22 min read · Updated July 2026
The EU AI Act compliance guide
The AI Act (Regulation (EU) 2024/1689) is the world's first horizontal AI law. This guide walks through the risk tiers, the obligations that apply to your system today, and the exact evidence you'll need if a Notified Body — or your enterprise customer's procurement team — comes knocking.
1. Where the Act applies
The Act applies extraterritorially. If your AI system's output is used in the EU — even if your company sits in the US, UK, or Nigeria — you're in scope as a provider, deployer,importer, or distributor. Roles carry different duties; providers carry the heaviest.
2. The four risk tiers
Social scoring, real-time biometric ID in public (with narrow exceptions), emotion recognition in workplaces, predictive policing based on profiling. Banned outright since Feb 2025.
Systems listed in Annex III (biometrics, critical infrastructure, education, employment, essential private services, law enforcement, migration, justice) and safety components of regulated products. Full conformity assessment, technical documentation, post-market monitoring. Enforceable from Aug 2026.
Chatbots, deepfakes, emotion recognition outside high-risk contexts. Transparency obligations — users must be told they're interacting with AI or seeing synthetic content.
Everything else. Voluntary codes of conduct encouraged.
3. Are you a GPAI provider?
General-Purpose AI (GPAI) models have their own regime (Articles 51-55). If you train a model that displays significant generality and is integrated into downstream systems — Llama-scale and above — you're a GPAI provider. Additional obligations apply above the 10^25 FLOPs systemic-risk threshold: model evals, adversarial testing, cybersecurity protections, and serious-incident reporting.
4. High-risk provider obligations (Articles 9–15)
- Article 9 — Risk management system across the lifecycle.
- Article 10 — Data governance: relevance, representativeness, bias examination, quality criteria.
- Article 11 — Technical documentation (Annex IV template).
- Article 12 — Automatic logging of events (traceability).
- Article 13 — Transparency & instructions for use for deployers.
- Article 14 — Human oversight measures.
- Article 15 — Accuracy, robustness, and cybersecurity.
5. Evidence checklist
These are the artifacts we've seen Notified Bodies and enterprise procurement actually ask for:
- Signed Risk Management Plan with quarterly review evidence.
- Data Governance Statement covering source, lineage, bias examination.
- Technical Documentation per Annex IV — model card, training regime, evaluation metrics.
- Log retention policy and sample logs demonstrating traceability.
- Human Oversight Design Document — who intervenes, when, with what authority.
- Robustness & Security Test Reports — adversarial, prompt-injection, jailbreak.
- Fundamental Rights Impact Assessment (FRIA) for high-risk public-sector deployment.
- Post-market monitoring plan plus serious-incident reporting workflow.
- Conformity Assessment outcome and EU Declaration of Conformity.
- CE marking and Annex VIII registration for the EU AI database.
6. Timeline
- Feb 2, 2025 — Prohibited practices in force. AI literacy obligation begins.
- Aug 2, 2025 — GPAI rules apply. National competent authorities designated.
- Aug 2, 2026 — Full application, including high-risk obligations for Annex III systems.
- Aug 2, 2027 — High-risk obligations for AI as safety component of regulated products (Annex I).
7. How Lumiaxiom helps
Lumiaxiom ships an EU AI Act control set mapped to every applicable article, an AI-BOM for automatic Annex IV documentation, and evidence collectors for logging, bias-testing, and post-market monitoring. Every artifact lands in a hash-chained ledger auditors can independently verify.
Get EU AI Act–ready in weeks, not quarters
Load the framework, connect your model registry, and let Lumiaxiom build your evidence pack.