What Is the EU AI Act?
The EU AI Act is the world’s first comprehensive AI regulation. It establishes a risk-based framework that classifies AI systems into four categories, each with different compliance obligations. The Act applies to any organization deploying AI systems in the European Union, regardless of where the organization is based.
Key Deadline: August 2026 — Full compliance required for most provisions. Non-compliance can result in fines up to 35 million EUR or 7% of global annual turnover.
Risk Classification Framework
Unrestricted Risk (Minimal Risk)
The majority of AI systems fall into this category. No specific obligations beyond general EU law (consumer protection, data protection, product safety). Voluntary compliance measures encouraged.
Examples: AI-powered spam filters, AI-enabled video games, inventory management tools.
Limited Risk
AI systems that interact with humans and could manipulate their behavior or pose safety risks.
Obligations (Article 52):
- Transparency: Users must be informed they are interacting with an AI
- AI-generated content must be clearly disclosed
- Emotion recognition and biometric categorization systems have additional transparency duties
Examples: Chatbots, AI sentiment analysis tools, AI recruitment screening (non-decision-making).
High-Risk
AI systems used in critical areas where failures could cause significant harm. This is the most regulated category.
Obligations (Annex III, Annex IV, Annex V):
- Conformity assessment before market placement
- Registration in the EU database
- Risk management system (Article 9)
- Data governance and quality controls (Article 10)
- Technical documentation covering all 14 Annex IV elements
- Transparency and user information (Article 13)
- Human oversight measures (Article 14)
- Accuracy, robustness, and cybersecurity (Articles 15-17)
- Post-market monitoring system (Article 72)
- Incident reporting (Article 73)
- CE marking and EU Declaration of Conformity
High-Risk Categories (Annex III):
- Biometric identification and categorization
- Emotion recognition in workplace and education
- Critical infrastructure management
- Education and vocational training
- Employment and worker evaluation
- Credit scoring and insurance assessment
- Law enforcement operations
- Migration and border control
- Administration of justice and democratic processes
Examples: AI hiring tools, medical device AI, autonomous vehicle systems, credit scoring algorithms.
Prohibited AI
Certain AI practices are banned entirely. These systems cannot be placed on the market or put into service within the EU.
Prohibited Practices (Article 5):
- Subconscious manipulation techniques
- Social scoring by public authorities
- Real-time remote biometric identification in public spaces (with limited law enforcement exceptions)
- Risk-based AI that exploits vulnerabilities of specific groups
- AI that enables inference of personality traits from biometric data
Penalties: Up to 35 million EUR or 7% of global annual turnover.
General-Purpose AI Models
A separate category for foundation models and large language models.
GPAI Obligations (Article 53):
- Technical documentation (Annex XI)
- Transparency information for downstream users (Annex XII)
- Copyright compliance for training data
- Policies to detect illegal content generation
GPAI with Systemic Risk (Articles 51, 55): Additional obligations for models with very high computational training capacity:
- Model evaluation and testing
- Adverse incident reporting
- Energy consumption monitoring and disclosure
- FLOPs computation
- Code of Practice compliance
The 14 Annex IV Elements
High-risk AI systems must provide technical documentation covering these elements:
- Name and address of provider — Provider identification and contact details
- Description of the AI system — System architecture, capabilities, and intended purpose
- General purpose — Intended use cases and deployment context
- Monitoring instructions — Procedures for ongoing performance monitoring
- Physical or logical interfaces — System integration points and API specifications
- Human oversight measures — Mechanisms for human control and intervention
- Robustness, accuracy and completeness — Performance metrics and validation results
- Cybersecurity measures — Security controls, penetration testing, threat modeling
- Data governance and training data — Data sourcing, quality assurance, bias analysis
- Technical constraints — Operating conditions, limitations, and boundary specifications
- Typical errors and interactions — Known failure modes and error handling
- Change control documentation — Version history, change management procedures
- Expected lifetime and retraining — System lifecycle planning and model update strategy
- Automated decision-making information — Decision logic explanation and appeal mechanisms
How aissurance Helps
aissurance automates the compliance workflow for each risk tier:
- Risk Classification Engine: Determines your system’s category using a JSON-driven rules engine based on Annex III / Article 6
- Evidence Locker: Organizes evidence for all 14 Annex IV elements with verification tracking
- Documentation Generator: Produces formal regulatory documents (PDF + JSON)
- Post-Market Monitoring: Tracks incidents (Article 73) and compliance deadlines
- Nomyo Router Discovery: Auto-inventories your AI systems from existing infrastructure