Skip to main content
Compliance Guide

EU AI Act Compliance Guide

Understand your obligations based on your AI system's risk classification. From prohibited practices to voluntary measures.

Risk Levels at a Glance

The EU AI Act classifies AI systems into four risk categories, each with different compliance requirements.

AI systems that pose an unacceptable risk to people's safety or fundamental rights are banned entirely under the EU AI Act.

Affected Systems

Social scoring, real-time remote biometric identification in public spaces, emotion recognition in workplace/education, predictive policing based on profiling

Obligations

  • Cease deployment immediately
  • Remove system from production environment
  • Document all compliance actions taken
  • Notify relevant national authorities if system was previously deployed
  • Conduct internal audit of remaining AI systems for similar practices

Documentation Requirements

  • Decommissioning report with timeline
  • Notification records to authorities
  • Internal audit results
  • Remediation action plan
Timeline

Already in effect since February 2, 2025

Penalty

Up to 7% of worldwide annual turnover or EUR 35 million

AI systems in critical areas like healthcare, finance, HR, education, and law enforcement must meet comprehensive compliance requirements before deployment.

Affected Systems

Credit scoring, medical diagnosis, biometric identification, HR/recruitment tools, employee monitoring, critical infrastructure, education/grading, fraud detection, autonomous vehicles

Obligations

  • Establish a risk management system covering the entire AI lifecycle
  • Implement data governance framework for training and validation data
  • Prepare comprehensive technical documentation
  • Ensure human oversight mechanisms are in place
  • Test for accuracy, robustness, and cybersecurity
  • Register the AI system in the EU database
  • Complete conformity assessment before market placement
  • Implement post-market monitoring system
  • Report serious incidents to authorities

Documentation Requirements

  • Risk management plan and assessment records
  • Data governance documentation (data sources, cleaning, bias testing)
  • Technical documentation (system architecture, algorithms, training process)
  • Conformity assessment report
  • EU database registration confirmation
  • Human oversight procedures and training records
  • Accuracy and robustness test results
  • Post-market monitoring plan
  • Incident response procedures
Timeline

Full compliance required by August 2, 2026

Penalty

Up to 3% of worldwide annual turnover or EUR 15 million

AI systems that interact with people or generate content must meet transparency requirements so users know they are dealing with AI.

Affected Systems

Chatbots, voice agents, content generation (text/image/video), LLM integrations, automated marketing, legal document analysis

Obligations

  • Clearly disclose that users are interacting with an AI system
  • Label all AI-generated content (text, images, audio, video)
  • Enable users to identify AI-generated decisions that affect them
  • Maintain records of AI system outputs for accountability
  • Provide accessible information about AI capabilities and limitations

Documentation Requirements

  • AI disclosure notices and their placement
  • Content labeling procedures and technical implementation
  • User notification templates and scripts
  • Output logging and retention policy
  • System capability and limitation descriptions
Timeline

Full compliance required by August 2, 2026

Penalty

Up to 1.5% of worldwide annual turnover or EUR 7.5 million

Most AI systems fall into this category and have no mandatory obligations under the AI Act. However, voluntary compliance demonstrates responsible AI use.

Affected Systems

Recommendation engines, document processing, predictive analytics, RPA, inventory management, code assistants, sentiment analysis, customer analytics

Obligations

  • Consider adopting a voluntary code of conduct
  • Monitor ongoing regulatory developments and updates
  • Document AI systems proactively for future-readiness
  • Implement basic AI governance practices
  • Stay informed about sector-specific guidelines

Documentation Requirements

  • AI system inventory and descriptions
  • Voluntary code of conduct (if adopted)
  • Internal AI governance policy
  • Regulatory monitoring log
Timeline

No mandatory deadline -- voluntary compliance recommended

Penalty

No penalties for minimal risk systems under the AI Act

Not Sure About Your Risk Level?

Run our free classifier to identify which risk categories your AI systems fall under.

Start Free Risk Classification