The EU AI Act in one page.
The EU AI Act, Regulation (EU) 2024/1689, creates a risk-based framework for AI systems placed on, supplied into, or used in the EU market. It does not treat every AI tool equally. The obligations depend on the role your organisation plays, the intended purpose of the system, the people affected, and the risk category.
1. Know your role.
A team can have different duties depending on whether it builds, deploys, imports, or distributes an AI system. One organisation can hold more than one role for different systems.
2. Classify the system by intended purpose.
The EU AI Act uses risk tiers. The most operationally important split is whether a system is prohibited, high-risk, limited-risk, or lower-risk. High-risk systems often need the strongest evidence trail.
Common risk signals
- Employment, worker management, recruitment, education, credit, law enforcement, migration, healthcare, or essential service access.
- Systems that affect people, access to opportunities, safety, rights, or essential decisions.
- Systems using personal data, special category data, biometric inputs, or sensitive profiling.
Art. 5 Art. 6 Annex III
3. Maintain the records reviewers usually ask for.
Readiness work is not only about a score. A reviewer will want to see what system exists, what it does, why the risk tier was chosen, who owns it, what controls are in place, and what evidence supports those claims.
Art. 9 Art. 10 Art. 11 Art. 12 Art. 13 Art. 14 Art. 15 Art. 72 Art. 73
4. Do not separate AI Act work from privacy work.
Many AI systems also process personal data. That means GDPR duties may sit beside AI Act duties. A DPIA and a Fundamental Rights Impact Assessment can overlap in facts, but they are not the same document.
- Map personal and special category data used by the system.
- Explain lawful basis, transparency notices, retention, rights handling, and automated decision concerns.
- Record human review, appeal routes, bias mitigation, and affected groups.
- Keep privacy records aligned with AI governance records so the story is consistent.
5. Dates and enforcement matter.
The EU AI Act applies in stages. Several provisions are already in force — others apply from 2026 and 2027. The table below shows the full timeline as of June 2026.
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | Regulation entered into force | ✓ IN FORCE |
| 2 Feb 2025 | Prohibited AI practices (Art. 5) — unacceptable-risk systems banned | ✓ IN FORCE |
| 2 Aug 2025 | General-purpose AI (GPAI) rules (Chapter V) — transparency, systemic-risk models | ✓ IN FORCE |
| 2 Aug 2026 | High-risk AI obligations (Art. 6, 9–15, 17, 20, 21, 23, 24, 26, 28) — risk management, data governance, transparency, human oversight, accuracy, logging | ⏳ UPCOMING |
| 2 Aug 2027 | High-risk AI embedded in Annex I regulated products (machinery, medical devices, vehicles) | FUTURE |
Penalty exposure can be significant, but the practical value of readiness work is not fear — it is being able to explain what AI you use, how you classified it, and what evidence supports the operating controls.
6. Where AICVS fits.
AICVS is designed to help teams turn scattered AI use into structured readiness records. It supports inventory, likely risk classification, evidence, Annex IV draft inputs, DPIA/FRIA readiness, explainability, monitoring, incidents, and audit-pack exports based on available records.
What it does not do
- It does not provide legal advice.
- It does not certify EU AI Act compliance.
- It does not replace a notified body, auditor, solicitor, DPO, or qualified reviewer.
- It does not guarantee a complete technical file when your underlying records are incomplete.