GRC Oversight

EU AI Act

The EU AI Act is a regulation that establishes harmonized, risk-based rules for AI systems placed on the EU market, with obligations scaled to the level of risk.

Governed by European Union (Regulation 2024/1689)
What it is

What EU AI Act is, in plain terms

The EU AI Act is the first comprehensive, binding regulation of artificial intelligence. It takes a risk-based approach, classifying AI systems as unacceptable, high, limited, or minimal risk and scaling obligations accordingly. It prohibits certain practices outright, imposes substantial requirements on high-risk systems, and adds specific obligations for general-purpose AI models placed on the EU market.

Typical effort & timeline

Obligations phase in over time after the regulation enters into force, with different requirements applying on different dates. Programs prioritize classifying systems and standing up risk-management and documentation for higher-risk uses.

Who needs it

Is this framework for you?

  • Providers and deployers of AI systems offered on the EU market.
  • Companies building high-risk AI applications subject to stricter obligations.
  • Developers of general-purpose AI models with EU exposure.
About the framework

Key facts about EU AI Act

  • Classifies AI systems by risk: unacceptable, high, limited, and minimal.
  • Prohibits certain AI practices deemed an unacceptable risk.
  • Sets requirements for high-risk AI systems (e.g., risk management, data governance, transparency).
  • Includes specific obligations for general-purpose AI models.

Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.

With this platform

How we help with EU AI Act

  • Track high-risk-system obligations against tests and evidence.
  • Maintain AI risk and data-governance documentation.
  • Align with ISO 42001 and the NIST AI RMF where they overlap.
  • Keep transparency and oversight documentation organized.
Step by step

Get and stay compliant

How the platform supports your EU AI Act program, from first scope to ongoing monitoring.

Classify your systems

Determine the risk category of each AI system, which drives the obligations that apply.

Stand up risk management

Maintain a risk-management system and AI risk documentation for high-risk uses.

Govern data & transparency

Document data governance, transparency, and human-oversight measures.

Monitor post-market

Keep post-market monitoring and oversight documentation current.

Representative areas

What EU AI Act covers

Public, high-level control or requirement areas, for orientation, not a complete control list.

Risk classification
Risk management system
Data & data governance
Transparency & documentation
Human oversight
Post-market monitoring
Do it once

Reuse evidence across frameworks

EU AI Act shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.

FAQ

Common questions about EU AI Act

By risk: unacceptable (prohibited), high, limited, and minimal, with obligations scaled to the level of risk.

Yes. It includes specific obligations for general-purpose AI models in addition to the risk-tiered system rules.

ISO 42001 and the NIST AI RMF provide governance and risk practices that align with many of the Act's high-risk requirements.

Get audit-ready for EU AI Act

Get a guided demo, or start by scanning any domain for free.