EU AI ACT

EU AI Act Compliance

The EU AI Act is the world’s first comprehensive AI regulation. If your organization deploys AI in the EU, this is what you need to know.

Latest: Digital Omnibus adopted — high-risk moved to Dec 2027 →

Overview

What Is the EU AI Act?

The EU Artificial Intelligence Act (Regulation 2024/1689) is a risk-based regulatory framework that classifies AI systems into four categories: unacceptable risk (banned), high-risk (regulated), limited risk (transparency obligations), and minimal risk (no requirements).

If your organization develops, deploys, or imports AI systems used in the EU — regardless of where you are headquartered — you are in scope.

Who is affected?

Common Questions

Does the EU AI Act Apply to Me?

Real scenarios from companies like yours.

If you use AI assistants for internal productivity (emails, summaries, code suggestions) and they don’t make decisions that affect people’s rights, you are likely in the minimal risk category — no obligations beyond general transparency.

However, if AI assistants are used for HR decisions (screening CVs, evaluating employees), credit scoring, or customer-facing decisions, those specific use cases may be classified as high-risk and require a risk management system, documentation, and an inventory.

Credit scoring and fraud detection models used in financial services are explicitly listed as high-risk AI in Annex III of the EU AI Act. You need:

  • A risk management system (Art. 9)
  • Technical documentation for each model (Annex IV)
  • A quality management system (Art. 17)
  • Registration in the EU database (Art. 49)
  • Human oversight measures (Art. 14)

Step zero: you need an inventory of all these models. You can’t document, register, or manage what you haven’t catalogued.

It depends on what the agent does, not what it is. An AI agent that automates document processing is likely minimal risk. But an agent that makes or influences decisions about people — hiring, loan approvals, insurance claims, medical triage — falls under high-risk.

The key question: does the AI output affect someone’s rights, safety, or access to services? If yes, you need to treat it as high-risk regardless of whether it’s called an “agent”, “model”, or “automation”.

Yes. The EU AI Act has extraterritorial reach, similar to GDPR. If the output of your AI system is used in the EU — even if your company is headquartered in the US, UK, or elsewhere — you are in scope as a “deployer” or “provider”.

Start with an AI inventory — a single, structured register of every AI system in your organization. For each system, capture: what it does, who owns it, what data it uses, its risk classification, and its EU AI Act category.

If your team already uses Jira, Model Inventory for Jira gets you from zero to a working registry in an afternoon — including EU AI Act risk classification and compliance checklists.

You are a “deployer” under the EU AI Act. Deployers of high-risk AI systems have obligations too — you must ensure proper use, human oversight, and monitor the system in operation (Art. 26). You still need to know what AI you’re using and document it.

The provider (vendor) handles conformity assessment and technical documentation. But you can’t outsource accountability — if the AI makes a harmful decision in your context, you share responsibility.

Timeline

Key Deadlines

February 2, 2025

Prohibited AI Practices

Ban on social scoring, manipulative AI, real-time biometric identification (with exceptions).

August 2, 2025

GPAI Rules

General-Purpose AI model obligations. Transparency, documentation, copyright compliance.

August 2, 2026 — upcoming

Transparency Obligations (Art. 50)

Chatbot disclosure, deepfake labelling, marking of AI-generated content. Not moved by the Digital Omnibus — only the Art. 50(2) machine-readable marking gets a grace period to December 2, 2026.

December 2, 2027

High-Risk AI Systems

Full compliance for Annex III high-risk AI: risk management, technical documentation, human oversight, accuracy, cybersecurity. AI embedded in Annex I regulated products: August 2, 2028.

Note: the Digital Omnibus on AI — adopted by the European Parliament on June 16, 2026 and by the Council on June 29, 2026, with Official Journal publication expected in July 2026 — moves the high-risk deadlines to fixed dates: December 2, 2027 (Annex III) and August 2, 2028 (Annex I). The bans, AI literacy duty, GPAI rules and Article 50 transparency stay on their original schedule. See what actually changed →

Requirements

What the Regulation Requires

For high-risk AI systems the obligations split between the provider (who builds the system or places it on the market under their own name) and the deployer (who uses it). Most organizations are deployers — but knowing which AI systems you have is the prerequisite for either role:

Article Requirement Falls on Why inventory is prerequisite
Art. 9 Risk management system Provider Can’t manage risk of systems you don’t know about
Art. 11 + Annex IV Technical documentation Provider Must know what to document
Art. 17 Quality management system Provider QMS must enumerate systems it covers
Art. 26 Deployer obligations — human oversight, log-keeping, monitoring Deployer Each duty attaches to a specific system you must track
Art. 49 + Annex VIII EU database registration Provider (+ public-authority deployers) Must know what to register
Art. 72 Post-market monitoring Provider Need a bounded set of systems to monitor

Using AI you didn’t build? You are usually a deployer — your core duties live in Article 26. Watch the line, though: under Article 25 a deployer can become a provider — inheriting the heavier provider duties — by substantially modifying a high-risk system or putting their own name on it.

The common denominator: none of these requirements can be met without knowing which AI systems you have. An AI inventory is step zero of EU AI Act compliance. Deloitte, PwC, KPMG, and Gartner all agree.

The Decoder

The EU AI Act, decoded article by article

Practical, plain-language explanations of the articles that decide your obligations — what each one says, and what it means for your AI inventory. Verified against the official text of Regulation (EU) 2024/1689.

Article 4 · in force now

AI literacy

The duty that already applies — since February 2025 — to providers and deployers: sufficient AI literacy of the people using your AI.

Read →
Article 5 · in force now

Prohibited AI practices

The eight practices the Act bans outright — from social scoring to workplace emotion recognition — and the €35M fine tier behind them.

Read →
Article 6 · Annex III

Is your AI system high-risk?

The two routes to high-risk classification, the eight Annex III areas, and the exceptions most summaries miss.

Read →
Annex III · Point 4

Employment & HR AI

CV screening, candidate scoring, performance monitoring — the use-case verdicts for HR teams, and the workplace emotion-recognition ban.

Read →
Annex III · Point 3

AI in education

Admissions, grading, exam proctoring — which education AI is high-risk, which is banned, and what schools and ed-tech must do.

Read →
Article 9

Risk management system

The continuous, lifecycle process at the core of high-risk compliance — the four required steps and how to document them.

Read →
Article 13

Transparency to deployers

What providers of high-risk AI must tell the organisations that use it — effectively a procurement checklist.

Read →
Article 14

Human oversight

What meaningful human oversight actually requires — and the two-person rule for biometric identification.

Read →
Article 26 · for deployers

Deployer obligations

Your duties when you use high-risk AI you didn’t build — and the Article 25 line that turns a user into a provider.

Read →
Article 50

Transparency obligations

Disclosure duties for chatbots, generative AI and deepfakes — which apply whether or not the system is high-risk.

Read →
Guide

Risk classification decision tree

A step-by-step walk through all eight high-risk categories with real-world examples.

Read →
Penalties

Non-Compliance Is Not a Technicality

€35M
or 7% of global turnover
€15M
or 3% of global turnover
High-risk AI obligations, GPAI
€7.5M
or 1% of global turnover
False information to authorities
Our Solution

Start with an AI Inventory

Model Inventory for Jira gives you a compliance-ready AI registry in your existing Jira instance. Register every AI system, classify risk (EU AI Act Art. 6), track lifecycle, and build an immutable audit trail — all in 30 seconds.

If your team already uses Jira, there is no new vendor, no procurement, no training. Your AI registry is one install away.

Learn More

Related Articles

Resources

Official Sources

Don’t Wait for the Deadline

High-risk registration moved to December 2027 — but the AI bans and literacy duties already apply, and Article 50 transparency lands in August 2026. Start building your AI inventory today.

Get Started with Model Inventory for Jira