Regulatory Framework
EU AI
Act
Artificial Intelligence Regulation
The EU AI Act is the European Union’s risk-based legal framework for artificial intelligence. It sets obligations for providers and deployers based on how AI systems are used and the level of risk they create. Prohibited AI practices are already subject to the rules, while transparency and other obligations apply on a phased timeline.
AI Act Overview
Type
EU Regulation – Direct Application
Entry into Force
1 August 2024
Key Application Dates
2 August 2026
Scope
AI providers, deployers and other operators
Certification
No single AI Act certificate – conformity requirements depend on the AI system
Maximum Penalty
Up to €35 million or 7% of worldwide annual turnover for prohibited practices or certain data-related violations
Current AI Act Timeline
The AI Act is now entering its broader application phase. Prohibitions and AI literacy rules have applied since February 2025, general-purpose AI obligations since August 2025, and transparency obligations under Article 50 from August 2026. High-risk rules have a later application date under the current EU implementation timeline.
What It Is
Understanding
the EU AI Act
The EU AI Act, Regulation (EU) 2024/1689, establishes harmonised rules for artificial intelligence across the European Union. It uses a risk-based approach covering prohibited AI practices, high-risk AI systems, transparency obligations, and general-purpose AI models. The regulation entered into force on 1 August 2024 and applies in stages.
The EU AI Act can affect organisations that develop, place on the market, deploy or otherwise operate AI systems within its scope. The practical work starts with identifying the role of the organisation, mapping AI use cases, determining the applicable risk category, and identifying the obligations attached to each system.
More About
EU AI Act
The AI Act does not create one universal certification scheme for every AI system. Depending on the system and its classification, organisations may need risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity controls, transparency measures, conformity assessment and post-market monitoring.
For organisations seeking EU AI Act advisory support, the regulation is broader than a single security checklist. It connects AI governance consulting, risk management, data practices, technical controls, transparency and accountability. Our EU AI Act consulting approach connects those requirements to the existing security and governance environment. For organisations using AI across cloud platforms, software products, internal operations or regulated environments, the first priority is a clear inventory and evidence-based classification of each relevant use case.
SUMMARY
Type
EU Regulation – Direct Application
Entry into Force
1 August 2024
Key Application Dates
2 August 2026
Primary Scope
Providers, deployers and other operators within scope
Certification
No universal AI Act certificate
Maximum Penalty
Up to €35 million or 7% of worldwide annual turnover for prohibited practices or certain data-related violations
What the EU AI Act Covers
The AI Act applies according to the role an organisation has in the AI value chain and the type of AI system involved. Providers, deployers, importers, distributors and other operators can have different responsibilities.
Compliance is demonstrated through the controls, documentation, governance processes and assessments required for the relevant AI system. Some high-risk systems are subject to conformity assessment requirements, while transparency and general-purpose AI obligations follow their own rules and timelines.
2 Dec 2027
Current target for the application of the main high-risk AI rules under the EU’s updated implementation timeline.
Risk-Based
Different obligations apply according to the AI system’s risk classification and role in the AI value chain.
Evidence
Policies, risk assessments, technical documentation, records and operational controls provide the evidence needed to demonstrate compliance.
Who is affected
The AI Act can affect providers and deployers across sectors, including organisations using AI for business operations, customer interactions, decision support, software products and regulated processes. The exact obligations depend on the system, intended purpose and role of the organisation.
Provider
Providers and AI Developers
Organisations that develop an AI system or place it on the market under the conditions defined by the AI Act can carry significant provider obligations, including risk management, technical documentation, quality controls and post-market responsibilities for applicable systems.
Deployer
AI Deployers
Organisations using AI systems in their operations may have deployer responsibilities, including following instructions for use, maintaining appropriate oversight, keeping required records and meeting transparency or other obligations that apply to the use case.
GPAI
General-Purpose AI Providers
Providers of general-purpose AI models have additional obligations covering areas such as technical documentation, information for downstream providers and, for models with systemic risk, additional evaluation and risk-management measures.
AI risk categories
Prohibited AI practices
Prohibited AI Practices
Certain AI practices are prohibited under the AI Act. Organisations should identify affected use cases early and establish effective controls to prevent prohibited practices from entering production or being introduced through third-party tools across their technology environment.
High-risk AI systems
High-Risk AI Systems
High-risk systems face extensive requirements. Depending on the category, organisations may need risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity and quality management measures.
Transparency obligations
Transparency Obligations
Article 50 introduces transparency obligations for specified AI systems and AI-generated or manipulated content. Organisations should assess where users need to be informed that they are interacting with AI or where generated content must be appropriately marked or detectable.
Key requirements
Key AI Act requirements depend on the system’s classification and role. For applicable high-risk systems, the regulation establishes requirements covering risk management, data governance, technical documentation, records, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.
Risk Management
Risk Management
Applicable high-risk AI systems require a continuous risk management process that identifies and analyses known and reasonably foreseeable risks, evaluates them against the intended purpose, and risk-control measures.
Mandatory
Data and Data Governance
Data and Data Governance
Training, validation and test data used for applicable high-risk systems must meet the relevant quality and governance requirements, including appropriate data practices for the intended purpose and risk profile.
Mandatory
Technical Documentation
Technical Documentation
Providers of applicable high-risk AI systems must maintain technical documentation that demonstrates how the system meets the relevant requirements and supports assessment, deployment and regulatory oversight.
Mandatory
Logging and Record Keeping
Logging and Record Keeping
Applicable high-risk systems must support appropriate automatic logging to enable traceability and monitoring of operation, subject to the requirements of the regulation and the system’s intended use.
Mandatory
Human Oversight
Human Oversight
High-risk AI systems require appropriate human oversight measures so that people can monitor operation, interpret outputs, intervene where necessary and manage risks arising from system use.
Mandatory
Accuracy, Robustness and Cybersecurity
Accuracy, Robustness and Cybersecurity
Applicable high-risk AI systems must achieve appropriate levels of accuracy, robustness and cybersecurity throughout their lifecycle, with controls designed to reduce foreseeable risks and support reliable operation.
Cybersecurity
€35M
Maximum administrative fine threshold for prohibited practices or certain data-related violations, or 7% of worldwide annual turnover, subject to the applicable rules and circumstances.
The AI Act provides different penalty thresholds depending on the infringement. Prohibited practices and certain data-related violations can attract fines of up to €35 million or 7% of worldwide annual turnover. Other obligations can attract fines of up to €15 million or 3% of worldwide annual turnover, with specific rules for SMEs.
AI Act compliance and readiness
The AI Act is not satisfied by a single policy document. Organisations need a traceable compliance framework that connects AI inventory, classification, risk assessment, governance, technical controls, documentation and ongoing monitoring.
For high-risk systems, the compliance pathway can involve risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, quality management and post-market monitoring. The exact route depends on the system and applicable provisions.
- AI inventory and role mapping
- Risk classification and obligation matrix
- Prioritised control gap assessment
- Evidence and readiness roadmap
How we deliver AI Act engagements
KairosVector provides EU AI Act consulting and AI Act compliance consulting for organisations that need a practical path from AI inventory to documented controls. We map AI use cases, classify systems, assess applicable obligations, identify control gaps and build the evidence needed for governance and regulatory readiness.
Step 1 – AI Inventory Review
AI Inventory and Scope
We identify AI systems and use cases across products, business functions, vendors and cloud environments, then establish the role of each organisation in the AI value chain and its regulatory responsibilities.
Output: AI inventory and role map with an initial scope and obligation assessment
Step 2 – Risk Classification
Risk Classification and Gap Assessment
We assess intended purpose, deployment context and relevant characteristics to determine whether each system falls into prohibited, high-risk, transparency, general-purpose AI or other applicable categories.
Output: AI risk classification and obligation matrix with prioritised findings
Step 3 – Control Design
Control Design and Remediation
We work with security, engineering, legal, product and governance teams to close gaps across risk management, data governance, human oversight, technical controls and transparency.
Output: Prioritised remediation plan with control owners, requirements and actions
Step 4 – Evidence and Readiness
Evidence and Regulatory Readiness
We help prepare policies, records, technical documentation and governance evidence needed for applicable AI Act obligations, and establish a practical process for ongoing review as requirements evolve.
Output: AI Act package with documented controls, and governance workflow
Related
Connected frameworks
and services
Start with a 30-minute discovery call
We scope your AI systems and map the obligations that apply. In a 30-minute discovery call, we can review your AI inventory, risk classification, governance model and the practical steps needed for EU AI Act compliance and readiness.
You leave with:
- Your AI system scope and role map
- Your risk classification and obligation matrix
- Your priority remediation plan
EU AI Act FAQ
What is the EU AI Act?
The EU AI Act is the European Union’s risk-based regulation for artificial intelligence. It sets different obligations for prohibited practices, high-risk AI systems, transparency-related use cases and general-purpose AI models.
When does the EU AI Act apply?
The regulation applies in stages. Prohibitions and AI literacy rules have applied since 2 February 2025. General-purpose AI obligations began on 2 August 2025, while transparency obligations under Article 50 apply from 2 August 2026. The current EU implementation timeline places the main high-risk rules from 2 December 2027 and AI embedded in regulated products from 2 August 2028.
Does every AI system need certification?
No. The AI Act does not create one universal certification requirement for every AI system. Obligations depend on the system’s role, intended purpose, risk category and the applicable provisions of the regulation.
How can KairosVector help with EU AI Act compliance?
KairosVector can help map AI systems, determine roles and risk categories, assess applicable obligations, identify control gaps, define remediation priorities and prepare governance and evidence needed for AI Act readiness.
What are the potential EU AI Act penalties?
The regulation sets different maximum thresholds. Certain prohibited practices and data-related violations can attract fines of up to €35 million or 7% of worldwide annual turnover. Other obligations can attract fines of up to €15 million or 3% of worldwide annual turnover, subject to the applicable rules and circumstances.