Regulatory Framework

EU AI
Act

The EU AI Act is the European Union’s risk-based legal framework for artificial intelligence. It sets obligations for providers and deployers based on how AI systems are used and the level of risk they create. Prohibited AI practices are already subject to the rules, while transparency and other obligations apply on a phased timeline.

AI Act Overview

Type

EU Regulation – Direct Application

Entry into Force

1 August 2024

Key Application Dates

2 August 2026

Scope

AI providers, deployers and other operators

Certification

No single AI Act certificate – conformity requirements depend on the AI system

Maximum Penalty

Up to €35 million or 7% of worldwide annual turnover for prohibited practices or certain data-related violations

Current AI Act Timeline

The AI Act is now entering its broader application phase. Prohibitions and AI literacy rules have applied since February 2025, general-purpose AI obligations since August 2025, and transparency obligations under Article 50 from August 2026. High-risk rules have a later application date under the current EU implementation timeline.

What It Is

Understanding
the EU AI Act

The EU AI Act, Regulation (EU) 2024/1689, establishes harmonised rules for artificial intelligence across the European Union. It uses a risk-based approach covering prohibited AI practices, high-risk AI systems, transparency obligations, and general-purpose AI models. The regulation entered into force on 1 August 2024 and applies in stages.

The EU AI Act can affect organisations that develop, place on the market, deploy or otherwise operate AI systems within its scope. The practical work starts with identifying the role of the organisation, mapping AI use cases, determining the applicable risk category, and identifying the obligations attached to each system.

More About
EU AI Act

The AI Act does not create one universal certification scheme for every AI system. Depending on the system and its classification, organisations may need risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity controls, transparency measures, conformity assessment and post-market monitoring.

For organisations seeking EU AI Act advisory support, the regulation is broader than a single security checklist. It connects AI governance consulting, risk management, data practices, technical controls, transparency and accountability. Our EU AI Act consulting approach connects those requirements to the existing security and governance environment. For organisations using AI across cloud platforms, software products, internal operations or regulated environments, the first priority is a clear inventory and evidence-based classification of each relevant use case.

SUMMARY

Type

EU Regulation – Direct Application

Entry into Force

1 August 2024

Key Application Dates

2 August 2026

Primary Scope

Providers, deployers and other operators within scope

Certification

No universal AI Act certificate

Maximum Penalty

Up to €35 million or 7% of worldwide annual turnover for prohibited practices or certain data-related violations

What the EU AI Act Covers

The AI Act applies according to the role an organisation has in the AI value chain and the type of AI system involved. Providers, deployers, importers, distributors and other operators can have different responsibilities.

Compliance is demonstrated through the controls, documentation, governance processes and assessments required for the relevant AI system. Some high-risk systems are subject to conformity assessment requirements, while transparency and general-purpose AI obligations follow their own rules and timelines.

2 Dec 2027

Current target for the application of the main high-risk AI rules under the EU’s updated implementation timeline.

Risk-Based

Different obligations apply according to the AI system’s risk classification and role in the AI value chain.

Evidence

Policies, risk assessments, technical documentation, records and operational controls provide the evidence needed to demonstrate compliance.

Who is affected

The AI Act can affect providers and deployers across sectors, including organisations using AI for business operations, customer interactions, decision support, software products and regulated processes. The exact obligations depend on the system, intended purpose and role of the organisation.

Provider

Providers and AI Developers

Organisations that develop an AI system or place it on the market under the conditions defined by the AI Act can carry significant provider obligations, including risk management, technical documentation, quality controls and post-market responsibilities for applicable systems.

Deployer

AI Deployers

Organisations using AI systems in their operations may have deployer responsibilities, including following instructions for use, maintaining appropriate oversight, keeping required records and meeting transparency or other obligations that apply to the use case.

GPAI

General-Purpose AI Providers

Providers of general-purpose AI models have additional obligations covering areas such as technical documentation, information for downstream providers and, for models with systemic risk, additional evaluation and risk-management measures.

AI risk categories

Prohibited AI practices

Prohibited AI Practices

Certain AI practices are prohibited under the AI Act. Organisations should identify affected use cases early and establish effective controls to prevent prohibited practices from entering production or being introduced through third-party tools across their technology environment.

High-risk AI systems

High-Risk AI Systems

High-risk systems face extensive requirements. Depending on the category, organisations may need risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity and quality management measures.

Transparency obligations

Transparency Obligations

Article 50 introduces transparency obligations for specified AI systems and AI-generated or manipulated content. Organisations should assess where users need to be informed that they are interacting with AI or where generated content must be appropriately marked or detectable.

Key requirements

Key AI Act requirements depend on the system’s classification and role. For applicable high-risk systems, the regulation establishes requirements covering risk management, data governance, technical documentation, records, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.

Risk Management

Risk Management

Applicable high-risk AI systems require a continuous risk management process that identifies and analyses known and reasonably foreseeable risks, evaluates them against the intended purpose, and risk-control measures.

Mandatory

Data and Data Governance

Data and Data Governance

Training, validation and test data used for applicable high-risk systems must meet the relevant quality and governance requirements, including appropriate data practices for the intended purpose and risk profile.

Mandatory

Technical Documentation

Technical Documentation

Providers of applicable high-risk AI systems must maintain technical documentation that demonstrates how the system meets the relevant requirements and supports assessment, deployment and regulatory oversight.

Mandatory

Logging and Record Keeping

Logging and Record Keeping

Applicable high-risk systems must support appropriate automatic logging to enable traceability and monitoring of operation, subject to the requirements of the regulation and the system’s intended use.

Mandatory

Human Oversight

Human Oversight

High-risk AI systems require appropriate human oversight measures so that people can monitor operation, interpret outputs, intervene where necessary and manage risks arising from system use.

Mandatory

Accuracy, Robustness and Cybersecurity

Accuracy, Robustness and Cybersecurity

Applicable high-risk AI systems must achieve appropriate levels of accuracy, robustness and cybersecurity throughout their lifecycle, with controls designed to reduce foreseeable risks and support reliable operation.

Cybersecurity

€35M

Maximum administrative fine threshold for prohibited practices or certain data-related violations, or 7% of worldwide annual turnover, subject to the applicable rules and circumstances.

The AI Act provides different penalty thresholds depending on the infringement. Prohibited practices and certain data-related violations can attract fines of up to €35 million or 7% of worldwide annual turnover. Other obligations can attract fines of up to €15 million or 3% of worldwide annual turnover, with specific rules for SMEs.

AI Act compliance and readiness

The AI Act is not satisfied by a single policy document. Organisations need a traceable compliance framework that connects AI inventory, classification, risk assessment, governance, technical controls, documentation and ongoing monitoring.

For high-risk systems, the compliance pathway can involve risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, quality management and post-market monitoring. The exact route depends on the system and applicable provisions.

  • AI inventory and role mapping
  • Risk classification and obligation matrix
  • Prioritised control gap assessment
  • Evidence and readiness roadmap

How we deliver AI Act engagements

KairosVector provides EU AI Act consulting and AI Act compliance consulting for organisations that need a practical path from AI inventory to documented controls. We map AI use cases, classify systems, assess applicable obligations, identify control gaps and build the evidence needed for governance and regulatory readiness.

Step 1 – AI Inventory Review

AI Inventory and Scope

We identify AI systems and use cases across products, business functions, vendors and cloud environments, then establish the role of each organisation in the AI value chain and its regulatory responsibilities.

Output: AI inventory and role map with an initial scope and obligation assessment

Step 2 – Risk Classification

Risk Classification and Gap Assessment

We assess intended purpose, deployment context and relevant characteristics to determine whether each system falls into prohibited, high-risk, transparency, general-purpose AI or other applicable categories.

Output: AI risk classification and obligation matrix with prioritised findings

Step 3 – Control Design

Control Design and Remediation

We work with security, engineering, legal, product and governance teams to close gaps across risk management, data governance, human oversight, technical controls and transparency.

Output: Prioritised remediation plan with control owners, requirements and actions

Step 4 – Evidence and Readiness

Evidence and Regulatory Readiness

We help prepare policies, records, technical documentation and governance evidence needed for applicable AI Act obligations, and establish a practical process for ongoing review as requirements evolve.

Output: AI Act package with documented controls, and governance workflow

Related

Connected frameworks
and services

Start with a 30-minute discovery call

We scope your AI systems and map the obligations that apply. In a 30-minute discovery call, we can review your AI inventory, risk classification, governance model and the practical steps needed for EU AI Act compliance and readiness.

You leave with:

  • Your AI system scope and role map
  • Your risk classification and obligation matrix
  • Your priority remediation plan

EU AI Act FAQ

What is the EU AI Act?

The EU AI Act is the European Union’s risk-based regulation for artificial intelligence. It sets different obligations for prohibited practices, high-risk AI systems, transparency-related use cases and general-purpose AI models.

When does the EU AI Act apply?

The regulation applies in stages. Prohibitions and AI literacy rules have applied since 2 February 2025. General-purpose AI obligations began on 2 August 2025, while transparency obligations under Article 50 apply from 2 August 2026. The current EU implementation timeline places the main high-risk rules from 2 December 2027 and AI embedded in regulated products from 2 August 2028.

Does every AI system need certification?

No. The AI Act does not create one universal certification requirement for every AI system. Obligations depend on the system’s role, intended purpose, risk category and the applicable provisions of the regulation.

How can KairosVector help with EU AI Act compliance?

KairosVector can help map AI systems, determine roles and risk categories, assess applicable obligations, identify control gaps, define remediation priorities and prepare governance and evidence needed for AI Act readiness.

What are the potential EU AI Act penalties?

The regulation sets different maximum thresholds. Certain prohibited practices and data-related violations can attract fines of up to €35 million or 7% of worldwide annual turnover. Other obligations can attract fines of up to €15 million or 3% of worldwide annual turnover, subject to the applicable rules and circumstances.

Scroll to Top