AI regulation
The EU AI Act: risk tiers, obligations and timeline
In short
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive, horizontal law governing artificial intelligence. It takes a risk-based approach: some AI practices are prohibited, high-risk AI systems carry strict obligations, and lighter transparency duties apply to limited-risk systems. It entered into force on 1 August 2024 and applies in phases through 2026 and beyond.
Last reviewed: August 2026
Who it applies to
The AI Act reaches providers, deployers, importers and distributors of AI systems placed on the EU market or whose output is used in the EU — regardless of where they are established. A US company whose AI system is used by EU customers is in scope. Obligations depend on your role and on the risk tier of the system.
The risk tiers
- Prohibited practices — e.g. social scoring and certain manipulative or biometric uses
- High-risk AI systems — e.g. AI in employment, credit, critical infrastructure, and certain products; strict obligations apply
- Limited-risk systems — transparency duties (e.g. telling people they are interacting with AI or seeing AI-generated content)
- Minimal-risk systems — no specific obligations
- General-purpose AI (GPAI) models — separate documentation and, for systemic-risk models, additional duties
Core obligations for high-risk systems
- A risk-management system across the AI lifecycle
- Data governance and quality for training, validation and testing
- Technical documentation and automatic record-keeping (logging)
- Transparency and instructions for use
- Human oversight designed into the system
- Accuracy, robustness and cybersecurity
- Conformity assessment, EU database registration and post-market monitoring
Application timeline
- 1Entered into force on 1 August 2024
- 2Prohibited practices apply from 2 February 2025
- 3GPAI model obligations apply from 2 August 2025
- 4Most high-risk and remaining obligations apply from 2 August 2026, with certain product-related rules from 2027
Typical compliance challenges
- Inventorying AI systems and classifying each by risk tier
- Producing and maintaining technical documentation as models evolve
- Designing meaningful human oversight and logging
- Coordinating with overlapping obligations under GDPR and NIS2
- Keeping evidence current as AI systems are retrained and redeployed
What can reasonably be automated
- An AI-system inventory with risk classification captured as structured records
- Documentation and evidence that travels with a model as it changes
- Continuous control monitoring and post-market monitoring signals
- Mapping AI Act controls onto ISO 27001 and (where used) ISO 42001
- A management-review pack for accountable oversight
Relationship to ISO 42001 and other frameworks
ISO/IEC 42001 is the international management-system standard for artificial intelligence and gives organizations a structured way to govern AI that supports AI Act readiness. GDPR still governs any personal data your AI processes, and NIS2 may apply to the security of the systems around it. Treating them as overlapping frameworks — one control mapped to several — avoids duplicating governance work.
How Isodora supports EU AI Act readiness
Isodora operationalizes AI governance on the same engine that runs your other frameworks — including ISO 42001, the AI management-system standard, as a built-in framework.
AI system inventory & classification
Capture each AI system and its risk tier as structured, maintainable records.
Documentation that stays current
Keep technical documentation and evidence attached to a model as it is retrained and redeployed.
ISO 42001, built in
Run ISO 42001, the AI management-system standard, alongside the AI Act — one control maps to both, so evidence is reused.
Shared controls
Reuse ISO 27001 and GDPR evidence for the security and data-governance parts of AI Act readiness.
Isodora helps you operationalize AI governance. Risk classification, conformity assessment and legal interpretation of the AI Act remain the responsibility of your organization and its advisers.
Frequently asked questions
- When does the EU AI Act apply?
- It entered into force on 1 August 2024 and applies in phases: prohibited practices from 2 February 2025, general-purpose AI model rules from 2 August 2025, and most high-risk obligations from 2 August 2026, with some product-related rules following in 2027.
- Who has to comply with the EU AI Act?
- Providers, deployers, importers and distributors of AI systems placed on the EU market or whose output is used in the EU, regardless of where they are based. The specific obligations depend on your role and the system’s risk tier.
- What is a high-risk AI system under the AI Act?
- High-risk systems include AI used in areas such as employment, credit scoring, critical infrastructure and certain regulated products. They must meet strict obligations covering risk management, data governance, documentation, human oversight, accuracy and cybersecurity, plus conformity assessment and registration.
- How does the EU AI Act relate to ISO 42001?
- ISO/IEC 42001 is the management-system standard for AI. It is voluntary, but implementing it gives you a structured governance system that supports AI Act readiness. ISO 42001 is a built-in framework in Isodora, so you can run it alongside the EU AI Act and reuse evidence across both.