EU AI Act Compliance Guide
Understand your obligations based on your AI system's risk classification. From prohibited practices to voluntary measures.
Risk Levels at a Glance
The EU AI Act classifies AI systems into four risk categories, each with different compliance requirements.
AI systems that pose an unacceptable risk to people's safety or fundamental rights are banned entirely under the EU AI Act.
Affected Systems
Social scoring, real-time remote biometric identification in public spaces, emotion recognition in workplace/education, predictive policing based on profiling
Obligations
- Cease deployment immediately
- Remove system from production environment
- Document all compliance actions taken
- Notify relevant national authorities if system was previously deployed
- Conduct internal audit of remaining AI systems for similar practices
Documentation Requirements
- Decommissioning report with timeline
- Notification records to authorities
- Internal audit results
- Remediation action plan
Already in effect since February 2, 2025
Up to 7% of worldwide annual turnover or EUR 35 million
AI systems in critical areas like healthcare, finance, HR, education, and law enforcement must meet comprehensive compliance requirements before deployment.
Affected Systems
Credit scoring, medical diagnosis, biometric identification, HR/recruitment tools, employee monitoring, critical infrastructure, education/grading, fraud detection, autonomous vehicles
Obligations
- Establish a risk management system covering the entire AI lifecycle
- Implement data governance framework for training and validation data
- Prepare comprehensive technical documentation
- Ensure human oversight mechanisms are in place
- Test for accuracy, robustness, and cybersecurity
- Register the AI system in the EU database
- Complete conformity assessment before market placement
- Implement post-market monitoring system
- Report serious incidents to authorities
Documentation Requirements
- Risk management plan and assessment records
- Data governance documentation (data sources, cleaning, bias testing)
- Technical documentation (system architecture, algorithms, training process)
- Conformity assessment report
- EU database registration confirmation
- Human oversight procedures and training records
- Accuracy and robustness test results
- Post-market monitoring plan
- Incident response procedures
Full compliance required by August 2, 2026
Up to 3% of worldwide annual turnover or EUR 15 million
AI systems that interact with people or generate content must meet transparency requirements so users know they are dealing with AI.
Affected Systems
Chatbots, voice agents, content generation (text/image/video), LLM integrations, automated marketing, legal document analysis
Obligations
- Clearly disclose that users are interacting with an AI system
- Label all AI-generated content (text, images, audio, video)
- Enable users to identify AI-generated decisions that affect them
- Maintain records of AI system outputs for accountability
- Provide accessible information about AI capabilities and limitations
Documentation Requirements
- AI disclosure notices and their placement
- Content labeling procedures and technical implementation
- User notification templates and scripts
- Output logging and retention policy
- System capability and limitation descriptions
Full compliance required by August 2, 2026
Up to 1.5% of worldwide annual turnover or EUR 7.5 million
Most AI systems fall into this category and have no mandatory obligations under the AI Act. However, voluntary compliance demonstrates responsible AI use.
Affected Systems
Recommendation engines, document processing, predictive analytics, RPA, inventory management, code assistants, sentiment analysis, customer analytics
Obligations
- Consider adopting a voluntary code of conduct
- Monitor ongoing regulatory developments and updates
- Document AI systems proactively for future-readiness
- Implement basic AI governance practices
- Stay informed about sector-specific guidelines
Documentation Requirements
- AI system inventory and descriptions
- Voluntary code of conduct (if adopted)
- Internal AI governance policy
- Regulatory monitoring log
No mandatory deadline -- voluntary compliance recommended
No penalties for minimal risk systems under the AI Act
Not Sure About Your Risk Level?
Run our free classifier to identify which risk categories your AI systems fall under.
Start Free Risk Classification