other non-EU companies, when their AI systems are placed on the EU market or their output is used within the Union.

02

The four risk tiers

The whole regulation hangs on a single idea: classify each AI system by risk, then apply obligations proportionate to that risk. There are four tiers, and almost everything else in the law follows from which one your system falls into.

Unacceptable risk sits at the top: a short list of practices considered a clear threat to fundamental rights, which are prohibited entirely. Below that, high-risk covers specific listed use cases and AI used as a safety component of regulated products; these carry the bulk of the regulation’s obligations. Limited risk applies to systems that interact with people or generate content, and owes mainly transparency duties. Minimal risk, the vast majority of AI in everyday use, carries no obligations under the Act at all.

Classifying your own system

The practical first task is honest classification: working out which tier each AI system you build or use actually falls into, and writing down why. Most systems turn out to be minimal or limited risk, but the consequences of getting a high-risk classification wrong are large, so the reasoning matters as much as the answer. The tier you land in determines every obligation that follows.

03

High-risk obligations

High-risk is where the EU AI Act has real weight. A system is high-risk in two broad situations: when it is used in one of the areas the regulation lists in Annex III, such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, or the administration of justice, or when it serves as a safety component of a product already covered by EU product-safety law.

For these systems the regulation sets out a substantial set of obligations. You must operate a risk management system across the lifecycle, apply data governance to the data your system is trained and tested on, maintain technical documentation and automatic record-keeping (logging), provide transparency and clear information to deployers, design for human oversight, and meet appropriate levels of accuracy, robustness and cybersecurity.

Those obligations are not a one-time deliverable. They describe a system you keep running: documentation that stays current, logs that keep flowing, oversight that is actually exercised. They are what a conformity assessment ultimately tests. Most of the work of EU AI Act readiness for a high-risk system is building and maintaining this evidence over time.

04

Prohibited practices

At the top of the risk pyramid is a category that is not regulated but banned. These are AI practices the EU considers an unacceptable threat to people’s rights and safety, and placing them on the market or putting them into service is prohibited outright.

The list includes practices such as social scoring by public authorities, certain manipulative or deceptive techniques that materially distort behaviour and cause harm, exploitation of vulnerabilities of specific groups, untargeted scraping of facial images to build recognition databases, and certain uses of biometric categorisation and real-time remote biometric identification — each defined with specific conditions and narrow exceptions in the text. Because the boundaries are precise, the prohibitions are worth reading against your actual use case rather than from memory.

The prohibitions were the first part of the regulation to bite: the bans on these practices have applied since 2 February 2025, ahead of the high-risk obligations. For most teams the prohibited list is a quick check rather than ongoing work — but it is a check worth doing early, because the consequences of crossing it are the most severe in the whole regulation.

05

General-purpose AI (GPAI) model obligations

The EU AI Act treats general-purpose AI models, the large, broadly capable models that can be adapted to many tasks, as a category of their own, separate from the risk-tier classification applied to AI systems. Providers of GPAI models carry their own set of obligations regardless of how any downstream system built on them is classified.

For all GPAI models, providers must maintain technical documentation, provide information to the downstream providers who integrate the model into their own systems, put a policy in place to respect EU copyright law, and publish a sufficiently detailed summary of the content used to train the model. Where a model is judged to pose systemic risk (broadly, the most capable, highest-impact models), additional duties apply, including model evaluation, assessment and mitigation of systemic risks, incident tracking and reporting, and heightened cybersecurity protection.

These obligations began applying on 2 August 2025, ahead of most high-risk system obligations. If you train or fine-tune your own general-purpose model, this part of the regulation applies to you directly; if you only build on someone else’s model, the relevant questions are which obligations they have met and what information they pass downstream to you.

06

Providers vs deployers

The EU AI Act assigns obligations by role, so the first thing to settle is which role you play for a given system — because the same system can make you a provider in one situation and a deployer in another. The two central roles are providers and deployers, with importers and distributors carrying their own lighter duties in the supply chain.

A provider develops an AI system (or has one developed) and places it on the market or puts it into service under its own name or trademark. Providers carry the heaviest load, especially for high-risk systems: building the risk management, documentation and quality measures, running the conformity assessment and affixing CE marking. A deployer uses an AI system under its own authority — for example, a company using a high-risk hiring tool. Deployers owe a narrower but real set of duties: using the system in line with its instructions, ensuring human oversight, monitoring its operation, and keeping the logs it generates.

Getting the role right is foundational, because a wrong answer here cascades through everything else. In particular, certain actions, such as substantially modifying a high-risk system or putting your own name on it, can turn a deployer into a provider and pull the full provider obligations along with it.

07

The phased timeline

The EU AI Act does not arrive all at once. It entered into force on 1 August 2024, but its obligations switch on in phases, so the deadline that matters to you depends entirely on what kind of AI you build or use.

The prohibitions on unacceptable-risk practices applied first, from 2 February 2025. The obligations on general-purpose AI models followed, from 2 August 2025. Most of the high-risk obligations apply from 2 August 2026, and a further set, covering certain high-risk AI systems that are embedded as safety components in products already regulated under EU product-safety law, applies from 2 August 2027.

The practical implication is that "are we ready for the EU AI Act?" is not a single yes or no. It depends on which systems you operate and which tier each one sits in. The sooner you classify your AI portfolio, the sooner you know which of these dates is actually yours — and how much runway you have to meet it.

08

Conformity assessment and CE marking

For high-risk AI systems, demonstrating compliance runs through conformity assessment — the EU’s established route for showing a product meets its legal requirements before it reaches the market. Depending on the type of system, this is done either through an internal assessment carried out by the provider itself, or with the involvement of a notified body (an independent third party), with the route set by the regulation rather than chosen freely.

Once a high-risk system passes conformity assessment, the provider draws up an EU declaration of conformity, affixes CE marking, and, where required, registers the system in the EU database for high-risk systems. CE marking signals that the system meets the applicable EU requirements, the same mark already used across regulated products. This is the closest the EU AI Act comes to a "certificate", and it is deliberately not the same thing: it is a self-affixed (or notified-body-supported) declaration backed by the documentation behind it, not a badge issued by a certification body.

Harmonised standards play a quiet but central role here. Conformity to certain harmonised standards, including work aligned with ISO/IEC 42001, can grant a presumption of conformity with the corresponding requirements, which is why an AI management system is such a practical foundation: it produces much of the evidence the assessment expects to see.

09

The EU AI Act vs ISO/IEC 42001

These two are often mentioned in the same breath, and it helps to be clear on how they differ. The EU AI Act is a binding law with legal obligations and penalties; ISO/IEC 42001 is a voluntary international management-system standard, the AI counterpart to ISO 27001 for information security, that you can certify against. One is something you must comply with; the other is something you choose to adopt.

They are complementary rather than competing. ISO/IEC 42001 gives you an AI management system: a structured, auditable way to govern how AI is developed and used across the organization, with risk management, documentation and oversight built in. That is precisely the machinery the EU AI Act expects a high-risk provider to run, which is why an ISO 42001 management system is a practical way to operationalise EU AI Act readiness — and why harmonised standards aligned with it can support a presumption of conformity.

In short: ISO 42001 will not, by itself, make you compliant with the EU AI Act, because the law has specific requirements the standard does not exactly mirror. But it is one of the most direct ways to build the governance, evidence and discipline that compliance demands.

10

Penalties for non-compliance

The EU AI Act backs its obligations with significant penalties, tiered to the severity of the breach. The heaviest fines are reserved for breaching the prohibitions on unacceptable-risk practices: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.

Lower ceilings apply to other breaches — for example, fines for non-compliance with most other obligations are capped at a lower level, with a further, lower tier for supplying incorrect, incomplete or misleading information to authorities. The structure mirrors GDPR’s turnover-based approach, and the message is the same: classification and compliance are not paperwork exercises, because the downside is sized to the global business, not the local one.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your EU AI Act programme, in one workspace.

Everything the regulation asks you to maintain, from classifications and risk management to technical documentation, oversight and evidence, connected and ready for assessment over time. Pick one to see it.

Classify each system, tier by tier

Sort every AI system you build or use into its risk tier (unacceptable, high, limited or minimal) with the reasoning recorded, so a classification you can defend stays live instead of being reconstructed when a deadline or an auditor arrives.

Learn more
Critical · 9.8CVE-2026-0991log4j
High · 8.6CVE-2026-1043openssl
Medium · 5.4CVE-2026-1180lodash
Document once. Reuse across every standard you add.

The EU AI Act overlaps heavily with ISO/IEC 42001 and GDPR — an AI management system, data governance and records that satisfy one largely satisfy the others. Map a control once in devguard and the same documentation and evidence carry across, so the second requirement is a fraction of the work of the first.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already working on AI governance? Move it across.

If you already maintain AI risk classifications, technical documentation or an ISO/IEC 42001 management system, you do not want to rebuild any of it from a blank page. In a scoped conversation we agree exactly what moves (your system classifications, risk records, documentation and oversight history) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
EU AI Act FAQ

EU AI Act, answered plainly.

Is the EU AI Act a certification?

No. It is a law, Regulation (EU) 2024/1689, not a standard you certify against, so there is no "EU AI Act certificate". For high-risk systems you demonstrate compliance through conformity assessment and CE marking, the same mechanism the EU uses for regulated products. The right words are "comply" and "conformity", not "get certified".

What are the four risk tiers in the EU AI Act?

Unacceptable risk (prohibited outright), high-risk (the bulk of the obligations, plus conformity assessment and CE marking), limited risk (mainly transparency duties, such as disclosing that someone is interacting with AI or labelling synthetic media) and minimal risk (no obligations under the Act). Which tier a system falls into determines everything that follows.

When does the EU AI Act apply?

It entered into force on 1 August 2024 and applies in phases. The bans on prohibited practices applied from 2 February 2025, the general-purpose AI model obligations from 2 August 2025, most high-risk obligations from 2 August 2026, and a further set for certain high-risk systems embedded in regulated products from 2 August 2027. Which date matters depends on your systems.

What is the difference between a provider and a deployer?

A provider develops an AI system and places it on the market or puts it into service under its own name, and carries the heaviest obligations — especially for high-risk systems. A deployer uses a system under its own authority and owes a narrower set of duties, such as following the instructions for use, ensuring human oversight and keeping logs. Substantially modifying a high-risk system, or putting your own name on it, can turn a deployer into a provider.

Does ISO/IEC 42001 make me compliant with the EU AI Act?

Not by itself — the EU AI Act has specific legal requirements that the standard does not exactly mirror. But ISO/IEC 42001 is a voluntary AI management-system standard that builds much of the governance, risk management and documentation the regulation expects, and harmonised standards aligned with it can support a presumption of conformity. It is one of the most direct ways to operationalise EU AI Act readiness.

What are the penalties for breaching the EU AI Act?

They are tiered to the severity of the breach. The heaviest fines apply to breaching the prohibitions on unacceptable-risk practices: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Lower ceilings apply to other obligations, with a further, lower tier for supplying incorrect or misleading information to authorities.

See how your EU AI Act program would look in devguard.

The fastest way to know if this fits is a short conversation about how you handle AI today — which systems you run, how you would classify them, and what meeting the obligations would involve. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free