22 min read · Updated July 2026

The EU AI Act compliance guide

The AI Act (Regulation (EU) 2024/1689) is the world's first horizontal AI law. This guide walks through the risk tiers, the obligations that apply to your system today, and the exact evidence you'll need if a Notified Body — or your enterprise customer's procurement team — comes knocking.

1. Where the Act applies

The Act applies extraterritorially. If your AI system's output is used in the EU — even if your company sits in the US, UK, or Nigeria — you're in scope as a provider, deployer,importer, or distributor. Roles carry different duties; providers carry the heaviest.

2. The four risk tiers

Unacceptable risk

Social scoring, real-time biometric ID in public (with narrow exceptions), emotion recognition in workplaces, predictive policing based on profiling. Banned outright since Feb 2025.

High-risk risk

Systems listed in Annex III (biometrics, critical infrastructure, education, employment, essential private services, law enforcement, migration, justice) and safety components of regulated products. Full conformity assessment, technical documentation, post-market monitoring. Enforceable from Aug 2026.

Limited risk

Chatbots, deepfakes, emotion recognition outside high-risk contexts. Transparency obligations — users must be told they're interacting with AI or seeing synthetic content.

Minimal risk

Everything else. Voluntary codes of conduct encouraged.

3. Are you a GPAI provider?

General-Purpose AI (GPAI) models have their own regime (Articles 51-55). If you train a model that displays significant generality and is integrated into downstream systems — Llama-scale and above — you're a GPAI provider. Additional obligations apply above the 10^25 FLOPs systemic-risk threshold: model evals, adversarial testing, cybersecurity protections, and serious-incident reporting.

4. High-risk provider obligations (Articles 9–15)

  • Article 9 — Risk management system across the lifecycle.
  • Article 10 — Data governance: relevance, representativeness, bias examination, quality criteria.
  • Article 11 — Technical documentation (Annex IV template).
  • Article 12 — Automatic logging of events (traceability).
  • Article 13 — Transparency & instructions for use for deployers.
  • Article 14 — Human oversight measures.
  • Article 15 — Accuracy, robustness, and cybersecurity.

5. Evidence checklist

These are the artifacts we've seen Notified Bodies and enterprise procurement actually ask for:

  • Signed Risk Management Plan with quarterly review evidence.
  • Data Governance Statement covering source, lineage, bias examination.
  • Technical Documentation per Annex IV — model card, training regime, evaluation metrics.
  • Log retention policy and sample logs demonstrating traceability.
  • Human Oversight Design Document — who intervenes, when, with what authority.
  • Robustness & Security Test Reports — adversarial, prompt-injection, jailbreak.
  • Fundamental Rights Impact Assessment (FRIA) for high-risk public-sector deployment.
  • Post-market monitoring plan plus serious-incident reporting workflow.
  • Conformity Assessment outcome and EU Declaration of Conformity.
  • CE marking and Annex VIII registration for the EU AI database.

6. Timeline

  • Feb 2, 2025 — Prohibited practices in force. AI literacy obligation begins.
  • Aug 2, 2025 — GPAI rules apply. National competent authorities designated.
  • Aug 2, 2026 — Full application, including high-risk obligations for Annex III systems.
  • Aug 2, 2027 — High-risk obligations for AI as safety component of regulated products (Annex I).

7. How Lumiaxiom helps

Lumiaxiom ships an EU AI Act control set mapped to every applicable article, an AI-BOM for automatic Annex IV documentation, and evidence collectors for logging, bias-testing, and post-market monitoring. Every artifact lands in a hash-chained ledger auditors can independently verify.

Get EU AI Act–ready in weeks, not quarters

Load the framework, connect your model registry, and let Lumiaxiom build your evidence pack.