EU AI Act: Comprehensive Compliance Guide
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Adopted in 2024 with phased enforcement through 2027, it establishes a risk-based regulatory approach that classifies AI systems into four risk tiers with corresponding obligations. The Act applies to providers and deployers of AI systems in the EU market, regardless of where they are established, with penalties up to 7% of global annual revenue.
What Is the EU AI Act and Who Enforces It
The EU AI Act was published in the Official Journal of the European Union on 12 July 2024 and entered into force 20 days later. It is directly applicable law across all 27 EU member states, enforced by national market surveillance authorities in each country. The European AI Office — a new body established within the European Commission — oversees enforcement for general-purpose AI models and cross-border cases. The Act is co-issued by the European Parliament and the Council of the European Union, making it primary EU legislation with the same legal weight as GDPR.
The Act carries penalties of up to 35 million euros or 7% of global annual turnover (whichever is higher) for violations involving prohibited AI practices, up to 15 million euros or 3% of turnover for violations of other obligations, and up to 7.5 million euros or 1.5% of turnover for providing incorrect information. These are among the highest potential fines in any technology regulation globally.
Who Must Comply
The Act applies to four categories of actors. Providers are the companies or individuals who develop AI systems or general-purpose AI models and place them on the EU market or put them into service in the EU. Deployers are organizations that use AI systems under their own authority in a professional context within the EU. Importers bring AI systems from non-EU countries into the EU market. Distributors make AI systems available within the EU without materially modifying them.
The extraterritorial reach is significant: a US-based company that develops an AI model used by EU customers is a provider subject to the Act. A non-EU company that deploys AI in EU operations is a deployer. Virtually any company developing or using AI for European customers or employees needs to assess its obligations.
The Four Risk Tiers Explained in Depth
Unacceptable Risk (Prohibited): The Act outright bans certain AI practices. These include social scoring systems by public authorities, real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions), AI systems that exploit psychological vulnerabilities or target protected characteristics to manipulate behavior, AI used for untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and educational institutions, and biometric categorization systems that infer sensitive attributes such as race, political opinion, or sexual orientation. These prohibitions have been enforceable since February 2025.
High-Risk AI Systems: This is where the majority of compliance investment is required. High-risk systems fall into two categories. Annex I covers AI embedded in products already subject to EU safety legislation — medical devices, machinery, aviation, automotive, and similar regulated products. Annex II covers eight standalone application areas: biometric identification and categorization, critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice. High-risk obligations become fully applicable in August 2026.
Requirements for high-risk systems include establishing and maintaining a risk management system throughout the AI lifecycle, implementing data governance requirements for training, validation, and testing datasets, creating and maintaining comprehensive technical documentation, enabling automatic logging sufficient for post-market monitoring, providing deployers with clear instructions for use, implementing meaningful human oversight enabling intervention or override, achieving appropriate accuracy, robustness, and cybersecurity levels, and registering in the EU AI systems database before market placement.
Limited Risk: Systems such as chatbots interacting with humans, AI-generated content, deepfakes, and emotion recognition systems face transparency obligations. Users must be informed they are interacting with an AI, AI-generated content must be labeled, and synthetic media representing real persons must be disclosed.
Minimal Risk: The vast majority of AI applications — spam filters, AI-powered recommendation engines, video games with AI opponents — fall here. These face no mandatory obligations, though providers are encouraged to adopt voluntary codes of conduct.
General-Purpose AI Model Obligations
The EU AI Act introduced a distinct regulatory category for general-purpose AI (GPAI) models — foundation models like large language models that can be used across many tasks. GPAI model providers have been subject to obligations since August 2025. All GPAI providers must prepare and publish technical documentation, make available information for downstream providers integrating the model, comply with EU copyright law and provide training data summaries, and publish model evaluation results.
GPAI models presenting systemic risk — determined by training compute exceeding 10^25 FLOPs — face additional requirements: adversarial testing and red-teaming, incident and near-miss reporting to the European AI Office, cybersecurity protection for the model and infrastructure, and energy efficiency reporting. The European AI Office may also designate models as systemic risk on qualitative grounds even below the compute threshold.
The Conformity Assessment Process
For most high-risk AI systems in Annex II, providers conduct internal conformity assessments before market placement. The provider must verify compliance with all applicable requirements, compile the technical documentation, establish the EU declaration of conformity, and affix the CE marking. Internal assessments are generally sufficient unless the system involves real-time remote biometric identification, in which case a notified body must conduct a third-party assessment.
For Annex I products where the AI is embedded in regulated hardware, the conformity assessment follows the rules of the applicable sectoral legislation (medical devices, machinery directive, etc.), which may already require notified body involvement.
The notified body regime is still maturing. Organizations should identify relevant notified bodies early, as capacity may be limited. Harmonized standards aligned with EU AI Act requirements are being developed by CEN-CENELEC and are expected to substantially simplify conformity assessment once published.
Costs and Timeline
| Activity | Typical Cost | Timeline |
|---|---|---|
| AI system inventory and risk classification | $10,000 – $30,000 | 1–3 months |
| High-risk system technical documentation | $20,000 – $80,000 per system | 2–6 months |
| Conformity assessment (internal) | $15,000 – $50,000 | 1–3 months |
| Conformity assessment (notified body) | $50,000 – $200,000 | 3–9 months |
| Post-market monitoring system setup | $20,000 – $100,000 | 2–4 months |
| GPAI transparency compliance | $30,000 – $150,000 | 2–6 months |
| Full high-risk compliance program | $100,000 – $500,000+ | 6–24 months |
Comparison with Related Frameworks
The EU AI Act, NIST AI RMF, and ISO 42001 address overlapping but distinct territory.
The NIST AI RMF (55% overlap) is voluntary and process-oriented, providing a governance approach that can be adapted to any context. The EU AI Act is mandatory and outcome-oriented, specifying requirements rather than leaving the approach to the organization. Companies in the US often align with NIST AI RMF first, then map obligations to EU AI Act requirements.
ISO 42001 (50% overlap) provides a certifiable management system standard for AI. ISO 42001 certification is expected to be recognized as supporting evidence for EU AI Act conformity assessments, making it an efficient dual investment. Organizations seeking EU AI Act compliance should consider whether an ISO 42001 AIMS provides a structured management foundation.
GDPR (30% overlap) intersects with the EU AI Act wherever personal data is involved in AI systems — which is common. High-risk AI systems processing personal data must comply with both regimes, with GDPR's data minimization and purpose limitation principles shaping how training and inference data is handled. Organizations should map the interaction carefully, as GDPR obligations predate and supplement the Act.
How Automation Helps
Managing EU AI Act compliance across a portfolio of AI systems involves maintaining technical documentation, monitoring post-market performance, tracking regulatory updates, and demonstrating ongoing conformity — tasks that quickly overwhelm manual processes. Platforms like LowerPlane cover 50+ frameworks including the EU AI Act, providing structured control libraries, evidence management, and automated monitoring starting at $4,000 per year with a free tier to begin assessment. AuditXYZ users rate LowerPlane 9.4/10 for reducing compliance overhead on multi-framework programs.
For AI systems processing personal data, TruePrivacy's AI governance module provides model mapping — linking each AI model to the personal data it processes — and privacy impact assessment workflows that satisfy both GDPR and EU AI Act documentation requirements simultaneously.
See also our comparison of best compliance automation platforms for a side-by-side view of tools supporting EU AI Act readiness.
Frequently Asked Questions
Does the EU AI Act apply to AI systems already deployed before August 2026? Systems already on the market before August 2026 generally have a transition period until August 2027 to comply with high-risk requirements. GPAI models already deployed before August 2025 had until August 2025 to comply with GPAI obligations. New systems placed on the market must comply on the applicable dates.
What counts as a "provider" versus a "deployer" and does it matter? It matters significantly. Providers bear the primary compliance obligations for high-risk systems — technical documentation, conformity assessment, CE marking. Deployers have narrower obligations (instructions for use, human oversight, incident reporting) but can become treated as providers if they substantially modify a system or place it under their own name. Many enterprise customers deploying third-party AI tools will be deployers, but those fine-tuning or customizing models may become providers.
Are non-EU companies subject to the Act? Yes. Any company whose AI system outputs affect EU users is subject to relevant obligations. A provider based in the US placing a high-risk AI system on the EU market must comply with all high-risk requirements. Non-EU providers without an EU establishment must appoint an EU authorized representative.
How do the EU AI Act and GDPR interact for AI systems processing personal data? Both regimes apply simultaneously and must be satisfied together. GDPR governs personal data processing throughout the AI lifecycle. The EU AI Act adds additional requirements for certain AI systems. Data protection impact assessments under GDPR and fundamental rights impact assessments under the EU AI Act can be conducted jointly to reduce duplication. Organizations should coordinate their DPO and AI compliance functions.
What is the timeline for mandatory standards under the EU AI Act? CEN-CENELEC is developing harmonized European standards that, once published and referenced in the Official Journal, will provide presumption of conformity with specific Act requirements. Standards covering risk management, technical documentation, and data governance are expected by late 2025 and 2026. Organizations implementing compliance programs now should build sufficient flexibility to adapt as standards are finalized.
Can smaller companies get any relief from the compliance requirements? The Act includes some SME relief provisions: reduced registration fees, simplified compliance documentation guidance from the European AI Office, and regulatory sandboxes operated by national authorities where SMEs can test AI systems before market launch with lighter-touch supervision. However, the substantive technical requirements for high-risk systems apply equally regardless of company size.