Online — typically replies instantly
Powered by Claude AI · Responses in seconds
The complete guide to understanding and complying with the EU AI Act. Risk classification, checklists, documentation templates, and cost estimates — everything your team needs to get compliant.
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Adopted on 13 June 2024 and entering into force on 1 August 2024, it establishes harmonized rules for the development, deployment, and use of AI systems across the European Union.
The Act takes a risk-based approach, categorizing AI systems into four tiers based on their potential to cause harm. Higher risk means stricter requirements — from outright bans on the most dangerous applications to light-touch transparency obligations for low-risk systems.
August 2024
EU AI Act enters into force
Already in effectFebruary 2025
Prohibited AI practices ban takes effect
Already in effectAugust 2025
GPAI model obligations apply
Already in effectAugust 2026
High-risk AI system obligations take effect
Approaching deadlineAugust 2027
Full enforcement for all AI systems
The EU AI Act uses a four-tier risk classification system. Your compliance obligations depend entirely on which tier your AI system falls into.
AI systems that pose a clear threat to safety, livelihoods, and rights. These are banned outright.
AI systems used in critical areas that significantly impact people. Subject to strict compliance requirements.
AI systems with specific transparency obligations. Users must be informed they are interacting with AI.
The majority of AI systems. No specific obligations, but voluntary codes of conduct are encouraged.
A 20-item checklist covering all critical compliance areas. Use this as a starting point for your compliance program.
High-risk AI systems require extensive technical documentation. Here is what regulators expect:
General description of the AI system, its intended purpose, and the provider details.
Detailed architecture, algorithms used, data processing logic, and computational resources.
Data sources, preparation methods, labeling procedures, data quality measures, and biases identified.
Metrics used, test datasets, performance benchmarks, and known limitations.
Risk identification, assessment methodology, mitigation measures, and residual risk analysis.
Version control, update procedures, modification logs, and impact assessments for changes.
Implement data quality checks, bias detection, and provenance tracking. Ensure training data is representative and free from discriminatory patterns.
Deploy real-time monitoring for model drift, performance degradation, and anomalous outputs. Set up automated alerting for threshold violations.
Build human-in-the-loop mechanisms for high-risk decisions. Ensure operators can override, pause, or shut down AI systems at any time.
Maintain comprehensive logs of AI system inputs, outputs, and decisions. Logs must be retained for the system lifetime plus 10 years for high-risk systems.
Establish clear procedures for AI-related incidents, including notification timelines (72 hours for serious incidents) and corrective action protocols.
A solid governance framework is the backbone of AI compliance. Here is a template structure your organization can adopt:
Executive-level body responsible for AI strategy, risk appetite, and compliance oversight. Meets monthly.
Cross-functional team reviewing high-risk AI applications before deployment. Includes legal, technical, and domain experts.
Dedicated role managing day-to-day compliance activities, documentation, and regulatory liaison.
Centralized registry of all AI systems, their risk classifications, and compliance status. Updated continuously.
Quarterly compliance reviews, annual governance audits, and ad-hoc reviews for new AI deployments or significant changes.
High-risk obligations kick in August 2026. Building a compliance program takes 6-12 months. If you haven't started, you're already behind.
The EU AI Act requires technical measures — monitoring, logging, testing, and documentation. Your engineering team needs to be involved from day one.
Many companies classify their systems as 'minimal risk' when they actually fall into the 'high risk' category, especially for HR, finance, and healthcare use cases.
If you deploy third-party AI systems (including SaaS tools with AI features), you have deployer obligations. You can't just point to the vendor.
You can't comply with what you don't know about. Many organizations have AI systems scattered across departments with no central visibility.
Not every AI system needs the same level of scrutiny. Start with your high-risk systems and work down. Don't burn resources on minimal-risk systems.
Compliance costs vary widely depending on the number and complexity of your AI systems. Here are typical ranges based on our experience with European companies:
Initial assessment of your AI systems against the Act
Detailed compliance plan with technical and organizational measures
Hands-on implementation of compliance measures across your AI systems
End-to-end compliance program for organizations with multiple high-risk AI systems
This playbook gives you the knowledge. We can give you the execution. Our team has helped dozens of European companies achieve compliance — from quick scans to full programs.