What Does EU AI Act Compliance Require?
EU AI Act compliance requires organizations to classify each AI system they develop, deploy, or use into one of four risk tiers: unacceptable, high, limited, or minimal, and then meet the obligations attached to that tier, which range from an outright ban to no formal requirements at all. The Act entered into force in August 2024, with obligations phasing in on a staggered schedule through 2027, so compliance is not a single deadline but a sequence of dates that apply differently depending on what an organization's AI systems do.
Key facts about EU AI Act compliance:
- Entered into force: August 1, 2024
- Applies to: any organization placing AI systems on the EU market or whose AI system's output is used in the EU, regardless of where the organization is headquartered
- Risk tiers: unacceptable (banned), high-risk (strict obligations), limited-risk (transparency obligations), minimal-risk (no formal obligations)
- Prerequisite for compliance: a complete inventory of AI systems in use, since classification cannot happen for AI nobody has identified
- Enforcement: national authorities in each EU member state, with fines up to €35 million or 7% of global annual turnover for the most serious violations
Does the EU AI Act apply to your organization?
The Act applies extraterritorially. It covers not just companies based in the EU, but any organization, anywhere, that places an AI system on the EU market, or whose AI system's output is used within the EU, even if the organization has no physical presence there. This catches a broad range of non-EU companies: a US SaaS vendor selling to EU customers, a company whose AI-powered support tool serves EU users, or an organization whose AI hiring tool screens candidates in an EU country. The practical test is not where the company is located, but whether its AI system touches the EU market in either direction.
What are the EU AI Act's risk tiers?
Unacceptable risk (prohibited). A narrow set of AI practices banned outright, including government social scoring, certain forms of biometric categorization, manipulative AI that exploits vulnerabilities, and most real-time remote biometric identification in public spaces by law enforcement. These prohibitions took effect first in February 2025.
High-risk. AI systems used in specified high-stakes contexts, including employment and worker management, access to essential services (credit scoring, insurance), law enforcement, migration and border control, education, and critical infrastructure. This tier carries the Act's most extensive obligations: risk management systems, data governance, technical documentation, human oversight, accuracy and robustness testing, and conformity assessment before market placement.
Limited risk. AI systems with specific transparency obligations rather than full compliance requirements, primarily systems that interact directly with people (chatbots) or generate synthetic content (deepfakes), which must be disclosed as AI-generated or AI-driven.
Minimal risk. The majority of AI use cases, spam filters, AI-enabled video games, and similar low-stakes applications, which carry no formal obligations under the Act, though voluntary codes of conduct are encouraged.
What are the key EU AI Act compliance deadlines?
- August 1, 2024 — the Act enters into force.
- February 2, 2025 — prohibitions on unacceptable-risk AI practices take effect, along with AI literacy obligations for staff involved in operating AI systems.
- August 2, 2025 — obligations for general-purpose AI (GPAI) models take effect, including transparency and, for the most capable models, systemic-risk obligations. Governance structures for member-state enforcement also become operational.
- August 2, 2026 — the majority of high-risk AI system obligations take effect, along with transparency requirements for limited-risk systems.
- August 2, 2027 — obligations extend to high-risk AI systems that are safety components of products already regulated under existing EU product-safety law (machinery, medical devices, and similar categories).
Organizations should treat these as tier-specific deadlines, not one universal date. An organization with only minimal-risk AI has effectively no compliance deadline; an organization with high-risk employment-screening AI needs to be substantially ready well before the August 2026 milestone.
What does compliance actually require, step by step?
- Build a complete AI inventory. Every subsequent step depends on knowing what AI systems exist. This includes AI adopted outside formal procurement, since the Act does not distinguish between sanctioned and shadow AI when determining whether an obligation applies.
- Classify each system against the four risk tiers. Map each AI system's actual use case, not its marketing description, against the Act's tier definitions. The same underlying model can fall into different tiers depending on how it is deployed.
- Confirm your role. The Act defines different obligations for providers (organizations that develop or place AI systems on the market) and deployers (organizations that use AI systems developed by others under their own authority), and many organizations hold both roles simultaneously for different systems.
- Implement tier-specific obligations. For high-risk systems: establish a risk management system, ensure data governance and quality, produce technical documentation, enable human oversight, and complete conformity assessment before deployment. For limited-risk systems: implement the required transparency disclosures. For general-purpose AI models: meet the applicable transparency and, where relevant, systemic-risk documentation requirements.
- Assign accountability and monitoring. Name an owner for AI Act compliance per system, and establish ongoing monitoring, since obligations for high-risk systems continue after deployment, not just at launch.
- Prepare for national authority oversight. Each EU member state designates a national authority responsible for enforcement; understand which authority applies to your organization's EU market activity and maintain documentation ready for review.
How does the EU AI Act relate to NIST AI RMF and ISO 42001?
The Act is binding law; NIST AI RMF and ISO/IEC 42001 are not. But the underlying activities overlap substantially: all three require an AI inventory, risk classification, documented governance, and ongoing monitoring. Organizations already following NIST's Govern-Map-Measure-Manage structure, or certified to ISO 42001, generally find EU AI Act compliance a smaller incremental step than organizations starting from nothing, since the foundational work, particularly the inventory and classification, is largely shared across all three. Neither NIST alignment nor ISO 42001 certification substitutes for EU AI Act compliance, but both meaningfully de-risk it.
What is the biggest practical obstacle to EU AI Act compliance?
For most organizations, it is not understanding the obligations, the tier system and requirements are publicly documented in detail. It is the inventory problem: classification and every downstream obligation depend on knowing what AI systems exist, and most organizations significantly undercount their own AI use because much of it was never formally procured. An organization that has only inventoried its sanctioned AI tools is compliant on paper for a fraction of its actual AI footprint. Continuous AI discovery, the same capability needed for shadow AI and enterprise AI security more broadly, is consequently a practical prerequisite for EU AI Act compliance rather than a separate initiative.
FAQ
Does the EU AI Act apply to companies outside the EU? Yes. It applies to any organization whose AI system is placed on the EU market or whose output is used within the EU, regardless of where the organization is based.
What happens if an AI system is misclassified under the EU AI Act? Misclassification, treating a high-risk system as limited risk, exposes the organization to the obligations it failed to meet and the associated penalties, which scale up to €35 million or 7% of global annual turnover for the most serious violations. Accurate classification against the actual use case, not the system's general description, is essential.
When do EU AI Act obligations for high-risk systems take effect? The majority of high-risk system obligations take effect on August 2, 2026. However, high-risk systems that are safety components of already-regulated products (like machinery or medical devices) have until August 2, 2027.
Is a chatbot considered high-risk under the EU AI Act? Generally no. A standard customer-service chatbot typically falls into the limited-risk tier, which requires disclosure that the user is interacting with AI rather than the full high-risk obligations. Classification depends on the specific use case, though, and a chatbot used in a high-stakes context (such as a health-advice chatbot) could fall into a different tier.
Do I need an AI inventory before I can comply with the EU AI Act? Yes, effectively. Every obligation under the Act depends on first classifying AI systems by risk tier, which requires knowing what AI systems exist. Organizations without a complete inventory are compliant only for the AI they happen to already know about.