The EU AI Act is the world’s first comprehensive AI regulation. If your organization deploys AI in the EU, this is what you need to know.
Latest: Digital Omnibus adopted — high-risk moved to Dec 2027 →
The EU Artificial Intelligence Act (Regulation 2024/1689) is a risk-based regulatory framework that classifies AI systems into four categories: unacceptable risk (banned), high-risk (regulated), limited risk (transparency obligations), and minimal risk (no requirements).
If your organization develops, deploys, or imports AI systems used in the EU — regardless of where you are headquartered — you are in scope.
Real scenarios from companies like yours.
If you use AI assistants for internal productivity (emails, summaries, code suggestions) and they don’t make decisions that affect people’s rights, you are likely in the minimal risk category — no obligations beyond general transparency.
However, if AI assistants are used for HR decisions (screening CVs, evaluating employees), credit scoring, or customer-facing decisions, those specific use cases may be classified as high-risk and require a risk management system, documentation, and an inventory.
Credit scoring and fraud detection models used in financial services are explicitly listed as high-risk AI in Annex III of the EU AI Act. You need:
Step zero: you need an inventory of all these models. You can’t document, register, or manage what you haven’t catalogued.
It depends on what the agent does, not what it is. An AI agent that automates document processing is likely minimal risk. But an agent that makes or influences decisions about people — hiring, loan approvals, insurance claims, medical triage — falls under high-risk.
The key question: does the AI output affect someone’s rights, safety, or access to services? If yes, you need to treat it as high-risk regardless of whether it’s called an “agent”, “model”, or “automation”.
Yes. The EU AI Act has extraterritorial reach, similar to GDPR. If the output of your AI system is used in the EU — even if your company is headquartered in the US, UK, or elsewhere — you are in scope as a “deployer” or “provider”.
Start with an AI inventory — a single, structured register of every AI system in your organization. For each system, capture: what it does, who owns it, what data it uses, its risk classification, and its EU AI Act category.
If your team already uses Jira, Model Inventory for Jira gets you from zero to a working registry in an afternoon — including EU AI Act risk classification and compliance checklists.
You are a “deployer” under the EU AI Act. Deployers of high-risk AI systems have obligations too — you must ensure proper use, human oversight, and monitor the system in operation (Art. 26). You still need to know what AI you’re using and document it.
The provider (vendor) handles conformity assessment and technical documentation. But you can’t outsource accountability — if the AI makes a harmful decision in your context, you share responsibility.
Ban on social scoring, manipulative AI, real-time biometric identification (with exceptions).
General-Purpose AI model obligations. Transparency, documentation, copyright compliance.
Chatbot disclosure, deepfake labelling, marking of AI-generated content. Not moved by the Digital Omnibus — only the Art. 50(2) machine-readable marking gets a grace period to December 2, 2026.
Full compliance for Annex III high-risk AI: risk management, technical documentation, human oversight, accuracy, cybersecurity. AI embedded in Annex I regulated products: August 2, 2028.
Note: the Digital Omnibus on AI — adopted by the European Parliament on June 16, 2026 and by the Council on June 29, 2026, with Official Journal publication expected in July 2026 — moves the high-risk deadlines to fixed dates: December 2, 2027 (Annex III) and August 2, 2028 (Annex I). The bans, AI literacy duty, GPAI rules and Article 50 transparency stay on their original schedule. See what actually changed →
For high-risk AI systems the obligations split between the provider (who builds the system or places it on the market under their own name) and the deployer (who uses it). Most organizations are deployers — but knowing which AI systems you have is the prerequisite for either role:
| Article | Requirement | Falls on | Why inventory is prerequisite |
|---|---|---|---|
| Art. 9 | Risk management system | Provider | Can’t manage risk of systems you don’t know about |
| Art. 11 + Annex IV | Technical documentation | Provider | Must know what to document |
| Art. 17 | Quality management system | Provider | QMS must enumerate systems it covers |
| Art. 26 | Deployer obligations — human oversight, log-keeping, monitoring | Deployer | Each duty attaches to a specific system you must track |
| Art. 49 + Annex VIII | EU database registration | Provider (+ public-authority deployers) | Must know what to register |
| Art. 72 | Post-market monitoring | Provider | Need a bounded set of systems to monitor |
Using AI you didn’t build? You are usually a deployer — your core duties live in Article 26. Watch the line, though: under Article 25 a deployer can become a provider — inheriting the heavier provider duties — by substantially modifying a high-risk system or putting their own name on it.
The common denominator: none of these requirements can be met without knowing which AI systems you have. An AI inventory is step zero of EU AI Act compliance. Deloitte, PwC, KPMG, and Gartner all agree.
Practical, plain-language explanations of the articles that decide your obligations — what each one says, and what it means for your AI inventory. Verified against the official text of Regulation (EU) 2024/1689.
The duty that already applies — since February 2025 — to providers and deployers: sufficient AI literacy of the people using your AI.
Read → Article 5 · in force nowThe eight practices the Act bans outright — from social scoring to workplace emotion recognition — and the €35M fine tier behind them.
Read → Article 6 · Annex IIIThe two routes to high-risk classification, the eight Annex III areas, and the exceptions most summaries miss.
Read → Annex III · Point 4CV screening, candidate scoring, performance monitoring — the use-case verdicts for HR teams, and the workplace emotion-recognition ban.
Read → Annex III · Point 3Admissions, grading, exam proctoring — which education AI is high-risk, which is banned, and what schools and ed-tech must do.
Read → Article 9The continuous, lifecycle process at the core of high-risk compliance — the four required steps and how to document them.
Read → Article 13What providers of high-risk AI must tell the organisations that use it — effectively a procurement checklist.
Read → Article 14What meaningful human oversight actually requires — and the two-person rule for biometric identification.
Read → Article 26 · for deployersYour duties when you use high-risk AI you didn’t build — and the Article 25 line that turns a user into a provider.
Read → Article 50Disclosure duties for chatbots, generative AI and deepfakes — which apply whether or not the system is high-risk.
Read → GuideA step-by-step walk through all eight high-risk categories with real-world examples.
Read →Model Inventory for Jira gives you a compliance-ready AI registry in your existing Jira instance. Register every AI system, classify risk (EU AI Act Art. 6), track lifecycle, and build an immutable audit trail — all in 30 seconds.
If your team already uses Jira, there is no new vendor, no procurement, no training. Your AI registry is one install away.
A week-by-week action plan to get your AI inventory and governance in place before the deadline.
Six qualities that separate good inventories from great ones.
How AI helps organizations reduce human error across industries.
High-risk registration moved to December 2027 — but the AI bans and literacy duties already apply, and Article 50 transparency lands in August 2026. Start building your AI inventory today.
Get Started with Model Inventory for Jira