Guide

    EU AI Act Compliance: Complete Guide and Requirements

    The EU AI Act is the first binding comprehensive legal framework for artificial intelligence, formally adopted in May 2024, in force since August 1, 2024, and now enforceable law: banned AI practices have been prohibited since February 2, 2025, and full compliance for high-risk systems is required by August 2, 2026. Penalties reach €35 million or 7% of global annual turnover, whichever is higher, and the Act's extraterritorial reach means it applies to any organization whose AI systems affect EU residents, regardless of where the company is headquartered.

    Key takeaways

    • Applies to any organization whose AI affects EU residents, regardless of headquarters location
    • AI systems fall into four risk tiers plus a General-Purpose AI category, each with distinct obligations
    • Your role as provider or deployer determines your specific obligations
    • Key dates: February 2025 (prohibited AI banned), August 2025 (GPAI governance rules), August 2026 (full high-risk compliance)
    • Just as GDPR became the global data-privacy template, the AI Act is shaping AI regulation worldwide

    Who needs to comply?

    Providers (organizations that develop or place AI systems on the EU market), deployers (organizations using AI systems in the EU or affecting EU residents), plus importers and distributors. The provider/deployer distinction drives obligations: providers carry conformity assessment, technical documentation, and quality-management duties; deployers carry usage controls, human oversight, monitoring, and record-keeping duties. Many enterprises are both, provider of some systems, deployer of many more.

    What are the risk categories?

    • Unacceptable risk, prohibited outright (e.g., social scoring, manipulative systems exploiting vulnerabilities) since February 2025
    • High risk, AI in domains like employment, credit, insurance, education, and critical services: subject to risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy/robustness requirements
    • Limited risk, transparency obligations (e.g., disclosing AI interaction, labeling synthetic content)
    • Minimal risk, no specific obligations, though voluntary codes apply
    • General-Purpose AI (GPAI), its own governance track for foundation models, with documentation and systemic-risk obligations phased from August 2025

    What should enterprises do now?

    Build the AI inventory (you cannot classify what you haven't listed, and many enterprises still lack even this); classify each system by risk tier and your role; map obligations per system; implement the operational requirements, logging, human oversight, monitoring, documentation; and stand up continuous evidence so conformity is demonstrable, not asserted. The operational core (per-interaction logging, runtime policy enforcement, oversight checkpoints, automatic evidence) is exactly what Trussed AI's control plane provides, turning AI Act obligations from a documentation project into properties of your AI infrastructure, with policy updates absorbing future guidance.

    Frequently Asked Questions

    We're US-based with EU customers, are we in scope? Almost certainly: the Act applies where AI outputs affect people in the EU, independent of company location.

    Do internal-only AI tools fall under the Act? They can, employment-related AI (hiring, worker management) is explicitly high-risk even when purely internal.

    What's the highest-priority gap to close before August 2026? Logging and human oversight on high-risk systems, they're operationally hardest to retrofit and the first things conformity assessment examines.

    Ready to govern your AI in production?