Aegis Oversight
Sign UpSchedule Demo
Aegis Oversight
Sign UpSchedule Demo
European Union

EU AI Act

The world’s first comprehensive AI law. Classify your systems, build technical documentation, prove human oversight, and prepare for conformity assessment — before high-risk obligations apply in August 2026.

In force August 2024; high-risk obligations apply from August 2026
1

Framework Overview

The EU AI Act (Regulation 2024/1689) is the first horizontal legal framework for artificial intelligence. It regulates AI systems placed on the EU market using a risk-based approach, with the strictest obligations reserved for high-risk applications.

AI systems are sorted into four risk tiers — unacceptable, high, limited, and minimal. Unacceptable practices (social scoring, untargeted facial scraping, manipulative subliminal techniques) are prohibited outright. Limited-risk systems must meet transparency obligations, while minimal-risk systems are largely unregulated.

High-risk systems listed in Annex III (and those that pose significant harm to health, safety, or fundamental rights) must implement a full risk management system, maintain technical documentation, ensure data governance and quality, provide human oversight, achieve robustness and cybersecurity, undergo conformity assessment, obtain CE marking, and be registered in the EU database.

General-purpose AI model providers carry transparency obligations (technical documentation, training-data summaries, copyright policy), and models presenting systemic risk must perform model evaluations, adversarial testing, and incident reporting.

Who must comply

Providers, deployers, importers, distributors, and authorised representatives that place AI systems on the EU market, plus providers of general-purpose AI models — including organisations based outside the EU when their systems are used in the EU.

Maximum penalties

Up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for breaching high-risk obligations; up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information.

2

Key Requirements Checklist

Use this checklist to scope your EU AI Act compliance program.

Classify every AI system by risk tier

Document each system as unacceptable, high, limited, or minimal and record the rationale. Unacceptable systems must be withdrawn.

Implement a risk management system

Identify, estimate, evaluate, and mitigate known and reasonably foreseeable risks across the AI lifecycle for high-risk systems.

Ensure data governance and quality

Address training, validation, and testing datasets for relevance, representativeness, and freedom from errors, with bias-mitigation measures.

Maintain technical documentation and logging

Keep Annex IV technical documentation up to date and automatically log events to ensure traceability.

Provide transparency to deployers and users

Supply instructions for use, intended purpose, and human-oversight measures so deployers can operate systems properly.

Guarantee human oversight

Design for meaningful human involvement with the ability to override or halt outputs where appropriate.

Achieve accuracy, robustness, and cybersecurity

Document accuracy metrics, resilience to errors and attacks, and cybersecurity protections with appropriate testing.

Run post-market monitoring and report incidents

Monitor system performance in real-world use and report serious incidents to national authorities within strict timeframes.

Complete conformity assessment and CE marking

Self-assess or involve a notified body depending on the system type, affix the CE mark, and register in the EU database.

Appoint an authorised representative (non-EU providers)

If established outside the EU, mandate a representative located in a Member State for compliance liaison.

Meet GPAI transparency obligations (if applicable)

For general-purpose AI models, maintain technical documentation, training-data summaries, a copyright policy, and downstream-provider documentation.

3

How Aegis Oversight Automates EU AI Act Compliance

Pre-built controls, continuous checks, and audit-ready evidence — so you implement the checklist once and stay compliant automatically.

Risk classification engine

Each registered AI model is automatically scored and classified against EU AI Act tiers, with the classification rationale documented for auditors.

Annex IV technical documentation

Generate and maintain required technical documentation sections from your model inventory and assessment results instead of building them by hand.

Control library mapped to the AI Act

200+ pre-built controls mapped directly to the Act’s articles and annexes, ready to assign, implement, and evidence.

Automated conformity checks

Schedule continuous compliance checks against the high-risk requirements so gaps surface before a conformity assessment, not during it.

Post-market monitoring and incident reporting

Real-time performance, drift, and security monitoring feed incident records and alert your team to serious-incident reporting obligations.

Evidence collection for CE marking

Consolidate assessment results, logs, and remediation evidence into audit-ready packages that support conformity assessment and EU database registration.

4

Frequently Asked Questions

When do EU AI Act high-risk obligations take effect?

The Act entered into force in August 2024. Prohibited practices apply from February 2025, general-purpose AI obligations from August 2025, and the full high-risk system requirements from August 2026 (with extensions to 2027 for certain embedded products).

Who is a provider and who is a deployer?

A provider develops an AI system and places it on the market under its own name. A deployer uses an AI system under its authority. Providers carry the heaviest obligations, but deployers must follow instructions, monitor, and report incidents for high-risk systems.

What counts as a high-risk AI system?

Systems listed in Annex III — including biometric identification, critical infrastructure, education and employment, essential services, law enforcement, and democratic processes — plus any system that poses significant risk to health, safety, or fundamental rights.

What are the maximum penalties?

Up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for breaching high-risk obligations, and €7.5 million or 1% for providing incorrect information to authorities.

Do non-EU companies need to comply?

Yes. If your AI system’s output is used in the EU, the Act applies regardless of where you are established, and you must appoint an authorised representative located in a Member State.

How should we start preparing?

Inventory every AI system, classify each by risk tier, map controls to the requirements for high-risk systems, build technical documentation, and run gap analysis — well before August 2026.

Start your EU AI Act compliance journey today

Get a personalized walkthrough of how Aegis Oversight maps controls to EU AI Act requirements and keeps you audit-ready as the regulation evolves.